Last updated: to be set upon publication
Kiipup — operated by wyzmo.ai L.L.C-FZ
This Data Processing Agreement ("DPA") forms part of the agreement between the Instructor ("Controller," "you," or "your") and wyzmo.ai L.L.C-FZ ("Kiipup," "Processor," "we," "us," or "our") for the provision of the Kiipup platform and related services (the "Service Agreement").
This DPA sets out the terms under which Kiipup processes personal data on behalf of the Controller in connection with the Service and ensures compliance with applicable data-protection legislation, including the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the EU General Data Protection Regulation ("GDPR"), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), and any other applicable data-protection laws.
Entity details of the Processor:
- Legal name: wyzmo.ai L.L.C-FZ
- Trade License: 2543059.01 | Formation No: 2543059
- Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
- Manager: Cagatay Guler
1. Roles of the Parties
1.1 Controller
The Instructor who subscribes to and uses the Kiipup platform is the data controller with respect to the personal data of their students, clients, patients, and other individuals whose data they input into or manage through the Service ("Client Data").
The Controller determines the purposes and means of processing Client Data and is responsible for ensuring that the processing is lawful.
1.2 Processor
wyzmo.ai L.L.C-FZ (operating the Kiipup platform) is the data processor. We process Client Data solely on behalf of and in accordance with the documented instructions of the Controller, as set out in this DPA and the Service Agreement.
2. Scope of Processing
2.1 Subject Matter
The processing of Client Data by the Processor is necessary for the provision of the Kiipup SaaS platform, which enables Instructors to manage their teaching, coaching, or tutoring practice.
2.2 Duration
The Processor will process Client Data for the duration of the Service Agreement between the Controller and the Processor. Upon termination or expiry of the Service Agreement, the provisions of Section 3.7 (Data Return and Deletion) apply.
2.3 Nature and Purpose of Processing
The processing includes the collection, storage, organization, structuring, retrieval, consultation, use, disclosure by transmission to authorized sub-processors, and erasure of Client Data for the following purposes:
- Providing and maintaining the platform functionality
- Student/client profile management and record-keeping
- Scheduling and calendar management
- Attendance tracking
- Payment and billing record-keeping
- Communication between the Instructor and their students/clients via the platform
- AI-powered content generation and assistance (with best-effort identifier redaction prior to transmission to AI sub-processors)
- Homework and materials management
- Reporting and analytics within the Instructor's workspace
2.4 Categories of Data Subjects
Client Data may relate to the following categories of individuals:
- Students, clients, or patients of the Instructor
- Parents, guardians, or emergency contacts of the above
- Other individuals whose data the Instructor inputs into the Service
Data subjects may include minors (individuals under the age of 18). The Controller bears responsibility for ensuring lawful processing of minors' data, including obtaining parental or guardian consent where required.
2.5 Categories of Personal Data
Client Data processed under this DPA may include, but is not limited to, the following categories:
- Identity data: Name, date of birth, gender, photograph
- Contact data: Email address, phone number, physical address
- Scheduling data: Lesson dates, times, recurrence, availability
- Attendance data: Attendance records, absence reasons, cancellation history
- Payment data: Payment status, amounts, transaction references (full payment card details are processed by Stripe and not stored by Kiipup)
- Notes and records: Instructor notes, progress notes, session summaries
- Homework and materials: Assignments, uploaded files, learning materials
- Messages: In-platform communications between the Instructor and their students/clients
- AI-generated content: Content generated by AI features based on inputs provided by the Instructor, including lesson plans, summaries, and feedback drafts
The Controller acknowledges that Client Data may include special categories of data (e.g., health information in the context of coaching or tutoring accommodations). The Controller is solely responsible for ensuring that the processing of any special-category data is lawful and that the necessary consents or legal bases have been secured (see Section 6).
3. Processor Obligations
3.1 Processing on Instructions
The Processor will process Client Data only on the documented instructions of the Controller, unless required to do so by applicable law to which the Processor is subject. In such a case, the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
The Controller's instructions are documented in and limited to:
- This DPA
- The Service Agreement (including the Terms of Service)
- Any additional written instructions agreed upon by the parties
If the Processor considers that an instruction from the Controller infringes applicable data-protection legislation, the Processor will promptly inform the Controller.
3.2 Confidentiality
The Processor will ensure that all persons authorized to process Client Data have committed to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
3.3 Security Measures
The Processor will implement and maintain appropriate technical and organizational measures to protect Client Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:
- Encryption in transit: All data transmitted between the Controller's devices and the platform is encrypted using TLS.
- Encryption at rest: Client Data is encrypted at rest within the database infrastructure.
- Row-Level Security (RLS): Database-level tenant isolation ensures that each Controller's Client Data is logically separated and accessible only to authorized users within their workspace.
- Least-privilege access: Internal access to Client Data is restricted on a need-to-know basis, with role-based access controls applied across all systems.
- Audit logging: Access to Client Data and critical operations are logged for security monitoring and incident investigation.
- AI data handling: Content sent to AI sub-processors undergoes best-effort identifier redaction. AI sub-processors are contractually prohibited from using Client Data to train their models.
