Data Processing Addendum
Last updated: 16.07.2026
1. Introduction and Scope
This Data Processing Addendum ("DPA") governs the processing of personal data by Apilex Teknoloji Anonim Şirketi, operating as Apilex ("Apilex", "we", "us"), on behalf of the customer identified in the applicable Customer Agreement ("Customer", "you"), in connection with Apilex's provision of the Services.
This DPA supplements, and forms part of, the Customer Agreement entered into between Apilex and the Customer, together with the General Terms and Conditions published on our website (collectively, the "Agreement"). In the event of any conflict or inconsistency among these documents, the following order of precedence applies: (1) the Standard Contractual Clauses, to the extent they apply under Section 6; (2) this DPA; and (3) the rest of the Agreement.
This DPA applies where Apilex processes personal data as a data processor on behalf of the Customer, who acts as data controller. It does not apply to personal data for which Apilex acts as an independent data controller, which is addressed in our Privacy Policy.
Any input submitted to, or output generated by, our platform, and any documents uploaded to our platform (collectively, "Content"), are processed by Apilex on behalf of the Customer, who is the data controller of that Content.
2. Definitions
Terms not defined in this Section have the meaning given to them elsewhere in this DPA.
- "Agreement": means, collectively, the Customer Agreement and the General Terms and Conditions, as defined in Section 1.
- "Content": has the meaning given in Section 1.
- "Data Controller" and "Data Processor": have the meanings given to them under Data Protection Law.
- "Data Protection Law": means the GDPR and any other data protection law applicable to the processing of Content under this DPA.
- "GDPR": means Regulation (EU) 2016/679.
- "Personal Data Breach": means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Content.
- "Restricted Transfer": means a transfer of Content that requires a data transfer mechanism under Chapter V of the GDPR.
- "Security Addendum": means the document of that name published by Apilex, as updated from time to time, describing the technical and organizational measures referred to in Section 7.
- "Standard Contractual Clauses": means the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, updated, or replaced.
- "Sub-Processor List": means the document of that name published by Apilex, as updated from time to time in accordance with Section 5.
3. Data Processing Roles and Instructions
3.1 Roles. As between Apilex and the Customer, the Customer is the Data Controller and Apilex is the Data Processor with respect to Content. Apilex processes Content solely on behalf of, and in accordance with the documented instructions of, the Customer.
3.2 Instructions. The Customer's instructions to Apilex regarding the processing of Content are set out in the Agreement, this DPA (including its Annexes), and the Customer's use of the Services' features and functionalities. Any additional instructions require the prior written agreement of the parties, including as to any additional costs resulting from carrying out such instructions. Where the Customer amends its processing instructions after the Effective Date, Apilex may charge for any reasonable additional costs this results in, except where the amendment is required to comply with Data Protection Law.
3.3 Processing Requirements. As a Data Processor, Apilex shall:
- (a) process Content only on behalf of, and in accordance with, the Customer's documented instructions; if Apilex is required by applicable law to process Content outside those instructions, Apilex shall promptly notify the Customer of that legal requirement before processing, unless applicable law prohibits Apilex from providing such notice;
- (b) promptly notify the Customer if, in Apilex's opinion, an instruction infringes applicable Data Protection Law;
- (c) ensure that persons authorized to process Content are subject to appropriate confidentiality obligations;
- (d) not sell Content, and not use it for any purpose other than to provide the Services, and in particular shall not use Content for analytics, marketing, or to train or improve any AI model;
- (e) taking into account the nature of the processing, provide reasonable assistance to the Customer, by appropriate technical and organizational measures, in fulfilling the Customer's obligations to respond to Data Subject Requests relating to Content.
4. Obligations of the Customer
4.1 The Customer represents and warrants that it has, and shall maintain throughout the term of the Agreement, all necessary rights, consents, and legal bases to provide Content to Apilex and to instruct Apilex to process it as contemplated by this DPA.
4.2 The Customer shall comply with all Data Protection Law applicable to it as a Data Controller of Content. In particular, with respect to any personal data of third parties (such as clients, opposing parties, or witnesses) contained in the documents or other materials it uploads to the Services, the Customer represents and warrants that:
- (a) such personal data has been lawfully obtained;
- (b) it has informed the relevant third parties of the processing, where required by applicable law; and
- (c) the processing rests on an appropriate legal basis.
Where such materials contain special categories of personal data within the meaning of Article 9 GDPR (for example, health data, data concerning criminal convictions, or trade union membership), the Customer remains the Data Controller of that data and is responsible for ensuring its lawful processing; Apilex processes it solely as a Data Processor, on the Customer's instructions.
