This Data Processing Agreement ("DPA") forms part of the Subscription Terms between Polatof, trading as Edunison, and the customer institution (the "Customer"). It applies wherever the Customer is the controller of personal data and we process that data on the Customer's behalf — which is the case for every student, parent, guardian and staff record held in the product. It is written to meet Article 28 of Regulation (EU) 2016/679 ("GDPR") and Article 12 of Turkish Law No. 6698 ("KVKK"). Where this DPA and the Subscription Terms conflict on the processing of personal data, this DPA governs.
1. Roles and subject matter
**Controller.** The Customer institution decides why and how personal data about its students, parents, guardians and staff is processed. It is the controller, and it is the party a parent asks about their child's record.
**Processor.** We process that data only to provide the Service. We are the processor.
We are a separate controller for the Customer's own account data — the names, work addresses and billing details of the people who administer the subscription — and that processing is described in the Privacy Policy, not here.
The subject matter, duration, nature, purpose, categories of data and categories of data subjects are set out in Annex 1.
2. Our instructions
We process personal data only on the Customer's documented instructions, including on transfers to a third country. The Subscription Terms, this DPA and the Customer's use of the product's own features are those instructions.
If we are required by Turkish or European Union law to process personal data beyond those instructions, we will tell the Customer before processing, unless that law forbids us from telling them on important grounds of public interest.
We will tell the Customer if, in our opinion, an instruction infringes the GDPR, the KVKK or other applicable data protection law. We may suspend an instruction we consider unlawful until it is withdrawn or confirmed in writing.
3. Confidentiality
Every person we authorise to process personal data is bound by a duty of confidentiality that survives the end of their engagement, and is given access only to what their role requires.
Access inside the product is limited by role and by institution. Permissions are resolved on every request on the server, and a change to a person's permissions is recorded with an audit trail.
4. Security
We implement appropriate technical and organisational measures under Article 32 GDPR and Article 12 KVKK. The measures the product actually implements include:
Every database query is scoped to the institution that owns the record, so one institution cannot read another's data.
Passwords are stored as bcrypt hashes. Password reset tokens are single-use and stored hashed.
Authorisation is enforced on the server for every request, not by hiding menu items, and can be narrowed to an individual user.
Personal data is encrypted in transit over TLS.
Card data never reaches our systems: it is captured and stored by iyzico on its own secure page.
**We hold no ISO 27001, SOC 2 or equivalent certification, and we do not claim one.** The measures above are what the product does; they are not a certification.
5. Sub-processors
The Customer gives a general authorisation for us to engage sub-processors. Each is bound by a written agreement imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for their performance.
The sub-processors engaged as at the date of this DPA are listed in section 4 of the Privacy Policy, with the country of each. That list is the operative one and is kept current.
We give reasonable prior notice of a new or replacement sub-processor to any Customer who has asked to be notified. If the Customer objects on reasonable data protection grounds within fourteen (14) days, we will use reasonable efforts to make the Service available without that sub-processor; if we cannot, the Customer may terminate the affected part of the subscription and receive a refund of fees paid for the unused remainder of the term.
6. International transfers
The database that holds customer data is provisioned in the European Union (Frankfurt, eu-central-1) and the file store in the region fra1, Frankfurt. Some sub-processors are established in the United States.
Where personal data is transferred out of the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporated into our agreements with those providers, together with the technical measures in section 4. Where the recipient is certified under the EU-U.S. Data Privacy Framework, we may rely on that adequacy decision instead.
Transfers out of Türkiye are made in accordance with Article 9 KVKK.
A copy of the relevant transfer safeguards is available on request to support@edunison.com.
7. Helping the Customer meet its own duties
**Data subject requests.** The product lets the Customer read, correct, export and delete the records it holds, so most requests can be answered without us. If a data subject comes to us directly, we will not answer on the Customer's behalf; we will pass the request on without undue delay. Where the Customer still needs our help, we will give it, taking into account the nature of the processing.
**Impact assessments.** We will give the Customer the information it reasonably needs for a data protection impact assessment or a prior consultation with a supervisory authority, to the extent that information is available to us.
We may charge for assistance that goes materially beyond what Article 28(3)(e) and (f) GDPR requires, at our then-current rates, and will say so before starting.
8. Personal data breach
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data we process for it, and in any event within seventy-two (72) hours.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot give all of it at once, we will give it in phases without further undue delay.
Notifying the supervisory authority and the affected individuals is the Customer's decision as controller, unless the law places the duty on us directly. We will not make that notification on the Customer's behalf without its instruction.
9. Return and deletion
On the Customer's instruction, and in any event at the end of the subscription, we will return the Customer's data in a structured, commonly used, machine-readable format, or delete it, at the Customer's choice.
Unless the Customer instructs otherwise, we delete customer data within thirty (30) days of the end of the subscription.
We keep personal data beyond that period only where Turkish or European Union law requires it — in particular the financial records we are required to retain for ten (10) years — and only for as long as that law requires.
Deletion in the product is by archiving rather than erasure where a record must stay referable for the institution's own accounting; the Privacy Policy explains which records those are.
10. Audits and information
We will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
An audit may be requested once in any twelve (12) month period, on thirty (30) days' written notice, during business hours, in a way that does not disrupt the Service or the confidentiality of other customers' data. A supervisory authority's audit is not subject to those limits.
Where a documented answer to the Customer's questions or a copy of our written sub-processor terms meets the need, that may be provided instead of an on-site inspection.
11. Term, liability and governing law
This DPA takes effect when the Subscription Terms do and lasts as long as we process personal data for the Customer.
Each party's liability under this DPA is subject to the limitations and exclusions in the Subscription Terms, including the total aggregate liability cap. Nothing in this DPA limits a liability that cannot be limited by law, including a data subject's rights against either party.
This DPA is governed by the laws of the Republic of Türkiye, and the courts and enforcement offices of Istanbul, Türkiye, have exclusive jurisdiction, as set out in the Subscription Terms.
Questions about this DPA: support@edunison.com.
Annex 1 — Details of the processing
**Subject matter.** Provision of the Edunison school management service to the Customer.
**Duration.** The term of the subscription, plus the return or deletion period in section 9.
**Nature and purpose.** Recording, storing, organising, retrieving, displaying and erasing personal data so that the Customer can run student records, admissions, attendance, timetabling, homework, assessment, library and inventory records, family and student portal access, staff records, and fee and collection records.
**Categories of data subjects.** Students; parents and guardians; the Customer's staff, including teachers and administrators; applicants and their families; visitors recorded in the visitor book.
**Categories of personal data.** Identity and contact data; family relationship data; enrolment, class and attendance data; academic work and assessment results; library loans and inventory assignments; staff employment data; fee plans, payment and debt records; login credentials in hashed form; and technical logs, including IP address and time of access.
**Special categories.** Health information a family chooses to record (for example an allergy or a medical note relevant to school life) and data revealing religious belief where a school records an elective course choice. We do not require these fields; the Customer decides whether to use them and is responsible for the lawful basis and any explicit consent.
**Children.** The service is used to hold records about children. They are not our users: accounts in the family and student portal are opened by the institution, and the institution decides who may see a child's record.