Legal

Data Processing Agreement

Version 1

Draft under legal review. The approved text will replace this page, and the date above will change with it.

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between the store owner who accepts it ("Customer" or "Controller") and Partnerfy.co ("Partnerfy" or "Processor"), registered at Partnerfy Bilgi Teknolojileri ve Pazarlama Sanayi Ticaret Ltd. Şti., Orta Mah. Kavaklar Cad. No:15 Ofisada Plaza D:104, Adapazarı, Sakarya, Türkiye under registration number MERSIS 0722116506400001, trade registry no. 43130 (Adapazarı), tax no. 7221165064, the operator of the Kambloo platform.

The DPA forms part of the Terms of Service. It applies to all personal data of the Customer's store customers, staff, and other data subjects that Partnerfy processes on the Customer's behalf in providing the Kambloo service ("Customer Data"). Acceptance of this DPA is a required step of the go-live wizard; the accepted version, date, and IP address are recorded.

This DPA is written to meet the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK") together with the decisions of the Personal Data Protection Board.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in GDPR and KVKK. "Sub-processor" means a third party engaged by Partnerfy to process Customer Data. "Instructions" means the Customer's documented instructions, which consist of the Terms of Service, this DPA, and the configuration choices the Customer makes in the admin panel.

3. Roles

The Customer is the controller of Customer Data and determines the purposes and means of its processing. Partnerfy is the processor and processes Customer Data only on the Customer's Instructions, except where required by law.

For personal data relating to the Customer's own Kambloo account, Partnerfy is an independent controller, and the Privacy Policy applies.

4. Details of processing

The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are set out in Annex 1.

5. Obligations of the Processor

Partnerfy shall:

  1. process Customer Data only on the Customer's Instructions, and inform the Customer if it believes an Instruction infringes data protection law;
  2. ensure that persons authorized to process Customer Data are bound by confidentiality obligations;
  3. implement the technical and organizational measures described in Annex 2 and keep them under review;
  4. engage sub-processors only in accordance with section 7;
  5. assist the Customer, taking into account the nature of the processing, in responding to data subject requests under section 9;
  6. assist the Customer in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the information available to Partnerfy;
  7. delete or return Customer Data at the end of the service in accordance with section 11;
  8. make available the information necessary to demonstrate compliance with this DPA and allow for audits in accordance with section 12;
  9. keep a record of processing activities carried out on behalf of the Customer where required by law.

6. Obligations of the Customer

The Customer shall:

  1. ensure that it has a lawful basis for collecting and processing Customer Data and for instructing Partnerfy to process it;
  2. publish a privacy notice to its data subjects and obtain any consents required by law, including consents for commercial electronic messages under Turkish Law No. 6563 and the İYS system;
  3. configure the store, including consent checkboxes, marketing sequences, and data retention settings, in accordance with applicable law;
  4. not upload special categories of personal data unless it has a lawful basis and has informed Partnerfy in writing;
  5. keep its account credentials secure and enable two-factor authentication for staff with access to Customer Data;
  6. respond to data subject requests and supervisory authority inquiries directed to it as controller.

7. Sub-processors

7.1 Authorization

The Customer gives general authorization for Partnerfy to engage the sub-processors listed in Annex 3. Partnerfy imposes on each sub-processor data protection obligations no less protective than those in this DPA and remains liable for the sub-processor's performance.

7.2 Changes

Partnerfy will publish changes to Annex 3 at kambloo.com/legal/dpa and notify the Customer by email at least 30 days before a new sub-processor begins processing Customer Data. The Customer may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may terminate the affected service in accordance with the Terms of Service.

8. Personal data breach

Partnerfy shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Partnerfy may provide information in phases as it becomes available.

Partnerfy's incident response process consists of detection, triage to identify affected stores, containment (including suspending an affected store if necessary), remediation, notification, and a post-incident review. Partnerfy will cooperate with the Customer in meeting the Customer's own notification obligations to supervisory authorities and data subjects, including the 72-hour notification period to the Personal Data Protection Board under KVKK.

9. Data subject requests

The Kambloo admin panel provides tools for the Customer to respond to data subject requests directly, including exporting a customer's data and anonymizing a customer's personal fields on request. Order records are retained in anonymized form where commercial and tax law require it.

If Partnerfy receives a request directly from a data subject of the Customer, Partnerfy will not respond on the merits but will forward the request to the Customer without undue delay and provide reasonable assistance.

10. International transfers

Customer Data is hosted primarily in Türkiye and the European Union. Where a sub-processor in Annex 3 processes Customer Data outside Türkiye or the European Economic Area, the transfer takes place under a mechanism permitted by applicable law: for GDPR, an adequacy decision or the European Commission's standard contractual clauses; for KVKK, one of the mechanisms in Article 9, including a standard contract notified to the Personal Data Protection Board. Partnerfy will provide the Customer with information about the mechanism used on request.

11. Deletion and return of Customer Data

11.1 During the service

The Customer can export the store's data at any time from the admin panel. The export contains the store database and media list in JSON and CSV format and is delivered through a signed link valid for 72 hours.

11.2 On termination

When the Customer deletes the store or the service otherwise ends, a 30-day cooling period begins. During it the store is suspended, the Customer can export Customer Data, and the deletion can be cancelled. At the end of the cooling period Partnerfy:

  1. drops the store's dedicated database;
  2. purges the store's media from object storage;
  3. deletes the store's search index;
  4. removes the store's custom hostnames and certificates;
  5. anonymizes the store's record in the central platform database, retaining only a deletion timestamp and a hash as proof of deletion.

