Relevant · relevant.com.tr
Legal
Data processing agreement
This agreement explains how Relevant processes personal data on behalf of customers: who is responsible for what, what we will and will not do with the data, how subprocessors and international transfers are handled, and what happens when the service ends.
It applies automatically to personal data in the datasets, traces and review items you upload. It is written to meet GDPR Article 28 and the equivalent processor obligations under other applicable data protection laws.
Last updated:
Parties, scope and order of precedence#
This data processing agreement (the “DPA”) is made between the customer that accepted the Relevant Terms of service (“Customer”) and Relevant (“Relevant”). It forms part of the Terms of service and applies to personal data that Relevant processes on Customer’s behalf while providing the service.
This DPA does not cover personal data for which Relevant is itself the controller, such as account details, billing contacts and website visitor data. Those activities are described in the Privacy policy and, where Law No. 6698 applies, the KVKK notice.
If the Terms and this DPA conflict on the processing of personal data, this DPA prevails. If the Standard Contractual Clauses described in the international transfers section apply and conflict with this DPA, the Standard Contractual Clauses prevail.
Definitions#
Capitalized terms not defined here have the meaning given in the Terms of service.
- Applicable Data Protection Law
- Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data protection law that applies to the processing, each as amended.
- Customer Content
- Datasets, traces, questions, answers, retrieved passages, gold answers, review decisions and other material that Customer or its users submit to, or generate in, the service.
- Customer Personal Data
- Personal data contained in Customer Content that Relevant processes as a processor on behalf of Customer.
- Controller, processor, data subject, personal data, processing
- Have the meanings given in Applicable Data Protection Law.
- Personal Data Breach
- A breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- Subprocessor
- A third party engaged by Relevant that processes Customer Personal Data on Relevant’s behalf.
- Standard Contractual Clauses
- The clauses annexed to Commission Implementing Decision (EU) 2021/914, as amended or replaced.
- Service
- The Relevant evaluation and failure-analysis platform, including the website, dashboard, API, SDKs and CLI.
Roles and responsibilities#
For Customer Personal Data, Customer is the controller and Relevant is the processor. Where Customer processes personal data on behalf of its own customers, Customer is a processor and Relevant is a subprocessor, and the obligations in this DPA apply accordingly.
Customer is responsible for
- Having a lawful basis for the processing and giving data subjects the notices that Applicable Data Protection Law requires.
- The accuracy and lawfulness of the Customer Content it submits and the instructions it gives.
- Submitting only the personal data needed for evaluation. Redacting identifiers before ingestion is the simplest way to reduce risk, and the acceptable use policy sets out data that must not be uploaded.
- Managing its own users, roles, API keys and integrations.
Relevant is responsible for
- Processing Customer Personal Data only as described in this DPA.
- Providing the security measures in Annex II and the cooperation described below.
- Engaging Subprocessors only on the terms in the Subprocessors section.
Processing instructions#
The Terms, this DPA and Customer’s use of the service’s features, such as importing a dataset, ingesting traces, configuring a run or enabling a judge, are Customer’s documented instructions. Relevant processes Customer Personal Data only on those instructions, unless a law that applies to Relevant requires otherwise. In that case Relevant informs Customer before processing unless the law prohibits it.
Relevant will tell Customer without undue delay if it believes an instruction infringes Applicable Data Protection Law.
In particular, Relevant:
- does not use Customer Personal Data to train or fine-tune models, and does not permit Subprocessors to do so;
- does not sell or share Customer Personal Data, and does not use it for advertising;
- does not combine Customer Personal Data with personal data from other sources except as Customer instructs.
Confidentiality and security#
Relevant ensures that personnel who can access Customer Personal Data are bound by written confidentiality obligations, receive security and data-protection training, and access Customer Content only when needed to provide the service, resolve a support request or maintain the platform.
Relevant implements and maintains the technical and organizational measures described in Annex II and on the security page, appropriate to the risk of the processing. Relevant may update those measures provided the overall level of protection is not reduced.
Subprocessors#
Customer gives Relevant general written authorization to engage Subprocessors. The current list, with the purpose, data accessed and location of each, is published on the subprocessors page.
- Relevant notifies workspace Owners and Admins by email, and updates the list, at least 30 days before a new Subprocessor begins processing Customer Personal Data or an existing one is replaced.
- Customer may object on reasonable data-protection grounds within those 30 days by writing to privacy@relevant.com.tr. The parties then discuss the objection in good faith.
