Legal
Data Processing Agreement
Terms under KVKK, GDPR, UK, Swiss and US law for the processing of customer data of businesses using Planfly as a processor, sub-processors and international transfers.
Contents · 24 sections
- Parties and Scope
- 1. Definitions
- 2. Roles of the Parties
- 3. The Business's Instructions
- 4. The Business's Obligations
- 5. Confidentiality
- 6. Security
- 7. Sub-processors
- 8. International Transfers
- 8.1. Businesses in Türkiye
- 8.2. Businesses in the European Economic Area
- 8.3. Businesses in the United Kingdom
- 8.4. Businesses in Switzerland
- 8.5. Other Countries and Onward Transfers
- 9. Data Subject Requests
- 10. Personal Data Breaches
- 11. Impact Assessments and Prior Consultation
- 12. Deletion and Return
- 13. Information and Audits
- 14. Requests from Public Authorities
- 15. Additional Terms for U.S. State Laws
- 16. HIPAA
- 17. Liability
- 18. Term and Termination
- 19. Changes
- 20. Language and Governing Law
- Annex 1: Details of Processing
- A. Parties
- B. Description of Processing and Transfer
- C. Competent Supervisory Authority
- Annex 2: Technical and Organizational Measures
- Annex 3: Sub-processors
This Agreement is made in Turkish and English. For businesses whose account country is Türkiye the Turkish version prevails; for all other businesses this English version prevails (Section 20).
Parties and Scope
This Data Processing Agreement (the "Agreement") is entered into between Mobiza Teknoloji ("Planfly"), which provides the Planfly service, and the business that opens a business account on Planfly and accepts the Terms of Use (the "Business"). The Agreement is an integral annex to the Terms of Use and takes effect, without a separate signature, when the Business accepts the Terms of Use.
The Agreement applies to personal data that Planfly processes on behalf of the Business. Data that Planfly processes as a controller for its own purposes (business accounts, subscriptions and invoicing, support and security records) is covered by the Privacy Policy and the KVKK Privacy Notice, not by this Agreement.
Section 11 of the Terms of Use and this Agreement apply together. On matters of personal data protection this Agreement prevails, and where the Standard Contractual Clauses apply, the Standard Contractual Clauses prevail.
1. Definitions
- Data Protection Law: the personal data protection laws that apply to the processing of Business Personal Data, in particular Law No. 6698 on the Protection of Personal Data ("KVKK"), Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act ("CCPA") and the privacy laws of other U.S. states.
- Business Personal Data: personal data collected through the Business's booking page, widget, dashboard or mobile app, or entered into Planfly by the Business, that Planfly processes on behalf of the Business.
- Sub-processor: a third party engaged by Planfly to process Business Personal Data.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Business Personal Data.
- Standard Contractual Clauses: the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- UK Addendum: the International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner's Office (ICO) under section 119A of the Data Protection Act 2018.
Terms not defined in this Agreement, such as "controller", "processor", "data subject", "processing" and "service provider", have the meaning given in Data Protection Law.
2. Roles of the Parties
For Business Personal Data, the Business is the controller and Planfly is the processor. If the Business itself acts as a processor on behalf of another controller, Planfly is the Business's sub-processor, and the Business warrants that its instructions to Planfly are consistent with the instructions of its own controller. For the purposes of the CCPA, Planfly is the Business's "service provider"; for the purposes of other U.S. state laws, it is the Business's "processor".
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
3. The Business's Instructions
Planfly processes Business Personal Data only on the Business's documented instructions. The Terms of Use, this Agreement, the settings the Business makes in the dashboard and the instructions it gives through the dashboard, the mobile app or support channels are the Business's documented instructions. If the law to which Planfly is subject requires other processing, Planfly informs the Business of that legal requirement before processing, unless that law prohibits it.
If Planfly considers that an instruction infringes Data Protection Law, it informs the Business immediately and may suspend the processing concerned until the instruction is corrected.
