DATA PROCESSING ADDENDUM
NUVOPOLL SERVICES
Effective Date: The date on which the Customer accepts this Data Processing Addendum, enters into the Agreement incorporating it, or, where executed separately, the date of the last signature below.
Parties
- Controller / “Customer”: The natural person, legal entity, public authority, academic institution, non-governmental organisation, company or other organisation that opens or holds an independent Nuvopoll customer account and determines the purposes and means of the relevant Processing of Customer Personal Data.
- Processor / “Seamlexly”: Seamlexly OÜ, an Estonian private limited company, registry code 17021816, VAT number EE102783597, registered at Harju maakond, Tallinn, Kesklinna linnaosa, Sakala tn 7-2, 10141 Estonia, providing the Nuvopoll Services.
The Customer and Seamlexly are together referred to as the “Parties” and individually as a “Party.”
1. Purpose, Scope and Order of Precedence
1.1 Purpose
This Data Processing Addendum (“DPA”) governs the Processing of Customer Personal Data by Seamlexly as Processor on behalf of the Customer as Controller in connection with the Customer’s use of the Nuvopoll Services. This DPA is intended, in particular, to satisfy the requirements applicable to agreements between controllers and processors under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and to provide a contractual framework for compliance with other Applicable Data Protection Law.
1.2 Relationship with the Agreement
This DPA forms part of, and supplements, the agreement governing the Customer’s use of the Nuvopoll Services, including any applicable terms of service, subscription agreement, order, statement of work or other service document (collectively, the “Agreement”). In the event of a conflict between this DPA and the Agreement concerning the Processing of Customer Personal Data, this DPA shall prevail to the extent of that conflict, unless mandatory law requires otherwise.
1.3 Stand-alone Effect
Where the Parties execute or accept this DPA separately, it may operate as a stand-alone controller–processor agreement and shall apply to all present and future Service Documents relating to the Nuvopoll Services unless expressly agreed otherwise in writing.
1.4 Processing Outside the Scope of this DPA
This DPA applies only to Personal Data processed by Seamlexly on behalf of the Customer. It does not govern Processing for which Seamlexly independently determines the purposes and means, including, as applicable, account administration, authentication, subscription and billing administration, fraud prevention, platform security and Seamlexly’s own legal or regulatory obligations. Such Processing is governed by the applicable privacy notice, Agreement and Applicable Data Protection Law. This exclusion does not affect Seamlexly’s obligations as Processor where the same technical systems or identifiers are used in connection with Processing carried out on behalf of the Customer.
1.5 Global Application
This DPA is intended for global use and applies to the Processing of Customer Personal Data by Seamlexly on behalf of the Customer regardless of the country in which the Customer, its Authorised Users or Data Subjects are located, subject always to Applicable Data Protection Law. The Parties acknowledge that Seamlexly is established in Estonia, European Union, and that the core Nuvopoll production infrastructure used to host and Process Customer Personal Data is located within the European Union. Where the Customer is established outside the European Economic Area, the Customer’s use of the Services may involve a transfer of Customer Personal Data from the Customer’s jurisdiction to Seamlexly and the Nuvopoll infrastructure in the European Union. The Customer is responsible for determining and satisfying any requirements imposed by the law of the exporting jurisdiction in relation to that transfer, and Seamlexly shall provide reasonable cooperation and information necessary to support the implementation of any required transfer mechanism.
2. Definitions
For purposes of this DPA:
- “Applicable Data Protection Law” means any mandatory data protection or privacy law applicable to the Processing governed by this DPA, including the GDPR where applicable, applicable national laws implementing or supplementing the GDPR, and other applicable national data protection laws, including Law No. 6698 on the Protection of Personal Data of Türkiye (“KVKK”) where applicable.
- “Authorised User” means an individual whom the Customer authorises to access its Nuvopoll account or workspace and to use the Services on its behalf, including administrators, researchers, analysts and other team members. An Authorised User does not become a separate Controller merely by being granted access to the Customer’s account.
- “Compliance Evidence” means technical records generated or maintained through the Services to evidence or support data-protection compliance, including consent records, privacy notice version and content hashes, erasure or purge records, audit records and related integrity metadata.
- “Controller” has the meaning given under Applicable Data Protection Law and, for purposes of this DPA, means the Customer with respect to Customer Personal Data.
