Sözleşme Eki
Contract Annex
Anexo Contractual

Veri İşleme Sözleşmesi

Data Processing Agreement

Acuerdo de Tratamiento de Datos

Last updated01.01.2026 Version1.0

CROMS Yazılım Lisans ve Hizmet Sözleşmesi'nin ayrılmaz ekidir.

1. Taraflar ve Roller

  • Veri Sorumlusu ("Müşteri"): Lisans Sözleşmesi'ni akdeden gerçek veya tüzel kişi.
  • Veri İşleyen ("ARKİTEK"): Arkitek Araştırma Geliştirme A.Ş., MERSİS: 0729082869300001, Adres: Hacettepe Teknokent, Üniversiteler Mh. 1596 Cd. No:6-E/6, Çankaya, Ankara, TÜRKİYE.

Müşteri, CROMS platformuna yüklediği kişisel verilerin veri sorumlusudur; işleme amaçlarını ve vasıtalarını belirler. ARKİTEK, bu verileri yalnızca Müşteri'nin belgelendirilmiş talimatları doğrultusunda ve bu Sözleşme kapsamında işler. Bu Sözleşme, 6698 sayılı KVKK ve - Müşteri'nin veya ilgili kişilerin GDPR kapsamında olması hâlinde - GDPR Art. 28 gereklerine göre düzenlenmiştir.

2. Konu, Süre ve Nitelik

İşlemenin konusu, CROMS platformunun (web, mobil, masaüstü uygulamaları ve ilgili modüller dâhil) Müşteri'ye hizmet olarak sunulmasıdır. İşleme; barındırma, kaydetme, düzenleme, raporlama, yedekleme ve silme faaliyetlerini kapsar ve Lisans Sözleşmesi süresince devam eder.

3. İşlenen Veri Kategorileri ve İlgili Kişi Grupları

İlgili kişi grupları: Müşteri'nin çalışanları, saha personeli, yöneticileri, iş ortakları yetkilileri, araştırma katılımcıları (gönüllüler) ve Müşteri'nin platforma verilerini girdiği diğer kişiler.

Veri kategorileri:

  • Kimlik ve özlük: ad-soyad, T.C. kimlik numarası, doğum tarihi, özlük dosyası içeriği, eğitim ve sertifika kayıtları
  • İletişim: adres, telefon, e-posta
  • Finans: IBAN, bordro, avans ve masraf kayıtları, fatura bilgileri
  • Çalışma verileri: iş girişleri, zaman çizelgeleri, izin ve performans kayıtları, görevlendirmeler
  • Konum: saha operasyonlarının doğrulanması amacıyla, Müşteri'nin talimatı ve yapılandırması doğrultusunda işlenen konum verileri
  • Özel nitelikli veriler: sağlık verileri (özlük dosyalarındaki sağlık raporları, SmartCRF/eCRF üzerinden toplanan araştırma katılımcısı sağlık verileri) ve Müşteri'nin yüklediği diğer özel nitelikli veriler

4. Müşteri'nin Yükümlülükleri

Müşteri; platforma yüklediği verilerin hukuka uygun elde edildiğini, işleme için geçerli hukuki sebebe (özel nitelikli veriler bakımından KVKK m. 6 / GDPR Art. 9 kapsamındaki şartlara) sahip olduğunu, ilgili kişilere karşı aydınlatma yükümlülüğünü yerine getirdiğini ve gerekli hâllerde açık rıza aldığını kabul ve taahhüt eder. Klinik araştırma verileri bakımından ilgili mevzuata (iyi klinik uygulamaları, etik kurul ve yetkili otorite izinleri dâhil) uyum Müşteri'nin sorumluluğundadır.

