Data Protection Agreement

This Data Protection Agreement (DPA) was issued by Fortune Mine Oyun Yazılım A.Ş. and the purpose of this Privacy Policy is to provide information on the collection, processing and use of the data provided by you in connection with the use of the Services (as defined below).

This Data Protection Agreement (“DPA”) is part of the agreement (“Agreement”) between Fortune Mine Oyun Yazilim A.S. (“Data Controller”) and [Processor’s Company Name] (“Data Processor”) with an effective date of [Effective Date].

  1. Definitions Personal Data: Any information relating to an identified or identifiable individual as defined under the GDPR. Data Controller: The party that determines the purposes and means of the processing of Personal Data. Data Processor: The party processing Personal Data on behalf of the Data Controller.

  2. Scope and Purpose Data Processor agrees to process Personal Data solely for the purpose defined by the Data Controller, as outlined in the Agreement, and not for any other purpose.

  3. Processing of Personal Data Data Processor shall:

Process Personal Data only on documented instructions from Data Controller. Ensure personnel involved in processing Personal Data are bound by confidentiality obligations. Implement appropriate technical and organizational measures to secure Personal Data. 4. Data Subject Rights Data Processor shall assist the Data Controller in responding to requests from data subjects to exercise their rights, such as access, rectification, and deletion, as per GDPR requirements.

  1. Sub-Processors Data Processor may engage sub-processors only with prior written consent from the Data Controller and shall ensure sub-processors comply with the same obligations under this DPA.

  2. Security Measures Data Processor shall implement security measures appropriate to the risk, including:

Access controls. Encryption (where applicable). Regular data protection reviews. 7. Data Breach Notification Data Processor shall promptly inform the Data Controller within 24 hours of any data breach involving Personal Data and provide all necessary information to assist the Data Controller in meeting its legal obligations.

  1. Data Deletion or Return Upon termination of the Agreement, Data Processor shall, at Data Controller’s discretion, either delete or return all Personal Data and delete existing copies, unless required to retain such data by applicable law.

  2. Audit Rights Data Controller may audit Data Processor’s compliance with this DPA, upon reasonable notice, either directly or through a third-party auditor.

  3. Liability Each party’s liability arising from or related to this DPA shall be limited to direct damages only.

  4. Governing Law This DPA shall be governed by the laws of [Specify Jurisdiction].

IN WITNESS WHEREOF, the parties hereto have executed this DPA as of the last date signed below.

Data Controller Data Processor Signature: _________________________ Signature: _________________________ Name: [Name of Authorized Signatory] Name: [Name of Authorized Signatory] Title: [Title] Title: [Title] Date: [Date] Date: [Date]