Data Processing Addendum
The terms between the controller (the Customer) and the processor (Specoria) for personal data Specoria processes on its customers’ behalf: GDPR article 28 and article 12 of Turkish data protection law (Law No. 6698).
1. Parties, scope and precedence
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies between Webtures Ltd (address: 494a Fulham Road, London SW6 5NH, United Kingdom; company no. 11948574 (England and Wales)) (“Specoria”, the processor) and the Customer using Specoria services (the controller) to personal data processed on the Customer’s behalf (“Customer Personal Data”). By accepting the Terms of Service the Customer also accepts this DPA; customers who want a signed copy can have the same text signed.
Data Specoria processes for its own purposes as a controller (panel account, billing, marketing preference) is covered by our privacy notice, not by this DPA. If this DPA conflicts with the Terms of Service on personal data, this DPA prevails; if it conflicts with the standard clauses referred to below, those clauses prevail.
2. Definitions
“Personal data”, “controller”, “processor”, “data subject”, “processing” and “explicit consent” have the meanings given in Turkish data protection law (Law No. 6698) and, where they apply, the GDPR and the UK GDPR. “Data Protection Law” means all of these as they apply to Customer Personal Data. A “subprocessor” is a third party Specoria engages to process Customer Personal Data.
3. Details of processing (Annex 1)
- Server access logs (agent traffic analysis): the data subjects are visitors to the Customer’s site; the data are IP address, browser identifier (User-Agent), time and address of each request. The purpose is to report how AI agents and bots visit the site. The full IP is read only in memory, to check whether a bot comes from its published IP ranges, and cut to its network (IPv4 /24, IPv6 /48); human visitors’ IP addresses and browser identifiers are not stored; query strings are dropped; raw logs are not kept; hourly summaries are deleted after 35 days.
- Google Analytics 4 and Search Console: aggregate numbers read with read-only access (sessions, landing pages, clicks, impressions, key event and revenue totals). No visitor-level data is read; aggregate numbers are generally not personal data, and this DPA applies to the extent they are.
- Store and marketplace data: product and listing data read from Shopify, WooCommerce, Trendyol and Hepsiburada, and the changes the Customer approves. We don’t ask for the Customer’s own customers’ orders or personal data; personal data that may incidentally appear in product data (such as a seller or author name) is covered by this DPA.
- Documents and messages uploaded to the panel: personal data that may appear in documents the Customer chooses to upload and in support messages; only to provide the service and answer the request.
- Duration: while the subscription or account lasts; at the end, deleted under section 10. Special categories of data are not processed; the Customer agrees not to send such data to the Service.
4. Customer instructions and responsibilities
- Specoria processes Customer Personal Data only on the Customer’s documented instructions. The Terms of Service, this DPA and the Customer’s settings in the panel (setting up connections, uploading logs, approving changes) are the Customer’s instructions.
- Specoria tells the Customer immediately if it believes an instruction infringes Data Protection Law. If the law requires other processing, Specoria tells the Customer before processing unless the law prohibits it.
- The Customer confirms that it has a legal basis for the processing of Customer Personal Data, has informed the data subjects (such as its site’s visitors) and has obtained their consent where needed.
5. Confidentiality and security (Annex 2)
Specoria staff and helpers who access Customer Personal Data are bound by confidentiality, and access is limited to what the task needs. Specoria takes technical and organisational measures appropriate to the risk under GDPR article 32 and article 12 of Law No. 6698; the main measures in place today:
- HTTPS with HSTS on all traffic; only our own scripts run on the site (Content Security Policy).
- Access tokens and API keys are stored encrypted with AES-GCM (256-bit); passwords are hashed one-way with PBKDF2-SHA256.
- Panel sessions use __Host- cookies sent only over secure connections; sign-in attempts and forms are rate limited; a bot check is used.
- Data minimisation: IP addresses are cut to network level, raw server logs are not kept, and the simulator stores only a salted hash of the IP address.
- Team access is authenticated and role-based; project data is available only to project members and authorised staff.
- The database is backed up daily; backups are deleted after 56 days. The infrastructure runs on Cloudflare, where data is stored encrypted by the hosting provider.
Specoria does not hold certifications such as ISO 27001 or SOC 2 today. Our security practices are described in the trust center.
6. Subprocessors
- The Customer gives general authorisation for the subprocessors listed on our Subprocessors page.
- Specoria updates that page and emails paying customers at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable grounds within that time; if the parties can’t resolve it, the Customer may terminate the affected service or the contract and receive a refund of the paid, unused period.
- Specoria puts written contracts in place with subprocessors giving essentially the same level of protection as this DPA and remains liable to the Customer for their performance.
7. International transfers
- Turkish law: Specoria’s transfers of Customer Personal Data to subprocessors abroad rely on the standard contracts announced by the Turkish Personal Data Protection Board (processor-to-processor module) under article 9 of Law No. 6698 and the Turkish regulation on transfers of personal data abroad; standard contracts are notified to the Board within 5 business days of signature. For customers established in Türkiye, the transfer from the Customer to Specoria is domestic.
- GDPR: if the Customer is established in the European Economic Area, Module Two (controller to processor) of the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 is incorporated into this DPA by reference for transfers from the Customer to Specoria in Türkiye: clause 7 (docking) does not apply; clause 9(a) option 2 (general authorisation, 30 days’ notice); the optional wording in clause 11 does not apply; clause 13: the supervisory authority competent for the Customer; clauses 17 and 18: the law and courts of Ireland. The annexes are sections 3 and 5 of this DPA and the Subprocessors page.
- United Kingdom: if the Customer is established in the UK, the International Data Transfer Addendum issued by the UK Information Commissioner (UK Addendum) applies to the clauses above.
- Specoria’s onward transfers to subprocessors rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses.
8. Help with data subject requests and the Customer’s obligations
- Specoria forwards to the Customer, without answering them and within 5 business days at the latest, requests it receives directly from data subjects about Customer Personal Data, and reasonably helps the Customer answer them.
- Taking into account the nature of processing and the information available, Specoria helps the Customer with its obligations on security, breach notification, data protection impact assessments and prior consultation with authorities.
9. Personal data breach notification
Specoria notifies the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice includes, as far as known at the time, the nature of the breach, the categories and approximate numbers of data and people concerned, its likely consequences, the measures taken or proposed and a contact person, and is completed as more becomes known. Notifying authorities and data subjects is the Customer’s obligation as controller; Specoria provides the information needed for it.
10. Deletion and return
When the service or account ends, the Customer can download its reports from the panel. Specoria deletes Customer Personal Data within 30 days of the end; copies in backups are deleted at the end of the backup cycle (56 days at the latest). Data the law requires us to keep is excluded and kept only for that purpose. The Customer may ask for written confirmation of deletion.
11. Information and audits
Specoria makes available, on the Customer’s written request, the information needed to show compliance with this DPA and first answers written questionnaires. If that is not enough, the Customer may audit, itself or through an independent auditor, at most once a year, with at least 30 days’ notice, during business hours, under confidentiality and at its own cost; audits don’t extend to other customers’ data or to subprocessors’ premises. These limits don’t apply to a request by a competent authority or after a breach affecting the Customer.
12. Liability and term
Each party’s liability under this DPA is subject to the limits in the Terms of Service; those limits do not restrict data subjects’ rights under Data Protection Law and the Standard Contractual Clauses. This DPA stays in force for as long as Specoria processes Customer Personal Data.