4.3 The Customer shall limit the personal data it provides to Apilex to what is necessary for the purpose of the Agreement. In particular, the Customer shall not include personal data, other than technical contact information, in support requests submitted to Apilex, including in screenshots, conversation excerpts, or other attachments.
4.4 The Customer shall reasonably cooperate with Apilex to enable Apilex to perform its obligations under this DPA and applicable Data Protection Law.
4.5 The Customer acknowledges that it, rather than Apilex, is responsible for certain configuration and usage decisions relating to the Services, including whether and how it uses optional features or third-party integrations (such as connecting the platform to Google Drive or a similar service), and the technology it uses to access the Services. The Customer is responsible for implementing such configurations and decisions in a manner that complies with applicable Data Protection Law. This Section does not affect Apilex's own obligations under Section 7 with respect to the Services it provides.
4.6 The Customer shall indemnify and hold Apilex harmless from and against any claims, damages, fines, or other losses arising from the Customer's breach of its representations and warranties under this Section 4, including any claim brought by a third party whose personal data was included in Content in violation of Section 4.2.
5. Sub-processors
5.1 The Customer grants Apilex a general written authorization to engage sub-processors to carry out the processing activities described in this DPA, provided that Apilex imposes on each sub-processor, by way of a written agreement, data protection obligations that are materially the same as those set out in this DPA.
5.2 Apilex's current sub-processors are listed in the Sub-Processor List. Apilex shall inform the Customer of any new sub-processor by updating the Sub-Processor List, at least 30 days before the change takes effect. The Customer may object in writing, within 30 days of the update being posted, on grounds relating to the new sub-processor's ability to comply with applicable Data Protection Law. Apilex shall not engage the new sub-processor before this 30-day period has elapsed.
5.3 If the Customer objects under Section 5.2, the parties shall discuss the objection in good faith and use reasonable efforts to find a mutually acceptable solution. Because Apilex is not always able to offer an alternative means of providing the Services without the relevant sub-processor, this may include the Customer accepting the sub-processor subject to additional safeguards, or the Customer and Apilex agreeing to adjust the scope of the Services accordingly. If the parties are unable to reach a resolution within 30 days of the objection, either party may terminate the affected Services or the Agreement for cause upon written notice.
5.4 The liability provisions set out in the Agreement shall apply to this DPA, including with respect to Apilex's liability for the acts and omissions of its sub-processors.
6. Cross-Border Data Transfers
6.1 The Customer acknowledges that, in order for Apilex to provide the Services, Content may be transferred from the Customer's location in the EEA to Apilex in Türkiye, and, as set out in the Sub-Processor List, to certain sub-processors located outside the EEA.
6.2 To the extent any transfer described in Section 6.1 constitutes a Restricted Transfer, the Standard Contractual Clauses, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914, are incorporated into this DPA by reference and shall apply as follows:
- (a) for the transfer of Content from the Customer (as data exporter) to Apilex (as data importer), Module Two (Controller to Processor) shall apply, completed as set out in Annex I;
- (b) for the onward transfer of Content from Apilex (as data exporter) to a sub-processor located outside the EEA (as data importer), Module Three (Processor to Processor) shall apply, completed as set out in Annex I.
6.3 For the purposes of the Standard Contractual Clauses incorporated under this Section:
- (a) the governing law under Clause 17 of the Standard Contractual Clauses shall be the law of the Netherlands;
- (b) the competent courts under Clause 18(b) of the Standard Contractual Clauses shall be the courts of the Netherlands;
- (c) the competent supervisory authority under Annex I.C shall be as set out in Annex I.C below;
- (d) the optional docking clause in Clause 7 of the Standard Contractual Clauses shall apply.
6.4 Apilex represents that, as of the effective date of this DPA, it has no reason to believe that the laws or practices applicable to it, or to any sub-processor located outside the EEA, prevent it from fulfilling its obligations under the Standard Contractual Clauses. The parties shall, upon either party's reasonable request but no more than once per year, review together whether this remains the case, taking into account any relevant developments in the law or practice of the jurisdictions concerned. If Apilex becomes unable to comply with these obligations, whether following such a review or otherwise, it shall promptly notify the Customer, and the Customer shall be entitled to suspend the relevant transfer.
6.5 Where a new international transfer mechanism becomes available under Data Protection Law (for example, an adequacy decision applicable to Türkiye), the parties shall cooperate in good faith to apply that mechanism in place of the Standard Contractual Clauses, provided this would not reduce the level of protection afforded to the Customer's personal data.