4. The Business's Obligations
The Business acknowledges and warrants that:
- it has a legal basis under Data Protection Law for processing Business Personal Data and has informed the data subjects; if it uses the privacy notice templates provided by Planfly, it has checked that they match its own activities,
- where consent is required, it has obtained consent in accordance with the law,
- it prepares intake questions in line with the principle of data minimization and does not request special categories of personal data (including health data) that are not necessary for the appointment,
- unless necessary, it does not use wording that may reveal a person's health condition in service names, payment descriptions or notification texts,
- it is responsible for responding to requests from data subjects,
- it gives dashboard access only to authorized persons and keeps its own account secure,
- it gives Planfly only lawful instructions.
5. Confidentiality
Planfly limits the access of its employees and contractors who can access Business Personal Data to what their duties require and ensures that these persons are bound by contractual or statutory confidentiality obligations.
6. Security
In accordance with Article 12 of the KVKK and Article 32 of the GDPR, Planfly implements technical and organizational measures appropriate to the nature of the processing and the risks. These measures are described in Annex 2. Planfly may update the measures in line with technical developments, provided that the level of protection is not reduced. Under the second paragraph of Article 12 of the KVKK, the parties are jointly responsible for taking security measures; the Business is responsible for the security of its own accounts and devices and for its settings in the dashboard.
7. Sub-processors
The Business gives general written authorization for Planfly to use the Sub-processors listed in Annex 3. At least 30 days before engaging a new Sub-processor or replacing an existing one, Planfly updates Annex 3 and informs the Business by email or dashboard notification. Within this period, the Business may object on reasonable data protection grounds; if the parties cannot resolve the objection within a reasonable time, the Business may terminate the subscription affected by the change.
Planfly imposes on each Sub-processor, by written contract, obligations providing at least the level of protection in this Agreement, and remains liable to the Business for the performance of the Sub-processor's obligations to the extent provided by Data Protection Law.
Services that the Business uses by connecting its own account (e.g., Google Calendar and Google Meet, the Business's own payment institution account) and payment institutions that provide payment services as controllers under their own laws are not Planfly's Sub-processors; data is transmitted to these providers on the Business's instructions.
8. International Transfers
8.1. Businesses in Türkiye
If the Business is located in Türkiye, transfers of Business Personal Data to Sub-processors abroad are based, under Article 9 of the KVKK and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, primarily on an adequacy decision and, in the absence of an adequacy decision, on appropriate safeguards such as the standard contract announced by the Personal Data Protection Board. Where necessary for these transfers, the Business authorizes Planfly to also enter into the standard contracts on its behalf.
8.2. Businesses in the European Economic Area
If the transfer of Business Personal Data by the Business to Planfly is subject to the GDPR, Module Two (controller to processor) of the Standard Contractual Clauses applies between the parties or, where the Business is a processor, Module Three (processor to processor), and these modules are incorporated into this Agreement by reference. The Business is the data exporter and Planfly is the data importer. The following choices apply:
- Clause 7 (docking clause) applies,
- in Clause 9(a), Option 2 (general written authorization) applies; the period for prior notice is the 30 days in Section 7 of this Agreement,
- the optional wording in Clause 11(a) does not apply,
- for Clause 13, the competent supervisory authority is the supervisory authority of the Member State in which the data exporter is established; if the data exporter is not established in the European Union, it is the supervisory authority of the Member State in which its representative under Article 27 of the GDPR is located or, if it is not required to appoint a representative, the supervisory authority of one of the Member States in which the data subjects are located,
- in Clause 17, Option 2 applies: the Standard Contractual Clauses are governed by the law of the Member State in which the data exporter is established or, where that law does not allow for third-party beneficiary rights, by the law of Ireland,
- for Clause 18(b), disputes are resolved by the courts of the Member State in which the data exporter is established or, if the data exporter is not established in the European Union, by the courts of Ireland,
- Annex I of the Standard Contractual Clauses is Annex 1 of this Agreement, Annex II is Annex 2 and Annex III is Annex 3.
8.3. Businesses in the United Kingdom
If the transfer is subject to the UK GDPR, the Standard Contractual Clauses in Section 8.2 apply together with the UK Addendum. The party details for Table 1 of the UK Addendum are set out in Annex 1, the modules and choices for Table 2 in Section 8.2 and the appendix information for Table 3 in Annexes 1 to 3; for Table 4, both the importer and the exporter may end the UK Addendum as set out in its Section 19. In case of conflict between the UK Addendum and the Standard Contractual Clauses, the UK Addendum applies.
