Data Processing Agreement
Updated:
This Data Processing Agreement (the "Agreement") sets out the rights and obligations of VesselCall ("VesselCall") and the customer company using the app.vesselcall.com platform (the "Customer") for the personal data VesselCall processes on behalf of the Customer and on its instructions. The Agreement is an integral part of the Terms of Use and takes effect when an authorized user of the Customer accepts it on the platform. The Turkish text prevails; this English version is provided for information.
VesselCall's contact details: Türkiye; MERSIS number: to be published once company registration is completed; e-mail: [email protected].
1. Definitions
- Data Protection Law: Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and its secondary legislation; Turkish Law No. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages; and, where applicable, the EU General Data Protection Regulation ("GDPR") and the data protection and electronic communication rules of the recipient's country.
- Customer Personal Data: personal data VesselCall processes on behalf of the Customer under this Agreement, described in Annex 1.
- Platform Database: the vessel, company and business contact information VesselCall compiles on its own behalf from publicly available sources.
- Instructions: this Agreement, the Terms of Use, the Customer's choices and settings on the platform (for example ports, range, sending mode, templates, lists and approvals) and the Customer's written notices.
- Sub-processor: a third-party service provider VesselCall uses to process Customer Personal Data.
- Data Breach: a breach of security leading to the unlawful destruction, loss or alteration of Customer Personal Data, or to its acquisition by or disclosure to unauthorized persons.
Terms not defined here have the meaning given in the Terms of Use and in Data Protection Law.
2. Roles of the parties
- The Customer is the data controller for Customer Personal Data. The Customer decides for which ports and vessels, with which companies, with what content and in which sending mode contact is made. VesselCall processes this data as a data processor, only on behalf of the Customer and in line with the Instructions.
- Using a recipient from the Platform Database for the Customer's sending happens on the Customer's Instruction; the Customer is the controller for that use.
- VesselCall is an independent controller for the Platform Database, the global opt-out list and the data it processes in its customer relationship (for example the account, security, payment, billing and agreement acceptance records of the Customer's users). That processing is described in our Privacy Policy and Personal Data Notice and is outside the scope of this Agreement.
- Under Turkish Law No. 6563 the Customer is the sender and the service provider of the introduction e-mails. VesselCall is an intermediary service provider and has no duty to check the Customer's content in advance (Law Art. 9(1), Regulation Art. 11(3)). VesselCall keeps its right to review content and to suspend sending to prevent abuse.
3. Customer obligations and representations
The Customer:
- accepts and represents that it has a lawful basis under Data Protection Law for processing Customer Personal Data and sending introduction e-mails, that it has given the required notices and that it has obtained explicit consent where Data Protection Law requires it;
- is responsible for the decision to send, for the content of the e-mails and for its obligations as the sender under Law No. 6563 and the commercial message rules of the recipient's country (including, where applicable, the Message Management System (IYS) and VERBIS registry obligations);
- represents that the consent records it enters for countries that require prior consent are real, valid and provable, and provides the consent documents to VesselCall and the competent authorities on request;
- does not enter special categories of personal data (for example health, religion or criminal convictions), or more personal data than business communication requires, into the platform, templates or lists;
- ensures that its Instructions comply with Data Protection Law and answers VesselCall's reasonable requests about opt-outs, complaints, consent documents and requests from authorities without delay;
- is responsible for the security of its account: it gives access only to authorized persons, keeps sign-in details confidential and reports unauthorized use without delay. The actions of its users on the platform count as the Customer's actions. Risks arising from not using two-factor sign-in are borne by the Customer;
- records opt-outs, objections and erasure requests it receives directly from recipients or other data subjects in the platform lists, or forwards them to VesselCall, without delay.
4. VesselCall obligations
VesselCall:
- processes Customer Personal Data only on the Instructions. If it believes an Instruction breaches Data Protection Law, it informs the Customer and may suspend the processing concerned until the Instruction is clarified. If Data Protection Law requires processing beyond the Instructions, it informs the Customer in advance unless the law prohibits this;
- ensures that its employees and other persons with access to the data are bound by confidentiality and that access is limited to those whose duties require it;
- applies the technical and organizational measures in Annex 2. It may update the measures as technology develops, without lowering the overall level of protection;
- does not use Customer Personal Data for its own purposes, sell it or disclose it to third parties, except under the Instructions, to Sub-processors (section 6), for the independent processing in section 5 and as required by law towards competent authorities;
- gives reasonable assistance, taking into account the nature of the processing and the information available to it, for the Customer's obligations under Data Protection Law (for example data security, Data Breach notification, data protection impact assessments and prior consultation of the supervisory authority).
5. Independent processing by VesselCall
The Customer agrees that VesselCall carries out the following processing as an independent controller:
- Global opt-out list: when a recipient opts out or objects, VesselCall adds a one-way hash of the address or domain to the global opt-out list. No e-mail is sent again to that address or domain through the platform on behalf of any customer, and waiting e-mails are cancelled. This entry cannot be removed at the Customer's request.
- Database accuracy: delivery results of sending (for example permanent bounces and invalid addresses) may be used to keep the Platform Database accurate.
- Abuse prevention: bounce, complaint and opt-out rates and sending records may be monitored to protect the security and reputation of the shared sending infrastructure.
- Anonymous statistics: aggregated, anonymous statistics that do not identify individuals may be produced to improve the service.
6. Sub-processors
- The Customer gives VesselCall general authorization to use Sub-processors. The current Sub-processor categories are listed in Annex 3; their names and addresses are provided on written request.
- VesselCall enters into written agreements with Sub-processors containing data protection obligations no less protective than those in this Agreement, or relies on their standard service terms providing that level of protection.
- VesselCall informs the Customer through the platform or by e-mail at least 10 days before adding or replacing a Sub-processor. The Customer may object in writing within 10 days of the notice on reasonable data protection grounds. If the parties cannot find a reasonable solution, the Customer may terminate the affected service by notice, and prepaid fees for the unused period are refunded. This is the Customer's sole remedy in case of objection.
- In urgent cases where security or continuity of service requires it, a change may be made without prior notice; notice is then given without delay and the Customer's right to object remains.
- VesselCall is responsible to the Customer for its Sub-processors' compliance with this Agreement, within the limits in section 12.
7. International transfers
- The platform infrastructure is hosted in a data center in Finland, in the European Union; encrypted backup copies are also kept in Türkiye. Some Sub-processors may be located outside Türkiye and the EU (Annex 3). The Customer authorizes the transfer of Customer Personal Data to these countries for the provision of the service.
- VesselCall bases transfers abroad on one of the safeguards in Article 9 of KVKK (for example the standard contract published by the Turkish Personal Data Protection Board, notified to the Board). Where the GDPR applies, it relies on the appropriate safeguards in Chapter V of the GDPR.
- If Data Protection Law requires a separate standard contract between the parties, the parties sign it without delay. If the standard contract and this Agreement conflict, the standard contract prevails.
- VesselCall may move the service infrastructure to a data center in Türkiye. The move is subject to the notice procedure in section 6.
8. Data breach
- VesselCall informs the Customer without undue delay, and where possible within 48 hours, after becoming aware of a Data Breach affecting Customer Personal Data.
- The notice includes, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, the measures taken or proposed and a contact person. Information may be provided in phases.
- Notifying the Personal Data Protection Board and data subjects is the Customer's obligation as the controller. VesselCall gives reasonable assistance and takes the measures needed to limit the effects of the breach.
- Where the law allows, the Customer shares public statements that name VesselCall with VesselCall in advance.
- Notice of a Data Breach is not an admission of fault or liability by VesselCall.
9. Data subject requests
- VesselCall forwards requests it receives about Customer Personal Data to the Customer and does not answer them on the Customer's behalf. Opt-outs and objections to direct marketing are the exception: VesselCall applies them at once (section 5).
- VesselCall answers requests about the Platform Database as the controller.
- VesselCall supports the Customer in answering requests with the tools on the platform (for example lists and records) and with reasonable additional help. A reasonable fee may be charged for help beyond the usual level.
10. Information and audits
- VesselCall provides the information needed to show compliance with this Agreement (for example a summary of security measures and the Sub-processor list) within a reasonable time after the Customer's written request.
- Where the written information is not sufficient, or at the request of a competent authority, the Customer may carry out an audit, or have an independent auditor bound by confidentiality carry it out, at most once a year, with at least 30 days' written notice, during business hours and without disrupting VesselCall's operations. The auditor may not be a competitor of VesselCall.
- An audit does not cover other customers' data, VesselCall's data sources and methods, source code, trade secrets or information whose disclosure would endanger security. The Customer bears the cost of the audit.
- If an audit finds a breach of this Agreement, VesselCall makes the necessary corrections within a reasonable time.
11. Term, termination, deletion and return
The Agreement remains in force for the term of the Customer's subscription and for as long as VesselCall continues to process Customer Personal Data.
Before the subscription ends, the Customer may request a copy of its records; VesselCall provides it in a common file format (for example CSV) within a reasonable time.
Within 30 days of termination VesselCall deletes or anonymizes Customer Personal Data, except:
- records that must be kept by law (for example commercial message and opt-out records for at least 3 years under Regulation Art. 13(2), and commercial books and documents);
- the global opt-out list (section 5);
- records needed to establish or defend legal claims, for the applicable limitation period;
- backups, until they are deleted in the normal backup cycle.
Retained records are processed only for these purposes and are kept out of use.
The Platform Database does not belong to the Customer and is not deleted on termination.
12. Liability and indemnity
- VesselCall's total liability under this Agreement and the Terms of Use is limited to the fees the Customer paid to VesselCall in the 12 months before the event giving rise to the damage. VesselCall is not liable for indirect damage, loss of profit, loss of business or reputation, or business interruption caused by loss of data.
