Data Processing Agreement (DPA)
Last updated: 23 Ağustos 2026
This is a courtesy translation. The original of this page is in Turkish; if the translation and the original text differ, the Turkish text governs.
This text is prepared to provide a data processing framework, compliant with Turkey's KVKK and, as far as possible, with GDPR, for when you manage WordPress sites belonging to your own clients through Watch Your WP ("the Service") as an agency or freelancer. Here, "User" refers to the agency/freelancer entering into this agreement, and "End Client" refers to the owner of the WordPress site managed by the User.
1. Definition of Roles
When you connect a WordPress site to Watch Your WP, you (the User) are the data controller for the data on that site (site users, media, commenter information, and the like). Watch Your WP acts only as a data processor, processing that data solely on your instructions and for the purpose of providing the Service. Watch Your WP's role as data controller over your own account/transaction data is separately explained in the Privacy Policy.
2. Categories of Data Processed and Purpose
Through the Watch Your WP Connector plugin, the connected site's site address, WordPress/PHP version, plugin/theme list, WordPress user list, media library metadata, backup files (including site files and database content), PHP error logs, and security scan findings are processed. The purpose of processing is exclusively to provide the Service: updates, backup, monitoring, and reporting.
3. No Processing Beyond Instructions
Watch Your WP does not use the data it processes for any purpose beyond your instructions (the normal operation of the Service), does not retain it for its own purposes, and does not transfer it to third parties for marketing purposes.
4. Sub-processors
The following sub-processors are used to provide the Service:
- Resend: sending notification and transactional emails.
- Railway: application and database hosting infrastructure.
- Cloudflare R2: an encrypted second (off-site) copy of backup files.
- WordPress.org's official checksum APIs: file integrity checks; contains no personal data.
This list is updated if a new sub-processor is added.
5. Security Measures
Passwords and API keys are stored irreversibly/encrypted, and critical actions go through authorization checks. Detailed measures are described in the Data Security section of the Privacy Policy.
6. Data Breach Notification
If a security breach that may affect End Client data is identified, the User is notified as soon as reasonably possible at [email protected].
7. Deletion and Disconnection
When you remove a site from the panel, the data belonging to that site (including backups) is deleted within a reasonable period. The same rule applies to all your sites when you close your account.
8. Beta Scope and Liability
Watch Your WP is currently in closed beta, operated by Erdinç Bulat without a separate legal entity; this text is also subject to the limitation of liability in the Terms of Service. This text will be updated once a company is formed.
9. Contact
For questions about this agreement, you can reach us at [email protected].