- “Customer Content” means surveys, research configurations, questions, privacy information, responses, audio content and other information submitted to, collected through, generated through or stored in the Services on behalf of the Customer.
- “Customer Personal Data” means Personal Data contained in Customer Content or otherwise Processed by Seamlexly on behalf of the Customer in connection with the Services.
- “Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
- “Documented Instructions” means instructions from the Customer concerning the Processing of Customer Personal Data, including instructions contained in this DPA, the Agreement, Service Documents, support requests or other written communications and instructions issued through the configuration or use of the Nuvopoll Services by the Customer or its Authorised Users.
- “Personal Data” has the meaning given under Applicable Data Protection Law and, for GDPR purposes, means any information relating to an identified or identifiable natural person.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
- “Processing” or “Process” means any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, retrieval, consultation, use, analysis, transmission, disclosure, making available, combination, restriction, deletion or destruction.
- “Processor” means an entity that Processes Personal Data on behalf of a Controller and, under this DPA, means Seamlexly.
- “Services” means the Nuvopoll research, survey, data collection, reporting and associated services provided by Seamlexly under the Agreement.
- “Special Categories of Personal Data” means Personal Data falling within Article 9 GDPR or any equivalent specially protected category under Applicable Data Protection Law.
- “Sub-processor” means a third party engaged by Seamlexly to Process Customer Personal Data on behalf of the Customer in connection with the Services.
- “Supervisory Authority” means an independent public authority responsible for monitoring compliance with Applicable Data Protection Law.
- “Technical and Organisational Measures” or “TOMs” means the technical and organisational safeguards maintained by Seamlexly to protect Customer Personal Data, including the measures described in Annex II.
3. Roles of the Parties
3.1 Controller and Processor
The Customer is the Controller of Customer Personal Data Processed through the Nuvopoll Services. Seamlexly shall Process Customer Personal Data as Processor on behalf of the Customer and in accordance with the Customer’s Documented Instructions.
3.2 Determination of Purposes and Means
The Customer determines the purposes for which Customer Personal Data is collected and Processed and is responsible for decisions concerning:
a. the purpose and scope of each research project or survey;
b. the categories of Personal Data to be collected;
c. whether directly identifying Personal Data is collected;
d. the applicable legal basis;
e. whether Special Categories of Personal Data are collected;
f. the applicable retention period;
g. whether optional features such as audio responses or public reporting are enabled;
h. the persons authorised to access Customer Personal Data; and
i. instructions relating to disclosure, export, erasure and other Processing operations.
3.3 Seamlexly's Role
Seamlexly shall not determine the independent purposes for which Customer Personal Data is Processed. Seamlexly may determine non-essential technical and organisational means necessary to provide, secure and maintain the Services, provided that those decisions do not alter the purposes of Processing determined by the Customer.
4. Documented Instructions
4.1 General Instruction
The Customer instructs Seamlexly to Process Customer Personal Data to the extent necessary to provide, operate, secure and support the Services in accordance with this DPA and the Agreement.
4.2 Platform Instructions
The Parties acknowledge that actions and configurations performed by the Customer or its Authorised Users through the Nuvopoll Services constitute Documented Instructions where those actions initiate or configure Processing, including:
a. creating, configuring and publishing a survey or research project;
b. selecting whether a study collects directly identifying Personal Data;
c. configuring data categories, privacy settings and retention periods;
d. enabling Special Category processing controls;
e. enabling optional audio responses;
f. configuring privacy notices and consent mechanisms;
g. enabling or disabling public reporting;
h. authorising users and access permissions;
i. accessing, querying or reviewing responses;
j. generating CSV, SPSS, portability or other authorised exports;
k. initiating Data Subject access, portability or erasure operations;
l. deleting a study or dataset; and
m. instructing any other Processing functionality made available through the Services.
4.3 Public Reporting
Where the Customer enables a public or live reporting function that makes individual or response-level information available to third parties or the public, that configuration shall constitute the Customer’s Documented Instruction to Seamlexly to make the selected information available in accordance with the configured access controls. The Customer remains responsible for determining whether such disclosure is appropriate and lawful.
4.4 Unlawful Instructions
If Seamlexly reasonably considers that a Documented Instruction infringes Applicable Data Protection Law, Seamlexly shall inform the Customer without undue delay, unless prohibited from doing so by law. Seamlexly may suspend execution of the affected instruction while the Parties clarify or modify it where necessary to avoid unlawful Processing.