- If the objection cannot be resolved, for example by Relevant offering a different configuration, Customer may terminate the part of the service that depends on the Subprocessor, without penalty, by written notice.
Relevant imposes data-protection obligations on each Subprocessor that are no less protective than this DPA and remains responsible for the Subprocessor’s performance of them.
International transfers#
Customer Content is hosted in the region Customer selects for its workspace. Relevant does not move Customer Content out of that region except where a Subprocessor listed for the purpose operates elsewhere, where Customer instructs it, or where a law requires it.
EEA, United Kingdom and Switzerland
Where a transfer of Customer Personal Data to a country without an adequacy decision takes place, the Standard Contractual Clauses apply and are incorporated by reference: Module Two (controller to processor) and, where Customer is a processor, Module Three (processor to processor). For transfers from the United Kingdom, the UK International Data Transfer Addendum applies. For transfers from Switzerland, the clauses apply with the amendments required by the Swiss authority. The elections are listed in Annex III.
Other jurisdictions
Transfers of personal data abroad from any other jurisdiction whose law restricts them are made only under a mechanism that law permits: an adequacy decision, appropriate safeguards such as a standard contract approved by the competent authority, binding corporate rules, or a listed exception. Where a standard contract is used, the parties sign it and make any notification to the authority within the period the law requires.
Data subject requests and assistance#
Customer, as controller, is responsible for responding to requests from data subjects. Relevant gives Customer tools to find, export and delete Customer Content so most requests can be completed without Relevant’s involvement.
If Relevant receives a request that concerns Customer Personal Data, it does not respond to the data subject except to say that the request has been passed to the controller, and forwards it to Customer within five business days. Customer remains responsible for answering within the statutory period, which is one month under GDPR Article 12 and can be shorter under other Applicable Data Protection Law.
Taking into account the nature of the processing, Relevant provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, and with Customer’s obligations to its data subjects. Assistance beyond the standard features and documentation may be charged at reasonable cost, agreed in advance.
Personal data breaches#
Relevant notifies Customer without undue delay, and in any event within 48 hours, after confirming a Personal Data Breach affecting Customer Personal Data. The notice goes to workspace Owners and any security contact on file and includes, as far as it is known:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to contain and remedy it;
- a point of contact for further information.
Where all details are not yet available, Relevant provides them in phases. The notice period is set so that Customer can meet its own deadlines, including the 72 hours that the GDPR gives a controller to notify the competent authority. Relevant does not notify authorities or data subjects on Customer’s behalf unless the law requires it or Customer instructs it to. See incident response for how breaches are handled.
Audits and information#
Relevant makes available the information needed to show compliance with this DPA, including security documentation, answers to reasonable security questionnaires and, where it holds them, summaries of independent assessments.
If that information is not enough, Customer or an independent auditor bound by confidentiality may audit Relevant’s compliance with this DPA, subject to the following:
- no more than once in any 12 months, unless a regulator requires it or a Personal Data Breach has occurred;
- on at least 30 days’ written notice, during business hours, and remotely wherever that is sufficient;
- limited to systems and records relevant to Customer Personal Data, without access to other customers’ data;
- at Customer’s cost, and without unreasonable disruption to the service.
Return and deletion of data#
While the agreement is in force Customer can export Customer Content as CSV and delete it at any time. Runs, traces and review decisions are also deleted automatically at the end of the retention period of Customer’s plan. Datasets and reference answers are kept until Customer deletes them or the workspace is closed:
- Free
- Retention
- 7 days
- Applies to
- Runs, traces and review decisions
- Pro
- Retention
- 30 days
- Applies to
- Runs, traces and review decisions
- Team
- Retention
- 90 days
- Applies to
- Extended retention add-on keeps data for 12 months
- Enterprise
- Retention
- Custom
- Applies to
- Set per workspace in the order form
When the agreement ends, Customer has 30 days to export its data. Relevant then deletes Customer Content from production systems within a further 30 days. Encrypted backups are overwritten on their normal cycle, which does not exceed 35 days, and are not restored except to recover the service. A workspace deleted by its Owner is scheduled for deletion after a 14-day period in which the Owner can cancel. Relevant may keep personal data that a law requires it to retain, and then only for that purpose.
Liability, term and governing law#
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of service, except where Applicable Data Protection Law or the Standard Contractual Clauses do not allow them. Nothing in this DPA limits a data subject’s rights.
