pursuant to Art. 28 GDPR including the EU Standard Contractual Clauses
Version 2026-09 · Last updated: September 2026
This translation is provided for information only. Only the German version is legally binding. German version
This agreement is concluded between the customer of the FibreAct platform as controller ("Client") and PARPALİ YAZILIM VE BİLİŞİM HİZMETLERİ TİCARET LİMİTED ŞİRKETİ, Beştepe Mah., Yenimahalle / Ankara, Türkiye, as processor ("Contractor"). It is agreed electronically upon conclusion of the usage contract for the platform on the basis of the General Terms and Conditions; the express confirmation in the customer account, for example before publishing a company website, reaffirms it. It applies to all processing of personal data that the Contractor carries out on behalf of the Client.
(1) The subject matter of the assignment is the provision of the FibreAct platform as software-as-a-service under the usage contract, in particular storage, provision and transmission of the data entered by the Client and its users, operation of the mobile apps and the company website with contact form, and technical support and maintenance.
(2) The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
(3) The term of this agreement follows the term of the usage contract. The obligations under this agreement continue as long as the Contractor processes personal data of the Client.
(1) The Contractor processes personal data only on documented instructions from the Client – including with regard to transfers of personal data to a third country or an international organisation –, unless it is required to carry out other processing by Union or Member State law to which it is subject; in such a case, it informs the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
(2) The Client’s instructions result from the usage contract, this agreement and the settings that the Client makes in the platform. The Client issues further instructions in text form to datenschutz@fibreact.com. The Contractor may make instructions that go beyond the agreed scope of services subject to a remuneration agreement or reject them; in the event of rejection, the Client may terminate the usage contract for cause.
(3) The Contractor informs the Client without undue delay if, in its opinion, an instruction infringes data protection provisions. It may suspend the execution of the instruction until it is confirmed or changed by the Client.
(1) The Contractor ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(2) The Contractor takes the technical and organisational measures under Art. 32 GDPR described in Annex 2. It may adapt them to technical progress, provided that the level of protection is not reduced.
(3) Taking into account the nature of the processing, the Contractor assists the Client by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects exercising their rights under Chapter III GDPR.
(4) Taking into account the nature of processing and the information available to it, the Contractor assists the Client in ensuring compliance with the obligations under Art. 32 to 36 GDPR.
(5) The Contractor notifies the Client of a personal data breach without undue delay, at the latest within 48 hours after becoming aware of it. The notification contains, where available, the information under Art. 33 (3) GDPR; information not yet available is provided without undue delay.
(6) The Contractor maintains a record of all categories of processing activities carried out on behalf of the Client under Art. 30 (2) GDPR.
(7) The Contractor’s data protection contact can be reached at datenschutz@fibreact.com.
(1) Subject to the sub-processors listed in Annex 3, the data are stored on servers in the Federal Republic of Germany.
(2) The Contractor has its registered office in Türkiye. There is no adequacy decision of the European Commission for Türkiye. Insofar as employees of the Contractor access the data from Türkiye for administration, maintenance and support, this constitutes a transfer to a third country.
(3) For these transfers, the parties hereby agree on the standard contractual clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module 2 (transfer controller to processor), available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj ("Standard Contractual Clauses"). They become part of this agreement unchanged by reference. The following applies:
(4) In the event of a conflict between this agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
(5) In accordance with Clause 14, the parties warrant that they have no reason to believe that the laws and practices in the third country prevent the data importer from fulfilling its obligations under the Standard Contractual Clauses. The Contractor has documented its assessment and makes this documentation and all information required for the Client’s own assessment available on request. In addition: subject to Annex 3, the data are stored exclusively in Germany and are not permanently copied to Türkiye; access from Türkiye only takes place as required for operation, maintenance or support, via encrypted connections and by authorised employees, and logins to the servers are logged. The Contractor examines disclosure requests from public authorities for their lawfulness, challenges them in accordance with Clause 15.2 where, after careful assessment, there are sufficient grounds to do so, discloses only the minimum data required and informs the Client in accordance with Clause 15.1 where permitted.
