Back to home

Data Processing Agreement

Our obligations as a processor for enterprise customers.

Last updated: 28 July 2026

1. Roles

The club, academy, federation or individual uploading athlete footage and data to the platform is the controller.

T4F Spor Teknolojileri ve Yazılım A.Ş. acts as processor for that data and processes it only on the controller's documented instructions.

For data arising from our own customer relationship (account details, billing, correspondence) we are the controller; that data is covered by the Privacy Policy.

2. Subject matter and duration

  • Subject matter: athlete detection, pose extraction, event and metric generation, and report production from uploaded footage.
  • Data categories: video recordings, skeletal/pose data, performance metrics, athlete identifiers (name, date of birth, team).
  • Data subjects: athletes, coaches and analysis staff.
  • Duration: for the subscription term plus a 30-day export window after termination.

3. Sub-processors

We use the sub-processors below. We give at least 30 days notice before adding a new one and provide a right to object.

Sub-processorPurposeLocation
Vercel Inc.Web hosting and content deliveryEU edge / USA
MongoDB AtlasDatabaseAWS Frankfurt (EU)
ResendTransactional email deliveryIreland (EU)

4. Security measures

  • Encryption in transit and at rest
  • Role-based access control; every record is isolated by organization identifier
  • Irreversible password hashing
  • Security events written to an audit log
  • Regular backups

5. Breach notification

On becoming aware of a personal data breach we notify the controller without undue delay and within 24 hours at the latest. The notice describes the nature of the breach, affected data categories, likely consequences and the measures taken.

6. Assistance with data subject requests

We provide the technical assistance you need to satisfy athlete requests for access, rectification, erasure or portability. We do not action requests sent directly to us; we refer them to the controller.

7. Data transfers

Data is processed primarily within the European Union (Frankfurt). Where transfer outside the EU is necessary, Standard Contractual Clauses and the safeguards under KVKK Art. 9 apply.

8. Deletion and return

After termination we export your data on request and delete it from our systems within 30 days. Copies in backups are removed as the backup cycle completes.

9. Audit

Enterprise customers may audit our compliance with this agreement on reasonable notice, no more than once per year. The scope and procedure of the audit are set out in the signed enterprise agreement.

T4F Spor Teknolojileri ve Yazılım A.Ş.

info@t4fsport.com