LEGAL
Data Processing Addendum
1. Scope and roles
This DPA applies when incorporated into the Customer’s agreed HY order or service agreement and while HY processes Customer Personal Data on the Customer’s behalf. For that processing, the Customer is controller and HY processor unless a specific activity is expressly documented otherwise. HY’s independent controller activities for its own accounts, billing and security are covered by the Privacy Notice.
2. Documented instructions
HY processes Customer Personal Data only on documented Customer instructions, including the agreed contract and the Customer’s service configuration, unless applicable law requires otherwise. HY will inform the Customer of a legally required instruction where the law permits and of an instruction it considers to infringe applicable data-protection law.
3. Confidentiality and security
Persons authorised to process Customer Personal Data must be bound by confidentiality. HY will implement appropriate technical and organisational security measures proportionate to the risks. The measures described in Annex 2 apply to the agreed service scope.
4. Subprocessors and other providers
Where the Customer grants general authorisation for subprocessors, HY will impose appropriate written data-protection obligations and provide notice of intended additions or replacements so the Customer has an opportunity to object under the agreed contract. HY remains responsible for its subprocessor obligations under applicable law. A customer-connected marketplace or payment provider is not automatically HY’s subprocessor; its role must be assessed for the particular data flow.
5. Assistance
Taking account of the nature of the processing and information available, HY will provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultation. Requests addressed directly to HY concerning Customer Data will be referred to the Customer where appropriate.
6. Personal data breaches
HY will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide available information reasonably needed for the Customer’s compliance. Additional information may be supplied as it becomes available.
7. International transfers
HY is based in Türkiye. UK Customer Data may be transferred to HY in Türkiye and to service providers in other countries. Where a transfer is restricted under applicable UK data protection law, an applicable lawful transfer route and the required assessment must be in place before it proceeds. Depending on the flow, appropriate safeguards may include the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum. This notice does not confirm that a particular transfer agreement has been executed. The parties must identify the exporter, importer, relevant safeguard and assessment for each restricted flow. This DPA does not itself replace an IDTA or the UK Addendum.
8. Return and deletion
At the end of the service, HY will return or delete Customer Personal Data at the Customer’s choice under the agreed export/return arrangements, unless law requires retention. Copies in backups are subject to the applicable replacement cycle and must remain protected while retained. Records held independently by a connected provider remain subject to that provider’s own duties.
9. Information and audits
HY will make available information reasonably necessary to demonstrate compliance and allow proportionate audits and inspections under the agreed confidentiality, notice and practical arrangements. These arrangements do not remove rights or obligations required by applicable law.
10. Duration and liability
This DPA continues for as long as HY processes Customer Personal Data. Contractual liability provisions apply only to the extent permitted by applicable law.
Annex 1. Details of processing
Subject matter and duration: provision of the agreed HY service during the subscription and agreed export/deletion arrangements.
- Nature and purpose: hosting, storing, organising, displaying and transmitting Customer Data for CRM, stock, order, invoice, messaging, Commerce AI and agreed support functions.
- Data subjects: the Customer’s authorised users, staff, customers, prospects and contacts whose information is included in Customer Data.
- Data categories: names, contact details, addresses, platform IDs, messages and attachments, product/order/delivery/invoice/payment-status information and account/activity records, according to enabled features.
- Special-category data is not intentionally required; free-text messages may contain it incidentally. The Customer must use and configure the service lawfully and avoid unnecessary sensitive data.
Annex 2. Security measures
The service uses logical tenant separation, authentication, role-based access, HTTPS and audit/security logging. Additional controls, including backup/recovery and connected-account credential protection, must reflect the agreed service and the actual provider configuration.
Annex 3. Providers and connected services
The Service Providers and Data Flows page (/legal/service-providers?lang=en) describes the identified provider functions and data flows. The agreed processing arrangements must distinguish Customer Data subprocessors from HY controller-side providers and the Customer’s own independent integrations. Provider contracts, processing locations and transfer safeguards must be assessed for the actual enabled services.
Annex 4. Transfer arrangements
For each restricted flow, the parties must complete the applicable transfer safeguard and assessment before the flow proceeds. The agreed transfer documents identify the parties, data, processing locations and any supplementary measures. No completed IDTA, SCC module or UK Addendum is represented by this page.