DIDOSHE OS — Data Processing Agreement (DPA)
Questo documento non è ancora disponibile nella tua lingua. Fa fede il testo inglese riportato di seguito.
Last updated: 26 August 2026
This agreement is an integral annex to the Terms of Service. It takes effect the moment the Studio begins using DIDOSHE OS; no separate signature is required.
1. Parties and purpose
1.1 This Data Processing Agreement ("DPA") is between the business subscribing to DIDOSHE OS ("Studio", "Controller") on the one hand and SCARPAX LLC ("DIDOSHE", "Processor") on the other.
1.2 This DPA applies to the personal data that the Studio enters into the system while using DIDOSHE OS and that DIDOSHE processes on the Studio's behalf.
1.3 This DPA takes the place of the written contract required under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and art. 28 of the European Union General Data Protection Regulation ("GDPR", 2016/679).
1.4 In the event of a conflict between this DPA and the Terms of Service, this DPA prevails on matters relating to the protection of personal data.
2. Roles
2.1 The Studio is the controller. The Studio decides for what purpose and by what means End Client data is processed.
2.2 DIDOSHE is the processor. DIDOSHE processes this data only on the Studio's instructions and for the purpose of providing the Service.
2.3 DIDOSHE is also a controller in its own right in respect of its own subscription, billing, support and security data. That data falls within the scope of the Privacy Policy, not this DPA.
2.4 The parties agree that this relationship is not a joint controllership relationship.
3. Subject matter and scope of the processing
Details are in Annex 1. In summary:
| Item | Description |
|---|---|
| Subject matter | Providing the Studio with appointment, client, staff, stock and business management software |
| Duration | The subscription term + a 30-day export window after termination |
| Nature and purpose | Storing, organising, displaying and transmitting the data and processing it on the Studio's instructions |
| Types of data | Listed in Annex 1 |
| Categories of data subject | End Clients, Studio staff |
4. DIDOSHE's obligations
DIDOSHE shall:
4.1 Process personal data only on the Studio's documented instructions. The Terms of Service, this DPA and the way the Studio uses the Service constitute documented instructions.
4.2 Not use the data for its own purposes, not sell or rent it to third parties and not use it for marketing purposes.
4.3 Ensure that all personnel with access to the data are under a duty of confidentiality. This duty continues indefinitely after the employment relationship ends (KVKK art. 12/4).
4.4 Limit access to the minimum number of people and the minimum scope the work requires.
4.5 Implement the technical and organisational measures set out in Annex 3 and keep them up to date.
4.6 In the event of a personal data breach, act in accordance with clause 7.
4.7 Provide the Studio with reasonable assistance so that it can respond to data subject requests and to its statutory obligations (impact assessments, notifications to the authority, and similar).
4.8 Delete or return the data in accordance with clause 11 when the subscription ends.
4.9 Provide the Studio with the information needed to demonstrate compliance with this DPA and allow the audit described in clause 8.
5. Special category data (health data)
5.1 Certain records kept in beauty and care services — allergies, skin problems, medication used, pregnancy status, contraindication forms, before/after photographs — may qualify as special category personal data (health data) within the meaning of KVKK art. 6 and GDPR art. 9.
5.2 Before entering data of this kind into the system, the Studio must:
- obtain the data subject's explicit consent (or rely on another valid exception),
- record that consent in a way that can be evidenced,
- separately inform the data subject,
- carry out an impact assessment on its own side where required.
DIDOSHE does not obtain these permissions on the Studio's behalf.
5.3 DIDOSHE applies the additional measures set out in Annex 3 in the areas where special category data is processed. The measures in place are set out item by item in Annex 3.
5.4 Recommendation to the Studio: rather than writing information of this kind into free-text note fields, keep it in the fields designed for that purpose. Free-text fields make it harder to give effect to deletion and rectification requests.
6. The Studio's obligations
6.1 The Studio warrants that the personal data it enters into the system has been collected lawfully and that it has a valid legal basis for processing it.
