Skip to content
SPOCK
How it works Analytics Platforms Features Packages
TREN
Request a demo

Legal

Data Processing Agreement

This agreement sets out the rules for personal data processed on customers' behalf within the GOSpock service and is an annex to the service contract.

Last updated: 8 October 2026Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti.

Contents

  1. 1. Parties and nature of this agreement
  2. 2. Definitions
  3. 3. Subject matter, duration, nature and purpose of processing
  4. 4. Categories of data subjects and personal data
  5. 5. Controller's instructions and obligations
  6. 6. Processor's obligations
  7. 7. Security measures
  8. 8. Assistance with data subject requests
  9. 9. Personal data breach notification
  10. 10. Sub-processors
  11. 11. Transfers abroad
  12. 12. Audits
  13. 13. Return and deletion of data
  14. 14. Liability
  15. 15. Term, precedence and governing law
  16. 16. Contact

This English text is a translation provided for convenience. The Turkish version (Veri İşleme Sözleşmesi) is the governing version; in case of any discrepancy, the Turkish text prevails.

1. Parties and nature of this agreement

This Data Processing Agreement ("Agreement") is entered into between the customer using the GOSpock service (the "Customer" or "Controller") and Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti. (the "Company" or "Processor").

This Agreement is an annex to and an integral part of the service contract or order form signed between the Customer and the Company (the "Service Contract"); it takes effect by reference in the Service Contract or by separate signature of the parties. Terms not defined in this Agreement have the meaning given in the Terms of Use.

This Agreement governs the relationship between data controller and data processor under Article 12 of Turkish Personal Data Protection Law No. 6698 ("KVKK"). To the extent the EU General Data Protection Regulation ("GDPR") applies to the Customer's activities, this Agreement also serves as the data processing agreement under Article 28 GDPR.

For personal data of Panel users, gospock.com visitors and business contacts, the Company is the data controller; this data is outside the scope of this Agreement and is described in the Privacy Policy and the KVKK Notice.

2. Definitions

  • Personal data, data subject, controller, processor, processing: have the meanings given in the KVKK and, where applicable, the GDPR.
  • End user: a data subject who uses the Customer's website or mobile app and whose data is processed within the Service.
  • Service: the GOSpock push notification, campaign management, event analytics and campaign attribution service.
  • Sub-processor: a third party used by the Company to process personal data on the Customer's behalf in order to provide the Service.
  • Personal data breach: a breach of security leading to personal data being obtained by others through unlawful means, or to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Board: the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).

3. Subject matter, duration, nature and purpose of processing

  • Subject matter: the Company's processing of personal data of the Customer's end users on the Customer's behalf while providing the Service.
  • Duration: the term of the Service Contract plus the period provided for the return and deletion of data after the contract ends (Section 13).
  • Nature: collecting data through the SDK, recording, storing, structuring, querying, reporting and aggregating it; transferring the data needed for delivery to push services; deleting or anonymising data.
  • Purpose: sending web, iOS and Android push notifications; targeting, scheduling and reporting campaigns; test sends; event analytics and live monitoring; attributing events within 30 minutes after a notification click or a link with the gs_cid parameter to the campaign; keeping the Service secure, preventing abuse and supporting the Customer.

4. Categories of data subjects and personal data

Category of data subjects: end users who use the Customer's website or mobile app and interact with the Service in environments where the SDK is integrated.

Data categoryPersonal dataNotes
Device and session dataDevice id (udid), session id, platform (web/iOS/Android), app version, SDK versionThe device id is a random UUID generated by the SDK.
Notification dataPush token or web push subscription (endpoint and keys), notification permission state, notification channel preferencesRecords reported invalid by the push service are deactivated.
Customer user idThe Customer's own user id sent with an identify() callA pseudonymous id chosen by the Customer; the Company does not ask for names, e-mail addresses or phone numbers.
Event dataEvents and their properties: screens and content viewed, videos started, searches, notification received/opened, campaign and variant id, UTM parametersEvent and property names are chosen by the Customer.
Time dataClient and server timestamps of events—
IP addressThe end user's IP addressUsed transiently only for security, rate limiting and abuse prevention; not stored with events.

Data not processed: the Service does not collect precise location, contacts, advertising identifiers or special categories of personal data. The Customer agrees not to send such data, or direct identifiers such as names, e-mail addresses or phone numbers, in event properties.

Retention: raw event data is kept for the retention period of the Customer's package (90, 180 or 395 days; for Enterprise, the period set in the Service Contract) and, unless the Service Contract provides otherwise, in any case for no longer than 13 months. Aggregated statistics that contain no personal data may be kept longer. Device records and push tokens are kept while the device is active.

5. Controller's instructions and obligations

The Customer is the controller that determines the purposes and means of processing end user data. The Customer's instructions consist of the Service Contract, this Agreement, the settings the Customer makes in the Panel, the campaigns it creates, the calls it makes through the SDK and API, and any additional written instructions. Additional instructions beyond the scope of the Service may be charged separately.

