The data processing terms between SmartIO (theProcessor) and the customer (the Controller) for personal data processed through the Browsonic service, made under Article 28 of Regulation (EU) 2016/679 (GDPR) and Article 12 of Law No. 6698 on the Protection of Personal Data (KVKK).
This Agreement is in force for every Browsonic account.It is incorporated into theTerms of Service by reference and takes effect when you create an account. You do not need to request it, sign it separately, negotiate it, or be on a particular plan. If your organisation requires a counter-signed copy on your own paper, write tobrowsonic-privacy@smartiobilisim.com; that is a formality, not a precondition — these terms already apply.
1. Roles and Subject Matter
For personal data contained in the telemetry, session recordings and other Customer Data you send into the Service, you are the controller and we are the processor. We process that data only to provide the Service to you and only on your documented instructions, of which your configuration of the SDK and the Service forms part.
For personal data about your account — the identity of the people who sign in, billing contacts, and the security records described in the Privacy Policy — we are the controller in our own right. That processing is governed by thePrivacy Policy, not by this Agreement.
Details of processing (Art. 28(3), opening paragraph)
- Subject matter: provision of application error and event monitoring, session replay, route and task mapping, and alerting.
- Duration: the term of your subscription, plus the retention period of your plan and the deletion window in Section 8.
- Nature and purpose: collection, storage, structuring, analysis, retrieval and deletion of telemetry, to let you diagnose faults and understand behaviour in your applications.
- Categories of data subject: the end users of your applications, and your own personnel who use the dashboard.
- Types of personal data: whatever your applications send. Typically online identifiers, IP addresses, device and browser metadata, URLs and route names, user identifiers you attach via
identify()orsetUser, console and network breadcrumbs, stack traces, and — where you enable Session Replay — a reconstruction of the browser session. You decide what is sent; the SDK's redaction, masking and sampling controls are yours. - Special categories: the Service is not designed for special-category data under Art. 9 GDPR, and you must not configure it to send such data. If your application handles it, mask it at source.
2. Processor Obligations (Art. 28(3)(a)–(h))
(a) Documented instructions
We process personal data only on your documented instructions, including on transfers to a third country, unless required to do otherwise by EU, Member State or Turkish law — in which case we will tell you of that requirement before processing, unless the law prohibits telling you. We will inform you if, in our opinion, an instruction infringes data-protection law.
(b) Confidentiality
Every person we authorise to process personal data is bound by an obligation of confidentiality, contractual or statutory, that survives the end of their engagement. Access is granted on a least-privilege basis and is itself recorded in the audit log described in the Privacy Policy.
(c) Security of processing
We implement appropriate technical and organisational measures under Art. 32. Concretely, and not as a list of aspirations:
- encryption in transit (TLS) and at rest for stored telemetry;
- tenant isolation enforced in the database itself by row-level security, not only in application code;
- SDK redaction of national identifiers, payment-card and telephone number shapes before events leave the end user's browser, plus a second scrubbing pass on ingest;
- multi-factor authentication on administrative access, and a network perimeter in front of the operator console;
- a tamper-evident audit log of security-relevant actions, retained 400 days;
- dependency scanning and security review of changes.
(d) Sub-processors
You give us general authorisation to engage the sub-processors listed in the Annex below. We will give you at least30 days' notice, by e-mail to your account owner and by notice in the dashboard, before a new sub-processor begins processing your personal data.
You may object. If you notify us of a reasonable, data-protection-related objection within that notice period, we will work with you to find a solution — a configuration that avoids the sub-processor, or an alternative provider. If none is available, you may terminate the affected part of the Service on written notice and we will refund any prepaid fees for the unused remainder of the term. An objection does not silently lapse into acceptance.
Each sub-processor is bound by written terms imposing the same obligations as this Agreement, and we remain fully liable to you for their performance.
