Customer contract
Data processing agreement
Article 28-aligned processor terms for personal data handled through an authorized Citeply workspace.
Last updated 14 August 2026Contract status and parties
This page is a review-ready DPA template and is not signed merely by being viewed. The processor is Engin Mutlu, operating Citeply independently in Türkiye, unless an accepted order identifies a successor provider. The controller is the customer identified in the applicable order. A binding DPA must identify both parties, their service addresses and contacts, the effective date, governing law, and authorized signatures or another legally valid acceptance mechanism.
1. Scope, roles, and definitions
This DPA applies when Citeply processes personal data in customer content on behalf of the customer. The customer is controller or business; Citeply is processor or service provider. Terms such as personal data, processing, controller, processor, data subject, personal-data breach, and subprocessor have the meanings given by applicable data-protection law. Paddle and Microsoft may separately act as independent controllers for their own payment, tax, fraud, identity, or service operations.
2. Documented instructions
Citeply processes personal data only on documented customer instructions, including the order, configured workspace actions, authorized connector requests, support instructions, and this DPA. This restriction also applies to international transfers. If law requires other processing, Citeply will inform the customer before processing unless that law prohibits notice. Citeply will promptly inform the customer if, in its reasonable opinion, an instruction infringes applicable data-protection law and may suspend that instruction while the parties resolve it.
3. Confidentiality and access
People authorized to process customer data are bound by confidentiality duties, receive access only for an assigned responsibility, and lose access when it is no longer required. Support personnel use approved, tenant-scoped diagnostic paths and must not request passwords, authentication codes, unrestricted connector tokens, or unnecessary customer documents by ordinary email.
4. Security of processing
Taking account of the state of the art, implementation cost, and processing risk, Citeply maintains the technical and organizational measures in Annex B. Citeply may improve those measures without materially reducing the overall level of protection during the service term.
5. Subprocessors
The customer grants general written authorization for the providers in the Subprocessor Register. Citeply will publish a material new subprocessor before it begins processing customer content and provide advance notice where the signed order requires it. A customer may object on reasonable data-protection grounds within the stated notice period. Citeply will impose data-protection obligations no less protective than the relevant obligations in this DPA and remains responsible for each subprocessor's performance of those delegated obligations.
6. International transfers
Citeply and its subprocessors will not transfer protected personal data across borders without a mechanism recognized by applicable law, such as an adequacy decision, standard contractual clauses, UK addendum, Turkish standard contract, binding corporate rules, or another valid safeguard. The parties will complete the applicable transfer module and supplementary measures where required. A transfer annex or customer order may identify the relevant countries, mechanism, importer, and exporter.
7. Assistance with individual rights
Considering the nature of processing, Citeply will assist the customer with appropriate technical and organizational measures for access, correction, deletion, portability, restriction, objection, and other applicable rights. Citeply will not disclose another tenant's data or respond substantively on the customer's behalf unless instructed or legally required.
8. Security, impact assessments, and regulators
Citeply will provide reasonable information and assistance for the customer's security obligations, personal-data breach assessment, data-protection impact assessment, prior consultation, and regulator inquiry, considering the information available to Citeply and the nature of processing.
9. Personal-data incidents
Reports should be sent to security@citeply.com. Citeply will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data. Available notices will describe the nature and scope, likely consequences, measures taken or proposed, and a contact point, and will be supplemented as facts become available. Notification is not an admission of fault or liability.
10. Return, deletion, and legal holds
At the customer's choice and subject to service functionality, Citeply will make an export available and delete or return personal data at the end of the service, unless applicable law requires retention. An owner deletion request requires fresh password and MFA verification, immediately blocks ordinary access and processing, and begins the documented 30-day recovery window. Final deletion inventories PostgreSQL, R2, connector, support, billing-link, and identity locations, verifies zero scoped data, and proves a separate tenant is unchanged. Any legal hold must record its authority, scope, owner, review date, and expiry.
11. Information and audits
Citeply will make available information reasonably necessary to demonstrate compliance and permit audits by the customer or an independent auditor bound by confidentiality. Unless a confirmed incident or regulator requires otherwise, one reasonable audit per year is permitted with advance notice, during business hours, without exposing another customer or sensitive security material. Current independent reports may satisfy overlapping requests. Each party bears its own cost unless a material breach is confirmed.
Annex A — Processing details
- Subject: evidence-backed questionnaire, assurance, review, export, and related support operations.
- Duration: the service term plus the configured recovery, backup, security, dispute, and legal-retention periods.
- Nature and purpose: receive, scan, store, extract, retrieve, compare, draft, cite, review, export, secure, support, and delete data under customer instructions.
- Data subjects: customer personnel, contractors, suppliers, customers, and people referenced in authorized source material.
- Data categories: business contact and identity data, questionnaire text, evidence, citations, reviewer decisions, audit events, support data, and explicitly authorized Microsoft 365 content.
- Special data: not intentionally required; customers must avoid uploading special-category or highly sensitive personal data unless expressly agreed and lawfully authorized.
Annex B — Technical and organizational measures
- Identity: verified email, strong password hashing, mandatory TOTP MFA, single-use recovery codes, tracked sessions, revocation, and sensitive-action step-up.
- Authorization and isolation: capability-based roles, consultancy/workspace scope, PostgreSQL row-level security, two-tenant negative tests, and server-generated R2 prefixes.
- Cryptography: TLS in transit; encrypted session, connector, and sensitive token material; secrets held outside source control.
- Application security: request and response contracts, origin protection, bounded payloads, rate limits, security headers, malware scanning, file-signature checks, and fail-closed provider timeouts.
- Reliability: durable queues, idempotency, retries, leases, dead-letter handling, correlation IDs, structured logs, metrics, and authenticated alerts.
- Data lifecycle: configurable retention, export controls, immediate deletion-request suspension, durable final erasure, backup/restore verification, and deletion replay after recovery.
- Governance: least privilege, confidentiality, incident response, change control, dependency and secret scanning, audit trails, and documented subprocessor activation boundaries.
12. Liability, precedence, and signatures
The liability terms in the accepted order or signed service agreement apply to this DPA. Mandatory data-protection law prevails. The negotiated order controls first, followed by a signed version of this DPA, the Service Agreement, and the Privacy Notice. The final copy should contain each party's legal name, address, authorized representative, signature or valid electronic acceptance, and effective date.