The Customer is responsible for:

  • having a lawful basis for processing end user data under Articles 5 and 6 KVKK and, where applicable, Articles 6 and 9 GDPR;
  • informing end users under Article 10 KVKK and, where applicable, Articles 13–14 GDPR, and naming GOSpock as a processor in its privacy notice;
  • obtaining notification permission through the operating system or browser, and providing cookie and consent notices on its own websites and apps;
  • complying with Law No. 6563 and the rules of the Message Management System (İYS) for commercial electronic messages;
  • not sending special categories of personal data and not processing data of children known to be under 13 in breach of the law;
  • deciding which platforms and notification channels to enable and assessing the consequences (Section 11);
  • fulfilling its own legal obligations, such as registration with the Data Controllers' Registry (VERBİS);
  • the confidentiality of its secret API keys and the actions of its Panel users.

6. Processor's obligations

The Company:

  • processes personal data only on the Customer's documented instructions and for the purpose of providing the Service, and does not use it for its own purposes. If the law requires other processing, it informs the Customer before processing unless legally prohibited;
  • informs the Customer immediately if, in its opinion, an instruction infringes the KVKK, the GDPR or other legislation;
  • ensures that its employees and other authorised persons with access to personal data are bound by confidentiality; under Article 12(4) KVKK this obligation continues after they leave. Company staff access personal data only when needed, for example for support, and only to the extent needed;
  • implements the technical and organisational measures listed in Section 7;
  • assists the Customer with data subject requests, personal data breaches and dealings with the Board or other competent authorities under Sections 8 and 9;
  • where the Customer considers it appropriate, provides reasonable information about the Service for data protection impact assessments carried out by the Customer;
  • makes available to the Customer the information demonstrating compliance with this Agreement under Section 12.

The Company may create anonymous, aggregated statistics that contain no personal data and identify no one, in order to operate and improve the Service; anonymised data is not personal data.

7. Security measures

Under Article 12(1) KVKK and, where applicable, Article 32 GDPR, the Company applies the following technical and organisational measures to prevent unlawful processing of and access to personal data and to safeguard it:

  • encryption in transit (HTTPS/TLS);
  • storing Panel user passwords as hashes;
  • two-factor authentication and passkey support for Panel users;
  • role-based access control;
  • separation of the data of each app under an account;
  • separation of secret API keys from public SDK keys, and the ability to define allowed web origins for SDK keys;
  • rate limiting and abuse prevention;
  • audit logs of administrative actions;
  • access to data by Company staff only when needed, for example for support;
  • regular backups;
  • hosting of servers and databases in data centers in Türkiye.

The Company may update these measures in line with technological developments, but will not make changes that lower the overall level of security.

8. Assistance with data subject requests

Responding to data subjects' requests under Article 11 KVKK and, where applicable, Articles 15–22 GDPR is the Customer's responsibility. Taking into account the nature of the processing, the Company provides the Customer with reasonable technical and organisational assistance in responding to such requests (e.g. locating, exporting or deleting the data associated with a particular device id or Customer user id).

If a data subject submits a request directly to the Company and the request can be linked to a particular Customer, the Company forwards it to the Customer without delay, without responding to it itself, and refers the data subject to the Customer.

9. Personal data breach notification

The Company notifies the Customer of a personal data breach affecting personal data it processes on the Customer's behalf without undue delay and at the latest within 48 hours of becoming aware of it. This period is set so that the Customer can notify the Board as soon as possible and within 72 hours of becoming aware of the breach under Article 12(5) KVKK (and, where applicable, the competent supervisory authority under Article 33 GDPR).

The notification includes, to the extent known at the time: the nature and time of the breach, the categories and approximate numbers of data and data subjects concerned, its likely consequences, the measures taken or proposed, and the Company's contact details. Information not yet known is provided without delay as it becomes available.

The Company immediately takes the measures necessary to limit the effects of the breach and provides reasonable assistance with the Customer's notifications to the Board and to data subjects. The Company does not notify data subjects about the breach without the Customer's approval, except where required by law.

10. Sub-processors

The Customer gives the Company general authorisation to use the following categories of sub-processors to provide the Service:

Sub-processorActivityLocation
Data centers / hosting provider in TürkiyeHosting of servers and databases, backupsTürkiye
Google Firebase Cloud Messaging (Google LLC / Google Ireland Ltd.)Delivery of Android notifications and of iOS notifications through FirebaseAbroad
Apple Push Notification service (Apple Inc.)Delivery of iOS notifications and Safari web notificationsAbroad
Browser push services (Google, Mozilla, Apple, Microsoft)Delivery of Web Push notifications to the relevant browserAbroad
E-mail service providersDelivery of account-related e-mails (invitations, password resets, limit warnings); no end user data is sentDepends on the provider

Only the data needed for delivery (the push token or web push subscription and the notification content: title, text, image link, link) is transferred to push services. Using these services is inherent to the Service, and the Customer decides to use them by enabling the relevant platforms and channels.

The Company imposes on sub-processors data protection obligations essentially equivalent to those in this Agreement; for the large platform providers (Google, Apple, Mozilla, Microsoft), these obligations are set by the provider's standard terms. The Company is responsible to the Customer for the acts of its sub-processors within the framework of this Agreement and the Service Contract.