Copies in backups are not restored after deletion and age out through backup rotation: daily backups within 14 days and weekly backups within 3 months. Partnerfy retains records required by law, such as invoices, in accordance with the Privacy Policy.

12. Audit

Partnerfy will make available to the Customer, on written request and not more than once per year unless a supervisory authority requires otherwise, documentation reasonably necessary to demonstrate compliance with this DPA, including summaries of its most recent external penetration test and its security policies. Where this documentation is insufficient, the Customer may conduct an audit, itself or through an independent auditor bound by confidentiality, at reasonable times, with at least 30 days' notice, without disrupting the service, and at the Customer's cost. Partnerfy may require that audit findings be treated as confidential.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent that applicable data protection law does not permit such limitation.

14. Term and precedence

This DPA applies for as long as Partnerfy processes Customer Data and survives termination of the Terms of Service until deletion under section 11 is complete. In case of conflict between this DPA and the Terms of Service regarding the processing of Customer Data, this DPA prevails. In case of conflict between this DPA and mandatory data protection law, the law prevails.

15. Contact

Partnerfy.co (Kambloo) Partnerfy Bilgi Teknolojileri ve Pazarlama Sanayi Ticaret Ltd. Şti., Orta Mah. Kavaklar Cad. No:15 Ofisada Plaza D:104, Adapazarı, Sakarya, Türkiye Registration number: MERSIS 0722116506400001, trade registry no. 43130 (Adapazarı), tax no. 7221165064 Data protection contact: [email protected] Security incidents: [email protected]

Annex 1: Details of processing

Item Description
Subject matter Provision of the Kambloo hosted e-commerce platform to the Customer
Duration The term of the Terms of Service plus the deletion process in section 11
Nature of processing Hosting, storage, backup, transmission, display, search indexing, sending of transactional and, where the Customer has obtained consent, marketing messages, generation of sitemaps and feeds, and related technical operations
Purpose Enabling the Customer to operate an online store, manage products, process orders, and communicate with its customers
Categories of data subjects The Customer's store customers (registered and guest), the Customer's staff users, and visitors to the Customer's storefront
Types of personal data Identity and contact data (name, email, phone, addresses); account data (hashed passwords, session records); order and transaction data (products, amounts, payment references, card brand and last four digits, shipping and tracking data); consent records (marketing consents with source, timestamp, IP); cart and behavioral data (cart contents, recovery sequence status); communication data (messages, reviews); technical data (IP address, user agent, logs)
Special categories None intended. The Customer must not upload special categories of data without a lawful basis and prior written notice

Annex 2: Technical and organizational security measures

Isolation. Each store's data is held in a dedicated database with credentials limited to that database. Cache, file storage, search indexes, and background jobs are partitioned per store, and job execution verifies the store context before running.

Access control. Role-based permissions in the admin panel. Two-factor authentication is available to all users and required for owners of live stores. Sessions are server-side, use secure and HTTP-only cookies, and expire after 12 hours for admin panels. Sensitive actions require password re-confirmation. Access by Partnerfy staff to a store is logged, requires a recorded reason, defaults to read-only, and is shown as a visible banner in the store's admin panel while active.

Encryption. TLS 1.2 or higher for all traffic; certificates issued and renewed automatically. Passwords hashed with a modern algorithm; two-factor secrets and API tokens encrypted at rest. Backups stored in a separate bucket with write-only credentials from the application side.

Payment security. Card data is entered only into the payment provider's hosted form and never reaches Partnerfy's systems. The platform operates within PCI DSS SAQ-A scope. Webhooks are signature-verified and protected against replay.

Application security. Development follows the OWASP Top 10 controls, with static analysis, dependency vulnerability scanning on every build, and a security checklist in code review. Third-party App Market modules pass automated and manual security review before listing. File uploads are validated and stored outside the web root.

Rate limiting and abuse prevention. Layered rate limits on authentication, store creation, and APIs. Automated scanning of new stores for phishing and impersonation. Periodic browsing-safety checks of store domains.

Logging and monitoring. Audit logs of administrative actions at platform and store level, with sensitive values masked. Store-level logs retained 400 days; platform-level logs 2 years, then archived immutably.

Backups and recovery. Nightly per-store database backups, retained 14 days daily and 3 months weekly. Central platform backups twice daily, retained 30 days daily and 12 months monthly. Monthly restore tests on randomly selected stores. Documented recovery objectives and a disaster recovery plan.

Patch management. Security vulnerabilities are patched according to severity: critical within 24 hours, high within 72 hours, medium within 14 days, low within 30 days. Security patches are applied to all stores automatically.

Testing. Annual external penetration test and internal security review of every major release. Responsible disclosure program at [email protected].

Incident response. Documented runbook covering detection, triage, containment, remediation, notification within 72 hours, and post-incident review.

Annex 3: Sub-processors

Sub-processor Purpose Location of processing
Cloudflare, Inc. Content delivery network, DNS, TLS certificates for custom domains, edge security and bot protection, object storage (R2) for media and backups, Turnstile form protection Global edge network; object storage located in the European Union
Stripe, Inc. and its affiliates Card payments and subscription billing for stores that enable Stripe European Union and United States
iyzico (iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş.) Card payments for stores that enable iyzico Türkiye
PayTR (PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş.) Card payments for stores that enable PayTR Türkiye
Email delivery provider Sending transactional and marketing email on behalf of stores The provider in use and its processing location are named in the current version of this annex at kambloo.com/legal/dpa

Payment sub-processors process Customer Data only for stores that have enabled the respective provider. Optional integrations that the Customer enables from the App Market (for example shipping carriers, invoicing services, or marketplaces) are engaged directly by the Customer and are not sub-processors of Partnerfy.

All legal documents