ivmero
Home

Data Processing Agreement

Last updated: 26 August 2026

This Data Processing Agreement (“DPA”) forms an integral part of the contract for the provision of the ivmero service and sets out the terms on which personal data is processed on the customer’s behalf under Article 28 GDPR.

1. Parties and scope

The customer acts as controller and ROADMAP Danışmanlık Anonim Şirketi (“ivmero”) acts as processor. This DPA covers all personal data processed by ivmero on the customer’s behalf while providing the service.

2. Definitions

“Personal data”, “processing”, “controller”, “processor” and “data subject” carry the meanings given in Article 4 GDPR. Where the customer is established in Turkey, the corresponding definitions in Law No. 6698 apply in parallel.

3. Subject matter and instructions

ivmero processes personal data only on the documented instructions of the customer and solely for the purpose of providing the service. The processing instructions are set out in Annex 1. ivmero informs the customer if, in its opinion, an instruction infringes applicable data protection law.

4. Security measures

  • Encryption in transit (TLS) and encryption of credentials at rest
  • Role-based access control with logging of access to production systems
  • Segregation of environments and least-privilege service accounts
  • Encrypted backups with regularly tested restore procedures
  • Confidentiality undertakings for all personnel with access to data

5. Sub-processors

The customer authorises the sub-processors listed in the Privacy Policy. ivmero gives at least 30 days’ notice before adding or replacing a sub-processor, and the customer may object on reasonable data protection grounds. Each sub-processor is bound by obligations no less protective than those in this DPA.

6. Data subject requests

ivmero does not respond directly to data subject requests concerning customer data. It forwards such requests to the customer without undue delay and provides reasonable assistance in responding to them.

7. International transfers

Primary processing takes place in the European Union. Where personal data is transferred outside the EEA, the European Commission’s Standard Contractual Clauses apply, supplemented by a transfer impact assessment where required.

8. Breach notification

ivmero notifies the customer without undue delay, and in any event within 24 hours of becoming aware, of any personal data breach, and provides the information the customer needs to meet its obligations under Articles 33 and 34 GDPR.

9. Audit

On reasonable notice and no more than once a year, the customer may request the information necessary to demonstrate compliance with this DPA. Where an on-site audit is required, the parties agree its scope and timing in advance.

10. Deletion and return

On termination of the contract, ivmero deletes or returns all personal data processed on the customer’s behalf within 30 days, except where retention is required by law.

Annex 1 — Processing instructions

  • Subject matter: providing product scoring, 13-way segmentation and channel label recommendations
  • Duration: the term of the contract plus the deletion period in section 10
  • Categories of data subjects: the customer’s employees and authorised users; end-customer data is not processed at identifiable level
  • Categories of personal data: account holder name and email, authorisation records, access logs
  • Special categories: none
  • Processing operations: collection, storage, aggregation, calculation, transmission to the customer’s own advertising channels, deletion

11. Contact

legal@ivmero.com · privacy@ivmero.com

Last updated: 26 August 2026
ROADMAP Danışmanlık A.Ş. · ivmero

We use cookies that are strictly necessary for the site to work. Analytics cookies that measure usage are loaded only if you consent. Cookie Policy