ENTWURF – nicht freigegeben, rechtlich prüfen lassenDRAFT – not yet approved, must be reviewed by a lawyer.
Data processing agreement (Art. 28 GDPR)
This agreement governs, under Art. 28 GDPR and KVKK m. 12, how the operator processes personal data on the HicretYolu.app platform on behalf of the agency.
Draft date: Oct 7, 2026
Parties and scope
This agreement is concluded between the agency using HicretYolu.app (controller under the GDPR, veri sorumlusu under the KVKK) and [[Firmenname]], [[Rechtsform]], [[Anschrift (Straße, PLZ, Ort, Land)]] (processor under the GDPR, veri işleyen under the KVKK, the “operator”). It becomes part of the terms of use for agencies when the agency account is approved.
Data the operator processes for its own purposes (agency accounts and applications, visitors of public pages, Kaswa on the platform homepage, beta feedback, invitations, platform invoices, logs, security) is covered by the privacy policy, not by this agreement.
Subject matter, nature and purpose
The operator processes personal data only to provide the platform functions to the agency: packages and bookings with payment plans and manually recorded payments, the pilgrim area (email link login, passport and visa upload, reviews, web push), tour guide tools, offer PDFs, the AI assistant Kaswa including voluntary contact requests, emails, anonymous surveys, and access and erasure in the console. The duration equals the term of the usage contract.
Types of data and data subjects
Data types: contact data, traveller data (date of birth, passport or ID number, T.C. Kimlik No where applicable), passport and visa scans (up to 5 MB), payment data without card data, Kafile messages, Kaswa conversations and contact requests, reviews, web push endpoints, data of staff and tour guides.
Data subjects: customers and pilgrims, fellow travellers, agency staff, tour guides and prospects using Kaswa. Religious affiliation may be inferable from an Umrah or Hajj booking: [[Bewertung Art. 9 DSGVO / KVKK m. 6 durch Rechtsberatung]].
Instructions and confidentiality
The operator processes data only on documented instructions of the agency and informs it if an instruction appears unlawful. Only persons bound to confidentiality have access, and only as far as necessary.
Technical and organisational measures
The operator implements in particular:
- TLS/HTTPS with HSTS
- AES-256-GCM encryption of personal fields (travellers, documents, offers, contact requests, push endpoints)
- tenant separation and role-based access
- audit log of all write actions without content; retention [[Aufbewahrungsdauer Audit-Protokoll]]
- rate limits, account lockout, internal API key, security headers and CSP
- encrypted backups (GPG AES256) with restore test; encrypted dumps deleted after 90 days
- deletion of Kaswa conversations after 90 days, contact requests and beta feedback after 365 days, email queue contents after at most 24 hours
Sub-processors
The agency approves the following sub-processors. Changes are announced [[Frist Vorankündigung Unterauftragsverarbeiter]] in advance; the agency may object. Transfers outside the EU/EEA follow Art. 44 et seq. GDPR; transfers abroad under KVKK m. 9: [[Übermittlungsmechanismus nach KVKK m. 9]].
- Vercel: frontend hosting, Frankfurt (fra1); [[Rechtsgrundlage Drittlandübermittlung Vercel]]
- Railway: API, PostgreSQL, Redis; [[Region Railway]]; [[Rechtsgrundlage Drittlandübermittlung Railway]]
- Cloudflare R2: object storage; [[Standort/Jurisdiktion R2]]
- Resend: email delivery from mail.hicretyolu.app; [[Region Resend]]
- Sentry: error reports, EU data region
- Langfuse (Langfuse Cloud EU): Kaswa traces, masked
- Anthropic: language model for Kaswa; [[Rechtsgrundlage Drittlandübermittlung Anthropic]]
- OpenAI: embeddings for the Kaswa knowledge base, only if configured; [[Rechtsgrundlage Drittlandübermittlung OpenAI]]
- GitHub Actions: backup jobs; [[Rechtsgrundlage Drittlandübermittlung GitHub]]
- Browser web push services: only after the pilgrim allows push notifications
Assistance and data subject requests
The agency handles access (export) and erasure requests itself in the console. The operator forwards requests it receives and assists with Art. 32 to 36 GDPR and KVKK m. 11 and m. 13 (reply within 30 days).
Personal data breaches
The operator notifies the agency without undue delay, at the latest within [[Meldefrist an die Agentur]]. Notification of the supervisory authority (Art. 33 GDPR, 72 hours) and of the Kişisel Verileri Koruma Kurulu (KVKK m. 12/5, 72 hours) is the agency’s responsibility.
Deletion, audits, liability and final provisions
After termination, the operator deletes the agency’s data within [[Frist Datenlöschung nach Vertragsende]]; backups expire on their own schedule. The operator provides information needed to demonstrate compliance and allows audits with reasonable notice.
Liability towards data subjects follows Art. 82 GDPR. Governing law: [[Anwendbares Recht]]; place of jurisdiction: [[Gerichtsstand]]. In data protection matters, this agreement prevails over the terms of use.