8.4. Businesses in Switzerland
If the transfer is subject to the FADP, the Standard Contractual Clauses in Section 8.2 apply with the following adaptations: to the extent the transfer is subject to the FADP, the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC); the term "Member State" may not be interpreted in a way that prevents data subjects in Switzerland from bringing claims in their place of habitual residence; references to the GDPR are to be read as references to the corresponding provisions of the FADP.
8.5. Other Countries and Onward Transfers
For Businesses in other countries, Planfly cooperates reasonably in putting in place the safeguards required for transfers abroad by the law of the country in which the Business is located. Onward transfers by Planfly to Sub-processors are based on an adequacy decision (for Sub-processors in the United States, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions) or on the Standard Contractual Clauses and their UK and Swiss adaptations.
9. Data Subject Requests
To enable the Business to respond to data subject requests, Planfly provides tools in the dashboard such as viewing, exporting, correcting and deleting customer records, and provides reasonable additional assistance where necessary. Planfly forwards to the Business without undue delay any request concerning Business Personal Data that reaches it directly and, other than referring the data subject to the Business, does not respond to the request without the Business's instructions.
10. Personal Data Breaches
If Planfly becomes aware of a Personal Data Breach, it informs the Business without undue delay and, where feasible, within 48 hours. To the extent known at the time, the notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed and Planfly's contact details; the information is supplemented as it becomes available. Planfly provides reasonable assistance to enable the Business to meet its obligations to notify the Personal Data Protection Board, the competent supervisory authority and data subjects. Notification of a breach does not mean that Planfly accepts fault for it.
11. Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to it, Planfly provides reasonable information and assistance to enable the Business to carry out a data protection impact assessment and, where necessary, to consult the supervisory authority.
12. Deletion and Return
The Business can export customer records from the dashboard during the subscription and before closing its account. After the business account is deleted, Planfly deletes or anonymizes Business Personal Data within 30 days. Copies in backups are deleted when the backup cycle completes, within 35 days at the latest, and until then are kept encrypted and only for disaster recovery. Records that the law applicable to Planfly requires to be kept longer (e.g., Payment Module transaction and acceptance records) are kept only for that purpose and for the required period.
13. Information and Audits
Planfly makes available to the Business the information necessary to demonstrate compliance with this Agreement (this Agreement, the measures in Annex 2, the list in Annex 3 and answers to the Business's reasonable questions). If a reasonable doubt cannot be resolved with this information, or if a competent authority requests it, the Business may have an audit carried out at its own expense by an independent auditor bound by confidentiality, at most once a year, during business hours and with at least 30 days' written notice. An audit does not include access to other customers' data or to information that would put Planfly's security at risk. The rights under Clause 8.9 of the Standard Contractual Clauses remain unaffected.
14. Requests from Public Authorities
If Planfly receives a request from a public authority or court for access to Business Personal Data, it informs the Business without undue delay unless prohibited by law; it assesses the lawfulness of the request, challenges a request it considers unlawful by the means available under applicable law, and discloses only the minimum data legally required.
15. Additional Terms for U.S. State Laws
If Business Personal Data is subject to the CCPA or the privacy laws of other U.S. states, Planfly, as service provider and processor:
- does not sell Business Personal Data or share it for cross-context behavioral advertising,
- retains, uses and discloses Business Personal Data only for the business purposes specified in Annex 1 and within its direct business relationship with the Business,
- does not combine Business Personal Data with personal data it receives from other persons or collects in its own interactions, except as permitted by law,
- complies with these laws and provides the level of protection they require, and informs the Business if it determines that it can no longer meet these obligations,
- allows the Business to take reasonable and appropriate steps to ensure that the data is used in accordance with this Agreement and to stop and remediate unauthorized use,
- cooperates with the Business in responding to consumer requests,
- imposes the same obligations on its Sub-processors.