5. Description of Processing
5.1 Subject Matter
The subject matter of the Processing is the provision of a SaaS research and survey platform enabling the Customer to design, publish, administer and analyse research and surveys and to collect, store, retrieve, manage, export and delete related data.
5.2 Nature and Purpose
The Processing may include, depending on the Customer’s configuration and use of the Services:
a. survey hosting and administration;
b. collection and storage of survey responses;
c. authorised retrieval and consultation of responses;
d. analysis and reporting;
e. generation and delivery of datasets and exports;
f. storage and controlled access to audio responses;
g. disclosure of selected response information through Customer-enabled public reporting;
h. capture and preservation of consent and compliance evidence;
i. assistance with Data Subject requests;
j. execution of Customer-defined retention and deletion policies; and
k. other Processing reasonably necessary to perform the Services in accordance with the Customer’s Documented Instructions.
5.3 Duration
Processing shall continue for the duration of the Services and for such additional periods as specified in this DPA, the Customer’s configured retention policies or Applicable Data Protection Law. Further details are set out in Annex I.
6. Processor Obligations
Seamlexly shall:
- 6.1 Instructions: Process Customer Personal Data only on the Customer’s Documented Instructions, including with regard to transfers of Personal Data, unless required to Process such data by applicable law. Where Processing is required by law, Seamlexly shall inform the Customer of that legal requirement before Processing unless prohibited by law.
- 6.2 Confidentiality: Ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations, have access only where necessary for their role, and receive appropriate instructions concerning the protection of Personal Data.
- 6.3 Security: Implement and maintain appropriate Technical and Organisational Measures having regard to the nature, scope, context and purposes of the Processing and the risks to Data Subjects (as described in Annex II).
- 6.4 Access Limitation: Restrict privileged access to Customer Personal Data to authorised personnel and systems to the extent reasonably necessary to provide, maintain or secure the Services or comply with applicable law.
- 6.5 Purpose Limitation: Not Process Customer Personal Data for advertising, unrelated marketing, profiling or any independent purpose incompatible with the Customer’s Documented Instructions.
- 6.6 Assistance: Provide reasonable assistance to the Customer in meeting obligations relating to: (a) Data Subject rights; (b) security of Processing; (c) Personal Data Breach notification; (d) data protection impact assessments; and (e) prior consultation with Supervisory Authorities.
- 6.7 Records of Processing: Maintain records of Processing required from Seamlexly in its capacity as Processor and provide information reasonably necessary to demonstrate compliance.
7. Data Protection Compliance Assistance Provided Through Nuvopoll
7.1 General
As part of the Services, Seamlexly provides technical and operational data-protection functionality designed to assist the Customer in implementing and evidencing its obligations as Controller. These functions constitute compliance assistance provided by Seamlexly as Processor. They do not transfer the Customer’s legal responsibilities as Controller to Seamlexly.
7.2 Privacy-by-Design Configuration
Nuvopoll provides configuration mechanisms allowing the Customer, at research or survey level, to determine and record: (a) whether directly identifying Personal Data will be collected; (b) relevant data categories; (c) the legal basis selected by the Customer; (d) whether the study may involve Special Categories of Personal Data; (e) retention settings; (f) privacy and consent configuration; and (g) other data-protection parameters.
7.3 Privacy Notice Assistance
Nuvopoll provides tools enabling the Customer to generate and present research-specific privacy information to Data Subjects based on information configured by the Customer. The Services provide multilingual privacy notice functionality, including AI-assisted translation. The Customer remains responsible for reviewing and determining the accuracy and completeness of the notice.
7.4 Privacy Notice Versioning and Evidence
The Services generate a cryptographic content hash for a published privacy notice, preserve versions of the notice, associate the hash with consent or response evidence, and identify when material changes require review before publication.
7.5 Pre-Publication Checks
Nuvopoll may prevent publication or issue warnings where required privacy configuration, Controller information or notice information is missing or has become stale.
7.6 Consent Management and Evidence
Where the Customer configures Processing to rely on consent, Nuvopoll provides technical mechanisms for presenting consent controls, recording affirmative actions, recording timestamps, associating the consent with the notice content hash, and preserving pseudonymous technical evidence (session hashes, IP-derived hashes, user-agent hashes).
