Rechtliches
Auftragsverarbeitungsvertrag
Last updated: 25 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Simay Yenice Astro Tasarım, a sole proprietorship established by Simay Yenice, operating RecapButler ("Processor," "RecapButler," "we," "us"), and the customer organization that has agreed to those Terms ("Controller," "Customer," "you"), whenever RecapButler processes personal data on your behalf in connection with the Service. It is intended to meet the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and, for customers subject to Turkish law, the equivalent obligations under Law No. 6698 on the Protection of Personal Data ("KVKK"). Capitalized terms not defined here have the meaning given in our Privacy Policy and Terms of Service.
1. Parties and Roles
For the meeting data described in Section 3 below, your organization is the data controller ("veri sorumlusu" under KVKK), and RecapButler is the data processor ("veri işleyen" under KVKK). This matches the roles already set out in our Privacy Policy. Nothing in this DPA changes the controller role RecapButler holds for website and waitlist data, which is described separately in the Privacy Policy.
2. Subject Matter and Duration
The subject matter of this DPA is RecapButler's processing of meeting recordings, transcripts, metadata, and the structured items drafted from them, on your organization's instructions. This DPA takes effect when your organization first connects a meeting to the Service and continues for as long as we process such data on your behalf, including any post-termination period described in Section 11.
3. Nature, Purpose and Categories of Processing
- Nature and purpose: capturing and transcribing meetings your organization chooses to connect, drafting proposed updates (decisions, tasks, account notes) for your team's review, and writing approved items into systems you connect, exactly as described in our Privacy Policy.
- Categories of data: meeting recordings, transcripts, and metadata (participants, times, titles); the structured items drafted from meetings; approval decisions forming the audit trail; and credentials or tokens needed to write into your connected systems, stored encrypted.
- Categories of data subjects: your organization's employees and contractors who attend or approve meeting-derived items, and meeting participants outside your organization who are recorded when you connect a meeting.
- Duration of processing: for the duration of your organization's use of the Service, and thereafter only as described in Section 11.
4. Processor Obligations
RecapButler will:
- Process personal data only on your documented instructions, as reflected in the Service's normal operation and this DPA, unless required to do otherwise by EU, member state, or Turkish law, in which case we will inform you before processing unless the law prohibits this.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement the security measures described in Section 5.
- Assist you, as described in Section 7, in responding to data subject requests and in meeting your own obligations under GDPR Articles 32 to 36 and equivalent KVKK provisions, taking into account the nature of processing and the information available to us.
- Not engage a subprocessor without the authorization and notice process described in Section 6.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for the audits described in Section 9.
- Not write any drafted item into your connected systems without the human approval step your organization controls, by product design.
5. Security Measures
RecapButler maintains technical and organizational measures appropriate to the risk of processing meeting content, consistent with GDPR Article 32 and KVKK Article 12, including: encryption of data in transit and at rest; encrypted storage of integration credentials and tokens; access controls limiting who at RecapButler can access customer data to what is necessary to operate and support the Service; and a documented incident response process, described further in Section 8. We review these measures periodically and update them as the Service evolves toward general availability.
6. Subprocessor Use and Notification
You authorize RecapButler to engage the subprocessors listed on our Subprocessors page as of the date you accept these Terms, which is incorporated into this DPA by reference. Before adding a new subprocessor that will process personal data in scope of this DPA, we will update that page and provide advance notice by email to active early access and paying customers so they may object on reasonable data protection grounds. If you object and we cannot resolve the concern, either party may terminate the affected part of the Service as its sole remedy. RecapButler remains liable for a subprocessor's performance to the same extent RecapButler would be liable if performing that processing itself, and imposes data protection obligations on each subprocessor materially equivalent to those in this DPA.
7. Assistance With Data Subject Requests
Taking into account the nature of the processing, RecapButler will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling requests to exercise data subject rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection) and under KVKK Article 11. Where such a request reaches us directly from a meeting participant or other individual whose data we process on your behalf, we will, without undue delay, direct that individual to you as the controller or, at your instruction, action the request ourselves.
8. Personal Data Breach Notification
RecapButler will notify you without undue delay, and in any event within 72 hours of becoming aware, of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data we process on your behalf. The notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available and cooperate with you in meeting your own breach notification obligations under GDPR Article 33/34 and KVKK's breach notification requirements to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
9. Audit Rights
You may request evidence of RecapButler's compliance with this DPA, including relevant policy documents. If such evidence is not sufficient to demonstrate compliance, you may conduct an audit of RecapButler's relevant processing activities, including inspections, no more than once every 12 months absent a specific reason to believe a breach has occurred, on at least 30 days' written notice, at your expense, during business hours, and subject to confidentiality obligations and reasonable limits to protect RecapButler's other customers and trade secrets.
10. International Data Transfers
Most of our infrastructure is pinned to the EU (Frankfurt); our meeting-bot subprocessor, Recall.ai, processes raw recordings in the region we configure for it, which defaults to the United States absent EU-region configuration, as described on our Subprocessors page. Where personal data originating in the EU/EEA or UK is transferred to a subprocessor outside those regions, the transfer is made subject to the European Commission's Standard Contractual Clauses (or a successor mechanism recognized under GDPR Chapter V) as incorporated into our contract with that subprocessor, or another adequacy mechanism where available. Where personal data originating in Türkiye is transferred abroad, the transfer relies on the statutory mechanisms available under KVKK Article 9, pending further guidance from the Kişisel Verileri Koruma Kurumu.
11. Return or Deletion of Data at End of Contract
On termination of your organization's use of the Service, and at your election, RecapButler will delete your meeting data on request, as described in our Privacy Policy, unless applicable law requires continued storage (for example, billing records retained for the statutory period under Turkish tax and commercial law). We will return or delete existing copies of your meeting data within a reasonable period following a verified deletion request.
12. Liability and Term
This DPA takes effect on the date you accept the Terms of Service and remains in effect for as long as RecapButler processes personal data on your behalf. Liability under this DPA is subject to the limitation of liability set out in the Terms of Service, except where such limitation cannot apply as a matter of mandatory law.
13. Governing Law
This DPA is governed by the same law as the Terms of Service: the laws of the Republic of Turkey, without prejudice to any mandatory data protection rights you hold under GDPR or KVKK regardless of choice of law.
14. Executing This DPA
For most customers, acceptance of our Terms of Service constitutes acceptance of this DPA; no separate signature is required. If your organization's procurement process requires a countersigned copy or a specific annex, email hello@recapbutler.com and we will provide one.
15. Contact
RecapButler is operated by Simay Yenice Astro Tasarım, a sole proprietorship established by Simay Yenice, registered at Hatboyu No 7/4, Erenköy, İstanbul, Türkiye. Questions about this DPA: hello@recapbutler.com.
Fragen zu diesem Dokument: hello@recapbutler.com