Data Processing Addendum
Last updated · 10 sections
If you process personal data of EU / UK / Türkiye residents while using Spatly, the GDPR / UK GDPR / KVKK position us as a data processor for your account data and as a sub-processor for any personal data you upload as surface content. This addendum sets out how we do that.
Sections
Scope and Roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (the workspace owner, “you”) and Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi (“Spatly”, “we”). It applies whenever personal data subject to the GDPR, the UK GDPR or the Turkish KVKK (Law No. 6698) is contained in the datasets, layers, surfaces or connections you place in a Spatly workspace.
- You are the controller (or, where you act for a client, a processor) of the personal data in your workspace content.
- Spatly is your processor for that content, acting only on your documented instructions, which are these terms, your configuration of the workspace, and the actions you and your agents take through Studio, the API and MCP.
- Spatly is an independent controller for your account, billing and usage data as described in the Privacy Policy.
Details of Processing
- Subject matter
- Hosting, storing, rendering, publishing and serving the customer’s spatial content, including live data refreshed on the customer’s schedule.
- Duration
- The term of the account, plus the 30-day deletion window.
- Nature and purpose
- Storage in PostGIS and object storage; transformation into map tiles, surfaces and snapshots; delivery to viewers at spatly.io/s/<id>, on custom domains and in embeds; API and MCP access; optional AI generation from dataset samples.
- Data subjects
- Whoever appears in the customer’s datasets (for example residents, customers, employees, incident records) and the customer’s own workspace members.
- Categories of data
- Determined by the customer. Typically location and address data, names, attributes attached to features, and timestamps. Special categories may only be processed where the customer has a lawful basis.
Processor Obligations
Spatly will:
- Process personal data only on your documented instructions, including with regard to transfers, unless required to do so by law, in which case we inform you unless the law prohibits it.
- Ensure that persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures listed below.
- Engage sub-processors only as set out in this DPA and remain responsible for their performance.
- Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations on security, breach notification and impact assessments.
- Delete or return all personal data at the end of the service, as set out in Return and Deletion.
- Make available the information necessary to demonstrate compliance and allow for audits, on reasonable notice and no more than once a year unless required by a supervisory authority.
Sub-processors
You authorise the following sub-processors. We will give at least 30 days’ notice by email to workspace owners before adding or replacing one; you may object on reasonable data-protection grounds and terminate the affected service if we cannot resolve the objection.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider | Servers, database (Postgres/PostGIS) and S3-compatible object storage for all workspace content, with encrypted daily backups. | Netherlands (EU) |
| Paddle | Payments, invoices and tax as Merchant of Record. Receives the billing contact’s name, email and payment details. | United Kingdom / United States |
| Anthropic | AI features. Receives dataset field names, statistics, bounding box and up to 20 sample rows per request. No training on inputs. | United States |
| OAuth sign-in, only for users who sign in with Google. Google Analytics 4, on our marketing site and the Studio app only, with IP anonymisation and advertising signals off; not used on customer-published surfaces or embeds. | United States / EU | |
| Zoho Mail | Transactional email delivery (verification, password reset, alerts, billing notices). | EU data centres |
| Map tile providers | OpenFreeMap (OpenStreetMap data), Esri World Imagery, AWS Terrain Tiles and OpenTopoMap. Tiles are requested by the viewer’s browser, so the provider sees the viewer’s IP address; no customer content is sent. Nominatim geocoding is proxied and cached by us. | EU / United States |
Security Measures
- TLS for all traffic; HSTS on spatly.io.
- Passwords hashed; API and MCP tokens stored as hashes with only the prefix in clear text; tokens scoped read / write / publish and revocable at any time.
- Connection credentials encrypted at rest with a key held outside the database.
- Per-workspace access control with owner, admin, editor and viewer roles; published surfaces can be public, password-protected or restricted to allowed domains.
- Rate limiting on the API, MCP and viewer endpoints; CSRF protection on Studio.
- Encrypted daily backups retained for 30 days; infrastructure in the EU.
- Access to production limited to named staff, logged, and reviewed.
International Transfers
Workspace content is stored in the EU. Where a sub-processor processes data outside the EEA or the UK, the transfer is covered by the European Commission’s Standard Contractual Clauses (and the UK Addendum) in our agreement with that sub-processor. Access by Türkol Yazılım staff from Türkiye for support and operations is a transfer under KVKK Art. 9 and GDPR Chapter V and is covered by the same clauses and, where required, by your explicit consent recorded at sign-up.
Data Subject Requests
If a data subject contacts us directly about content in your workspace, we will refer them to you and will not respond on your behalf unless you instruct us to. You can search, edit and delete records in your datasets from Studio and through the API at any time; where you need our help, write to support@spatly.io and we will assist within 10 business days.
Personal Data Breaches
We will notify workspace owners without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting their content, with the information reasonably available at that time and updates as the investigation proceeds.
Return and Deletion
You can export every project as JSON from Studio at any time during the term. On termination or on your request, we delete the workspace content within 30 days and it ages out of backups on the same schedule, unless the law requires us to keep specific records. On request we confirm deletion in writing.
Data Controller Details
- Company
- Türkol Yazılım Bilgisayar Sanayi ve Ticaret Limited Şirketi
- Tax ID (Vergi No)
- 8800579984, Tax Office: Şarköy
- Address
- İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey
- support@spatly.io
To sign a written DPA for your organisation, including the Standard Contractual Clauses, email support@spatly.io.
- Tax ID (Vergi No)
- 8800579984 Tax Office: Şarköy
- Address
- İSTİKLAL MAH. GANOS SK. NO: 5 B, 59800 Şarköy / Tekirdağ, Turkey
- support@spatly.io
Spatly is a product of Türkol Yazılım. Paddle.com Market Ltd. is the Merchant of Record for all paid plans.
Questions about any of these documents: support@spatly.io. We answer within 30 days, usually much sooner.