This is a courtesy translation. The Turkish text is the governing version; in case of conflict, the Turkish text prevails.
This addendum defines the obligations of NESNET (the "Processor") with respect to personal data processed through the applications a customer (the "Controller") runs on nesly, and forms an integral part of the Terms of Service. The processing of data belonging to your platform account itself (identity, invoicing, usage) is described separately in the Personal Data Notice.
Roles and instructions
For personal data collected by the customer's applications, the customer is the controller; the platform processes that data solely to provide the service, on the customer's instructions (deploy, store, back up, delete). The platform does not use, read or profile this data for its own purposes.
Scope and location of processing
- Subject matter: hosting and building the customer's applications, operating and backing up their databases.
- Duration: for the life of the subscription; on account closure the 'Deletion and return' section applies.
- Location: customer applications and data are hosted in Türkiye (İstanbul).
Security measures
The technical measures in force (workload and network isolation, encryption in transit and at rest, image scanning, access roles) are published, in their current form, on the security page; that page is the reference for this addendum.
Sub-processors
The current list of sub-processors used to operate the service is published on the security page. Additions are recorded there before the related feature goes live; a customer who does not accept an addition may end the subscription at the end of the paid period.
Deletion and return
- While the account is open, the customer can export all account data as a single archive (console or CLI).
- On account closure, running applications are stopped, databases are fenced off, and data is permanently deleted at the end of the retention window.
- Deleting a database addon first cuts access; the data is permanently deleted at the end of the recovery window.
Breach notification
Upon detecting a personal data breach affecting customer data, NESNET notifies the customer without undue delay at the e-mail address registered to the account, sharing the known impact and the measures taken.
Requests
Send requests concerning this addendum to nesly@nesly.net.