7.7 Special Category Safeguards
Where a survey potentially involves Special Categories of Personal Data, Nuvopoll provides warnings, additional configuration requirements and participant-side consent controls.
7.8 Audio Response Safeguards
Where audio responses are enabled: (a) Nuvopoll does not use audio responses for biometric identification; (b) the participant is offered a written response alternative; (c) additional notice is presented; (d) audio files are not directly publicly accessible; and (e) access is provided via time-limited signed URLs (currently 15 minutes).
7.9 Data Subject Rights Functionality
Nuvopoll provides functionality for: (a) locating relevant records; (b) preparing access/portability datasets; (c) exporting response records; (d) deleting response records; (e) deleting associated audio files; and (f) generating erasure/purge evidence.
7.10 Retention and Erasure Controls
Nuvopoll enables study-level retention policies. Expired data is automatically purged, and Customer-initiated study deletion and individual erasure are supported.
7.11 Audit and Accountability Functionality
Nuvopoll records authorised operations (exports, configuration changes, deletions) in Customer audit stores, while privileged administrative operations are kept in separate security audit stores. Audit metadata strictly excludes respondent answers, names, or emails.
7.12 Audit Classification Benchmark
For certain audit events, Nuvopoll uses processing-operation categories derived from BDSG §76 as a high-assurance audit classification benchmark.
7.13 Compliance Evidence
Nuvopoll preserves consent evidence, notice integrity info, deletion/purge evidence, and audit evidence separately from substantive survey responses.
7.14 Processor Records and ROPA
Seamlexly maintains electronic processor records, including a living Processor ROPA framework recording the Controller relationship and categories of Processing.
8. Security and Personal Data Breaches
8.1 Security Measures
Seamlexly maintains appropriate measures designed to preserve the confidentiality, integrity, availability and resilience of Customer Personal Data (described in Annex II).
8.2 Personal Data Breach Notification
Seamlexly shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification includes: (a) nature of the breach; (b) affected categories of Data Subjects and data; (c) approximate numbers; (d) likely consequences; (e) mitigation measures; and (f) contact point.
8.3 Cooperation
Seamlexly shall reasonably cooperate with the Customer in investigating, containing, and remediating the breach and preparing required notifications.
8.4 Public Authority Requests
Where legally permitted, Seamlexly shall inform the Customer of binding public authority disclosure requests and limit disclosure to what is strictly legally required.
9. Data Subject Requests
9.1 Requests Received by Seamlexly
If Seamlexly receives a request from a Data Subject relating to Customer Personal Data, Seamlexly shall notify the Customer without undue delay and shall not substantively respond except on Documented Instructions or as required by law.
9.2 Technical Assistance
Seamlexly provides technical and organisational assistance through Service functionality to enable the Customer to respond to access, rectification, erasure, restriction, portability, or objection requests.
10. Retention, Deletion, Return and Compliance Records
10.1 Customer-Controlled Retention
Customer Personal Data shall be retained in accordance with the Customer's configured retention policy, Documented Instructions, Agreement, and Applicable Data Protection Law.
10.2 Automated Deletion
Seamlexly executes automated deletion and purge operations upon expiry of configured retention periods.
10.3 Customer-Initiated Deletion
The Customer may initiate deletion of studies or individual respondent records at any time.
10.4 Compliance Evidence Retention
The Customer instructs Seamlexly to retain Compliance Evidence (consent records, deletion/purge evidence, audit logs) for ten (10) years in the Nuvopoll compliance archive.
10.5 Immutable Archive
Compliance Evidence archived under clause 10.4 is stored using immutable write-once-read-many (“WORM”) controls and cannot be selectively altered or deleted prior to expiry.
10.6 Termination
Upon termination of Services, Seamlexly shall return or delete Customer Personal Data, except data already purged or data retained as Compliance Evidence or required by law.
10.7 Processor Compliance Records
Seamlexly may retain processor-side ROPA and security records necessary to demonstrate legal compliance.
11. Audit and Accountability
11.1 Information
Seamlexly makes available information reasonably necessary to demonstrate Processor compliance.
11.2 Customer Compliance Interface
Nuvopoll provides Customer-accessible privacy and audit interfaces to review Compliance Evidence.
