Data Processing Agreement
Effective July 25, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Astro Tasarım Simay Yenice, operating BeCited ("Processor," "BeCited," "we," "us"), and the customer entity that has agreed to those Terms ("Controller," "Customer," "you"), whenever BeCited processes personal data on your behalf in connection with the Service. It is intended to meet the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and, for customers subject to Turkish law, the equivalent obligations under Law No. 6698 on the Protection of Personal Data ("KVKK"). Capitalized terms not defined here have the meaning given in our Privacy Policy and Terms of Service.
1. Parties and Roles
For the personal data described in Section 3 below, you (or the organization on whose behalf you use the Service) are the data controller ("veri sorumlusu" under KVKK), and BeCited is the data processor ("veri işleyen" under KVKK). Nothing in this DPA changes the controller/processor roles set out for website, marketing, and billing data in our Privacy Policy, where BeCited itself acts as controller.
2. Subject Matter and Duration
The subject matter of this DPA is BeCited's processing of personal data submitted to, or generated by, the Service on your instructions: account identifiers of your team members, the domain(s) you submit for measurement, and any data you connect through an optional integration such as Google Search Console. This DPA takes effect when you first submit personal data to the Service and continues for as long as we process such data on your behalf, including any post-termination period described in Section 11.
3. Nature, Purpose and Categories of Processing
- Nature and purpose: operating your account, running GEO/SEO visibility measurement, generating reports, processing payment, and providing support, exactly as described in our Privacy Policy.
- Categories of data: account identifiers (name, email), the domain(s) you submit, derived measurement data, billing metadata, and, if you opt in, Google Search Console performance data.
- Categories of data subjects: your authorized users (employees or contractors who hold an account), and, incidentally, individuals named in publicly available pages of the domain you submit.
- Duration of processing: for the life of your account or subscription, and thereafter only as described in Section 11.
4. Processor Obligations
BeCited will:
- Process personal data only on your documented instructions, as reflected in the Service's normal operation and this DPA, unless required to do otherwise by EU, member state, or Turkish law, in which case we will inform you before processing unless the law prohibits this.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement the security measures described in Section 5.
- Assist you, as described in Section 7, in responding to data subject requests and in meeting your own obligations under GDPR Articles 32 to 36 and equivalent KVKK provisions, taking into account the nature of processing and the information available to us.
- Not engage a sub-processor without the authorization and notice process described in Section 6.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for the audits described in Section 9.
5. Security Measures
BeCited maintains technical and organizational measures appropriate to the risk, consistent with GDPR Article 32 and KVKK Article 12, including: encryption of data in transit (TLS) and of sensitive credentials at rest (for example, encrypted storage of Google Search Console OAuth tokens); role-based access control limiting internal access to personal data to what is necessary to operate and support the Service; logging and monitoring through our error-tracking subprocessor; separation of production credentials from development environments; and a documented incident response process, described further in Section 8. We review these measures periodically and update them as the Service and its risk profile evolve.
6. Sub-processor Use and Notification
You authorize BeCited to engage the subprocessors listed on our Subprocessors page as of the date you accept these Terms, which is incorporated into this DPA by reference. Before adding a new subprocessor that will process personal data in scope of this DPA, we will update that page and, where we hold contact details for an active paid account, provide advance notice by email so you may object on reasonable data protection grounds. If you object and we cannot resolve the concern, either party may terminate the affected part of the Service as its sole remedy. BeCited remains liable for a subprocessor's performance to the same extent BeCited would be liable if performing that processing itself, and imposes data protection obligations on each subprocessor materially equivalent to those in this DPA.
7. Assistance With Data Subject Requests
Taking into account the nature of the processing, BeCited will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling requests to exercise data subject rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection) and under KVKK Article 11. Where a request reaches us directly from an individual whose data we process on your behalf, we will, without undue delay, either direct that individual to you as the controller or, at your instruction, action the request ourselves.
8. Personal Data Breach Notification
BeCited will notify you without undue delay, and in any event within 72 hours of becoming aware, of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data we process on your behalf. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available and cooperate with you in meeting your own breach notification obligations under GDPR Article 33/34 and KVKK's breach notification requirements to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
9. Audit Rights
You may request evidence of BeCited's compliance with this DPA, including relevant policy documents and, where available, third-party audit reports (for example, subprocessor SOC 2 reports where the subprocessor makes these available). If such evidence is not sufficient to demonstrate compliance, you may conduct an audit of BeCited's relevant processing activities, including inspections, no more than once every 12 months absent a specific reason to believe a breach has occurred, on at least 30 days' written notice, at your expense, during business hours, and subject to confidentiality obligations and reasonable limits to protect BeCited's other customers and trade secrets.
10. International Data Transfers
BeCited's subprocessors are primarily based in the United States. Where personal data originating in the EU/EEA or UK is transferred to such a subprocessor, the transfer is made subject to the European Commission's Standard Contractual Clauses (or a successor mechanism recognized under GDPR Chapter V) as incorporated into our contract with that subprocessor, or another adequacy mechanism where available. Where personal data originating in Türkiye is transferred abroad, the transfer relies on the statutory mechanisms available under KVKK Article 9, including standard contractual undertakings, pending further guidance from the Kişisel Verileri Koruma Kurumu. Details of each subprocessor's location are listed on our Subprocessors page.
11. Return or Deletion of Data at End of Contract
On termination or expiry of your subscription, and at your election, BeCited will either delete or return all personal data processed on your behalf within a reasonable period, and delete existing copies, unless applicable law requires continued storage (for example, billing records retained for the statutory period under Turkish tax and commercial law). You may export your report and measurement data from your account before deletion; if you request a copy after account closure, we will provide it if technically feasible within 30 days of your request.
12. Liability and Term
This DPA takes effect on the date you accept the Terms of Service and remains in effect for as long as BeCited processes personal data on your behalf. Liability under this DPA is subject to the limitation of liability set out in the Terms of Service, except where such limitation cannot apply as a matter of mandatory law.
13. Governing Law
This DPA is governed by the same law as the Terms of Service: the laws of the Republic of Turkey, without prejudice to any mandatory data protection rights you hold under GDPR or KVKK regardless of choice of law.
14. Executing This DPA
For most customers, acceptance of our Terms of Service constitutes acceptance of this DPA; no separate signature is required. If your organization's procurement process requires a countersigned copy or a specific annex (for example, listing your Standard Contractual Clauses module), email hello@becited.co and we will provide one.
Last updated: 25 July 2026
See also our Privacy Policy and Subprocessors.