Legal / Data Processing Agreement

Data Processing Agreement

The Article 28 terms under which Uplift Funnel processes end-user personal data on your behalf, including sub-processors and international transfers.

Effective 2026-07-25

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Doğukan Özgür Yılmaz trading as Uplift Funnel("Processor"), and applies whenever the Processor processes personal data on the Controller behalf. It is intended to satisfy Article 28(3) of the GDPR, the equivalent provisions of the UK GDPR, and Article 8 of the Turkish Personal Data Protection Law (KVKK).

No signature is required: this DPA takes effect on acceptance of the Terms. If your procurement process needs a countersigned copy, email privacy@upliftfunnel.com.

1. Roles

The Controller determines the purposes and means of processing end-user personal data. The Processor processes it only on the Controller instructions. For the Processor own customer account data it acts as a controller in its own right, governed by the Privacy Policy rather than this DPA.

The Controller is responsible for having a lawful basis for the processing, for the content of its flows, for what it chooses to collect through them, and for providing any notice or obtaining any consent its own end users require.

2. Instructions

The Processor processes personal data only as set out in Annex 1, as further instructed through the Controller use of the platform, and as required by law. If the Processor believes an instruction breaches data protection law, it will inform the Controller and may suspend that processing.

3. Confidentiality

The Processor ensures that any person authorised to process the personal data is bound by confidentiality and processes it only as necessary to provide the service.

4. Security

The Processor implements the technical and organisational measures described in Annex 2, appropriate to the risk, as required by Article 32. The Processor may update those measures provided the level of protection is not reduced.

5. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed on the Sub-processors page. The Processor will give at least 30 days notice by email before a new sub-processor begins processing, during which the Controller may object on reasonable data-protection grounds. If no alternative can be found, the Controller may terminate the affected part of the service without penalty.

The Processor imposes data protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance.

6. Assistance with data subject rights

The platform lets the Controller access, export, correct, and delete end-user data directly, which will usually be enough to answer a data subject request without our involvement. Where it is not, the Processor will provide reasonable assistance. If a request reaches the Processor directly, it will not respond substantively but will refer the individual to the Controller and inform the Controller promptly.

7. Personal data breaches

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller data, with the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken. The Processor will assist the Controller with its own obligations under Articles 33 and 34.

8. Data protection impact assessments

The Processor will provide reasonable assistance with any impact assessment or prior consultation with a supervisory authority relating to the processing under this DPA.

9. Audit and information

The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a documented security questionnaire not more than once a year. Where that is insufficient, and subject to reasonable notice, confidentiality, and no disruption to other customers, the Controller may audit the Processor at the Controller expense.

The Processor holds no third-party security certification today, and says so plainly on its Security page rather than implying otherwise here.

10. Deletion and return

On termination the Controller may export its data through the platform. The Processor will delete the personal data within 30 days of termination, except where storage is required by law — in which case it continues to protect it and processes it for no other purpose. Billing and revenue records retained for tax and accounting purposes are the main example.

11. International transfers

The Processor is established in Türkiye and uses sub-processors located in the European Union and the United States, so personal data will be transferred internationally. Where a transfer is from the EEA or the UK to a country without an adequacy decision, the parties rely on the European Commission Standard Contractual Clauses (Module Four, processor to controller, or Module Three as applicable), together with the UK Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference, and in the event of conflict they prevail.

Where KVKK applies to a transfer out of Türkiye, the Processor relies on the Controller explicit consent or another lawful ground under Article 9 of KVKK.

12. Liability and precedence

Each party liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict, this DPA prevails over the Terms in respect of the processing of personal data, and the Standard Contractual Clauses prevail over both.

Annex 1 — Details of the processing

Subject matter and duration

Provision of the Uplift Funnel platform, for the duration of the Controller account plus the retention periods in section 10.

Nature and purpose

Hosting and delivering onboarding and purchase funnels to the Controller application; receiving, storing, and aggregating funnel analytics events; receiving subscription transaction records from a provider the Controller connects and matching them to funnel activity in order to report and bill attributed revenue; and, at the Controller option, forwarding events to third-party destinations the Controller configures.

Categories of data subjects

End users of the Controller mobile applications.

Types of personal data

  • An anonymous identifier generated by the SDK, scoped to the Controller application.
  • A user identifier supplied by the Controller, where the identify method is used.
  • Funnel interaction data: session identifiers, flow and screen identifiers, event types, timestamps, and the answers the Controller flow was designed to collect.
  • Subscription transaction records received from the Controller revenue provider: product, price, currency, transaction identifiers, trial and renewal status, entitlements, environment.
  • Where the Controller enables a mobile measurement partner integration, an advertising identifier collected by that partner and sent to the Processor in a postback.

Special categories of personal data

None are required by the platform. The Processor does not request them. The Controller may inadvertently collect them through the questions it chooses to ask in a flow — for example health data in a wellness questionnaire — and remains responsible for having an Article 9 basis. See the Acceptable Use Policy.

What the Processor does not collect

The SDK does not read the advertising identifier (IDFA), the vendor identifier (IDFV), the Android advertising ID, or any other cross-app or cross-site tracking identifier.

Annex 2 — Technical and organisational measures

The measures in force are described in full on the Security page and are incorporated here. In summary: TLS in transit and encryption at rest; envelope encryption for connected-service credentials; API keys stored only as hashes and scoped to a single application; per-request tenancy checks on every read and write; append-only audit logging of changes; authenticated inbound webhooks with constant-time comparison and, for payments, HMAC signature verification with a replay window; database-backed rate limiting and request size caps; managed backups with point-in-time recovery; and restricted, multi-factor authenticated access to production.