Skip to content
Atelyea product of Murat Gözel

Data Processing Addendum

Version
1
Effective date

This Data Processing Addendum ("Addendum") governs the processing of personal data that Murat Gözel, a sole proprietor established in Türkiye trading as Atelye ("Atelye", "we", "us"), carries out on behalf of a customer of the Atelye platform ("Customer", "you") under the Terms of Service.

It is written against Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and includes the transfer safeguard described in section 14.

Terms defined in the GDPR — "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", "supervisory authority" — carry their GDPR meanings here.

1. How this addendum applies

This Addendum forms part of the Terms of Service and is incorporated into them automatically. It applies from the effective date shown above, to every Customer, without a separate signature and without a per-Customer negotiation.

That is deliberate. A published, versioned addendum that applies identically to everyone can be read before you commit, can be produced later exactly as it stood on any given date, and does not depend on a countersigned copy surviving in someone's filing system. Superseded versions remain published at /legal/archive/dpa/<version>.

If you require a signed counterpart for your own records, write to legal@atelye.net.

2. The parties and their roles

For personal data that you place on the platform, or that reaches the platform through a channel you have connected — your content, your catalogue and orders, your buyer records, and the messages your customers send you — you are the controller and Atelye is your processor.

For a separate and much smaller set of data, Atelye is itself the controller: the accounts of your staff who sign in to the platform, billing and account records, support correspondence with you, and the operational telemetry and security logs Atelye generates while running the service. That processing is described in the Privacy Policy and is outside this Addendum.

Atelye is established in Türkiye. Its infrastructure is in the European Union. Section 14 explains why that combination matters and what it requires.

3. Subject matter, duration, nature and purpose

Subject matter. The processing of personal data necessary to provide the Atelye platform to you: content management, commerce, and AI-assisted handling of inbound messages from your customers on connected messaging channels.

Duration. For as long as your account is active, and thereafter only for the period described in section 12.

Nature. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission to the sub-processors listed in section 17, restriction, erasure and destruction — by automated means.

Purpose. Solely to provide, secure and support the platform for you, and to carry out the processing you instruct through your use of it. Atelye does not process your personal data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train machine-learning models.

4. Categories of personal data

Depending on which parts of the platform you use:

  • Message content and media — the text, images, audio, video and files exchanged between you and your customers on connected channels, and the reply drafts generated to answer them.
  • Channel-scoped identifiers — the opaque identifier a messaging platform assigns to a person in the context of your account (for example an Instagram-scoped ID, a Page-scoped ID, or a WhatsApp number), together with any display name that platform exposes.
  • Buyer and order records — the names, contact details, delivery and billing addresses, order lines and order history you hold about the people who buy from you.
  • Content you publish — any personal data you choose to place inside your own content, such as an author name or a photograph.
  • Interaction metadata — timestamps, message direction, conversation state, and the record of which of your staff acted on what.

Atelye does not require, and the platform is not designed to receive, special categories of personal data under Article 9 or data relating to criminal convictions under Article 10. The Acceptable Use Policy prohibits routing such data through the conversation surface.

5. Categories of data subjects

  • The people who message you on a connected channel — your customers and prospective customers.
  • The people who buy from you, or on whose behalf a purchase is made.
  • Any individual whose personal data you include in content you publish through the platform.
  • Your own staff, to the extent their identity appears in the record of an action they took. Their account data is covered by the Privacy Policy, not by this Addendum.

6. Processing only on documented instructions

Atelye processes your personal data only on your documented instructions, including as regards transfers to a third country. The Terms of Service, this Addendum, and the configuration and actions you carry out in the platform together constitute your complete documented instructions.

Atelye processes on another basis only where required to do so by a law to which it is subject. In that case it will inform you of that requirement before processing, unless that law prohibits it from doing so on important grounds of public interest.

Atelye will tell you if, in its opinion, an instruction you give infringes the GDPR or another applicable data-protection provision, and may suspend the affected processing until the instruction is withdrawn or amended.

