KobiGPT
FeaturesHow it worksPricingUse casesWhy choose us
Log inStart free
Log in
Back to home

Data Processing Agreement (DPA)

Last updated: 21 Feb 2026

The authoritative version of this document is in Turkish. The text below is a translation provided for convenience only.

Terms of ServicePrivacy notice (KVKK)Privacy policyCookie policyDelivery & returnsDistance salesExplicit consentData processing (DPA)
KobiGPTKobiGPT

Dedicated AI assistants for your company — department-scoped workflows trained on your own data.

Phone0850 242 85 53
Email[email protected]

Language

Choose interface language

Product

  • Features
  • How it works
  • Pricing
  • Use cases

Company

  • About
  • Blog
  • FAQ
  • Contact
  • Terms of Service
  • Privacy notice (KVKK)
  • Privacy policy
  • Cookie policy
  • Delivery & returns
  • Distance sales
  • Explicit consent
  • Data processing (DPA)
Accepted payment methods:PayTR, Mastercard, VISA, American Express, Troy

© 2024 KobiGPT. All rights reserved.

Designed and built in Türkiye.

View Turkish original

1. Parties

Data Controller ("Customer"): The natural or legal person using the KobiGPT platform and uploading personal data to the platform.

Data Processor ("Service Provider"): X MIND SOLUTIONS YAZILIM VE DANIŞMANLIK ANONİM ŞİRKETİ
Address: Kazlıçeşme Mah. 245. Sk. No: 5 Zeytinburnu / İstanbul | Email: [email protected] | KVKK: [email protected]

2. Subject and Scope

This Data Processing Agreement regulates the rights and obligations of the parties regarding the processing of personal data transferred by the Customer to the Service Provider via the KobiGPT platform, within the framework of KVKK (Law No. 6698) and relevant legislation.

3. Data Processing Details

  • Categories of data processed: Text, documents, tables and images uploaded to the Platform and the personal data they contain
  • Processing purposes: Delivery of AI-powered business assistant services
  • Processing location: GCP/AWS (USA, EU) under standard plans; Turkey location possible with Enterprise Plan

4. Obligations of the Service Provider

  • Process personal data only in accordance with the Customer's instructions and the scope of the agreement
  • Take necessary technical and administrative measures (encryption, access control, log records)
  • Have employees sign confidentiality undertakings
  • Conclude agreements with sub-processors providing at least the same level of protection as this agreement
  • Inform the Customer without delay in case of a data breach
  • Delete or return personal data upon request when the agreement ends

5. Obligations of the Customer

  • Guarantee that personal data uploaded to the Platform was obtained lawfully
  • Fulfil the obligation to inform data subjects under KVKK Art. 10
  • ACCEPT AND UNDERTAKE NOT TO UPLOAD SPECIAL CATEGORIES OF PERSONAL DATA TO THE PLATFORM

6. Sub-Processors

  • Google Cloud Platform (GCP) – Cloud server infrastructure (USA/EU)
  • Amazon Web Services (AWS) – Cloud server infrastructure (USA/EU)
  • LLM Providers – AI model processing (USA)
  • PayTR – Payment transactions (Türkiye)

7. Data Breach Notification

If the Service Provider detects a personal data breach, it informs the Customer as soon as possible and in any event within 48 hours in writing.

8. Contact

X MIND SOLUTIONS YAZILIM VE DANIŞMANLIK ANONİM ŞİRKETİ | Address: Kazlıçeşme Mah. 245. Sk. No: 5 Zeytinburnu / İstanbul | Email: [email protected] | KVKK: [email protected]