Data Processing Agreement (DPA)

Last updated: 20.07.2026

This Data Processing Agreement ("DPA"), when you use the rankzupAI service operated by rankzupAI as a corporate customer, agency or reseller ("Customer"), governs the roles and obligations of the parties within the scope of Law No. 6698 on the Protection of Personal Data ("KVKK") and the relevant secondary legislation. This document must be read together with the KVKK Disclosure Notice and the Privacy Policy, and is consistent with them.

1. Definitions and Parties

2. Determination of Roles

rankzupAI has a dual role with respect to the personal data within the scope of the service:

3. Subject, Duration and Purpose of Processing

4. Categories of Data Processed

The following categories of data are processed within the scope of the service (consistent with the KVKK Disclosure Notice):

5. Sub-processors

rankzupAI relies on the following sub-processors to provide the service. The Customer is deemed to have approved this list; in the event of a material change to the list, the Customer is informed a reasonable time in advance.

6. Principle of No Personal Data Transfer to LLM APIs (KVKK Art. 9)

The core architectural principle of rankzupAI is that no personal data (full name, email, IP, Turkish ID number, etc.) is sent to the APIs of the artificial intelligence providers listed in Article 5 above (OpenAI, Google, Anthropic, xAI, DataForSEO). Only the brand name, product/service information, industry and monitoring query text required for the measurement are transmitted to these APIs.

Thanks to this principle, the fact that the infrastructures of those providers are located abroad (e.g. the USA) does not trigger a regime of transferring personal data abroad within the meaning of KVKK Article 9; because the transmitted information is not of the nature of personal data. rankzupAI designs and operates the system so as to preserve this principle.

Customer obligation: The Customer (and the users accessing the panel) undertake not to enter personal data belonging to natural persons (e.g. "is Dr. Ahmet Yılmaz's clinic good") into monitoring queries and project fields. Queries must be brand-, product- and industry-focused. If the Customer enters personal data contrary to this rule, the resulting KVKK liability belongs to the Customer; rankzupAI is not obliged to inspect the nature of this content.

7. Data Security Measures

8. Data Retention, Return and Deletion

Upon termination of the agreement, at the Customer's request the Customer content is deleted, destroyed or (if requested) returned within a reasonable period. Without prejudice to statutory retention obligations (e.g. tax/invoice records), any remaining personal data is deleted, destroyed or anonymized at the end of this period. For details, see KVKK Disclosure Notice, Article 6.

9. Data Breach Notification (72-Hour Commitment)

When rankzupAI detects a breach affecting personal data security, it informs the relevant data controller/Customer without delay and within at most 72 hours; it shares reasonable information about the nature of the breach, the affected data categories, its likely consequences and the measures taken/recommended. rankzupAI provides reasonable support to the Customer in notifications to be made to the Personal Data Protection Authority and to the data subjects. The breach response procedure is documented in the operational handbook (RUNBOOK).

10. Support for Data Subject Rights

rankzupAI provides reasonable technical and administrative support to the Customer so that data subjects can exercise their rights under KVKK Article 11 (access, correction, deletion, objection, etc.). Requests that reach rankzupAI directly and relate to data under the Customer's responsibility are forwarded to the relevant Customer without delay.

11. Contact

For questions regarding this DPA and corporate procurement processes, you can reach us at kvkk@rankzup.ai. A wet-ink/electronically signed version can be provided for corporate customers requesting a signed copy.

For your questions: info@rankzup.ai