(1) The Client grants general authorisation to engage further processors ("Sub-processors"). The Sub-processors engaged at the time of conclusion of the contract are listed in Annex 3 and are deemed approved.
(2) The Contractor informs the Client in text form, for example by e-mail or by a notice in the customer account, at least four weeks before engaging or replacing a Sub-processor. The Client may object to the change for an objective data protection reason in text form within this period. If the parties cannot agree, either party may terminate the affected service or, if it cannot be separated, the usage contract as of the date the change takes effect.
(3) The Contractor imposes on each Sub-processor by way of a contract the same data protection obligations as set out in this agreement and in the Standard Contractual Clauses, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, the Contractor remains liable to the Client for their performance (Art. 28 (4) sentence 2 GDPR, Clause 9 (d) of the Standard Contractual Clauses). An onward transfer to a third country only takes place under the conditions of Clause 8.7 of the Standard Contractual Clauses.
(4) Services that the Contractor uses as ancillary services, such as telecommunications and transport services, and services that the Client itself agrees with third parties do not constitute sub-processing. Paddle.com Market Limited acts as an independent controller for payment processing.
(1) The Contractor makes available to the Client all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this agreement.
(2) The Client may carry out audits, including inspections, itself or through an auditor mandated by it who is bound to confidentiality and is not a competitor of the Contractor. When deciding on an audit, the Client may take into account suitable evidence provided by the Contractor, such as audit reports of independent bodies. Audits must be announced with reasonable notice, generally 30 days; where there are specific indications of a violation, the notice period may be reasonably shortened. Audits take place during normal business hours and must not impair the protection of other customers’ data.
(3) Each party bears its own costs arising from audits.
If a data subject contacts the Contractor directly, the Contractor refers them to the Client, where the request can be attributed to the Client, and forwards the request to the Client without undue delay. The Contractor does not respond to the request itself unless instructed to do so by the Client. The platform provides functions for access to, rectification and erasure of data.
(1) During the term of the contract, the Client can retrieve and delete its data via the platform’s export functions.
(2) After termination of the usage contract, the Contractor deletes the Client’s personal data within 90 days unless Union or Member State law requires storage. If the Client requests the return of data that cannot be retrieved via the export functions before the end of the contract, the Contractor provides them in a common machine-readable format. Until deletion, access to the data is limited to the purpose of return. Backups are overwritten no later than 14 days after deletion in the production system.
(3) The Contractor confirms deletion in text form.
(1) Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the usage contract apply; they do not apply to liability under Clause 12 of the Standard Contractual Clauses or towards data subjects.
(2) Changes to this agreement are governed by the provisions of the General Terms and Conditions on changes; Annex 3 is changed in accordance with § 5. The Standard Contractual Clauses cannot be changed in this way; changes must not contradict them.
(3) The law of the Federal Republic of Germany applies. If individual provisions are invalid, the validity of the remaining provisions remains unaffected.
Categories of data subjects:
Types of personal data:
Special categories of personal data (Art. 9 GDPR) are not subject of the processing. The Client ensures that such data are not entered.
Nature and purpose of the processing: storage, organisation, evaluation, provision and transmission within the functions of the platform, in particular job management, mobile documentation, reporting, geocoding of work site addresses, sending notifications, translation of website content, delivery of the company website and forwarding of contact enquiries, as well as support, maintenance and security.
Purpose of the transfer to Türkiye: remote access as required for administration, maintenance and support.
Frequency of the transfer: as required during the term of the contract; processing on the servers is continuous.
Retention: term of the contract and thereafter in accordance with § 8; contact form enquiries are deleted automatically after the period set by the Client (30 to 730 days, default 180 days).
Transfers to Sub-processors: see Annex 3 (subject matter, nature and duration correspond to the services listed there and the term of the contract).
Confidentiality (physical access, system access, data access and separation control):
Pseudonymisation and data minimisation:
Integrity (transmission and input control):
Availability and resilience:
Procedures for regular review: