Data Processing Addendum (DPA)

This DPA forms part of the Terms of Service for Pinlyx

Not affiliated with Telegram

1. Overview

This Data Processing Addendum ("DPA") governs the processing of personal data on behalf of Customer by EMİRHAN GÜVEN GÜVEN YAZILIM HİZMETLERİ, a sole proprietorship registered in Istanbul, Türkiye (MERSİS 4872729489000001), operating as "Pinlyx", in connection with the services available at pinlyx.com and app.crmsolid.com, and forms part of the Terms of Service.

Capitalized terms not defined in this DPA have the meanings set out in the Terms of Service.

2. Definitions

  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing" have the meanings in GDPR Article 4
  • "Customer Data" means Personal Data submitted to the Service by or on behalf of Customer
  • "Subprocessor" means any Processor engaged by Pinlyx to process Customer Data

3. Roles & Responsibilities

  • Customer is the Controller of Customer Data; Pinlyx is the Processor
  • Customer determines the purposes and means of processing Customer Data
  • Pinlyx processes Customer Data only on documented instructions from Customer

4. Scope of Processing

  • Subject Matter: Provision of Telegram CRM AI services
  • Duration: For the subscription term and 30 days thereafter for export
  • Nature and Purpose: Hosting, storage, messaging automation, analytics, support
  • Categories of Data: Contacts, messages, identifiers, usage logs
  • Data Subjects: Customer’s end-users, leads, and contacts

5. Security Measures

Pinlyx implements appropriate technical and organizational measures, including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Access controls, least privilege, and MFA
  • Network segmentation and firewalling
  • Regular security assessments and penetration testing
  • Employee training and confidentiality obligations

6. Subprocessors

Customer authorizes the use of Subprocessors for the delivery of the Service. The current list of Subprocessors is available upon request atsupport@pinlyx.com. Pinlyx will provide notice of material changes and allow objections where required by law.

7. International Transfers

Where Customer Data is transferred outside the EEA/UK, Pinlyx uses appropriate safeguards, including Standard Contractual Clauses (SCCs) and supplementary measures. Primary data processing is in the European Union (Frankfurt, Germany).

8. Data Subject & Supervisory Authority Assistance

  • Pinlyx assists Customer in fulfilling data subject requests (access, deletion, etc.)
  • Pinlyx assists with DPIAs and consultations with supervisory authorities as required

9. Incident Management & Breach Notification

  • Pinlyx maintains an incident response program
  • Pinlyx notifies Customer without undue delay after becoming aware of a Personal Data Breach
  • Pinlyx provides information reasonably required for Customer’s notifications

10. Data Retention & Deletion

  • Customer Data is retained for the subscription term
  • Upon termination or request, Pinlyx deletes Customer Data within 30 days unless legally required to retain
  • Backups roll off within 90 days

11. Audit & Compliance

  • Upon request, Pinlyx provides available audit reports and security documentation
  • Customer may conduct audits up to once per year with reasonable notice and scope
  • Audits are subject to confidentiality and may be satisfied by third-party certifications

12. Termination

  • This DPA terminates automatically upon termination of the Terms of Service
  • Obligations that by their nature should survive, will survive (e.g., confidentiality)

13. Contact & Notices

For privacy and data protection matters, contact our DPO atprivacy@pinlyx.com.

We value your privacy

We use cookies to improve our site, analyze traffic, and personalize ads. You can accept all, reject non-essential, or customize your choices. Read our Cookie Policy.