Customer data terms
Data Processing Addendum
Last updated: August 22, 2026
This page is a general template of terms for customer personal-data processing. It is not a certification, legal advice, or a promise that a particular transfer mechanism or security measure applies in every customer's circumstances, and it makes no unsupported certification promises.
1. Roles and scope
When Refleks processes personal data submitted or connected by a customer through the Service, the customer determines the purposes and means of that processing and acts as the controller (or equivalent role). Refleks, operated by Ebubekir Korkut, acts as the processor (or equivalent role) only to provide the Service under the customer's documented instructions.
This addendum applies to customer personal data in website content, chat conversations, visitor contact submissions, and related service records. It does not change the Terms of Service or the Privacy Policy for data we process as an independent controller, such as account administration and billing records.
2. Processing instructions
The subject matter, duration, nature, and purpose of processing are the provision, security, support, and maintenance of the Service for the duration of the customer account and any applicable retention period. We will not use customer personal data for advertising or sell it. We may process it as needed to follow the customer's configuration, prevent abuse, maintain reliability, and comply with a binding legal obligation.
The customer is responsible for giving lawful instructions, providing required notices, and configuring the widget and connected websites appropriately. The customer must not submit data to the Service unless it has a lawful basis to do so.
3. Data and people covered
Depending on the customer's configuration, data may include names, contact details, questions, messages, website content, URLs, and technical or abuse- prevention metadata. People may include the customer's staff, website visitors, leads, and other people described in the customer's content. Customers should avoid submitting sensitive data unless the Service and their legal arrangements support that use.
4. Confidentiality and access
Persons authorized by us to process customer personal data are subject to confidentiality obligations appropriate to their role. Access is limited to what is reasonably needed to operate, secure, support, and improve the Service. The current security measures are described on the Security page; those descriptions do not constitute a certification or warranty.
5. Service providers and transfers
We may use infrastructure and service providers to process customer personal data for the purposes above. The current categories and providers are described in thePrivacy Policy. We remain responsible for selecting providers appropriate to the Service and for requiring protections suitable to the processing. Where applicable law requires a transfer safeguard, the parties will use a legally recognized mechanism that is appropriate to the transfer and circumstances.
6. Requests and incidents
Taking into account the nature of the processing, we will provide reasonable assistance with legally required requests from data subjects and with security assessments, to the extent the information is available to us and the request is reasonably specific. If we become aware of a confirmed security incident affecting customer personal data, we will notify the customer without undue delay where required by applicable law and provide information reasonably available for the customer's assessment.
7. Return, deletion, and retention
On account closure or a customer's documented request, we will delete or return customer personal data where technically available, subject to the customer's instructions, the Service's retention settings, legal obligations, security logs, and restricted backups. The retention periods and deletion controls are described in the Privacy Policy. Data that must be retained by law is isolated and protected for that purpose.
8. Customer audit information
We can provide reasonable information about the Service's processing and relevant controls to help a customer assess compliance, subject to confidentiality, security, and proportionality limits. Any audit or questionnaire should be arranged in advance and must not disrupt the Service or expose another customer's information.
9. Order of precedence and contact
If this addendum conflicts with the Terms of Service about processing of customer personal data, this addendum controls for that conflict. It does not expand either party's obligations beyond applicable law or the agreed Service.
Questions about these customer data terms can be sent to support@refleks.dev.
