Data Protection Addendum

Effective date: 15 August 2026

Company: Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş.

This Data Protection Addendum ("DPA") forms part of the agreement governing the Services between Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş. ("Aspect") and the customer identified in the applicable order form, statement of work or other services agreement ("Customer"). This DPA applies whenever Aspect Processes Customer Personal Data on behalf of Customer.

1. Definitions

"Applicable Data Protection Law" means any privacy, data protection or data security law applicable to the Processing of Customer Personal Data under the Agreement, including where applicable: Regulation (EU) 2016/679 (GDPR); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection; Turkish Personal Data Protection Law No. 6698 (KVKK) and related regulations and Board decisions; the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); other comprehensive US state privacy laws; Brazil's Lei Geral de Proteção de Dados (LGPD); Canada's Personal Information Protection and Electronic Documents Act and applicable provincial privacy laws; Australia's Privacy Act 1988; and successor or implementing legislation. "Customer Personal Data" means Personal Data contained in Customer Data that Aspect Processes on behalf of Customer in connection with the Services. "EU SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914, as amended or replaced. "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Aspect. "Subprocessor" means a third party engaged by Aspect to Process Customer Personal Data on behalf of Customer. Terms such as Controller, Processor, Business, Service Provider, Contractor, Data Subject, Consumer, Personal Data, Process and Processing have the meanings assigned under Applicable Data Protection Law. If more than one definition applies, the term will be interpreted to provide the protection required by the applicable law.

2. Scope and order of precedence

This DPA governs Aspect's Processing of Customer Personal Data. If there is a conflict between this DPA and the Agreement concerning privacy or data protection, this DPA controls. If incorporated transfer clauses conflict with this DPA, the mandatory transfer clauses control for the relevant transfer.

3. Roles of the parties

Customer determines the purposes and means of Processing Customer Personal Data and acts as Controller or Business. Aspect Processes Customer Personal Data on Customer's documented instructions and acts as Processor, Service Provider or Contractor, as applicable. If Customer itself acts as a Processor for another Controller, Aspect will act as Customer's Subprocessor. Customer represents that it is authorized to appoint Aspect and provide the instructions contemplated by the Agreement and this DPA. Aspect remains an independent Controller for personal data it processes for its own account administration, billing, security, fraud prevention, legal compliance, business communications and other purposes described in its Privacy Policy that are not performed solely on Customer's behalf.

4. Processing instructions

Aspect will Process Customer Personal Data only on documented instructions from Customer, including the Agreement, this DPA, Customer's configuration and use of the Services, support instructions and other written instructions accepted by Aspect, unless Processing is required by applicable law. If applicable law requires Processing beyond Customer's instructions, Aspect will inform Customer before Processing unless the law prohibits notice. Aspect will promptly inform Customer if it reasonably believes an instruction violates Applicable Data Protection Law. Aspect may suspend the affected Processing while the parties work in good faith to resolve the issue.

5. Confidentiality and personnel

Aspect will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive privacy and security training appropriate to their responsibilities. Access will be limited to personnel and contractors with a legitimate need to access the data.

6. Security measures

Aspect will maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing, and the risks to individuals. The baseline measures are described in Appendix 2. Customer is responsible for evaluating whether the Services and agreed security measures are appropriate for Customer's intended Processing, including any sensitive or regulated data Customer chooses to process.

7. AI subprocessors and model training

The Services may use third-party AI model providers to perform Customer-requested extraction, classification, summarization, research, enrichment or generation. Aspect will treat such providers as Subprocessors where they Process Customer Personal Data on Aspect's behalf. Aspect will not intentionally opt Customer Personal Data into a provider program that uses such data to train generalized or foundation models without Customer's prior written authorization. This restriction does not prohibit providers from performing security, abuse prevention or legal compliance Processing permitted under their applicable data processing terms, provided such Processing is consistent with Applicable Data Protection Law and Aspect's agreement with the provider.

8. Subprocessors

Customer gives Aspect general written authorization to use Subprocessors to provide the Services. Aspect will impose data protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to the relevant Processing under this DPA, as required by Applicable Data Protection Law. Aspect will remain responsible for its Subprocessors' performance of their data protection obligations to the extent required by Applicable Data Protection Law and the Agreement. Aspect may add or replace Subprocessors. Where legally required or contractually agreed, Aspect will provide advance notice of a material new Subprocessor. Customer may object on reasonable data protection grounds within 15 days after notice. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate the affected Service without penalty for the unused prepaid portion attributable to that Service.

9. Data subject and consumer requests

Taking into account the nature of the Processing, Aspect will provide reasonable assistance to Customer through appropriate technical and organizational measures to help Customer respond to requests to exercise rights under Applicable Data Protection Law. If Aspect receives a request relating to Customer Personal Data and can identify the relevant Customer, Aspect may direct the requester to Customer and will not respond on Customer's behalf except as required by law or authorized by Customer.

10. Assistance with compliance

Taking into account the nature of Processing and information available to Aspect, Aspect will provide reasonable assistance with Customer's obligations relating to security, breach response, data protection impact assessments, prior consultations and regulatory inquiries where required by Applicable Data Protection Law. Customer will reimburse reasonable costs for assistance that materially exceeds ordinary Service support, unless the assistance is required because of Aspect's breach of this DPA.

11. Security incidents

Aspect will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include, to the extent known and reasonably available, the nature of the incident, affected data and data subjects, likely consequences, mitigation measures and a contact for follow-up information. Aspect will take reasonable steps to contain, investigate and remediate the Security Incident and will reasonably cooperate with Customer. Notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and regulators unless Applicable Data Protection Law places that obligation directly on Aspect.

12. Return and deletion

At Customer's choice and subject to the functionality of the Services, Aspect will return or delete Customer Personal Data after termination of the Services or when Processing is no longer required, unless applicable law requires retention. Deletion is performed according to Aspect's Data Retention & Deletion Policy. Backup copies may remain until overwritten through normal backup rotation, provided they remain protected and are not restored except for legitimate disaster recovery or security purposes.

13. Audits and information rights

Aspect will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, independent assessments or responses to reasonable questionnaires. Customer may conduct an audit where required by Applicable Data Protection Law, subject to reasonable advance notice, confidentiality, security restrictions and measures to avoid disruption. Unless a regulator requires otherwise or a Security Incident or material breach reasonably justifies an additional audit, Customer may conduct no more than one audit in any 12-month period. Remote review and existing audit materials will be used first where they can reasonably satisfy the request. Customer bears its audit costs unless the audit reveals a material breach by Aspect.

14. International transfers

14.1 EEA transfers

If Customer Personal Data subject to the GDPR is transferred to Aspect in a country not recognized as providing an adequate level of protection and no other lawful transfer mechanism applies, the EU SCCs are incorporated into this DPA by reference. Module Two applies where Customer is a Controller and Aspect is a Processor. Module Three applies where Customer is a Processor and Aspect is a Subprocessor. Clause 7, the docking clause, applies. For Clause 9, Option 2 applies and the time period for advance notice of Subprocessor changes is 15 days unless the Agreement states a longer period. The optional language in Clause 11 is not included. For Clause 17, the governing law is the law of Ireland. For Clause 18, disputes will be resolved before the courts of Ireland. The competent supervisory authority will be determined under Clause 13 of the EU SCCs. The information in Appendix 1, Appendix 2 and Appendix 3 of this DPA supplies the corresponding Annex information required by the EU SCCs to the extent applicable. The parties will cooperate in good faith with transfer risk assessments and supplementary measures required by applicable European data protection law.

14.2 United Kingdom transfers

For restricted transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the UK Information Commissioner's Office and amended from time to time, is incorporated by reference. The tables are completed using the information in the Agreement and this DPA. The EU SCCs apply as modified by the UK Addendum.

14.3 Swiss transfers

For transfers subject to Swiss data protection law, the EU SCCs apply with modifications necessary for the Swiss Federal Act on Data Protection, including references to the competent Swiss authority and recognition that individuals in Switzerland may enforce applicable rights. To the extent required, references to the GDPR will be interpreted to include corresponding Swiss law requirements.

14.4 Türkiye transfers

For transfers of personal data from Türkiye to recipients abroad that are subject to KVKK Article 9, Aspect will use a lawful transfer basis and appropriate safeguards required by Turkish law. Where Aspect relies on a standard contract adopted by the Turkish Personal Data Protection Board, Aspect will execute the appropriate controller-to-controller, controller-to-processor, processor-to-processor or processor-to-controller form for the relevant transfer relationship and will complete any required notification to the Turkish Data Protection Authority within the legally prescribed period. Where Aspect acts as Processor for a Customer established in Türkiye and transfers Customer Personal Data to an overseas Subprocessor, Aspect will be responsible for implementing the transfer mechanism required for that onward transfer to the extent required by KVKK.

14.5 Other jurisdictions

If another jurisdiction requires specific cross-border transfer terms, the parties will apply a valid statutory mechanism or enter into supplementary terms reasonably necessary to permit the transfer while preserving the commercial allocation of responsibilities in this DPA as far as legally permitted.

15. US state privacy law terms

To the extent CCPA/CPRA or another US state privacy law applies and Aspect Processes Personal Information on behalf of Customer as a Service Provider, Contractor or Processor: Aspect will Process Personal Information only for the specific business purposes described in the Agreement, this DPA and Customer's documented instructions. Aspect will not sell or share Customer Personal Data as those terms are defined under CCPA/CPRA. Aspect will not retain, use or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the permitted business purposes, except as permitted by applicable law. Aspect will not combine Customer Personal Data with personal information received from another person or collected from Aspect's own interaction with a consumer except to the extent permitted for a Service Provider or Contractor under applicable law. Aspect will provide the same level of privacy protection required of service providers, contractors or processors under the applicable law and will notify Customer if Aspect determines it can no longer meet those obligations. Customer may take reasonable and appropriate steps to help ensure that Aspect uses Customer Personal Data consistently with Customer's obligations, and may require reasonable remediation where unauthorized Processing is identified. Aspect will reasonably assist Customer with consumer rights requests and other legally required processor assistance.

16. Compliance with other privacy laws

Where LGPD, Canadian privacy laws, Australian privacy laws or another Applicable Data Protection Law imposes additional Processor obligations relevant to the Services, Aspect will comply with those obligations to the extent applicable to Aspect's role and Processing. The parties will execute reasonable supplementary terms if a mandatory local law requires terms that cannot be satisfied by this DPA alone.

17. Liability

The liability of each party arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Applicable Data Protection Law prohibits such limitation.

18. Duration

This DPA remains in effect for as long as Aspect Processes Customer Personal Data. Provisions concerning confidentiality, deletion, audit, liability and international transfer obligations survive as necessary to give them effect.

Appendix 1: Details of Processing

ItemDescription
Subject matterProvision of the Services described in the Agreement, including digital profiles, lead capture, scanning, enrichment, research, integrations, AI-assisted processing, workflow automation, analytics, support and related services.
DurationFor the term of the Services and any limited post-termination period required for export, deletion, legal retention or backup rotation.
Nature and purposeHosting, storing, organizing, extracting, scanning, converting, enriching, researching, matching, deduplicating, classifying, summarizing, analyzing, transmitting, synchronizing, generating, displaying, supporting and securing data as instructed by Customer.
Data subjectsCustomer users and administrators; Customer employees and contractors; contacts, leads, prospects and customers of Customer; event attendees; business card and badge holders; individuals contained in Customer CRM or connected systems; individuals referenced in notes or records; and other individuals whose Personal Data Customer submits or instructs Aspect to Process.
Personal dataNames, business contact details, professional and employment information, company information, profile images, social or professional profile links, event and interaction details, notes, lead status, relationship data, CRM fields, identifiers, IP and device data, support information, AI prompts and outputs, and other Customer-configured fields.
Sensitive dataThe Services are not intended for general processing of special category or sensitive data. Such data may be processed only if Customer lawfully submits it, the relevant Service supports it, and additional safeguards required by law are in place.
FrequencyContinuous or as initiated by Customer and authorized users during use of the Services.

Appendix 2: Technical and Organizational Measures

Access control: role-based and need-to-know access to production systems and Customer Personal Data, with privileged access restricted to authorized personnel. Authentication: appropriate account authentication controls and stronger controls for administrative or production access where practicable. Encryption: encryption in transit using current transport security standards and encryption at rest for production data stores where supported and appropriate. Logging and monitoring: logging of relevant authentication, administrative, security and service events, with monitoring and alerting appropriate to the risk. Infrastructure security: cloud-hosted infrastructure with network segmentation, security groups, firewalls and provider security controls appropriate to the architecture. Secure development: code review, dependency management, testing, separation of development and production access, and remediation of material vulnerabilities. Data minimization: limiting access, collection and transfer to what is reasonably necessary for the relevant Service function. Backup and recovery: protected backups and recovery procedures appropriate to the Services, with backup rotation and restoration controls. Incident response: documented processes for identifying, investigating, containing, remediating and communicating security incidents. Personnel security: confidentiality obligations and security/privacy awareness for personnel with access to Customer Personal Data. Vendor management: reasonable diligence and contractual data protection requirements for Subprocessors that Process Customer Personal Data. Business continuity: reasonable measures designed to maintain or restore critical Services following material disruption.

Appendix 3: Core Subprocessors

SubprocessorPurposeDataLocation / transfer note
Amazon Web Services (AWS) and applicable affiliatesCloud infrastructure, compute, database, object storage, backup, logging and related hosting services.Customer Data, account data, logs and service data as required to host and operate the Services.Processing location depends on the AWS region and service configuration used by Aspect; international transfers are subject to applicable safeguards.
OpenAI and applicable affiliatesAI model API processing for extraction, classification, summarization, research, enrichment and generation where enabled.Prompts, relevant Customer Data and generated outputs required for the requested feature.Locations and retention depend on the API service configuration and applicable OpenAI business terms.
Anthropic and applicable affiliatesClaude API processing for extraction, classification, summarization, research, enrichment and generation where enabled.Prompts, relevant Customer Data and generated outputs required for the requested feature.Locations and retention depend on the API service configuration and applicable Anthropic commercial terms.
Google and applicable affiliatesGemini or Google Cloud AI processing for extraction, classification, summarization, research, enrichment and generation where enabled.Prompts, relevant Customer Data and generated outputs required for the requested feature.Locations and retention depend on whether the feature uses Google Cloud, Vertex AI, Gemini API or another configured business service.

Appendix 4: EU SCC Annex Information

Data importer: Aspect Bilişim Hizmetleri ve Danışmanlık A.Ş., Acarlar Mah. Derbent Sk. Acarkent A050 No: 23/1 Beykoz / Istanbul, Türkiye. Contact: info@aspect.contact. Activities relevant to the transfer are described in Appendix 1. The data importer is a Processor or Subprocessor as applicable. Data exporter: the Customer identified in the Agreement. The exporter's contact information and role are those stated in the Agreement or Order. Categories of data subjects, categories of personal data, frequency, nature, purpose and duration are described in Appendix 1. Technical and organizational measures are described in Appendix 2. Subprocessors are described in Appendix 3.