Data Processing Agreement (DPA) — Plazio
Effective date: 12 June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between:
- Plazio — the Processor ("Plazio"); and
- the Management Company that registers for and uses the Plazio web panel — the Controller.
It governs the processing of personal data by Plazio on behalf of the Controller through the Service. By registering for the Panel and accepting the Terms of Service, the Controller accepts this DPA.
1. Roles
The Controller determines the purposes and means of processing the personal data of the residents and other individuals it enters into the Service ("Controller Data"). Plazio processes Controller Data only as a Processor, on the Controller's documented instructions, including those set out in this DPA, the Privacy Policy and the use of the Service.
2. Subject matter, duration, nature and purpose
Plazio processes Controller Data to provide the residential-complex management Service (resident management, dues, announcements, documents, tasks, notifications) for as long as the Controller uses the Service and as required to fulfil this DPA.
3. Categories of data and data subjects
- Data subjects: residents (owners/tenants), their household contacts, and the Controller's own staff users.
- Data categories: name, phone, e-mail, apartment/block, resident role, language, invite and login data, device and push token, dues status/amounts/references and notes, uploaded documents, photos, bank statement files, announcements and tasks.
- Special categories: none are intended to be processed. The Controller must not upload special-category data.
4. Controller obligations
The Controller warrants that it has a lawful basis (and, where required, consent and KVKK clarification/açık rıza) to collect resident data and to instruct Plazio to process it, including sending notifications and uploading bank statement files. The Controller is responsible for the accuracy and lawfulness of the data it enters.
5. Processor obligations
Plazio shall:
- process Controller Data only on the Controller's documented instructions;
- ensure persons authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Annex 1);
- respect the conditions for engaging sub-processors (Clause 6);
- assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification and impact-assessment obligations;
- at the Controller's choice, delete or return Controller Data at the end of the service, subject to legal retention;
- make available information necessary to demonstrate compliance and allow for reasonable audits.
6. Sub-processors
The Controller authorises Plazio to engage the sub-processors listed in the Privacy Policy (currently: hosting provider in Germany, Expo, Google FCM, Apple APNs, DeepL SE, and the e-mail provider Resend). Plazio imposes data-protection obligations on each sub-processor and remains responsible for their performance. Plazio will inform the Controller of intended changes and give the Controller the opportunity to object.
7. Data subject rights and breaches
Plazio will assist the Controller in responding to data-subject requests and will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller Data, with information reasonably available to it.
8. International transfers
Controller Data is hosted in Germany and may be processed by sub-processors located abroad. Plazio carries out such transfers only with appropriate safeguards and/or on the basis of the necessity to perform the service and the consent obtained by the Controller, consistent with KVKK, the GDPR and Law 152-FZ as applicable.
9. Liability and term
This DPA runs for the duration of the Service. Liability is subject to the limitations in the Terms of Service, except for liability that cannot be limited by law. If there is a conflict between this DPA and the Terms regarding data protection, this DPA prevails.
Annex 1 — Security measures
Encryption in transit (TLS); passwords stored as salted hashes; token-based authentication and signed, time-limited file links; multi-tenant isolation enforced per complex; role-based access control; rate-limiting and brute-force protection; restricted access on a need-to-know basis; files not served directly by the web server; logging and monitoring.
Annex 2 — Sub-processors
As listed in the Privacy Policy, Section "Who we share data with", as updated from time to time.
Plazio: [email protected] Controller: the registering Management Company, accepting electronically upon registration.