Data Processing Agreement (DPA)
Last updated: 8 July 2026
This Data Processing Agreement (DPA) governs the processing of personal data between the tour company using the Your Next Tours service and First Point (Your Next Tours). It is intended to comply with GDPR Article 28 and is interpreted as a data processor relationship under KVKK in Turkey. This DPA forms an integral part of the main service agreement between the parties; in the event of any conflict between the main agreement and this DPA regarding the processing of personal data, this DPA prevails.
1. Parties and Roles
Under this DPA, the tour company (customer) is the data controller; it determines the purposes and means of processing the personal data of its guides and tour participants.
First Point (Your Next Tours) is the data processor; it processes personal data solely on behalf of and in accordance with the instructions of the data controller.
Processor contact: [email protected]. The legal name, address, and registry details will be completed in the per-customer signature annexes.
2. Subject Matter, Duration, Nature, and Purpose
Subject matter: the processing of personal data required to provide the Your Next Tours service (account, configuration, session, and evaluation functions related to phone-based, offline audio broadcasting during tours).
Duration: processing continues for the term of the main service agreement and ends upon its expiry or termination in accordance with Section 9.
Nature and purpose: data is processed by automated means to create and manage the account, store tour templates and WiFi/wallet configuration, run pre-tour check-ins, store and report session and rating data, and provide support.
3. Categories of Data Subjects and Personal Data
Categories of data subjects: the controller's guides/staff and tour participants.
Account data: email address, display name, organization (company) name, language preference, and profile image (avatar).
Usage data: tour sessions and durations, participant counts, rating scores and comments, and the participant display name.
Configuration data: crypto wallet addresses (network and address), WiFi profile details (SSID and password), and tour templates.
Support data and pre-tour check-in data: participant name entered, phone model, headphones/power bank status, and free-text notes.
No special category (sensitive) data is intended to be processed; the controller undertakes not to enter such data into the service.
4. Controller Obligations
The controller warrants that its instructions and processing of data subjects' personal data are lawful, that it has provided the required notices, and that it has obtained consent where required.
The controller is responsible for the documented instructions it gives to the processor and for the accuracy and lawfulness of the data it uploads to the service.
5. Processor Obligations and Documented Instructions
The processor processes personal data only on the controller's documented instructions, which are constituted by this DPA and the main agreement. If the processor considers an instruction to be unlawful, it will inform the controller.
It ensures persons with access to the data are bound by confidentiality (contractual or statutory) and grants access only on a need-to-know basis.
The processor does not use the personal data for its own purposes, sell it, or share it with third parties outside the provision of the service.
6. Security Measures (Article 32 GDPR)
The processor implements technical and organizational measures appropriate to the risk. In general terms these include: appropriate encryption/protection in transit and at rest, access control and least-privilege, authentication, logging/monitoring, backups, and regular review.
Audio broadcast DURING the tour runs over a portable local WiFi network without reaching the internet; this live communication does not pass through the cloud backend. Live translation is the single, opt-in exception: when the guide explicitly enables it and confirms the consent dialog, the guide's own voice -- never a participant's microphone -- is streamed to our backend and to Google Gemini for real-time translation, and is not stored on our servers. This architecture minimizes the transfer of participant data during the tour.
No specific certification (e.g. ISO 27001) is claimed in this text; details and the current list of applied controls may be specified in a per-customer security annex.
7. Sub-Processors
The controller grants the processor general authorization to engage sub-processors (e.g. hosting and infrastructure providers) for the provision of the service.
A current sub-processor list is provided to the customer (Annex). The processor binds each sub-processor in writing to data protection obligations equivalent to those in this DPA and remains liable for the sub-processor's actions.
The processor will inform the controller before adding or replacing a sub-processor and will allow the controller a reasonable period to object.
8. Data Subject Rights, Breach Notification, and Assistance
The processor assists the controller, to a reasonable extent and by appropriate technical/organizational measures, in responding to requests by data subjects to exercise their rights (access, rectification, erasure, objection, portability).
The processor will notify the controller without undue delay after becoming aware of a personal data breach and provide the information needed for the controller to meet its statutory notification obligations.
The processor reasonably assists the controller with the obligations under Articles 32-36 GDPR (security, breach notification, and data protection impact assessments).
9. Deletion or Return of Data
After the end of the processing activity, the processor will, at the controller's choice, delete or return the personal data and destroy existing copies within a reasonable period, unless retention is required by applicable law.
The controller may also delete the account and parts of the data via the panel during the service term.
10. Audits
The processor makes available to the controller, to a reasonable extent, the information necessary to demonstrate compliance with the obligations in this DPA.
The controller may request an audit/inspection on reasonable notice and during business hours, subject to confidentiality and security restrictions and without unduly disrupting the service. Specifics may be agreed per customer.
11. International Transfers
Where personal data is transferred outside Turkey or the European Economic Area, valid transfer mechanisms and appropriate safeguards under KVKK and GDPR (e.g. standard contractual clauses) are applied.
The countries to which data is transferred and the safeguards applied are specified in the sub-processor annex where relevant.