7. Confidentiality

Access to your personal data is restricted to those who need it to provide, secure or support the platform for you. Every person with such access is bound by a duty of confidentiality that survives the end of their engagement.

You should know a specific fact about the shape of this operation: Atelye is run by one person. Administrative access to production systems rests with the operator named in section 20. There is no wider staff to restrict — and equally, no separation-of-duties control to point to. The Security Overview states this among the other things Atelye does not have.

8. Security measures

Atelye implements the technical and organisational measures set out in the Security Overview, which forms Annex II of this Addendum (section 16). Those measures are described at a level of detail sufficient for you to assess them, and every control stated there is one that exists today.

Atelye may change a measure, but not in a way that materially reduces the overall level of security of the processing. A material change follows the notification process in section 19.

9. Sub-processors

General authorisation. You give Atelye general written authorisation to engage sub-processors for the processing described in this Addendum. The current list is published at /legal/subprocessors and forms Annex III (section 17).

Terms imposed on sub-processors. Atelye engages a sub-processor only under a written contract imposing data-protection obligations that are, in substance, no less protective than those in this Addendum, including the transfer safeguards in section 14 where the sub-processor is outside the EEA. Atelye remains fully liable to you for a sub-processor's performance of its obligations.

Change notification — 30 days. Before adding a new sub-processor or replacing an existing one, Atelye will give you at least 30 days' prior notice, sent to the address registered on your account.

Objection window. You may object to a proposed new or replacement sub-processor on reasonable, documented data-protection grounds by writing to legal@atelye.net within those 30 days. Atelye will work with you in good faith towards a resolution — a configuration change, an alternative provider, or withholding the affected feature from your account. If no resolution is reached, you may terminate the affected part of the service without penalty, and section 12 governs what happens to your data.

Emergency replacement. If a sub-processor must be replaced sooner than 30 days to protect the security or continuity of the service — because it has suffered a breach, or has ceased to operate — Atelye will make the change and notify you without undue delay, with the reason. Your right to object under this section is unaffected and runs from that notice.

10. Assistance with your obligations

Data subject requests. Taking into account the nature of the processing, Atelye will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.

A request a data subject sends directly to Atelye is not acted on unilaterally. Atelye forwards it to you promptly and acts only on your instruction. You are the controller; how to answer your customer is your decision, not ours.

The one exception, and it is deliberate: where a person removes the Atelye application from a connected Meta platform or withdraws its access, that platform sends Atelye a deletion instruction directly, and Atelye honours it directly, because the Meta Platform Terms require it to. The Data Deletion page describes that route.

Data protection impact assessments. Atelye will provide you, on request and taking into account the information available to it, with reasonable assistance for a data protection impact assessment and for any prior consultation with a supervisory authority relating to the processing under this Addendum.

Personal data breach. Atelye will notify you without undue delay, and in any event within 24 hours, after becoming aware of a personal data breach affecting your personal data. The notification will describe, so far as known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; and the measures taken or proposed. Where information is not available at once, it follows in phases, without undue delay. Atelye will not delay notifying you in order to complete its own investigation first.

Reporting the breach to a supervisory authority and, where required, to the affected data subjects remains your responsibility as controller. Atelye will provide what you need in order to do so.

11. Personalisation of your own prompts and business context

This is a named processing activity, described here because a processor should not carry out a processing activity its controller has not been told about.

Where you use the AI-assisted messaging features, the platform improves the prompts and business context it uses for your account by drawing on your account's own conversation history, so that replies drafted for you come to reflect how you actually answer.

Three boundaries apply, and they are the point of this section:

  • Within your account only. No signal, statistic, phrasing or example derived from your conversations is used for any other customer's account, and nothing derived from another customer's conversations is used for yours.
  • No verbatim third-party content. A refined prompt or business-context record may encode how you answer — a tone, a recurring policy, a frequently asked question — but not a customer's message text, name, address, order number or channel identifier. Where a refinement would require verbatim content, that content is summarised or discarded rather than copied.
  • It is not model training. Nothing here trains, fine-tunes or otherwise adjusts a machine-learning model. It adjusts the instructions and reference material sent to a model at the time of a request, and only for your account.