11.3 Audits
The Customer may audit compliance subject to: (a) prior desk review; (b) 30 days prior written notice; (c) maximum once per 12 months (unless mandated by Supervisory Authority or major breach); (d) normal business hours; (e) confidentiality; and (f) Customer bearing audit costs unless a material breach is found.
11.4 Protection of Other Customers
Audits shall not compromise the security, confidentiality, or data of other customers or disclose trade secrets.
12. Sub-processors
12.1 General Authorisation
The Customer grants general written authorisation to engage Sub-processors (identified in Annex III).
12.2 Sub-processor Obligations
Seamlexly enters into written agreements with Sub-processors imposing substantially equivalent data protection obligations.
12.3 Responsibility
Seamlexly remains responsible for Sub-processor performance to the extent required by law.
12.4 Changes and Notification
Seamlexly provides at least ten (10) business days' prior notice of Sub-processor changes.
12.5 Objection
The Customer may object on reasonable data protection grounds. If unresolved, either Party may terminate the affected Service.
12.6 Independent Controller Providers
Providers used solely for Seamlexly's independent controller activities (e.g. payment processors) are not Sub-processors under this DPA.
13. International and Cross-Border Transfers
13.1 EU Processing Destination
Seamlexly OÜ is established in Estonia and core Nuvopoll infrastructure is hosted in Google Cloud Platform europe-west1 (Belgium), European Union.
13.2 Customers Outside the EEA
Where a Customer outside the EEA submits Customer Personal Data to the Services, such activity constitutes a cross-border transfer from the Customer’s jurisdiction to the EU. The Customer is responsible for export requirements, and Seamlexly provides reasonable cooperation.
13.3 Mandatory Transfer Instruments
Where mandatory transfer instruments are required, the Parties shall execute them in addition to this DPA.
13.4 EEA-Originating Transfers
Where data is transferred from the EEA to a third country under Chapter V GDPR, Seamlexly implements required transfer mechanisms prior to transfer.
13.5 Country-Specific Mechanisms
Specific mechanisms for Türkiye (KVKK Art. 9), the UK, and other jurisdictions are set out in Annex IV.
14. Controller Responsibilities
The Customer shall:
- 14.1 Lawfulness: Ensure collection and processing comply with Applicable Data Protection Law.
- 14.2 Legal Basis: Determine and document an appropriate legal basis.
- 14.3 Transparency: Provide accurate notices to Data Subjects.
- 14.4 Consent: Ensure consent requests satisfy statutory standards.
- 14.5 Special Categories: Establish conditions and safeguards for sensitive data.
- 14.6 Data Minimisation: Collect only necessary data.
- 14.7 Retention: Set appropriate retention periods.
- 14.8 Access Control: Manage Authorised User permissions.
- 14.9 Audio: Determine appropriateness of audio features.
- 14.10 Public Reporting: Determine lawfulness of public disclosure before enabling live reports.
- 14.11 Rights: Ensure full rights to instruct Processing.
15. Changes to Technical and Organisational Measures
Seamlexly may update TOMs to reflect technical progress without materially reducing overall protection.
16. Liability
Governed by the liability provisions of the Agreement, subject to mandatory data protection laws.
17. Term and Survival
Effective for the duration of Processing. Confidentiality, compliance archive retention, and liability survive termination.
18. Governing Law and Miscellaneous
Governed by the Agreement's governing law. Standard severability, written amendment, and electronic acceptance terms apply.
ANNEX I: DETAILS AND DESCRIPTION OF PROCESSING
- A. Parties: Controller: The Customer. Processor: Seamlexly OÜ (Registry: 17021816, VAT: EE102783597, Estonia, privacy@nuvopoll.com).
- B. Subject Matter: SaaS research, survey, data collection, reporting, and data protection functionality.
- C. Duration: Continuous for service duration, plus 10-year Compliance Evidence retention.
- D. Data Subjects: Survey participants, respondents, prospective participants, Customer Authorised Users.
- E. Categories of Personal Data: Identification/contact data, demographic data, survey responses/opinions, audio recordings (where enabled), pseudonymous metadata (IP/UA hashes, session IDs), Compliance Evidence.
- F. Processing Operations: Collection, storage, retrieval, analysis, reporting, export, controlled disclosure, pseudonymous evidence generation, WORM archiving, automated deletion.
