TrackCanary legal

Data Processing Addendum

Last updated: 1 October 2026

TrackCanary is being incorporated as a joint-stock company (anonim şirket) in Türkiye. The trade name, MERSİS number, trade registry details and registered address will be published on our legal pages as soon as registration is complete. Until then, requests about these documents or your personal data can be sent to contact@trackcanary.com.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“Customer”) and TrackCanary (joint-stock company in formation in Türkiye) (“TrackCanary”). It applies whenever TrackCanary processes personal data on the Customer's behalf, in particular data collected by the optional TrackCanary snippet on the Customer's websites, and is accepted when the Customer installs the snippet or otherwise instructs such processing.

1. Roles

The Customer is the controller and TrackCanary is the processor (under Turkish law: veri sorumlusu and veri işleyen). Each party complies with the data protection laws that apply to it, including the GDPR, the UK GDPR, Turkish Law No. 6698 (KVKK) and the Saudi Personal Data Protection Law where applicable.

2. Details of the processing

Subject matter and purpose
Recording lead actions on the Customer's websites (WhatsApp, phone and email link clicks, important button clicks, form submissions) and showing the Customer statistics and alerts about them
Duration
For as long as the Customer uses the snippet, plus the deletion period in section 9
Data subjects
Visitors to the Customer's websites
Personal data
Page address and referrer without query strings or fragments, page title, campaign (UTM) parameters, event type, a short description and selector of the clicked element, a random session identifier, browser user-agent string and event time. IP addresses are used only transiently for rate limiting and are not stored.
Special categories
None. The Customer must not use the snippet to collect them
Frequency
Continuous while the snippet is installed
Retention
13 months from collection, or shorter on the Customer's instruction

3. Instructions

TrackCanary processes Customer personal data only on the Customer's documented instructions, which are these Terms, this DPA and the Customer's configuration of the service, unless the law requires otherwise; in that case TrackCanary informs the Customer before processing unless the law prohibits it. TrackCanary tells the Customer if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

Everyone authorised to process Customer personal data is bound by confidentiality.

5. Security

TrackCanary implements the technical and organisational measures in Annex A and may update them as long as the overall level of protection is not reduced.

6. Sub-processors

The Customer gives TrackCanary general authorisation to use the sub-processors listed in Annex B. TrackCanary notifies the Customer of any intended addition or replacement at least 14 days in advance by email or in the product. The Customer may object on reasonable data protection grounds; if no solution is found, the Customer may terminate the affected service. TrackCanary imposes data protection obligations on each sub-processor that are equivalent to this DPA and remains responsible for their performance.

7. Assistance

Taking into account the nature of the processing, TrackCanary assists the Customer with data subject requests, security, breach notifications, data protection impact assessments and prior consultations. If TrackCanary receives a request from a data subject about Customer personal data, it forwards the request to the Customer and does not respond itself unless authorised.

8. Personal data breaches

TrackCanary notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to help the Customer meet its own notification obligations, including the 72-hour deadlines under the GDPR and KVKK.

9. Deletion and return

When the Customer stops using the snippet or closes its account, TrackCanary deletes Customer personal data within 30 days, unless the Customer asks for an export before then or the law requires retention.

10. Information and audits

TrackCanary makes available the information needed to demonstrate compliance with this DPA and allows audits by the Customer or an independent auditor bound by confidentiality, on 30 days' notice, at the Customer's cost and no more than once a year, unless a breach or a supervisory authority requires otherwise.

11. International transfers

Customer personal data is processed in Türkiye and in the countries where our sub-processors operate (Annex B). Where the GDPR or the UK GDPR applies to a transfer, the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) between the Customer and TrackCanary and Module 3 (processor to processor) with sub-processors, together with the UK Addendum where relevant, all incorporated by reference. Their annexes are completed by section 2 and Annexes A and B of this DPA; the competent supervisory authority is determined under Clause 13, and for Clauses 17 and 18 the clauses are governed by the law of Ireland and disputes are resolved by the courts of Ireland.

Where KVKK applies, the parties sign the standard contract published by the Personal Data Protection Board when required, and the exporting party notifies it to the Authority. Where the Saudi Personal Data Protection Law applies, the parties use the standard contractual clauses issued by SDAIA when required.

12. Customer obligations

The Customer ensures that it has a lawful basis for the processing, gives its visitors the required information, obtains any consent required before the snippet runs, and does not use the snippet on pages directed at children or to collect sensitive data.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow them. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data; the Standard Contractual Clauses prevail over both.

Annex A — Technical and organisational measures

  • Encryption in transit (HTTPS/TLS) for the snippet, the dashboard and all APIs.
  • Data minimisation by design: no form-field contents, no query strings or fragments stored, redaction of text that looks like an email address or card number, forms with password or payment-card fields skipped, Do Not Track honoured by default.
  • Access control: administrative access limited to authorised staff with separate, short-lived sessions; customer sessions use random tokens stored only as hashes.
  • Passwords stored only as bcrypt hashes; one-time codes stored hashed, short-lived and attempt-limited.
  • Rate limiting and payload size limits on public endpoints; origin checks so that events are accepted only from the registered website.
  • Network isolation of the scanning component from internal networks.
  • Managed hosting with provider-level physical security, redundancy and backups.
  • Automatic deletion of expired data according to defined retention periods.
  • An incident response procedure with breach notification as described in section 8.
  • Confidentiality obligations and least-privilege access for everyone handling personal data.

Annex B — Sub-processors

Sub-processorPurposeLocation
Railway CorporationHosting of the application and database, including snippet eventsUnited States
ResendDelivery of alert and digest emails to the Customer's users (no visitor data)United States