6.2 The Studio is responsible for meeting its duty to inform its own End Clients. That information notice must state that the data is held in software called DIDOSHE OS and is transferred abroad.
6.3 The Studio is responsible for obtaining the permissions required to send messages via WhatsApp or other channels (see Terms of Service, clause 8).
6.4 Unlawful instructions. If DIDOSHE forms the view that an instruction breaches the applicable legislation, it will inform the Studio and may refuse to carry out that instruction. If the Studio insists on the instruction, DIDOSHE may suspend the processing concerned or terminate the agreement; it will not be liable for any loss arising as a result.
6.5 The Studio is responsible for managing its own user accounts and for closing off access for staff who leave.
7. Personal data breach
7.1 When DIDOSHE becomes aware of a personal data breach affecting Studio Data, it will inform the Studio without undue delay and in any event within 48 hours.
7.2 The notification will include the following information as available at that time: the nature of the breach, the categories of data affected and the approximate number of people affected, the likely consequences, the measures taken and planned, and a point of contact.
7.3 All of the information may not be available at the outset; in that case the information will be provided in phases. The initial notification will not be delayed on the grounds that information is incomplete.
7.4 Notifying the relevant authority (in Turkey the Personal Data Protection Authority, in the EU the competent supervisory authority) and the data subjects is the Studio's obligation; DIDOSHE will provide the information and support needed for those notifications.
7.5 DIDOSHE will itself notify the relevant authority of a breach affecting the data it holds in its own capacity as a controller (subscription, billing, support and security logs). A breach affecting Studio Data is subject to clause 7.4 as regards notification to the authority, even if it occurred in DIDOSHE's infrastructure; DIDOSHE does not make that notification on the Studio's behalf.
8. Audit
8.1 To demonstrate its compliance, DIDOSHE will provide the Studio with its current security documentation, a summary of any independent audit/certification reports, and written answers to reasonable question lists.
8.2 If this information does not resolve the Studio's reasonable doubt, the Studio may carry out an audit once a year, on at least 30 days' prior written notice, during business hours and in a manner that does not disrupt operations. If a personal data breach has occurred, or if a competent authority has required an audit, the annual limit does not apply and the notice period is reduced to 10 days.
8.3 The audit may be carried out by the Studio or by an independent auditor appointed by the Studio who is not a competitor of DIDOSHE and who signs a confidentiality undertaking.
8.4 The costs of the audit are borne by the requesting party. If a material non-compliance is identified in the audit, the costs are borne by DIDOSHE.
9. Data subject requests
9.1 If a data subject request that reaches DIDOSHE directly relates to the Studio's data, DIDOSHE will not answer the request itself; it will forward it to the Studio within 72 hours.
9.2 DIDOSHE provides access, rectification, deletion and export tools within the Service so that the Studio can respond to these requests. These tools are: viewing and editing records, deletion, and exporting the client list and reports in Excel format.
9.3 For unusual and labour-intensive requests that cannot be met with the tools within the Service, DIDOSHE may charge a reasonable fee; that fee will be notified in advance.
10. Sub-processors
10.1 The Studio is deemed to have given general authorisation for DIDOSHE to use the sub-processors listed in Annex 2.
10.2 DIDOSHE will inform the Studio by email at least 30 days before adding a new sub-processor or replacing an existing one.
10.3 The Studio may object within that 30-day period on reasonable and documented data protection grounds. If the parties do not agree on a solution within 15 days of the date of the objection, the Studio may, within 30 days of the end of that 15-day period, terminate only the affected service on 10 days' notice.
10.4 DIDOSHE enters into written contracts with sub-processors on terms equivalent to the obligations in this DPA and remains liable to the Studio itself for the acts of the sub-processor.