5. ARKİTEK'in Yükümlülükleri

ARKİTEK:

  1. Verileri yalnızca Müşteri'nin talimatlarıyla ve hizmetin gerektirdiği ölçüde işler; kendi amaçları için kullanmaz.
  2. Verilere erişimi olan personelin gizlilik taahhüdü altında olmasını sağlar.
  3. Bölüm 7'deki teknik ve idari tedbirleri uygular.
  4. İlgili kişilerin haklarını kullanmasına ilişkin taleplerde (erişim, düzeltme, silme vb.) Müşteri'ye makul destek sağlar; doğrudan kendisine ulaşan talepleri gecikmeksizin Müşteri'ye yönlendirir.
  5. Veri koruma etki değerlendirmesi ve denetim makamlarıyla istişare süreçlerinde Müşteri'ye makul destek sağlar.
  6. Bir talimatın KVKK'ya veya GDPR'a aykırı olduğu kanaatindeyse Müşteri'yi derhâl bilgilendirir.

6. Özel Nitelikli Veriler

Sağlık verileri dâhil özel nitelikli veriler bakımından:

  • Hukuki dayanağın sağlanması, katılımcı/çalışan aydınlatması ve gerekli hâllerde açık rızanın temini münhasıran Müşteri'nin yükümlülüğündedir.
  • ARKİTEK, bu verileri Kişisel Verileri Koruma Kurulu'nun özel nitelikli kişisel verilerin işlenmesinde alınması gereken yeterli önlemlere ilişkin kararına uygun ek tedbirlerle işler: kriptografik şifreleme (aktarımda ve depolamada), erişimlerin loglanması, yetki matrisi ve erişimlerin düzenli gözden geçirilmesi, veri kaynaklarının kodlanarak anonimleştirilebilmesi (eCRF katılımcı numaralandırması).
  • SmartCRF üzerinden toplanan katılımcı verileri, atanmış katılımcı numaraları ile temsil edilir; kimlik eşleştirme anahtarlarının yönetimi Müşteri'nin kontrolündedir.

7. Güvenlik Tedbirleri

ARKİTEK, KVKK m. 12 ve GDPR Art. 32 uyarınca asgari şu tedbirleri uygular: uçtan uca şifreleme, rol bazlı yetkilendirme ve merkezi kimlik yönetimi (SSO), merkezi log yönetimi, güvenlik duvarları ve saldırı önleme sistemleri, düzenli yedekleme ve felaket kurtarma planı, düzenli sızma testleri ve güvenlik denetimleri, personel farkındalık eğitimleri. Barındırma sağlayıcısının veri merkezi güvenlik sertifikaları ayrıca ilgili sağlayıcı tarafından yürütülür.

8. Alt İşleyenler

Müşteri, aşağıdaki alt işleyenlerin kullanımına genel yetki verir:

Alt işleyenHizmetKonum
UpCloudBarındırma ve altyapıEurope-2, Frankfurt, Almanya
GoogleE-posta iletimi, takvim/randevu ve ilgili altyapı hizmetleriGoogle altyapısının hizmet verdiği ülkeler
NatroE-posta, alan adı ve ilgili altyapı hizmetleriTürkiye

ARKİTEK, alt işleyen eklemeden veya değiştirmeden önce Müşteri'yi 30 gün önceden bilgilendirir; Müşteri makul gerekçeyle itiraz edebilir. ARKİTEK, alt işleyenlere bu Sözleşme'dekiyle eşdeğer veri koruma yükümlülükleri yükler ve alt işleyenlerin fiillerinden Müşteri'ye karşı sorumlu olmaya devam eder.

9. Barındırma ve Uluslararası Aktarım

Platform verileri UpCloud Europe-2, Frankfurt, Almanya bölgesinde barındırılır. Türkiye'den AB'ye aktarımlar KVKK m. 9 uyarınca yürütülür; Müşteri'nin kendi KVKK yükümlülükleri kapsamında ihtiyaç duyması hâlinde ARKİTEK aktarım mekanizmasına ilişkin belgeleri paylaşır. AEA'dan gelen veriler bakımından ARKİTEK'in Türkiye'den erişimi GDPR Bölüm V kapsamındaki güvencelere tabidir.

10. Veri İhlali Bildirimi

ARKİTEK, kişisel veri ihlalinden haberdar olduğunda Müşteri'yi gecikmeksizin bilgilendirir; ihlalin niteliği, etkilenen veri kategorileri ve kişiler, olası sonuçlar ve alınan tedbirlere ilişkin bilgileri sağlar. Kurum'a/denetim makamına ve ilgili kişilere bildirim yükümlülüğü veri sorumlusu sıfatıyla Müşteri'ye aittir; ARKİTEK gerekli desteği verir.

11. Denetim

Müşteri, yılda 1 defayı aşmamak ve 15 gün önceden bildirmek kaydıyla, bu Sözleşme'ye uyumu makul kapsamda denetleyebilir veya bağımsız denetçiye denetletebilir. ARKİTEK, kendi güvenlik denetim kayıtları ile barındırma sağlayıcısının veri merkezi güvenlik sertifikalarını ve ilgili dokümantasyonu mevcut olduğu ölçüde sunarak bu yükümlülüğü karşılayabilir.

12. Sözleşmenin Sona Ermesi

Lisans Sözleşmesi'nin sona ermesi hâlinde ARKİTEK, Müşteri'nin tercihine göre tüm kişisel verileri yaygın bir formatta iade eder ve/veya 90 gün içinde sistemlerinden geri döndürülemez şekilde siler; yasal saklama yükümlülüğüne tabi kayıtlar bu sürelerin sonunda imha edilir. Silme işlemi talep hâlinde yazılı olarak teyit edilir.

13. Sorumluluk ve Uygulanacak Hukuk

Tarafların sorumluluğu Lisans Sözleşmesi'ndeki sorumluluk hükümlerine tabidir; şu kadar ki, her taraf kendi yükümlülük alanına giren ihlallerden doğan idari yaptırımları üstlenir. Bu Sözleşme Türk hukukuna tabidir; uyuşmazlıklarda Ankara Mahkemeleri ve İcra Daireleri yetkilidir.

An integral annex to the CROMS Software License and Service Agreement.

1. Parties and Roles

  • Data Controller ("Customer"): The natural or legal person executing the License Agreement.
  • Data Processor ("ARKITEK"): Arkitek Araştırma Geliştirme A.Ş., MERSIS: 0729082869300001, Address: Hacettepe Teknokent, Üniversiteler Mh. 1596 Cd. No:6-E/6, Çankaya, Ankara, TÜRKİYE.

The Customer is the data controller of the personal data it uploads to the CROMS platform and determines the purposes and means of processing. ARKITEK processes such data solely on the Customer's documented instructions and under this Agreement. This Agreement is drawn up in accordance with Turkish Law No. 6698 (KVKK) and - where the Customer or the data subjects fall within the scope of the GDPR - the requirements of GDPR Art. 28.

2. Subject Matter, Duration and Nature

The subject matter of the processing is the provision of the CROMS platform (including web, mobile and desktop applications and related modules) to the Customer as a service. Processing covers hosting, recording, organizing, reporting, backup and deletion activities and continues for the term of the License Agreement.

3. Categories of Data and Data Subjects

Data subject groups: The Customer's employees, field staff, managers, business partner contacts, research participants (volunteers) and other persons whose data the Customer enters into the platform.

Data categories:

  • Identity and HR: name-surname, Turkish national ID number, date of birth, personnel file content, training and certification records
  • Contact: address, phone, e-mail
  • Financial: IBAN, payroll, advance and expense records, invoicing details
  • Work data: work entries, timesheets, leave and performance records, assignments
  • Location: location data processed for the verification of field operations, in line with the Customer's instructions and configuration
  • Special categories of data: health data (health reports in personnel files, research participant health data collected via SmartCRF/eCRF) and other special-category data uploaded by the Customer

4. Customer's Obligations

The Customer represents and warrants that the data it uploads to the platform has been obtained lawfully, that it holds a valid legal basis for processing (for special categories, the conditions under KVKK Art. 6 / GDPR Art. 9), that it has fulfilled its obligation to inform data subjects, and that it has obtained explicit consent where required. Compliance with applicable legislation regarding clinical research data (including good clinical practice, ethics committee and competent authority approvals) is the Customer's responsibility.

5. ARKITEK's Obligations

ARKITEK shall:

  1. Process the data only on the Customer's instructions and to the extent required by the service; not use it for its own purposes.
  2. Ensure that personnel with access to the data are bound by confidentiality undertakings.
  3. Apply the technical and organizational measures in Section 7.
  4. Provide reasonable assistance to the Customer with data subject requests (access, rectification, erasure, etc.); forward any requests received directly to the Customer without delay.
  5. Provide reasonable assistance with data protection impact assessments and consultations with supervisory authorities.
  6. Immediately inform the Customer if it considers an instruction to infringe the KVKK or the GDPR.

6. Special Categories of Data

With respect to special categories of data, including health data:

  • Providing the legal basis, informing participants/employees, and obtaining explicit consent where required are exclusively the Customer's obligations.
  • ARKITEK processes such data with additional safeguards in line with the Turkish Personal Data Protection Board's decision on adequate measures for the processing of special categories of personal data: cryptographic encryption (in transit and at rest), access logging, an authorization matrix with regular access reviews, and the ability to pseudonymize data sources through coding (eCRF participant numbering).
  • Participant data collected via SmartCRF is represented by assigned participant numbers; the management of identity mapping keys remains under the Customer's control.

7. Security Measures

Pursuant to KVKK Art. 12 and GDPR Art. 32, ARKITEK applies at minimum: end-to-end encryption, role-based authorization and central identity management (SSO), central log management, firewalls and intrusion prevention systems, regular backups and a disaster recovery plan, regular penetration tests and security audits, and staff awareness training. The hosting provider's data center security certifications are maintained separately by the relevant provider.

8. Sub-processors

The Customer grants general authorization for the use of the following sub-processors:

Sub-processorServiceLocation
UpCloudHosting and infrastructureEurope-2, Frankfurt, Germany
GoogleE-mail delivery, calendar/appointment and related infrastructure servicesCountries where Google infrastructure provides services
NatroE-mail, domain name and related infrastructure servicesTürkiye

ARKITEK shall inform the Customer 30 days in advance before adding or replacing a sub-processor; the Customer may object on reasonable grounds. ARKITEK imposes data protection obligations equivalent to those in this Agreement on its sub-processors and remains liable to the Customer for their acts.

9. Hosting and International Transfers

Platform data is hosted in UpCloud Europe-2, Frankfurt, Germany. Transfers from Türkiye to the EU are carried out under KVKK Art. 9; where the Customer requires it for its own KVKK obligations, ARKITEK shares documentation regarding the transfer mechanism. For data originating from the EEA, ARKITEK's access from Türkiye is subject to the safeguards under GDPR Chapter V.

10. Data Breach Notification

Upon becoming aware of a personal data breach, ARKITEK shall notify the Customer without undue delay, providing information on the nature of the breach, the data categories and data subjects affected, the likely consequences and the measures taken. Notification to the Authority/supervisory authority and to data subjects is the Customer's obligation as data controller; ARKITEK provides the necessary assistance.

11. Audit

The Customer may audit compliance with this Agreement within reasonable scope, or have it audited by an independent auditor, no more than 1 time per year and with 15 days' prior notice. ARKITEK may satisfy this obligation by providing its own security audit records and the hosting provider's data center security certifications and related documentation to the extent available.

12. Termination

Upon termination of the License Agreement, ARKITEK shall, at the Customer's choice, return all personal data in a commonly used format and/or irreversibly delete it from its systems within 90 days; records subject to statutory retention obligations are destroyed at the end of those periods. Deletion is confirmed in writing upon request.

13. Liability and Governing Law

The parties' liability is subject to the liability provisions of the License Agreement; provided that each party bears the administrative sanctions arising from breaches within its own sphere of obligations. This Agreement is governed by Turkish law; the Ankara Courts and Enforcement Offices shall have jurisdiction over disputes.

Anexo integrante del Contrato de Licencia y Servicio de Software CROMS.

1. Partes y Roles

  • Responsable del tratamiento ("Cliente"): La persona física o jurídica que suscribe el Contrato de Licencia.
  • Encargado del tratamiento ("ARKITEK"): Arkitek Araştırma Geliştirme A.Ş., MERSIS: 0729082869300001, Dirección: Hacettepe Teknokent, Üniversiteler Mh. 1596 Cd. No:6-E/6, Çankaya, Ankara, TÜRKİYE.

El Cliente es el responsable del tratamiento de los datos personales que carga en la plataforma CROMS y determina los fines y medios del tratamiento. ARKITEK trata dichos datos únicamente conforme a las instrucciones documentadas del Cliente y en el marco de este Acuerdo. Este Acuerdo se redacta conforme a la Ley turca n.º 6698 (KVKK) y - cuando el Cliente o los interesados estén comprendidos en el RGPD - a los requisitos del art. 28 del RGPD.

2. Objeto, Duración y Naturaleza

El objeto del tratamiento es la prestación de la plataforma CROMS (incluidas las aplicaciones web, móviles y de escritorio y los módulos relacionados) al Cliente como servicio. El tratamiento comprende actividades de alojamiento, registro, organización, elaboración de informes, copia de seguridad y supresión, y se mantiene durante la vigencia del Contrato de Licencia.

3. Categorías de Datos y Grupos de Interesados

Grupos de interesados: Empleados del Cliente, personal de campo, directivos, contactos de socios comerciales, participantes en investigaciones (voluntarios) y otras personas cuyos datos el Cliente introduzca en la plataforma.

Categorías de datos:

  • Identidad y expediente laboral: nombre y apellidos, número de identidad nacional turco, fecha de nacimiento, contenido del expediente de personal, registros de formación y certificación
  • Contacto: dirección, teléfono, correo electrónico
  • Finanzas: IBAN, nómina, registros de anticipos y gastos, datos de facturación
  • Datos laborales: registros de trabajo, hojas de tiempo, registros de permisos y desempeño, asignaciones
  • Ubicación: datos de ubicación tratados para la verificación de operaciones de campo, conforme a las instrucciones y la configuración del Cliente
  • Categorías especiales de datos: datos de salud (informes médicos de los expedientes de personal, datos de salud de participantes recogidos mediante SmartCRF/eCRF) y otros datos de categorías especiales cargados por el Cliente

4. Obligaciones del Cliente

El Cliente declara y garantiza que los datos que carga en la plataforma se han obtenido lícitamente, que dispone de una base jurídica válida para el tratamiento (para las categorías especiales, las condiciones del art. 6 de la KVKK / art. 9 del RGPD), que ha cumplido su obligación de informar a los interesados y que ha obtenido el consentimiento explícito cuando resulte necesario. El cumplimiento de la normativa aplicable a los datos de investigación clínica (incluidas las buenas prácticas clínicas y las aprobaciones de comités de ética y autoridades competentes) es responsabilidad del Cliente.

5. Obligaciones de ARKITEK

ARKITEK se obliga a:

  1. Tratar los datos únicamente según las instrucciones del Cliente y en la medida que exija el servicio; no usarlos para fines propios.
  2. Garantizar que el personal con acceso a los datos esté sujeto a compromisos de confidencialidad.
  3. Aplicar las medidas técnicas y organizativas de la Sección 7.
  4. Prestar asistencia razonable al Cliente en las solicitudes de los interesados (acceso, rectificación, supresión, etc.); remitir sin demora al Cliente las solicitudes recibidas directamente.
  5. Prestar asistencia razonable en las evaluaciones de impacto y en las consultas con las autoridades de control.
  6. Informar de inmediato al Cliente si considera que una instrucción infringe la KVKK o el RGPD.

6. Categorías Especiales de Datos

Respecto de las categorías especiales de datos, incluidos los datos de salud:

  • Disponer de la base jurídica, informar a participantes/empleados y obtener el consentimiento explícito cuando proceda son obligaciones exclusivas del Cliente.
  • ARKITEK trata estos datos con salvaguardias adicionales conforme a la decisión de la Autoridad turca sobre medidas adecuadas para el tratamiento de categorías especiales: cifrado criptográfico (en tránsito y en reposo), registro de accesos, matriz de autorizaciones con revisiones periódicas y la posibilidad de seudonimizar las fuentes de datos mediante codificación (numeración de participantes en eCRF).
  • Los datos de participantes recogidos mediante SmartCRF se representan con números de participante asignados; la gestión de las claves de correspondencia de identidad permanece bajo el control del Cliente.

7. Medidas de Seguridad

Conforme al art. 12 de la KVKK y al art. 32 del RGPD, ARKITEK aplica como mínimo: cifrado de extremo a extremo, autorización basada en roles y gestión centralizada de identidades (SSO), gestión centralizada de registros, cortafuegos y sistemas de prevención de intrusiones, copias de seguridad periódicas y plan de recuperación ante desastres, pruebas de penetración periódicas y auditorías de seguridad, y formación de concienciación del personal. Las certificaciones de seguridad del centro de datos del proveedor de alojamiento son mantenidas separadamente por dicho proveedor.

8. Subencargados

El Cliente otorga autorización general para el uso de los siguientes subencargados:

SubencargadoServicioUbicación
UpCloudAlojamiento e infraestructuraEurope-2, Frankfurt, Alemania
GoogleEnvío de correo, calendario/citas y servicios de infraestructura relacionadosPaíses donde la infraestructura de Google presta servicios
NatroCorreo electrónico, nombre de dominio y servicios de infraestructura relacionadosTürkiye

ARKITEK informará al Cliente con 30 días de antelación antes de añadir o sustituir un subencargado; el Cliente podrá oponerse por motivos razonables. ARKITEK impone a sus subencargados obligaciones de protección de datos equivalentes a las de este Acuerdo y sigue respondiendo ante el Cliente por sus actos.

9. Alojamiento y Transferencias Internacionales

Los datos de la plataforma se alojan en UpCloud Europe-2, Frankfurt, Alemania. Las transferencias desde Turquía a la UE se realizan conforme al art. 9 de la KVKK; si el Cliente lo necesita para sus propias obligaciones KVKK, ARKITEK comparte la documentación del mecanismo de transferencia. Para los datos originados en el EEE, el acceso de ARKITEK desde Turquía está sujeto a las garantías del Capítulo V del RGPD.

10. Notificación de Violaciones de Datos

Al tener conocimiento de una violación de datos personales, ARKITEK notificará al Cliente sin dilación indebida, facilitando información sobre la naturaleza de la violación, las categorías de datos y los interesados afectados, las posibles consecuencias y las medidas adoptadas. La notificación a la Autoridad/autoridad de control y a los interesados corresponde al Cliente como responsable; ARKITEK presta la asistencia necesaria.

11. Auditoría

El Cliente podrá auditar el cumplimiento de este Acuerdo dentro de un alcance razonable, o encargarlo a un auditor independiente, con un máximo de 1 vez al año y un preaviso de 15 días. ARKITEK podrá satisfacer esta obligación aportando sus propios registros de auditoría de seguridad y las certificaciones de seguridad del centro de datos del proveedor de alojamiento y documentación relacionada, en la medida en que estén disponibles.

12. Terminación

Al terminar el Contrato de Licencia, ARKITEK, a elección del Cliente, devolverá todos los datos personales en un formato de uso común y/o los eliminará de forma irreversible de sus sistemas en un plazo de 90 días; los registros sujetos a obligaciones legales de conservación se destruirán al término de dichos plazos. La supresión se confirma por escrito previa solicitud.

13. Responsabilidad y Ley Aplicable

La responsabilidad de las partes se rige por las disposiciones del Contrato de Licencia; no obstante, cada parte asume las sanciones administrativas derivadas de los incumplimientos de su propio ámbito de obligaciones. Este Acuerdo se rige por el derecho turco; los Tribunales de Ankara y las Oficinas de Ejecución serán competentes para los litigios.