Data Processing Addendum
Last updated: 12 September 2026
This Data Processing Addendum (the "Addendum") forms part of the Terms of Use between YouReply Teknoloji Ticaret Eğitim Danışmanlık Araştırma Organizasyon A.Ş. ("YouReply", the "Data Processor") and the customer using the YouReply Qualitative platform (the "Customer", the "Data Controller"), and applies to the research data the Customer uploads to the platform. Account and billing data are outside its scope; for those, YouReply is the data controller and the Privacy Notice (KVKK) applies.
1. Roles
For research data the Customer is the data controller under Turkish Law No. 6698: it determines the purposes and means of processing and ensures that participants are informed and that an appropriate legal ground exists. YouReply is the data processor for that data and acts only on the Customer's instructions.
2. Subject matter, duration, nature and purpose
| Subject matter | Coding, theme development, reporting and storage of qualitative research data |
|---|---|
| Duration | For as long as the Customer's account is active and the data has not been deleted |
| Nature and purpose | Providing the platform service and, when requested, generating AI-assisted code and theme suggestions |
| Data categories | Transcript and field note text, participant codes, pseudonyms and attributes, codings, themes, memos and reports. Depending on the content, it may include special categories of personal data. |
| Categories of data subjects | Interviewees, focus group participants and survey respondents in the Customer's research |
3. Processing on instructions
The Data Processor processes research data only to provide the service and in line with the instructions the Customer gives through the platform. The data is not used for our own purposes, for example to train AI models or to build features for other customers. If we consider an instruction to be unlawful, we inform the Customer.
4. Confidentiality
Personnel with access to the data are bound by confidentiality obligations, and access is limited to what their role requires.
5. Security measures
The Data Processor implements technical and organizational measures appropriate to the risk. The measures in place, and the claims we deliberately do not make, are described on the Security page and may be updated as the service evolves; updates will not materially weaken protection.
6. Sub-processors
The Customer authorizes the use of the sub-processors listed on the Sub-processors page. When a new sub-processor is added, that page is updated and the change is announced with the date shown on it. Sub-processors are placed under obligations that are substantially the same as those in this Addendum, and the Data Processor remains responsible for their performance.
7. International transfers
Providing the service requires transfers to some providers located outside Türkiye, as marked in the sub-processor list. Transfer to the AI provider happens only while AI is enabled for the study in question; the Customer can stop that transfer by switching the setting off. Transfers are made within the framework of Article 9 of Law No. 6698, and the parties cooperate to put the required transfer mechanism in place.
8. Data subject requests
Requests that participants send us directly are referred to the Customer as data controller. We provide reasonable technical assistance (locating, exporting, correcting or deleting data) so the Customer can respond.
9. Breach notification
If we become aware of a security breach affecting research data, we inform the Customer without undue delay and within 72 hours at the latest. The notice includes the information available to us about the nature of the breach, the data categories affected, the known consequences and the measures taken. Notifying the Authority and the data subjects is the Customer's obligation as data controller; we assist in that process.
10. Deletion and return
The Customer can delete documents permanently in the platform and export data as Word and Excel files. When the service ends, or when the Customer asks, research data is deleted; deletion requests go to kvkk@youreply.com.tr. Copies in backups disappear once the retention period of the backup schedule (currently 90 days) has passed; during that period backups are used for recovery only.
11. Information and audit
We provide the information the Customer reasonably requests, at reasonable intervals, to verify compliance with this Addendum. Audit requests are submitted in writing in advance and are accommodated during business hours, under confidentiality obligations and without disrupting the service.
12. Term
This Addendum takes effect when the Customer starts using the platform and ends when processing of the research data ends. The current version is published on this page; the date at the top shows the last change.
13. Contact
For questions about this Addendum: hukuk@youreply.com.tr. For personal data requests: kvkk@youreply.com.tr.