Data Processing Addendum (DPA)

Effective date: 2026-08-05 Last updated: 2026-08-05

DRAFT — PENDING COUNSEL REVIEW. This document is a working draft prepared for public Beta and for review by the operator's legal counsel. It is not legal advice and does not constitute a final, counsel-approved addendum. It will be replaced by a counsel-reviewed final version before general availability (GA).

This Data Processing Addendum ("DPA") forms part of, and is governed by, the Terms of Service (the "Agreement") between Legal Eye Yazılım A.Ş. (Türkiye; Trade Registry No. 1020744; VKN 6081733803), trading as "AllAPI" ("we", "us"), and the customer that accepts the Agreement ("you", "Customer"). Capitalized terms not defined here have the meaning given in the Agreement and the Privacy Policy.


1. Purpose and the parties' data-protection roles

This DPA records how personal data is handled in connection with the Service and resolves the parties' respective roles under KVKK (Türkiye, Law No. 6698) and the GDPR / UK-GDPR (Regulation (EU) 2016/679 and the UK equivalent).

1.1 The parties are independent (separate) controllers — not controller and processor.

The Service is a unified, read-only gateway that retrieves only publicly available data using anonymous, unauthenticated requests and returns it in a normalized JSON envelope. In doing so:

Because neither party processes personal data on behalf of and under the documented instructions of the other, the relationship is controller-to-controller (independent controllers), and a classic GDPR Article 28 processor arrangement does not apply to the standard use of the Service. This DPA therefore sets out controller-to-controller terms, not processor terms.

Why not a processor DPA? An Article 28 / KVKK veri işleyen addendum governs a provider that processes personal data solely on a customer's instructions for the customer's purposes (e.g. a payroll or hosting vendor). AllAPI does not do that: we do not act on your instructions to target specific individuals, we do not store response payloads (Privacy §2.4), and we independently decide how the gateway retrieves public data. Characterizing us as your processor would misdescribe the relationship and is not offered.

1.2 Narrow processor fallback (bespoke enterprise only). If, under a separate signed enterprise order, we ever agree to process personal data exclusively on your documented instructions (for example, ingesting a list of identifiers you supply and processing it only as you direct), that specific arrangement would be governed by a separate Article 28 processor addendum executed for that order. Absent such a signed addendum, this controller-to-controller DPA governs, and no processor relationship is created by the standard Service.


2. Subject-matter, duration, nature and purpose


3. Each party's obligations as a controller

Each party, acting as an independent controller, shall:

  1. Process personal data in compliance with KVKK, GDPR / UK-GDPR, and all other applicable data-protection law;
  2. Have and maintain its own lawful basis for its processing (for us, see Privacy §3 and §14.2; for you, your downstream lawful basis, which we do not warrant on your behalf per Privacy §14.2);
  3. Provide any privacy notices and honor any data-subject rights for which it is responsible as controller;
  4. Implement appropriate technical and organizational security measures (for our measures, see Privacy §13 and §5 below);
  5. Not cause the other party to breach applicable law by its own acts or omissions.

Your downstream-controller obligations (re-identification prohibition, mass personal-data harvesting without a lawful basis, no profiling/surveillance tooling, honoring notices and data-subject rights in your use) are set out in Terms §7 and the Acceptable Use Policy and are incorporated here.


4. Sub-processors

For our own controller processing, we engage sub-processors — including our Merchant of Record, Creem / Armitage Labs OÜ (payment processing) — listed and kept current in Privacy §6.1, where the current named list is available to customers on request. Each is engaged under a written agreement imposing confidentiality, security, and — where applicable — international-transfer safeguards. Material changes are announced per Privacy §15, and you may object to a new sub-processor as described there. These are our sub-processors as controller; they are not your processors.


5. Security measures

We apply the technical and organizational measures in Privacy §13, including: hashed passwords and API keys; TLS 1.2+ in transit (1.3 preferred); encryption at rest; least-privilege, role-separated database credentials; hardware-key 2FA for production access; and 30-day encrypted rolling backups. These measures may evolve, provided the level of protection is not materially reduced.


6. Personal-data breach

If we become aware of a personal-data breach affecting personal data we control, we will act in line with Privacy §13: GDPR — notify the competent supervisory authority within 72 hours where required and affected individuals where the risk is high; KVKK — notify the Board and affected data subjects as soon as reasonably possible. As independent controllers, each party is responsible for its own breach-notification duties; we will provide reasonable information to help you meet yours where a breach on our side affects data you also control.


7. Data-subject requests and cooperation

Each party handles the data-subject requests for which it is the responsible controller. Where an individual asks us to suppress third-party personal data appearing in Service responses, we operate the removal/suppression and objection mechanism in Privacy §14.3 ([email protected]). We will provide reasonable cooperation to help you respond to requests you receive that concern data you obtained through the Service, taking into account the nature of the processing and the information available to us.


8. International transfers

Transfers are handled as described in Privacy §7: infrastructure in the EU / EEA; controller established in Türkiye; GDPR/UK transfers on an adequacy decision or SCCs (plus the UK IDTA where applicable); KVKK cross-border transfers on a permitted basis (adequacy, standard contract, BCR/undertaking, or an exceptional ground).


9. Return or deletion; audit


10. Precedence, changes, and contact

This DPA supplements the Agreement. In case of conflict on data-protection matters, this DPA and the Privacy Policy prevail over the general Terms for those matters. We may update this DPA consistent with Privacy §15; material reductions of protection are announced in advance.

Contact — data protection: [email protected]. Controller: Legal Eye Yazılım A.Ş., Sultan Selim Mah. Yamaç Sk. No:6 İç Kapı No:3, Kağıthane / İstanbul, Türkiye.


Draft — pending counsel review. Not legal advice. Prepared for Legal Eye Yazılım A.Ş. / AllAPI. Adopts the independent-controller characterization consistent with Privacy §0/§14 and Terms §15, with a narrow signed-order processor fallback. Counsel to confirm the characterization, the KVKK/GDPR transfer mechanisms, and whether any customer segment (e.g. bespoke enterprise ingestion) requires a separate Article 28 processor addendum.