With respect to the Washington My Health My Data Act and similar consumer health data laws, Planfly processes consumer health data only on the Business's instructions and within the scope of this Agreement; the privacy policy and consent obligations under those laws rest with the Business.
16. HIPAA
Planfly does not sign business associate agreements under the U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the service is not designed for the obligations HIPAA imposes. A Business that is a "covered entity" or "business associate" within the meaning of HIPAA agrees not to use Planfly to create, receive, maintain or transmit protected health information (PHI).
17. Liability
The parties' liability under this Agreement is subject to the liability provisions of the Terms of Use. This provision does not limit the rights of data subjects under the Standard Contractual Clauses and Data Protection Law.
18. Term and Termination
This Agreement remains in force for as long as the Terms of Use are in force. After the Terms of Use end, the relevant provisions continue to apply for as long as Planfly processes or stores Business Personal Data.
19. Changes
Planfly may update this Agreement because of legislative changes, decisions of competent authorities or changes to the service; material changes to the Business's detriment are notified at least 30 days before they take effect. Officially amended or replaced versions of the Standard Contractual Clauses and the UK Addendum apply from the date they take effect.
20. Language and Governing Law
This Agreement is made in Turkish and English. For Businesses whose account country is Türkiye, the Turkish version prevails; for all other Businesses, the English version prevails. The Standard Contractual Clauses and the UK Addendum are governed by the law specified in their own provisions; for the other provisions of this Agreement, the governing law and jurisdiction provisions of the Terms of Use apply.
Annex 1: Details of Processing
A. Parties
- Data exporter / controller: the Business; its name, address and contact details are recorded in the Business account. Activity: providing services by appointment. Role: controller (processor where the Business acts on behalf of another controller).
- Data importer / processor: Mobiza Teknoloji, Ovaakça Santral Mah. Ovaakça Fatih Sultan Mehmet Cad. No: 86, 16335 Osmangazi, Bursa, Türkiye; contact: legal@planfly.app. Activity: the Planfly online booking software service. Role: processor.
- The date on which the Business accepts the Terms of Use electronically is the date on which the parties accept this Agreement and the Standard Contractual Clauses.
B. Description of Processing and Transfer
- Categories of data subjects: the Business's customers and people who book appointments (clients, patients, members, students, etc.) and their legal representatives; the Business's staff members and team members; people who leave reviews.
- Categories of personal data: identity and contact details (first name, last name, phone, email); appointment details (service, staff member, date, time, status, cancellation and no-show records, appointment note); date of birth, tags, private notes and appointment history added by the Business; an attendance likelihood indicator calculated from the appointment history and shown only to the Business; intake form answers; notification and delivery records; reviews; records of privacy notices, consent and commercial message consent (date, IP address, browser information, text version); if the Payment Module is used, limited payment data (amount, date, transaction number, card type and masked last four digits; the card number and security code are not processed); meeting links for online appointments; staff member details (name, title, photo, working hours, user account); security logs and cookieless visit statistics.
- Special categories of data: depending on the Business's choices, intake answers, appointment notes and customer notes may contain health data. Additional safeguards: encryption of private notes on the customer card in the database, role-based access, the discreet message option that hides the service name in reminders, recording of optional explicit consent with date, IP address and text version, and the measures in Annex 2.
- Frequency of transfer: continuous.
- Nature of processing: hosting, storage, organization, display, transmission (email, messages, push notification), computation (availability, statistics), export and deletion.
- Purpose of processing: providing the Business with online booking, calendar, customer records, notifications, reviews, statistics and, where used, online payment services; and the security, support and maintenance of these services.
- Retention period: according to deletions and settings made by the Business in the dashboard; at the latest within the periods in Section 12 of this Agreement.
- Transfers to Sub-processors: with the subject matter, nature and duration stated in Annex 3.
C. Competent Supervisory Authority
For Businesses in the European Economic Area, the authority determined under Section 8.2; for the United Kingdom, the Information Commissioner's Office (ICO); for Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); for Businesses in Türkiye, the Personal Data Protection Board.
Annex 2: Technical and Organizational Measures
- Transmission security: encrypted transmission with TLS (HTTPS) on all connections and HTTP Strict Transport Security.