11. Deletion or return after termination
11.1 When the subscription ends, the Studio is given 30 days to export its data.
11.2 At the end of that period Studio Data is permanently deleted.
11.3 Copies held in backup systems are deleted in the ordinary course of the backup cycle; the protection obligations in this DPA continue to apply throughout that period.
11.4 Records that must be retained by law (invoices, payments) are an exception and are kept solely for the purpose of retention.
12. Liability
12.1 Each party is liable for loss arising from a breach of its own obligations.
12.2 The Studio will cover any claims, proceedings and administrative fines directed at DIDOSHE because the data entered into the system was collected unlawfully, because the necessary permissions were not obtained, or because the Studio gave an unlawful instruction.
12.3 Liability cap. Liability arising under this DPA is subject to the limits and the cap in clause 19 of the Terms of Service. This DPA does not increase the cap in the main agreement. The Studio's indemnity obligation under clause 12.2 falls outside that cap.
12.4 The joint liability of the controller and the processor for taking data security measures under KVKK art. 12/2 is reserved. The provisions of this clause govern only the internal relationship between the parties.
13. Term and general provisions
13.1 This DPA applies for as long as the Terms of Service are in force and, in addition, until the deletion under clause 11 is complete. In respect of copies remaining in backup systems and records retained under the applicable legislation, the confidentiality and security obligations in this DPA continue until those records are deleted.
13.2 The confidentiality obligations, the deletion obligation in clause 11 and the liability provisions in clause 12 survive termination of the agreement.
13.3 DIDOSHE may update this DPA because of a change in the law or a change of sub-processor. Material changes will be notified 30 days in advance.
13.4 The governing law and the competent court are those set out in clause 24 of the Terms of Service.
13.5 Data protection contact point. For all notices under this DPA (breach notification, sub-processor change, data subject request, audit request): kvkk@didoshe.co. Notices to the Studio are sent to the email address registered on the Studio's account.
ANNEX 1 — Description of the processing activity
Subject matter of the processing: provision of the DIDOSHE OS software to the Studio.
Duration: the subscription term + a 30-day export window after termination (see clause 11.1).
Nature and purpose: storage, organisation, display, search, transmission, backup, deletion; running the Studio's appointment, client, staff, stock and business management processes.
Types of personal data processed:
| Group | Data |
|---|---|
| Identity and contact | Full name, telephone, email, address (if the Studio enters it) |
| Appointment | Date, time, service, assigned staff member, status, cancellation/no-show record |
| Commercial | Services and packages purchased, payment records, balance (End Client payment records are held only in Supabase; they are not sent to the payment provider) |
| Free text | Client notes, appointment notes |
| Image | Staff expense receipt photographs and screenshots attached to issue reports. There is no before/after photograph feature |
| Special category (if the Studio enters it) | Allergies, skin condition, medication, pregnancy, contraindications |
| Staff | Full name, contact details, role, working hours, performance/sales records |
| Technical | IP address, login records, device information |
Categories of data subject: the Studio's End Clients; the Studio's employees; people using the public booking page.
Frequency of processing: continuous.
ANNEX 2 — Approved sub-processors
The current list is also published at https://os.didoshe.co/en/sub-processors.
| Sub-processor | Service | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All Studio Data | USA — North Virginia (AWS us-east-1) |
| Vercel | Application hosting, network | Request data, IP, technical logs | USA — Washington D.C. |
| Stripe | Subscription payments | The Studio's billing data (not End Client data) | USA |
| Resend | Transactional emails | Recipient address and message content | USA |
| Twilio | WhatsApp message delivery | End Client telephone number, message content | USA |
| Meta Platforms (WhatsApp) | Messaging infrastructure | End Client telephone number, message content | Meta's global infrastructure |
| Anthropic PBC | Text and image processing (receipt reading) | Images/text submitted | USA |
| ElevenLabs Inc. | Speech-to-text in voice booking | Voice recording and extracted text | USA |
| ElevenLabs | Voice generation (briefings) | Text converted to speech | USA |
Notes:
- Anthropic does not use content submitted through the commercial API for model training, and a data processing agreement is included in its commercial terms.