- VesselCall is not liable for damage arising from processing carried out in line with the Instructions.
- The Customer covers third-party claims, administrative fines, court costs and reasonable attorney fees arising from (a) its Instructions, content or sending decisions breaching Data Protection Law, (b) a missing lawful basis, notice or consent, and (c) its breach of this Agreement or the Terms of Use. VesselCall notifies the Customer of any such claim without delay and allows the Customer to take part in the defense.
- If the parties are held jointly liable towards a data subject or an authority (for example under KVKK Art. 12(2)), liability between them is shared according to their degree of fault, subject to the limits in this section.
- The limits in this section do not apply in cases of intent or gross negligence or in other cases where the law does not allow liability to be limited (Turkish Code of Obligations No. 6098, Art. 115).
13. Confidentiality
The parties protect confidential information learned under this Agreement and use it only for the purpose of the Agreement. The Customer keeps confidential the information on VesselCall's data sources, methods, details of its security measures and prices. Information that must be disclosed by law is outside this obligation.
14. Changes
VesselCall may update this Agreement because of changes in Data Protection Law, decisions of competent authorities or changes in the service. The new version is presented to the Customer for acceptance on the platform, and use of the platform may be conditional on that acceptance. A Customer who does not accept the new version may terminate the agreement, and prepaid fees for the unused period are refunded.
15. Other provisions
- On matters of personal data protection this Agreement takes precedence over the Terms of Use, subject to section 7.3.
- The Agreement is accepted electronically on the platform. The accepted version, the date and time of acceptance, the IP address and the browser details are recorded. The parties agree that these records and VesselCall's system records form an evidence agreement under Article 193 of the Turkish Code of Civil Procedure No. 6100 and are valid evidence unless proven otherwise.
- The Agreement is governed by Turkish law. the Courts and Enforcement Offices of İstanbul (Central) have jurisdiction over disputes.
- If a provision of the Agreement is invalid, the other provisions remain in force.
- The Turkish text of the Agreement prevails; texts in other languages are for information.
Annex 1: Details of the processing
| Item | Description |
|---|---|
| Subject matter and nature | Preparing introduction e-mails on behalf of the Customer (templates and translation), selecting the recipient, applying the sending rules, sending the e-mails, tracking delivery and bounces, handling opt-outs and objections, keeping and reporting sending records |
| Purpose | Introducing the Customer's maritime services to companies that manage, operate or own vessels approaching ports |
| Data subjects | Employees and representatives of recipient companies whose business contact details are used; persons the Customer adds to its exclusion and consent lists; the Customer's employees named in template signatures and sender identities |
| Data categories | Identity (name, if any); contact (business e-mail address, telephone if any); professional (company, department, role); marketing (sending history, e-mail content, delivery status, opt-out, objection and consent records); transaction security (sending and delivery records, bounce reports) |
| Special categories | Not processed |
| Duration | For the subscription term and the retention periods in section 11 |
| Places of processing | Data center in Finland (EU); Türkiye (encrypted backup copies and e-mail delivery); countries of the Sub-processors in Annex 3 |
Annex 2: Technical and organizational measures
VesselCall applies at least the following measures:
- All connections to the platform and the website are encrypted (HTTPS, HSTS).
- Passwords are stored hashed with Argon2id; failed sign-in attempts are rate limited and lead to a temporary account lock.
- Two-factor sign-in (TOTP) is available and is mandatory for admin accounts.
- Session cookies are protected with the HttpOnly, Secure and SameSite attributes; requests that change data are protected against CSRF.
- Secret keys and account credentials (for example domain signing keys and service passwords) are stored encrypted.
- Customer data is separated by customer at the application layer; a customer cannot access another customer's data.
- Administrative actions are logged; administrative access to the servers is limited to authorized personnel.
- The servers use a firewall, protection that blocks repeated failed sign-in attempts and automatic security updates.
- The database is backed up daily; encrypted copies of the backups are kept off the server and restores are tested regularly.
- E-mails are DKIM-signed with the Customer's domain; sending rate limits, gradual warm-up and automatic pausing in risky situations are applied.
- Opt-outs are applied at once; the global opt-out list keeps addresses and domains only as one-way hashes.
- Employees and other persons with access are bound by confidentiality; access rights are limited to what their duties require.
Annex 3: Sub-processor categories
| Service | Location | Data processed |
|---|---|---|
| Server hosting | Finland (EU) | Customer Personal Data on the platform |
| E-mail delivery | Türkiye | Sent e-mails, recipient addresses, delivery and bounce reports |
| AI text translation | Countries outside Türkiye and the EU, including the USA | Template text only; no recipient data is sent. Information written into a template (for example a name in the signature) is processed as part of the text |
| Instant notifications (optional) | Countries outside Türkiye and the EU | If a Customer user links a Telegram account, the content of the notifications sent to that user |