This DPA lasts for as long as Relevant processes Customer Personal Data and survives termination of the Terms until the deletion described above is complete. Its governing law and forum follow the Terms of service. The Standard Contractual Clauses are governed by the law listed in Annex III.
Annex I: Details of processing#
- Subject matter
- Provision of the Relevant evaluation and failure-analysis service to Customer.
- Duration
- For the term of the agreement, plus the return and deletion period described above.
- Nature and purpose
- Storage, retrieval, analysis, scoring and display of Customer Content in order to run evaluations, diagnose failures, support review workflows and produce reports and exports that Customer requests.
- Frequency
- Continuous while Customer uses the service, including scheduled and automated runs.
- Categories of data subjects
- End users and customer-support contacts whose questions or messages appear in submitted datasets and traces; Customer’s employees, contractors and reviewers who use the service.
- Categories of personal data
- Free-text content of questions, answers and retrieved passages, which may include names, contact details, account or order identifiers and service-related information; user identifiers supplied in trace metadata; names, email addresses and review decisions of Customer’s users.
- Special categories
- None intended. Customer must not submit special categories of personal data (GDPR Article 9 and equivalent provisions of other Applicable Data Protection Law) unless it has agreed the arrangement with Relevant in writing and applied suitable safeguards.
- Retention
- Runs, traces and review decisions: the retention period of Customer’s plan, or until Customer deletes them, whichever is earlier. Datasets and reference answers: until Customer deletes them or the workspace is closed.
- Competent supervisory authority
- The supervisory authority responsible for Customer’s establishment, as identified in the Standard Contractual Clauses elections in Annex III.
Annex II: Technical and organizational measures#
The measures below are summarized from the security page, which describes them in more detail and is updated as they evolve.
- Encryption
- Measure
- TLS 1.2 or higher for all traffic in transit; AES-256 encryption for data at rest, including backups.
- Tenant isolation
- Measure
- Every request is scoped to a single workspace. Customer Content is logically separated between workspaces and stored in the selected region.
- Access control
- Measure
- Role-based access with Owner, Admin, Member and Viewer roles; SSO (SAML, OIDC) and SCIM on Enterprise; API keys are shown once, stored hashed and revocable.
- Audit and monitoring
- Measure
- Administrative actions are logged and, on Enterprise, available as audit logs. Platform access and errors are monitored.
- Personnel
- Measure
- Confidentiality undertakings, security training, and need-to-know access to Customer Content with review of privileged access.
- Resilience
- Measure
- Encrypted backups and tested recovery procedures; infrastructure hosted with a provider listed as a Subprocessor.
- Secure development
- Measure
- Peer review of changes, dependency monitoring, separation of environments and secrets management.
- Incident response
- Measure
- Documented procedure with triage, containment, customer notification within 48 hours and post-incident review.
- Data minimization
- Measure
- Plan-based retention periods, customer-controlled export and deletion, and no use of Customer Content for model training.
Annex III: Subprocessors and transfer elections#
The Subprocessors authorized on the date of this version are listed on the subprocessors page, which is part of this Annex. The elections below apply where the Standard Contractual Clauses are used.
- Module
- Election
- Module Two (controller to processor); Module Three (processor to processor) where Customer is a processor
- Clause 7, docking clause
- Election
- Included
- Clause 9(a), Subprocessors
- Election
- Option 2, general written authorization, with 30 days’ notice of changes
- Clause 11(a), redress body
- Election
- Optional language not included
- Clause 13, supervisory authority
- Election
- The supervisory authority responsible for ensuring Customer’s compliance with Regulation (EU) 2016/679
- Clause 17, governing law
- Election
- The law of the EU Member State in which Customer is established or, where that law does not allow third-party beneficiary rights, the law of Ireland
- Clause 18(b), forum
- Election
- The courts of the EU Member State whose law governs under Clause 17
- Annex I.A and I.B
- Election
- As set out in Annex I of this DPA
- Annex II
- Election
- As set out in Annex II of this DPA
- Annex III
- Election
- The subprocessors page
Contact and requests#
Send questions about this DPA, requests for a countersigned copy, and subprocessor objections to the contacts below, or use the contact form.
- Legal entity
- Relevant
- Privacy and data protection
- privacy@relevant.com.tr
- Legal notices
- legal@relevant.com.tr
Material changes to this DPA are notified to workspace Owners at least 30 days before they take effect.