- Access control: separation of business data on a per-business basis; role-based authorization (owner, manager, staff member); optional two-factor authentication; passwords stored only in hashed form; session cookies with the HttpOnly, Secure and SameSite attributes and CSRF protection.
- Encryption: encryption in the database of private notes on the customer card, card and account keys of payment institutions, payment account details and third-party access tokens; encryption of database backups.
- Application security: rate limiting, bot traps and misuse detection; content security policy (CSP) and security headers; input validation.
- Infrastructure security: database and cache services not exposed to the internet; network-layer protection against denial-of-service attacks and malicious traffic.
- Logging and monitoring: keeping and reviewing security, access and transaction logs.
- Continuity: daily encrypted backups and a restore procedure.
- Data minimization: card numbers and security codes are not processed by Planfly (payment pages are hosted by the payment institution); booking page statistics are kept without cookies and without storing IP addresses, and Do Not Track and Global Privacy Control signals are respected; discreet message option for reminders.
- Personnel: least privilege, confidentiality obligations and removal of access when roles change.
- Sub-processor management: contractual data protection and security obligations and assessment of security configurations.
- Incident management: detecting and recording Personal Data Breaches and notifying them in accordance with Section 10 of this Agreement.
Annex 3: Sub-processors
Planfly uses the following Sub-processors to process Business Personal Data (last updated: October 10, 2026).
| Sub-processors | Service and processed data | Place of processing |
|---|---|---|
| Data center hosting provider for Planfly servers | Sunucu, veritabanı ve uygulama barındırma (tüm İşletme Kişisel Verileri) | Provider's data center |
| Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, United States) | İçerik dağıtım ağı, DNS ve ağ güvenliği; R2 dosya depolama (logo, kapak ve personel fotoğrafları, yüklenen dosyalar) | ABD ve Cloudflare küresel ağı |
| Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, United States) | Şifrelenmiş veritabanı yedekleri (Google Drive); mobil uygulama anlık bildirimleri (Firebase Cloud Messaging, bildirimdeki randevu bilgileri) | United States |
| Netgsm İletişim ve Bilgi Teknolojileri A.Ş. (Türkiye) | SMS gönderimi (telefon numarası ve mesaj metni) | Türkiye |
| Email delivery service provider | E-posta gönderimi (e-posta adresi ve ileti içeriği) | Provider's data center |
| OpenAI, L.L.C. (United States) | Destek sohbet asistanı (yalnızca İşletme kullanıcılarının görüşmeye kendilerinin yazdığı bilgiler) | United States |
The following providers are not Planfly's Sub-processors; data is transmitted to them on the Business's instructions and they process it under their own responsibility:
- Google Calendar and Google Meet (Google LLC), if the Business connects its own Google account,
- payment institutions that provide the payment service in the Payment Module (iyzico Ödeme Hizmetleri A.Ş. and payment institutions to which the Business connects its own account),
- third-party services linked by the Business on its booking page.
Other legal documents
- KVKK Privacy NoticeOctober 10, 2026
- GDPR Privacy Notice (European Economic Area and Switzerland)October 10, 2026
- UK Privacy NoticeOctober 10, 2026
- US Privacy NoticeOctober 10, 2026
- Privacy PolicyOctober 10, 2026
- Terms of UseOctober 10, 2026
- Cookie PolicyOctober 11, 2026
- Distance Sales AgreementOctober 10, 2026
- Refund and Delivery PolicyOctober 10, 2026
- Partner (Sales Brokerage) AgreementOctober 11, 2026
- Partner Privacy NoticeOctober 10, 2026
- Account and Data DeletionOctober 11, 2026
Company information
Planfly is a product developed and operated by Mobiza Teknoloji.
- Title
- Mobiza Teknoloji
- Address
- Ovaakça Santral Mah. Ovaakça Fatih Sultan Mehmet Cad. No: 86, 16335 Osmangazi, Bursa, Türkiye
- Tax office (vergi dairesi)
- Uludağ Tax Office
- Tax ID
- 1280527561
- DUNS number
- 751143161
- Corporate website
- mobiza.com.tr