This English text is provided for information only. If it differs from the Turkish text, the Turkish text prevails.
Applies when the Customer is controller and Liyova processes personal data on its instructions.
Service provider and contact
Liyova services are provided by Hasan Eksi (Lone), registered with Setbaşı Tax Office under tax number 3300731863, at Dikkaldırım Mah. 2. Halis Sok. No:15 Kat:3 D:4 Osmangazi/Bursa, Türkiye, info@liyova.com, +90 507 858 50 83. “Liyova” or “Service Provider” in these documents means this business.
1. Scope and roles
This Addendum forms part of the Business Service Agreement. The Customer is controller and Liyova processor for personal data uploaded for purposes and means determined by the Customer. Liyova’s independently determined account, contract, billing, support, security and legal-compliance processing is covered by its Privacy Notice instead.
2. Processing details
| Item | Scope |
|---|---|
| Subject | Hosting and operation of property-management software |
| Duration | Service term and agreed exit/deletion period |
| Operations | Storage, organisation, query, reporting, transmission, backup, support and deletion |
| People | Residents, owners, tenants, managers, employees, suppliers, visitors and contacts |
| Data | Identity, contact, unit, finance, request, visitor, employee, document, message and technical data |
3. Instructions, confidentiality and security
Liyova processes data only under the Agreement, Order Form, platform settings and documented instructions from authorised Customer users. It may pause an instruction reasonably believed unlawful. Personnel and providers are bound by confidentiality and appropriate role-based access, encryption, secret management, audit, backup and incident controls are maintained.
4. Subprocessors
The Customer gives general authorisation for necessary subprocessors. Liyova gives at least 15 days’ notice before a new subprocessor or material purpose change, allowing a reasoned data-protection objection.
| Provider/group | Service | Likely data |
|---|---|---|
| Vercel | Web hosting | Technical access logs |
| Railway | API/runtime/database | Platform and technical data |
| Google/Firebase/reCAPTCHA | Identity, push, error/security | Account, device, token and security signals |
| AWS/CloudFront | Files, backup and app distribution | Files, images and technical data |
| Netgsm/email provider | OTP and operational messages | Phone, email and message |
| Finekra/Obifin | Enabled bank integration | Bank transaction and matching data |
5. International transfers
Where data or support access leaves Türkiye, Liyova identifies the destination, recipient and purpose and uses a valid safeguard under Article 9. Any required standard contract is signed without altering the regulator’s text and notified within the statutory period. This Addendum is not itself that standard contract.
6. Requests and incidents
Liyova provides reasonable technical assistance with access, correction, export, deletion and regulator requests. A verified personal-data breach affecting Customer Data is reported without undue delay, targeting 48 hours after awareness, with available facts and mitigation. Customer notification duties remain with the Customer.
7. Audit and data exit
Liyova provides reasonable compliance evidence. The Customer may request one remote audit per year on 15 business days’ notice, except for a substantiated incident or authority request. After termination, data can be exported for 30 days and is deleted or anonymised from active systems within 90 days unless law or a documented instruction requires otherwise. Isolated backups expire through the secure recovery cycle.