7. Security and Confidentiality
7.1 Security Measures. Apilex shall implement and maintain appropriate technical and organizational measures designed to protect Content against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, and risks of the processing. These measures are further described in the Security Addendum, which is incorporated into this DPA by reference. These measures include, among others, automatically detecting and masking personal data contained in Content before it is transmitted to any AI model, such that the model does not process the underlying personal data in identifiable form; the original values are restored only after the model's output is returned to the Customer.
7.2 Confidentiality. Apilex shall ensure that any person authorized to process Content is subject to an obligation of confidentiality, whether contractual or statutory, and that access to Content is limited to personnel who require it to perform their duties in connection with the Services.
7.3 Personal Data Breach Notification. Apilex shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Content. This notification shall, to the extent then known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it; where not all information is available at the time of notification, Apilex shall provide it in phases without undue further delay. The obligations in this Section 7.3 and in Section 7.4 do not apply to the extent a Personal Data Breach results from the Customer's own act or omission.
7.4 Assistance. Apilex shall provide the Customer with reasonable assistance and cooperation as the Customer may require to comply with its own obligations under Data Protection Law in relation to the Personal Data Breach, including any notification to a supervisory authority or affected data subjects.
7.5 Audit Rights. Apilex shall make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including on-site inspections, conducted by the Customer or an auditor mandated by the Customer. Such audits shall be carried out in the manner, and subject to the frequency, cost allocation, and confidentiality protections, set out in the Security Addendum.
8. Assistance to the Customer
Upon the Customer's written request, Apilex shall provide reasonable assistance to the Customer, taking into account the nature of the processing and the information available to Apilex, with:
- (a) responding to requests from data subjects seeking to exercise their rights under Data Protection Law with respect to Content, where Apilex is not authorized to respond to such requests directly; and
- (b) the Customer's data protection impact assessments and, where necessary, prior consultations with a competent supervisory authority, to the extent these relate to Apilex's processing of Content under this DPA.
Assistance under this Section shall be provided at the Customer's reasonable expense, except where the need for assistance results directly from Apilex's own act or omission.
9. Notice to Customer
Apilex shall, to the extent legally permitted, inform the Customer without undue delay if Apilex receives:
- (a) a legally binding request from a public authority for the disclosure of Content;
- (b) any notice, inquiry, or investigation by a supervisory authority relating to Apilex's processing of Content under this DPA; or
- (c) a complaint or request from a data subject relating to Content.
Other than to request further information necessary to identify the data subject or the request, Apilex shall not respond to a request described in paragraph (c) without the Customer's prior written authorization.
Upon receiving a request described in paragraph (a), Apilex shall first attempt to redirect the requesting authority to seek the Content directly from the Customer, and may share the Customer's basic contact details with the authority for this purpose. If Apilex is nonetheless compelled to disclose Content, it shall give the Customer reasonable notice of the request to allow the Customer to seek a protective order or other appropriate remedy, unless legally prohibited from doing so. Apilex shall not voluntarily disclose Content to any public authority.
10. Measures Upon Completion of Processing
Upon termination or expiry of the Agreement, Apilex shall, at the Customer's instruction, either delete Content or return it to the Customer, and delete existing copies, unless applicable law requires Apilex to retain it.
The Customer may instruct immediate deletion, or a grace period of up to 30 days during which the account is suspended and Content remains available for export or reactivation before deletion. For a corporate tenant, only an authorized administrator may give this instruction and determine its scope; for an individual account, the account holder may do so directly. Further detail on how to exercise this choice is available in Apilex's account settings and support documentation.
Apilex shall retain records it is required to keep for its own legal obligations (for example, invoicing and tax records) separately from Content, for the periods required by law, with access restricted to personnel with a legitimate need.
Where Content is subject to an ongoing legal hold of which Apilex has been made aware, Apilex shall suspend deletion until the hold is lifted.
Apilex shall instruct its sub-processors to delete or return Content in accordance with this Section, and shall maintain records of deletion activity for 3 years for audit purposes. Apilex shall certify deletion to the Customer upon the Customer's request.
11. Term
This DPA takes effect on the date the Customer accepts the Agreement and remains in effect for as long as Apilex processes Content on the Customer's behalf, notwithstanding any termination or expiry of the Agreement. Sections 7 (Security and Confidentiality), 9 (Notice to Customer), and 10 (Measures Upon Completion of Processing) survive termination to the extent necessary to give them effect.
