This summary describes how our group companies process personal data on behalf of clients. For contracted engagements, a full Data Processing Agreement (“DPA”) is executed as part of the client contract and prevails over this summary.

1. Roles

When we provide services, the client is the controller and the relevant group company is the processor. We process personal data only on the client’s documented instructions.

2. Scope and purpose

Processing is limited to what is necessary to deliver the agreed service. We do not use client personal data for our own purposes or to train shared models without explicit authorization.

3. Security measures

  • Encryption in transit and at rest.
  • Role-based access control and least-privilege access.
  • Immutable audit logging of material actions.
  • Support for sovereign, isolated and air-gapped deployment.

4. Subprocessors

We engage subprocessors only under written contracts imposing protections equivalent to ours, and we remain responsible for their performance. A current list of subprocessors is made available to clients on request, with reasonable notice of changes.

5. International transfers

Any transfer is made under the safeguards required by the KVKK and GDPR, or avoided entirely where the deployment keeps data within the client’s jurisdiction.

6. Assistance and audits

We assist clients with data-subject requests, security, breach notification and impact assessments, and make available the information reasonably needed to demonstrate compliance.

7. Return and deletion

On termination, we return or delete client personal data in line with the DPA, except where retention is required by law.

Data processing enquiries: privacy@ulutengroup.com