This document sets out the rights and obligations under Article 12 of Personal Data Protection Law No. 6698 ("KVKK") between the business using the Dualyx Appointment platform (the "Platform") as the "Data Controller" and [LEGAL ENTITY NAME] as the "Data Processor", in respect of the personal data the business records on the Platform. It forms an integral part of the Terms of Use.
Version: v1 · Last updated: 4 September 2026
For the customer, appointment, payment, expense, notification, feedback and document data a business records on the Platform, the business is the data controller. The business determines the purposes and means of processing.
[LEGAL ENTITY NAME] acts as the data processor for that data, solely on the business's instructions and within the framework of the Terms of Use. It does not use that data for its own purposes, does not sell it to third parties and does not expose it to another business.
Panel users' account data and the Platform's own security and audit records are not the subject of this Agreement; for those, the data controller is [LEGAL ENTITY NAME] and the KVKK Privacy Notice applies.
Groups of data subjects: The business's customers, third parties requesting appointments, and the recipients to whom the business sends notifications.
Data categories:
The Platform provides no field dedicated to special categories of personal data (KVKK Art. 6). However, free-text areas such as customer notes, appointment notes and uploaded documents can technically hold special category data, including health data.
If special category data is entered into those areas, it is the business's responsibility to secure explicit consent or another condition provided in the Law, to take the adequate measures determined by the Board, and to provide the required notice. [LEGAL ENTITY NAME] does not inspect the content of these fields and assumes no responsibility arising from that content.
The national identification number field on a customer record is optional. This data should be processed only where it rests on a concrete purpose and legal ground; where it is not needed, the field should be left empty. The decision to fill in the field, and its consequences, belong to the business.
[LEGAL ENTITY NAME] shall:
Under KVKK Art. 12/1 the Data Processor is jointly responsible with the business for obligations relating to data security.
The business shall:
The following sub-processors are used to provide the service:
SMS and WhatsApp providers come into play only to the extent the business uses the relevant feature. Where the business configures its own provider account, it is responsible for its relationship with that provider.
This document is updated when the sub-processor list changes, and significant changes are communicated through the Panel. A business that objects to a change has the right to terminate the agreement.
Because hosting and some providers are located outside Türkiye, transfers take place. These transfers are carried out in accordance with the conditions set out in KVKK Art. 9, relying on an adequacy decision, one of the appropriate safeguards (including standard contractual clauses) or one of the exceptions listed in the Law.
If a data subject sends a request about their data to [LEGAL ENTITY NAME], the request is not actioned; the data subject is directed to the business acting as data controller and the business is informed.
The business can satisfy access, correction, deletion and export requests itself through the Panel. Where a request cannot be satisfied from the Panel, technical assistance can be requested from the support screen.
When [LEGAL ENTITY NAME] becomes aware of a personal data breach affecting the business's data, it informs the business without delay and shares what it knows about the scope of the breach, the categories of data affected and the measures taken.
Notifying the Board and the data subjects is the obligation of the business as data controller. [LEGAL ENTITY NAME] provides reasonable support in preparing those notifications.
When the service relationship ends, the business can export its data through the Panel. Closing the account and deleting the data is carried out within the periods and by the means described in the Account and Data Deletion document.
Upon a deletion request, the business's data is deleted or anonymised, subject to retention obligations arising from legislation; copies in backups disappear once the backup cycle completes.
This Agreement may be updated. The current version is published at this address; significant changes are communicated through the Panel.
For questions and requests about data processing: info@dualyxlabs.com · [ADDRESS] · KEP: [REGISTERED E-MAIL ADDRESS]