- ElevenLabs' setting allowing customer content to be used for model development is on by default and must be turned off in the account settings. This preference has been switched off in our account.
- Twilio and Meta accept no liability for loss arising from a message failing to be delivered; this risk is dealt with in clause 8 of the Terms of Service.
ANNEX 3 — Technical and organisational measures
The list below shows the measures actually in place as at 26 August 2026.
Access control
- Role-based authorisation: studio owner and staff permissions are distinct; staff cannot reach settings or sales screens
- Row level security (RLS) at database level: each Studio can access only its own data. This is a rule enforced by the database itself, not a filter in the application layer
- Staff see only the expense records they entered themselves
- End Client phone numbers and e-mail addresses are never sent to a staff member's device unless permission is granted separately
- System keys carrying full privileges are held only on the server side
- The administrator panel is served from an undisclosed address and returns a not-found response to unauthorised access
Encryption
- TLS in transit
- Encryption at rest: provided at disk level by the infrastructure provider
- Passwords stored as irreversible hashes
Integrity and verification
- Scheduled jobs are protected by a secret key; calls without it are rejected
- Notifications from the payment provider are verified by signature
Resilience and backup
- Backups are taken as part of the infrastructure provider's standard backup service
Monitoring and logging
- Message delivery history (successful and failed deliveries)
- Cancelled sales records (who, when)
- Account deletion requests
- System event stream (new registrations, payments, e-mail delivery failures)
Organisational
- Access limited to what the role requires
- Removal of access on departure
Measures not implemented. The following are not currently in place and are not undertaken under this agreement: multi-factor authentication, comprehensive access audit logging, regular penetration testing, backup restore drills, data loss prevention software, endpoint management and regular staff security training.
Additional measures for special category data (referred to in clause 5.3) The Service is not designed for the processing of special category personal data, and entering such data is the Studio's own responsibility under the Terms of Service. For that reason no separate set of measures is applied to special category data; the general measures above apply.
ANNEX 4 — International transfers
A. For Studios established in Turkey
A.1 Studio Data is transferred outside Turkey because of the sub-processors listed in Annex 2.
A.2 Under art. 9 of Turkish Law No. 6698, this transfer is made on the basis of the module of the standard contract governing controller-to-processor transfers, as published by the Personal Data Protection Board.
A.3 The text of the standard contract published by the Board must be inserted, without modification and in Turkish, following this annex, and must be signed by the parties. The text of that contract has not been reproduced in this document; it is essential that the current version of the Board's text is used.
A.4 Notification duty. The signed standard contract must be notified to the Authority (Kurum) within 5 business days of the date of signature. Under the Law, this notification duty falls on the party making the transfer (the Studio). To make the process easier, DIDOSHE will provide the Studio with the signed counterpart and the information required; it is not liable for administrative sanctions arising from a failure to make the notification.
A.5 Explicit consent is not a valid basis for continuous and systematic transfers (the exception for incidental cases in art. 9/6). Transfers under this Service are therefore not based on explicit consent.
B. For Studios established in the European Union / United Kingdom
B.1 For transfers outside the EU, the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module 2 (controller to processor), apply and are deemed to have been entered into between the parties upon signature of this annex.
B.2 For transfers from the United Kingdom, the UK Addendum (IDTA addendum) applies.
B.3 The Standard Contractual Clauses are the primary basis for the transfer. Reference to the EU-US Data Privacy Framework (DPF) is made only as a supplementary matter; should the Framework cease to be valid, the transfer continues uninterrupted on the basis of the Standard Contractual Clauses.
B.4 For the Standard Contractual Clauses annexes: data exporter = the Studio. Data importer = SCARPAX LLC. The description of the processing is in Annex 1, the security measures in Annex 3 and the sub-processors in Annex 2. Supervisory authority: the data protection authority of the EU member state in which the Studio is established.