- G. Processing Categories: (1) Survey hosting; (2) Response collection/storage; (3) Authorised retrieval; (4) Analytics/reporting; (5) Dataset export; (6) Audio storage/access; (7) Public reporting; (8) Consent/evidence preservation; (9) DSR assistance; (10) Retention/deletion execution.
- H. Frequency: Continuous or event-driven.
- I. Location: Google Cloud Platform — europe-west1 — Belgium, European Union.
ANNEX II: TECHNICAL AND ORGANISATIONAL MEASURES (TOMs)
- EU-Based Cloud Infrastructure: Hosted strictly in GCP europe-west1 (Belgium).
- Encryption at Rest: AES-256 storage encryption on Firestore and Cloud Storage.
- Encryption in Transit: Strict HTTPS/TLS for all external and internal API communications.
- Authentication: Firebase Authentication with secure credential handling.
- Role-Based Access Control: Granular RBAC and custom claims.
- Tenant Isolation: Firestore Security Rules and backend tenant partition.
- Privileged Administration: Administrative actions separated and restricted.
- Controlled Audio Access: 15-minute time-limited signed URLs.
- Authoritative Audit Logging: Dual-store audit trails with Auth Context triggers.
- Audit Data Minimisation: No respondent answers or names in audit logs.
- Audit Classification Benchmark: BDSG §76 operation categories as technical benchmark.
- Immutable Compliance Evidence Archive: Dedicated 10-year locked WORM bucket (
gs://global-poll-jqkgs-compliance-logs). - Integrity Controls: Structured NDJSON with SHA-256 manifests.
- Automated Retention Enforcement: Nightly automated cron purge of expired data.
- Data Subject Erasure: Instant cascading purge of response and audio data.
- Storage Hygiene: Weekly cleanup of orphaned audio files.
- Logging and Monitoring: GCP Cloud Logging and audit anomaly monitoring.
- Platform Protection: Rate limiting, DDoS defense, and abuse prevention.
- Privacy-by-Design Controls: Built-in notice generators, hash versioning, and validation checks.
ANNEX III: AUTHORISED SUB-PROCESSORS
| Sub-processor | Service / Purpose | Processing Location | Relevant Data |
|---|---|---|---|
| Google Ireland Limited / GCP & Firebase | Cloud infrastructure, Firestore, Cloud Functions, Cloud Storage, Auth | European Union (europe-west1, Belgium) | Customer Content, responses, audio, compliance data |
| Google Cloud Gemini / Genkit | AI-assisted survey design and multilingual notice translation | Google Cloud EU Environment | Survey questions & notice texts (No respondent datasets submitted) |
ANNEX IV: INTERNATIONAL TRANSFER MECHANISMS
1. General Framework
- 1.1 EU-Based Destination: Seamlexly OÜ operates strictly on EU infrastructure in Belgium (europe-west1).
- 1.2 Global Application: Applies to all cross-border inward transfers to the EU.
- 1.3 Exporting Jurisdiction: Customer determines export requirements under local laws.
- 1.4 Processor Cooperation: Seamlexly provides necessary technical and corporate documentation.
- 1.5 Mandatory Instruments: Executed alongside this DPA where required.
2. Transfers Originating in the EEA
Processed within the EEA. Any onward transfers subject to Chapter V GDPR safeguards (EU SCCs).
3. Transfers Originating in Türkiye (KVKK Madde 9)
- 3.1 Transfer to EU: Constitutes cross-border transfer to EU under KVKK Art. 9.
- 3.2 Turkish Standard Contract: Parties execute the official Standard Contract (Controller-to-Processor) published by the Turkish DPA (KVKK) where standard contract is relied upon.
- 3.3 Other Mechanisms: Explicit consent or other Article 9 mechanisms may be utilised.
- 3.4 Customer Responsibilities: Exporter manages KVKK notifications, filings, and legal grounds.
4. Transfers Originating in the United Kingdom
Governed by the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs where applicable.
5. Transfers Originating in Other Jurisdictions
Customer satisfies local export rules; Seamlexly cooperates within technical feasibility. Data localization mandates requiring data to stay outside EU are incompatible with standard EU hosting.
6. Sub-processors & Onward Transfers
Sub-processors bound by equivalent transfer safeguards. AI features do not process raw respondent datasets.
7. Changes and Priority
Parties cooperate on legal updates. Annex IV governs cross-border transfers and prevails in event of specific transfer conflict.