This activity is carried out as a processor, under your instructions, as part of providing the service to you. It is not carried out in Atelye's own legitimate interest — framing it that way would make it Atelye's purpose rather than yours and would place it outside your instructions. Its lawful basis is the one you have determined for the underlying conversation processing.

You may ask for the feature to be disabled for your account by writing to support@atelye.net.

12. Deletion or return at the end of the service

On termination or expiry of the Terms of Service, and at your choice notified within 30 days of that date, Atelye will either return your personal data to you in a structured, commonly used, machine-readable format, or delete it. If you make no choice within those 30 days, Atelye deletes it.

Deletion means deletion from live systems. Two qualifications are stated here, because an undisclosed retention is worse than a disclosed one:

  • Backups. Deleted data persists in encrypted database backups until those backups age out on their ordinary retention schedule. Backups are never restored except in a disaster, and the restore procedure re-applies completed deletions before the restored system serves traffic again. The Security Overview states the backup windows.
  • Records Atelye must keep. Atelye retains a content-free record of platform activity — who did what, to which record, and when — for the establishment, exercise or defence of legal claims and to meet its own record-keeping obligations. That record carries references and state changes. It does not carry the content of your customers' personal data.

Atelye will confirm deletion in writing on request.

13. Audit and information rights

Atelye will make available to you the information necessary to demonstrate compliance with Article 28 and with this Addendum, and will allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate.

In practice, and proportionately for an operation of this size:

  • The Security Overview is the standing description of the technical and organisational measures, and it is kept current.
  • You may send a written security or data-protection questionnaire once in any 12-month period, and Atelye will answer it within 30 days.
  • An on-site or hands-on inspection may be requested where you have a specific, documented concern that the material above does not resolve, or where a supervisory authority requires one. It is arranged on reasonable notice, during business hours, without unreasonable disruption to the service, subject to confidentiality — and, except where it follows a personal data breach or is required by a supervisory authority, at your cost.

Atelye holds no SOC 2 report, no ISO 27001 certificate and no third-party security attestation, and does not represent otherwise.

14. International transfers

The direction that matters here is the counter-intuitive one. The platform's servers are inside the European Union — compute and databases at Hetzner in Frankfurt, object storage on Cloudflare R2 in the EU. The operator is established in Türkiye, a third country for which the European Commission has not issued an adequacy decision. So the transfer needing a safeguard is the inbound one — your personal data, as an EU-established controller, being made accessible to a processor in Türkiye — and not the storage location, which never leaves the EU.

The safeguard. For that transfer the parties adopt the Standard Contractual Clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor), which are incorporated into this Addendum by reference and form part of it. The clauses apply as published; nothing in this Addendum is intended to contradict or restrict them, and in the event of a conflict the clauses prevail.

For the purposes of those clauses:

  • The data exporter is you. The data importer is Murat Gözel, trading as Atelye.
  • Clause 7 (docking clause) applies.
  • Clause 9 (use of sub-processors): Option 2, general written authorisation applies, with the notice period set at 30 days (section 9).
  • Clause 11 (redress): the optional independent dispute-resolution paragraph does not apply.
  • Clause 17 (governing law): the law of Ireland.
  • Clause 18 (choice of forum and jurisdiction): the courts of Ireland.
  • Annex I is section 15 of this Addendum. Annex II is section 16. Annex III is section 17.

Where you are established in the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs applies to the same transfer, and the above is read with the modifications that Addendum requires. Where you are established in Switzerland, the clauses are read with the amendments published by the Swiss Federal Data Protection and Information Commissioner.

