Last updated: 13 September 2026
1. Scope
This DPA forms part of the ZenitERP agreement between Customer (“Controller”) and Ferhat Canberk Döğer (sole proprietorship, trading as ZenitERP) (“Processor”). Customer Data means personal data entered in ZenitERP by Customer or generated on its behalf through use of the service.
2. Instructions and duties
Zenit processes Customer Data only on documented instructions to provide, secure, back up, support, export and delete the service data. Zenit informs Customer of an apparently unlawful instruction and may suspend it pending clarification. Customer determines purposes, legal bases and retention; provides notices; manages access; and establishes an appropriate condition for special-category data.
3. Confidentiality, security and subprocessors
Only authorised persons bound by confidentiality may access the data. Zenit uses role-based access, HTTPS, multi-factor authentication for administrator services, logging, backups, patch management and separation of test and production. Subprocessors are bound to equivalent data-protection duties. Current subprocessors are listed in the Privacy Policy; material changes are notified to the administrator e-mail 30 days in advance. Customer may submit a reasoned objection within 15 days. If it cannot be resolved, the affected function or agreement ends and prepaid fees for the unused term are refunded.
4. Transfers, incidents and assistance
Before an international transfer begins, the parties establish an appropriate KVKK Article 9 safeguard and, for EEA data where required, a GDPR Chapter V mechanism and transfer assessment. Zenit notifies Customer of a confirmed personal-data breach affecting Customer Data without undue delay, with a target of 24 hours after becoming aware. The incident contact is [email protected].
Zenit provides reasonable assistance with data-subject requests, impact assessments, incident investigation and regulatory duties. Ordinary assistance is included in support; extraordinary work may be charged at a rate disclosed in advance.
5. Audit, return and deletion
Zenit permits one reasonable documentary audit per year on at least 15 days' notice and subject to confidentiality and security. The limit does not apply to a competent authority's request or a confirmed incident.
Customer Data remains exportable for 30 days after termination. Production data is then deleted unless law requires retention; backup copies expire through the ordinary cycle. Statutory accounting and contract records are separated from service data and retained only for the required period.