12. Governing Law
Except as otherwise required by Data Protection Law, this DPA is governed by the same law, and subject to the same dispute resolution provisions, as the Agreement.
13. Amendments
Apilex may update this DPA from time to time to reflect changes in Data Protection Law, industry practice, or its business operations. Apilex shall notify the Customer of any material change at least 30 days before it takes effect, by posting the updated DPA and notifying the Customer through the contact details on file.
If a material change reduces the level of protection afforded to the Customer's personal data, the Customer may object in writing within 30 days of the notice. If the parties are unable to resolve the objection, the Customer may terminate the Agreement upon written notice, effective before the change takes effect, without penalty. Continued use of the Services after a change takes effect constitutes acceptance of the updated DPA.
Notwithstanding the foregoing, Apilex may update the Sub-Processor List and the Security Addendum in accordance with Sections 5 and 7.
Annex I — Completion of the Standard Contractual Clauses
This Annex I completes the Standard Contractual Clauses incorporated by reference under Section 6 of the DPA, for both Module Two (Controller to Processor) and Module Three (Processor to Processor).
Module Two (Controller to Processor) — Customer to Apilex
A. List of Parties
Data exporter
- Name: As set out in the Agreement.
- Address: As set out in the Agreement.
- Activities relevant to the data transferred: Use of the Services as described in the Agreement.
- Role: Controller.
Data importer
- Name: Apilex Teknoloji Anonim Şirketi (operating as Apilex).
- Address: Osmangazi Mah. 3117. Sokak Altınbaş Teknopark No:3/15 Esenyurt/İstanbul
- Activities relevant to the data transferred: Providing the Services in accordance with the Customer's instructions, as described in the DPA.
- Role: Processor.
B. Description of Transfer
- Categories of data subjects: Individuals identified in Content, which may include the Customer's clients, opposing parties, witnesses, employees, or other individuals named in documents uploaded to the Services.
- Categories of personal data: Determined by the Customer, according to the content of the documents and other materials it uploads to the Services.
- Special categories of data (if applicable): May include personal data described in Article 9 GDPR (such as health data, data concerning criminal convictions, or trade union membership) where contained in Content, as described in Section 4.2 of the DPA. Where such data is transferred, Apilex applies the access restrictions and confidentiality obligations described in Section 7 of the DPA.
- Nature of the processing: Storage, retrieval, analysis, and generation of outputs by an AI-powered legal research and document-generation platform, in accordance with the Customer's instructions; personal data contained in Content is automatically masked before being transmitted to any AI model and restored only in the output returned to the Customer.
- Purpose of the transfer and further processing: Providing the Services under the Agreement.
- Duration of processing: For the term of the Agreement, and thereafter as provided in Section 10 of the DPA.
- Frequency of the transfer: Continuous, for as long as the Customer uses the Services.
- For transfers to sub-processors, subject matter, nature, and duration of processing: As described in the Sub-Processor List.
C. Competent Supervisory Authority
The supervisory authority of the EEA member state in which the Customer is established.
Module Three (Processor to Processor) — Apilex to Sub-processors Located Outside the EEA
A. List of Parties
Data exporter
- Name: Apilex Teknoloji Anonim Şirketi (operating as Apilex).
- Address: Osmangazi Mah. 3117. Sokak Altınbaş Teknopark No:3/15 Esenyurt/İstanbul
- Activities relevant to the data transferred: Instructing the relevant sub-processor to process Content on behalf of the Customer, as described in the DPA.
- Role: Processor.
Data importer(s)
- Name, address, and contact details: As identified for each relevant sub-processor in the Sub-Processor List.
- Activities relevant to the data transferred: As described for each relevant sub-processor in the Sub-Processor List.
- Role: Sub-processor.
B. Description of Transfer
Categories of data subjects, categories of personal data, special categories of data, nature of the processing, and duration: As set out in Section B of Module Two above, limited in each case to the specific processing activity carried out by the relevant sub-processor, as described in the Sub-Processor List.
Purpose of the transfer and further processing: Performing the specific processing activity described for the relevant sub-processor in the Sub-Processor List, in furtherance of providing the Services.
Frequency of the transfer: Continuous, for as long as the relevant sub-processor is engaged.
C. Competent Supervisory Authority
The supervisory authority of the EEA member state in which the Customer is established.
Annex II — Technical and Organizational Measures
The technical and organizational measures implemented by Apilex are described in the Security Addendum.
Annex III — List of Sub-processors
Apilex's sub-processors, including those located outside the EEA, are listed in the Sub-Processor List, which the Customer has generally authorized under Section 5 of the DPA.