Transfer impact — Türkiye. The parties have considered the circumstances of the transfer:

  • What is actually transferred. The data stays stored in the EU. What crosses a border is remote administrative and support access from Türkiye, over authenticated and encrypted connections, by the single operator named in section 20, recorded in an append-only activity log.
  • The legal framework in the destination country. Türkiye has a general data-protection statute (Law No. 6698 on the Protection of Personal Data) and is a party to the European Convention on Human Rights and to Convention 108. Turkish criminal-procedure and national-security legislation permits public authorities to compel the production of data or to conduct surveillance in defined circumstances, generally subject to judicial authorisation. Türkiye is not subject to United States surveillance legislation such as section 702 FISA or Executive Order 12333.
  • The realistic exposure. Atelye is a sole proprietor providing business software. It is not a telecommunications operator, not the hosting provider of record for the data, and not a category of entity subject to standing data-production or interception obligations. A Turkish authority seeking data held on EU infrastructure would have to compel the operator personally.
  • Supplementary measures. Data at rest stays on EU infrastructure. Traffic between the operator and production systems is encrypted in transit. Database backups are encrypted client-side before they leave the host, with the key held outside the storage provider. Customer data is isolated at the database row level, so an access is scoped rather than wholesale. Administrative actions are recorded in an append-only log.
  • Commitments on public-authority access. Atelye will notify you of any legally binding request from a public authority for your personal data, unless prohibited from doing so; will challenge a request that appears unlawful or excessive, including by seeking interim measures; and will disclose only the minimum data covered by the request. Where a prohibition on notification applies, Atelye will seek a waiver and will keep a record to give you once the prohibition lapses.

Onward transfers. Where Atelye transfers your personal data to a sub-processor outside the EEA, it does so under that sub-processor's own Article 46 safeguard — in each case, the Standard Contractual Clauses or an equivalent mechanism. Section 17 states each sub-processor's processing location.

This section states a position taken in good faith on the basis of the facts described. It is not legal advice to you and it does not displace your own assessment as controller.

15. Annex I — Description of the processing

A. List of parties.

  • Data exporter (controller): the Customer, as identified by the account registered on the platform, together with the contact details held on that account. Activities relevant to the transfer: use of the Atelye platform for content management, commerce and AI-assisted messaging. Role: controller.
  • Data importer (processor): Murat Gözel, sole proprietor trading as Atelye. Address: Akarca Mah. Fatma Seher Hanım Cad. Yuvam Akarca B1-B1 No: 98 İç Kapı No: 9 41310 İzmit Kocaeli Türkiye. Contact: privacy@atelye.net. Activities relevant to the transfer: providing, securing and supporting the platform. Role: processor.

B. Description of the transfer.

  • Categories of data subjects: as set out in section 5.
  • Categories of personal data: as set out in section 4.
  • Special category data: none. The platform does not require it and the Acceptable Use Policy prohibits routing it through the conversation surface.
  • Frequency of the transfer: continuous, for the duration of the service.
  • Nature and purpose of the processing: as set out in section 3.
  • Retention: for the duration of the account, then as set out in section 12. Conversation records are retained for five years from the last inbound message unless you instruct earlier deletion, which is always honoured. Media and generated drafts follow the conversation they belong to.
  • Transfers to sub-processors: subject matter, nature, duration and location as set out in section 17.

C. Competent supervisory authority. Determined in accordance with Clause 13 of the Standard Contractual Clauses — the supervisory authority of the Member State in which you, as data exporter, are established; or, where you are not established in the EU but have appointed a representative under Article 27, the supervisory authority of the Member State in which that representative is established.

16. Annex II — Technical and organisational measures

The technical and organisational measures implemented by Atelye as data importer, including those ensuring the security of the data, are set out in the Security Overview, which is incorporated here by reference and which carries its own version and effective date.

That page is written to be read as this annex. It describes tenant isolation, authorisation, authentication, secrets management, network and transport security, encryption, activity recording, monitoring, backup and recovery, change control, and the process for reporting a vulnerability. It also states, without softening them, the assurances Atelye does not hold.

17. Annex III — Sub-processors

The list of sub-processors authorised under section 9, with each one's role, the categories of personal data it processes and its processing location, is published and versioned at /legal/subprocessors and is incorporated here by reference.

Changes to that list follow the 30-day notice and objection process in section 9.

18. Disclosure text for your own privacy notice

You cannot name Atelye as a processor in your own privacy notice unless we tell you what to say. The two paragraphs below are written to be copied into your notice and edited to fit it. They are supplied in English and in Turkish.

