Data Processing Addendum
Last updated: Not yet issued
Between: the Customer (controller) and Hublinkly Ai Software Technology Ltd. (processor)
1. Roles
For data the Customer enters into the platform about its own clients, staff and suppliers, the Customer is the controller and Hublinkly Ai Software Technology Ltd. is the processor, acting only on the Customer’s documented instructions.
2. Subject matter and duration
Provision of the Clavix360 platform, for the duration of the subscription plus the retention period in Section 8.
3. Categories of data and data subjects
As determined by the Customer. Typically: the Customer’s clients, employees, tenants, patients, suppliers and contacts. Where the Customer processes special categories — health data in the Health Tourism engine — additional obligations apply under KVKK Article 6 and GDPR Article 9.
4. Our obligations
Process only on instruction; keep personnel under confidentiality; apply the security measures in Annex A; assist with data-subject requests, impact assessments and breach notification; delete or return data on termination.
5. Sub-processors
The Customer authorises the sub-processors listed publicly on our Sub-processor List. We give at least 30 days’ notice before adding one, and the Customer may object on reasonable grounds.
6. Security
Annex A — encryption in transit and at rest, workspace isolation per customer, role-based access control, logging, backup and recovery. We hold no security certification and have commissioned no external penetration test; if that changes it will be stated on the Security page. A penetration testing cadence is to be confirmed.
7. Breach
We notify the Customer without undue delay after becoming aware, with the information the Customer needs to meet its own notification duties.
8. Return and deletion
On termination, data is available for export for 30 days, then deleted, subject to legal retention obligations.
9. Audit
We provide the information reasonably needed to demonstrate compliance. On-site audit rights are to be confirmed; until they are defined we will answer a documentation-based audit.
10. Transfers
The same Article 9 and Chapter V analysis as the Privacy Policy applies, and the two must match. The mechanism is to be confirmed.
