B2B — For Customer Companies

Data Processing Agreement (DPA)

Last updated: July 2026 — KVKK art. 12 / GDPR Art. 28 compliant

This translation is provided for convenience; the official and legally binding version is the Turkish one.

This agreement is concluded between the following parties:

DATA CONTROLLER

Customer Company

The company that integrates Bitenta into its own website

DATA PROCESSOR

Bitenta

The service company providing the live-support platform

1Definitions

Personal DataAny information relating to an identified or identifiable natural person.
Data ControllerThe natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system (the Customer Company).
Data ProcessorThe natural or legal person who processes personal data on behalf of the data controller (Bitenta).
PlatformThe entire WebRTC-based live-support service provided by Bitenta.
VisitorThe end user who starts a support call via the embed widget on the Customer Company’s website.

2Subject and Purpose of the Agreement

This agreement regulates the rights and obligations relating to the personal data processing activities that Bitenta will carry out on behalf of the Customer Company, within the framework of Article 12 of Law No. 6698 (KVKK) and the relevant secondary legislation.

While providing the Platform service, Bitenta will process the personal data of the Customer Company’s visitors only in accordance with the Customer Company’s instructions and limited to the purposes set out in this agreement.

3Processed Personal Data and Processing Purposes

DataProcessing PurposeDuration
Name, emailStarting a call, visitor identity2 years
IP addressSecurity, abuse detection1 year
Chat messagesSupport call record2 years
Shared filesFile transfer during the call30 days
Survey responsesService quality measurement2 years
Video/audio streamP2P communication (not recorded on the server)Not recorded

4Bitenta’s Obligations

To process personal data only in accordance with the Customer Company’s written instructions
To ensure that personnel with access to personal data are bound by confidentiality obligations
To take the necessary technical and administrative security measures under Article 12 of the KVKK
Not to use sub-processors without the Customer Company’s approval
To notify the Customer Company in writing within 72 hours at the latest in the event of a data breach
To delete or return all personal data when the agreement ends
To permit audits and inspections

5Customer Company’s Obligations

To ensure the necessary legal grounds (explicit consent or legitimate interest, etc.) exist for processing personal data
To fulfil the privacy-notice obligation toward visitors under KVKK art. 10
To use the Platform only for legitimate and lawful purposes
To act in coordination with Bitenta when data subjects wish to exercise their rights
To ensure the security of Platform access credentials

6Security Measures

Bitenta applies the following technical and administrative security measures:

🔐

TLS/SSL Encryption

All communication channels are encrypted

🔑

Bcrypt Hashing

Passwords are not stored in plain text

📡

WebRTC DTLS-SRTP

Video/audio end-to-end encrypted

🗝️

Signed URLs

File access is time-limited and signed

👥

RBAC

Role-based access control

🛡️

CSRF Protection

Active on all form operations

🔍

Access Logs

Unauthorized access detection

🗑️

Automatic Deletion

Expired data is cleaned up automatically

7Sub-processors

Bitenta uses the following approved sub-processors:

ServicePurposeLocation
Server InfrastructureApplication hostingTürkiye / EU
Email ServiceSystem notificationsTürkiye

If a new sub-processor is added, the Customer Company is notified 30 days in advance.

8Responding to Data Subject Requests

If a visitor applies to exercise their rights under the KVKK, Bitenta notifies the Customer Company and provides the necessary technical support within 5 business days. The obligation to respond rests with the Customer Company.

9Duration and Termination

This agreement enters into force when the Customer Company registers on the Platform and remains valid until the subscription ends.

Within 30 days of the termination of the agreement, Bitenta deletes all personal data belonging to the Customer Company. Within this period, the Customer Company may request that the data be transmitted to it.

10Governing Law and Contact

This agreement is subject to the law of the Republic of Türkiye and Law No. 6698 (KVKK). Turkish courts have jurisdiction over disputes.

For your data processing requests and questions:

info@bitenta.com