They deliberately do not state a lawful basis. Which lawful basis applies to your processing is your determination as controller — it depends on your business and your relationship with the people concerned, and it is not ours to choose for you.

English.

Who processes your data. We use Atelye, a business platform operated by Murat Gözel, a sole proprietor established in Türkiye, to manage our website content, our catalogue and orders, and the messages you send us on Instagram, Facebook Messenger and WhatsApp. Atelye acts as our processor and handles personal data only on our instructions. The data concerned may include the content of your messages and any media you send, the identifier the messaging platform assigns to you, your contact and order details where you place an order, and the times of those interactions. It is stored on servers in the European Union.

Artificial intelligence and sub-processing. Replies to your messages may be drafted with the help of artificial intelligence, and a member of our team reviews and approves every reply before it is sent. To do this, Atelye passes the content of the conversation to third-party AI providers acting as its sub-processors. Atelye publishes the full list of its sub-processors at https://atelye.net/legal/subprocessors and the data processing terms that govern them at https://atelye.net/legal/dpa. You can ask to speak to a person at any time.

Turkish.

Verilerinizi kim işliyor. Web sitemizin içeriğini, kataloğumuzu ve siparişlerimizi ve Instagram, Facebook Messenger ile WhatsApp üzerinden bize gönderdiğiniz mesajları yönetmek için, Türkiye'de yerleşik şahıs şirketi Murat Gözel tarafından işletilen Atelye adlı iş platformunu kullanıyoruz. Atelye, veri işleyenimiz sıfatıyla hareket eder ve kişisel verileri yalnızca bizim talimatlarımız doğrultusunda işler. Söz konusu veriler; mesajlarınızın içeriğini ve gönderdiğiniz medya dosyalarını, mesajlaşma platformunun size atadığı kimlik bilgisini, sipariş vermeniz hâlinde iletişim ve sipariş bilgilerinizi ve bu etkileşimlerin zamanını kapsayabilir. Bu veriler Avrupa Birliği'nde bulunan sunucularda saklanır.

Yapay zekâ ve alt işleyenler. Mesajlarınıza verilecek yanıtlar yapay zekâ desteğiyle taslak hâline getirilebilir; gönderilmeden önce her yanıt ekibimizden bir kişi tarafından incelenip onaylanır. Bunun için Atelye, görüşmenin içeriğini kendi alt işleyeni sıfatıyla hareket eden üçüncü taraf yapay zekâ sağlayıcılarına aktarır. Atelye, alt işleyenlerinin tam listesini https://atelye.net/tr/legal/subprocessors adresinde, bunlara uygulanan veri işleme şartlarını ise https://atelye.net/tr/legal/dpa adresinde yayımlar. Dilediğiniz an bir kişiyle görüşmeyi talep edebilirsiniz.

The Turkish paragraphs are a translation provided for your convenience. They are not a KVKK aydınlatma metni and must not be presented as one — a notice under Law No. 6698 is a different instrument with different mandatory content, and preparing one is your responsibility as controller.

19. Changes to this addendum

Atelye may change this Addendum. On a material change it publishes the new version with a future effective date, moves the outgoing version to /legal/archive/dpa/<version>, and notifies you at the address registered on your account at least 30 days before the new version takes effect. Non-material changes — corrections, formatting, link fixes — are made without a version change.

Continuing to use the platform after a new version takes effect constitutes acceptance of it. If you do not accept a material change you may terminate under the Terms of Service before it takes effect, and section 12 governs your data.

20. Contact

Data protection matters: privacy@atelye.net

Contractual matters, including a request for a signed counterpart: legal@atelye.net

Security matters, including vulnerability reports: security@atelye.net

Murat Gözel, trading as Atelye — Akarca Mah. Fatma Seher Hanım Cad. Yuvam Akarca B1-B1 No: 98 İç Kapı No: 9 41310 İzmit Kocaeli Türkiye — +90 532 590 2141

No representative under Article 27 GDPR has been appointed. The Privacy Policy states the position and the circumstances in which one will be.