Changes and right to object: the Company informs the Customer by e-mail or through the Panel at least 30 days before adding or replacing a sub-processor. The Customer may object in writing on reasonable data protection grounds within 15 days of the notice. If the parties cannot reach a reasonable solution, the Customer may terminate the Service Contract for the affected part of the Service before the change takes effect. An objection to a push service can also be addressed by the Customer disabling the relevant platform or channel.

11. Transfers abroad

The Company's servers and databases are hosted in data centers in Türkiye. Personal data is transferred abroad only for push delivery, as inherent to the Service, to the push services listed in Section 10. The data transferred is limited to what is needed for delivery (the push token or web push subscription and the notification content); event data is not transferred abroad.

These transfers are made under Article 9 KVKK as amended by Law No. 7499, in force since 1 June 2024:

  • where there is an adequacy decision for the destination country, that decision is relied on;
  • where there is no adequacy decision, one of the appropriate safeguards, such as the standard contracts published by the Board, is provided; standard contracts are notified to the Personal Data Protection Authority within 5 business days of signature;
  • where appropriate safeguards cannot be provided, a transfer may only be made to the extent the conditions of the occasional-transfer exceptions listed in the law are met.

For end user data, the Customer as controller decides to use these notification channels by enabling the relevant platforms and channels. The Customer is responsible for mentioning these transfers in its own privacy notice and for taking any steps required on its side; the Company provides reasonable assistance with this.

Where the Customer transfers personal data from the European Economic Area to Türkiye within the scope of the GDPR, the parties will, to the extent necessary, separately sign the European Commission's standard contractual clauses.

12. Audits

On the Customer's written request, the Company provides documents and information demonstrating its compliance with this Agreement. Audits are primarily carried out through these documents and the Company's answers to the Customer's written questions.

If the documents are insufficient, or if the Board or another competent authority requires it, the Customer may carry out an audit itself or through an independent auditor who is not a competitor of the Company and is bound by confidentiality. Such audits take place with at least 30 days' written notice, no more than once a year, during business hours, in a way that does not affect the operation of the Service or the confidentiality of other customers' data, and at the Customer's expense. Audits following a personal data breach or at the request of a competent authority do not count towards the annual limit.

13. Return and deletion of data

After the Service Contract ends for any reason, the Company deletes or anonymises the personal data it processes on the Customer's behalf within 90 days, except for data it is required by law to retain. Before this period ends, the Customer may request an export of its data in a commonly used, machine-readable format by writing to info@gospock.com.

Copies in backups are deleted within the normal backup cycle and are kept inaccessible until deleted. Data that must be retained by law is kept only for that purpose and for the necessary period. On the Customer's request, the Company confirms in writing that deletion or anonymisation has been completed.

14. Liability

The parties' liability under this Agreement is subject to the liability provisions and limitations in the Service Contract and the Terms of Use. These limitations do not apply to liability for intent or gross negligence or to liability that cannot be limited by law.

The parties acknowledge that under Article 12(2) KVKK they may be jointly liable towards data subjects and competent authorities for taking data security measures. As between the parties, each party is liable for damage resulting from its own breach of its obligations.

15. Term, precedence and governing law

This Agreement takes effect together with the Service Contract and remains in force until the Company stops processing personal data on the Customer's behalf. In matters of personal data protection, if this Agreement conflicts with the Service Contract or the Terms of Use, this Agreement prevails unless the parties expressly agree otherwise.

The Company may update this Agreement to comply with changes in legislation; changes that materially affect the Customer's rights are notified at least 30 days before they take effect.

This Agreement is governed by Turkish law; the İstanbul (Çağlayan) Courts and Enforcement Offices have jurisdiction over disputes. Where the GDPR applies mandatorily, its relevant provisions remain reserved. The Turkish text of this Agreement is the governing version.

16. Contact

For notices, personal data breach notifications and requests relating to this Agreement:

  • Processor: Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti.
  • Address: İstiklal Mah. Piyalepaşa Bulv. No:22/1 B-C Blok, Beyoğlu / İstanbul, Türkiye
  • Tax office and number: Kasımpaşa Vergi Dairesi, 6300431044
  • E-mail: info@gospock.com

Notices from the Company to the Customer are sent to the e-mail address specified in the Service Contract or the account owner's e-mail address registered in the Panel. Effective and last updated: 8 October 2026.

Other legal documents

  • Terms of Use
  • Privacy Policy
  • KVKK Notice
  • Cookie Policy
SPOCK

Push notifications and event analytics for web, iOS and Android.

info@gospock.com

Legal

  • Terms of Use
  • Privacy Policy
  • KVKK Notice
  • Cookie Policy
  • Data Processing Agreement

Company

Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti.
İstiklal Mah. Piyalepaşa Bulv. No:22/1 B-C Blok
Beyoğlu / İstanbul
Kasımpaşa Tax Office · Tax no 6300431044
info@gospock.com
© 2026 GOSpock. All rights reserved. GOSpock is a service of Neden Olmasın Reklam ve İlet. Hiz. Dan. Tic. Ltd. Şti..