(e) Assistance with data-subject rights
The Service gives you the controls to answer most data-subject requests yourself: search by identifier, per-subject export, and a deletion path that removes a subject's events, page views and session recordings across every one of your applications. Where those controls are not enough, we will assist you by appropriate technical and organisational measures. If a data subject contacts us directly about your data, we will not respond substantively — we will tell them to contact you, and tell you that they wrote.
(f) Assistance with Art. 32–36 obligations
We will assist you in ensuring compliance with your security, breach-notification, data-protection-impact-assessment and prior consultation obligations, taking into account the nature of the processing and the information available to us.
Breach notification. We will notify you without undue delay and in any event within72 hours of becoming aware of a personal-data breach affecting your personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — and where we cannot provide all of that at once, we will send what we have and follow up rather than wait.
(g) Deletion or return
At the end of the Service you may export your data through the Service's own export functions. Following termination we delete personal data processed on your behalf within30 days, and from backups within a further90 days as backup rotation reaches them, unless EU, Member State or Turkish law requires us to keep it. Anonymised, aggregated statistics that cannot be attributed to a data subject may be retained.
One exception, stated here rather than left to be discovered: the security and audit records described in Section 6 of thePrivacy Policy are records ofour own processing, for which we are the controller. They are retained for their own period and are not deleted on your instruction, because an audit trail that the audited party can erase is not one.
(h) Audits and information
We will make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice: send questions tobrowsonic-privacy@smartiobilisim.comand we will answer them and provide our security documentation. An on-site or on-system audit may be requested once in any twelve-month period, on 30 days' notice, at your cost, under confidentiality, and scheduled so as not to disrupt the Service — and immediately, without those limits, following a breach affecting your data.
3. International Transfers
The Service is hosted in the European Union (Amsterdam, Netherlands). Where personal data is transferred outside the EEA to a country without an adequacy decision, the transfer is made under theStandard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 — Module Two (controller to processor) between you and us, and Module Three (processor to processor) between us and the relevant sub-processor — supplemented by the UK International Data Transfer Addendum where UK data is involved. Those Clauses are incorporated into this Agreement by reference and prevail over it in the event of conflict.
For data subjects in Türkiye, transfers abroad are made under Art. 9 of Law No. 6698 and the standard contract / undertaking regime of the Personal Data Protection Board. See theKVKK Aydınlatma Metni.
The Annex marks which sub-processors involve a transfer outside the EEA. Two are worth calling out because they are easy to miss:OpenAI, L.L.C. in the United States receives an error message and its stack trace when a user asks for an AI insight — the feature is optional and inert unless configured — and the transactional e-mail provider receives the recipient address and the contents of account e-mail.
4. Annex — Sub-processors
| Sub-processor | Purpose | Location | Outside EEA |
|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting and storage for the Service | Amsterdam, Netherlands (EU region) | No |
| iyzico Ödeme Hizmetleri A.Ş. | Payment processing and subscription billing | Türkiye | Yes |
| Google Ireland Ltd. | Google Analytics 4 — aggregate usage analytics, consent-gated | Ireland (EU) | No |
| OpenAI, L.L.C. | AI error-insight generation — an error message and its stack are sent to the model when a customer requests an insight. Optional: the feature is inert unless an API key is configured. | United States | Yes |
| Transactional e-mail (SMTP) provider | Delivery of account e-mail — verification, password reset, invitations and alert notifications | As configured for the deployment; disclosed on request | Yes |
To be notified when this list changes, write tobrowsonic-privacy@smartiobilisim.comwith the subject line Sub-processor notifications.
5. Precedence and Term
This Agreement forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this Agreement prevails; where it conflicts with the Standard Contractual Clauses, the Clauses prevail. It remains in force for as long as we process personal data on your behalf, and the confidentiality, deletion and audit obligations survive its termination.
6. Contact
SMARTIO BİLİŞİM SİSTEMLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Balcalı Mah. Güney Kampüs/5 Sk., Teknokent No:4, İç Kapı No:108, Sarıçam / Adana, Türkiye
Office: +90 322 911 0941 · Call Center: 0850 308 8824
Email:browsonic-privacy@smartiobilisim.com
Mersis No: 0772138018200001