Our comprehensive legal framework ensures transparency, compliance, and clarity in all our service agreements and policies.
Last Updated: 1 May 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between you ("Customer") and the applicable Contracting Entity (as defined in the Terms of Service) and governs the processing of personal data in connection with the services.
For personal data related to Customer accounts, billing, and service administration (e.g., name, email, payment details, usage records), we act as the Data Controller.
For personal data that Customer uploads, stores, or processes using our cloud computing services, Customer acts as the Data Controller and we act as the Data Processor, processing such data solely in accordance with Customer's instructions.
We process Personal Data only for the following purposes:
We use the following sub-processors in the delivery of our services:
| Sub-Processor | Country | Purpose |
|---|---|---|
| OVH SAS | France/USA | Physical server infrastructure |
| Supabase | USA | Database and authentication |
| Airwallex | Singapore | Payment processing |
| Garanti BBVA | Turkiye | Banking and Payment processing |
| Prelude | France | SMS/phone verification |
| Intercom | USA | Customer support |
| PostHog | USA | Product analytics |
| USA | Advertising (Google Ads) | |
| Meta | USA | Advertising (Meta Ads) |
We will notify Customer of any intended changes to sub-processors at least 30 days in advance by posting updates to our legal page at https://rafftechnologies.com/legal. Customer may object to a new sub-processor by contacting us within 15 days of notification.
All sub-processors are bound by data processing agreements that impose obligations no less protective than those in this DPA.
| Data Category | Retention Period |
|---|---|
| Identity and contact information | Duration of account + 10 years (commercial law requirements) |
| Financial information and invoices | 10 years from last transaction (tax law requirements) |
| Usage and transaction records | 10 years from last transaction |
| Internet access logs | 2 years (Law No. 5651, where applicable) |
| Support requests | 3 years after account closure |
| Marketing communication data | Until consent is withdrawn |
| Cookie data | As specified in our Cookie Policy |
Upon expiry of the applicable retention period, Personal Data is deleted, destroyed, or anonymized in accordance with our data retention procedures.
Personal Data may be transferred internationally to the sub-processors listed in Section 4. Such transfers are protected by:
Customer data is hosted in the data center location selected at the time of order. Data is not moved to a different country without Customer's written consent, except as necessary for the sub-processors listed in Section 4 to provide their respective services.
We implement the following technical and organizational measures:
In the event of a Personal Data breach:
We will assist Customer in responding to data subject requests to exercise their rights under applicable data protection laws, including rights of access, rectification, erasure, restriction, portability, and objection. We will respond to such requests within the timeframes required by applicable law.
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to Customer in fulfilling Customer's obligations under GDPR Articles 35 and 36 (Data Protection Impact Assessments and prior consultation with supervisory authorities), where such obligations relate to the processing of Personal Data under this DPA.
Customer may export their data at any time using the tools provided in the account dashboard.
Customer may request an audit of our data processing activities with at least 30 days' prior written notice. Audits:
We may satisfy audit requests by providing relevant third-party audit reports, certifications, or compliance documentation where available.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Service. For the avoidance of doubt, each party's total aggregate liability under this DPA and the Terms of Service combined shall be treated as a single claim for the purposes of any liability cap.
This DPA is effective for the duration of the Terms of Service. Upon termination of the Terms of Service, data processing obligations continue until all Personal Data has been deleted or returned in accordance with Section 11.
Contact Information:
For questions about this DPA:
Raff Technologies LLC
Dynamis Teknoloji Anonim Şirketi
Last updated: 1 May 2026