# [](#data-processing-agreement--overview)Data Processing Agreement — Overview

This page summarizes the structure of the Data Processing Agreement (DPA) Maya signs with enterprise customers. The full template is shareable under NDA prior to engagement.

## [](#data-residency--türkiye)Data residency — Türkiye

Maya is a Turkish company. **All data processed under this DPA is hosted and processed on servers located in Türkiye.** No tenant data is transferred outside Türkiye for processing or storage.

*   Data residency: **Türkiye only**
*   Cross-border data transfer: **none** (no EU, US, or other jurisdictions for tenant data)
*   KVKK alignment: data stays inside Turkish borders, no Article 9 cross-border transfer concerns
*   Backups, replicas, and disaster-recovery copies: all retained within Türkiye
*   Sub-processors used for tenant data: all operate within Türkiye, listed in Annex B

If your compliance program requires a written attestation of data residency, we provide one as part of the engagement.

## [](#roles)Roles

*   **Data Controller:** the customer (the brand deploying Maya).
*   **Data Processor:** Maya.
*   **Sub-processors:** named explicitly in Annex B of the DPA.

For most Maya deployments, the data processed under the DPA does not include personal data as defined under KVKK / GDPR (see [PII Handling](./pii-handling.md)). The DPA is signed regardless, because:

*   It establishes contractual obligations even if the personal-data threshold is not met.
*   It survives any future expansion of scope.
*   Enterprise compliance teams consistently expect a DPA on file regardless.

## [](#structure)Structure

The DPA is structured in the following sections:

1.  **Parties and definitions**
2.  **Scope of processing** — purpose, duration, categories of data, categories of data subjects
3.  **Processor obligations** — confidentiality, security, sub-processors, assistance with rights requests
4.  **Security measures** — Annex A
5.  **Sub-processors** — Annex B
6.  **Data transfers** — including any cross-border arrangements
7.  **Audit rights** — frequency, scope, cost allocation
8.  **Incident response and breach notification** — SLA defined here
9.  **Return and deletion of data** — timelines and procedures
10.  **Liability and indemnity**
11.  **Term and termination**
12.  **Governing law and jurisdiction**

## [](#annex-a--technical-and-organizational-measures)Annex A — Technical and Organizational Measures

Annex A is a long-form description of Maya's security controls. It mirrors what is summarized in this documentation site:

*   Encryption (in transit / at rest)
*   Access control (RBAC, SSO, audit logging)
*   Network controls
*   Vulnerability management
*   Penetration testing cadence
*   Backup and disaster recovery
*   Personnel screening and training
*   Physical security (cloud-provider attestations)
*   Secure development lifecycle

## [](#annex-b--sub-processors)Annex B — Sub-processors

The current list of Maya sub-processors:

Provider

Function

Region

Cloud infrastructure provider

Hosting and storage of tenant data

Türkiye

Observability provider

Application monitoring (no tenant data)

Türkiye

Email provider

Transactional email to brand admins

Türkiye

Model providers (zero-retention enterprise endpoints)

Prompt simulation only; no tenant log data — bot UA + page URL only

Outside Türkiye (no tenant PII or log content transmitted)

Maya provides advance written notice of any sub-processor change, with the brand's right to object as defined in the DPA.

## [](#annex-c--data-categories)Annex C — Data Categories

Maya processes:

*   **Bot traffic metadata** — as defined in [Data Minimization](./data-minimization.md).
*   **Brand-supplied prompt sets** — provided by the brand for prompt simulation.
*   **Brand admin contact data** — necessary for account administration (name, business email).

Maya does NOT process:

*   End-user personal data of any kind.
*   Banking customer records, account data, or payment instruments.
*   Authenticated session data.
*   Content of any internal banking systems.

## [](#customizations-available)Customizations available

Brands frequently request the following addenda:

*   **KVKK Aydınlatma Metni** — published by the brand to its end users where applicable.
*   **DPIA addendum** — Data Protection Impact Assessment, prepared jointly.
*   **Cross-border transfer addendum** — typically not required for Maya, since all tenant data stays in Türkiye.
*   **Banking-specific compliance addendum** — referencing BDDK requirements where applicable.
*   **Audit cadence addendum** — for brands with strict third-party audit programs.

## [](#process)Process

1.  Brand legal/compliance receives the standard DPA under NDA.
2.  Brand redlines or proposes addenda.
3.  Maya legal reviews; usually 5–10 business days for first round.
4.  Signature.
5.  DPA becomes effective concurrent with the Master Services Agreement.

## [](#single-point-of-contact)Single point of contact

For DPA matters: [\[email protected\]](/cdn-cgi/l/email-protection#026e6765636e42756b766a6f637b632c636b).

[PreviousWhat Maya Does Not Collect](/docs/security/what-maya-does-not-collect)[Next Looker Studio Connector](/docs/integrations/looker-studio)