The Processor will regularly review and, where appropriate, update these measures to reflect changes in technology, industry practices, and evolving threats.
3.4 Assistance with Data Subject Requests
The Processor will assist the Controller, by appropriate technical and organizational measures (insofar as this is possible), in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under applicable data-protection law (including rights of access, rectification, erasure, restriction, portability, and objection).
Where a data subject contacts the Processor directly with a request relating to Client Data, the Processor will promptly redirect the individual to the Controller or notify the Controller of the request, unless otherwise instructed.
3.5 Assistance with Compliance Obligations
The Processor will assist the Controller in ensuring compliance with the obligations relating to:
- Security of processing
- Data protection impact assessments (where required)
- Prior consultation with supervisory authorities (where required)
- Notification to supervisory authorities and data subjects in the event of a personal data breach
3.6 Personal Data Breach Notification
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Client Data. The Processor will target notification within seventy-two (72) hours of confirmed awareness, in line with KVKK Board guidance and GDPR requirements.
The notification will include, to the extent available:
- A description of the nature of the breach, including (where possible) the categories and approximate number of data subjects and records concerned
- The name and contact details of the Processor's point of contact for further information
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects
The Processor will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
3.7 Data Return and Deletion on Termination
Upon termination or expiry of the Service Agreement, the Processor will, at the Controller's election:
- Return the Client Data to the Controller in a structured, commonly used, and machine-readable format; or
- Delete all Client Data and existing copies, unless applicable law requires retention.
If the Controller does not provide instructions within thirty (30) days of termination, the Processor will proceed to delete all Client Data, subject to any legal retention obligations.
The Processor will certify the deletion of Client Data in writing upon the Controller's request.
4. Sub-Processors
4.1 Authorized Sub-Processors
The Controller provides general written authorization for the Processor to engage sub-processors to assist in the provision of the Service. As of the effective date of this DPA, the Processor engages the following sub-processors:
| Sub-Processor | Function | Location |
|---|---|---|
| Supabase | Database hosting, authentication, and backend infrastructure | United States |
| Stripe | Payment processing and billing | United States |
| Anthropic | AI content generation and processing | United States |
| Vercel | Application hosting and content delivery | United States |
| Mailtrap | Transactional and system email delivery | United States |
| Sentry | Error monitoring and application performance | United States |
4.2 Obligations Regarding Sub-Processors
The Processor will:
- Enter into a written agreement with each sub-processor that imposes data-protection obligations no less protective than those set out in this DPA.
- Remain fully liable to the Controller for the performance of each sub-processor's obligations.
4.3 Changes to Sub-Processors
The Processor will notify the Controller of any intended addition or replacement of sub-processors by updating the sub-processor list and providing notice (via email to the address associated with the Controller's account or through the platform) at least fourteen (14) days before the new sub-processor begins processing Client Data.
The Controller will have the opportunity to object to the appointment of a new sub-processor within that fourteen-day period. If the Controller raises a reasonable objection, the parties will discuss the concern in good faith and the Processor will make reasonable efforts to address the objection (for example, by offering an alternative sub-processor or configuration). If the objection cannot be resolved, the Controller may terminate the affected Service by providing written notice, without prejudice to any fees owed for the period prior to termination.
5. International Data Transfers
5.1 Transfer Acknowledgment
The Controller acknowledges that the Processor and its sub-processors are located outside of Turkey and the EU/EEA, and that the processing of Client Data necessarily involves international data transfers.
5.2 Safeguards
The Processor will ensure that international transfers of Client Data are made in accordance with appropriate safeguards as set out in the Privacy Policy, including:
- KVKK Article 9: Explicit consent of data subjects obtained by the Controller, and/or adequate contractual protections between the Processor and its sub-processors.
- GDPR Chapter V: Standard Contractual Clauses adopted by the European Commission, supplemented by additional technical and organizational measures where required.
- UAE PDPL: Compliance with the cross-border transfer requirements under the UAE data-protection framework.
5.3 Controller's Responsibility for Transfer Consent
Where the lawful basis for international transfer relies on the explicit consent of data subjects (particularly under KVKK Article 9), the Controller is responsible for obtaining, documenting, and maintaining such consent from the relevant data subjects.
6. Controller's Responsibilities
The Controller warrants and undertakes that:
6.1 Lawful Basis
The Controller has established and will maintain a valid lawful basis for the collection and processing of Client Data, including any special categories of personal data, under all applicable data-protection laws.
6.2 Privacy Notices
The Controller has provided (and will continue to provide) appropriate and transparent privacy notices to data subjects whose personal data is included in Client Data, informing them of the processing, international transfers, and their rights.
6.3 Consent
Where consent is the lawful basis for processing (including for international data transfers), the Controller has obtained and will maintain valid consent from the relevant data subjects. For data subjects who are minors, the Controller has obtained verifiable parental or guardian consent in accordance with applicable law.
6.4 No Unlawful Instructions
The Controller will not instruct the Processor to process Client Data in any manner that would violate applicable data-protection legislation. The Controller acknowledges that the Processor is not obligated to assess the lawfulness of the Controller's instructions but will inform the Controller if, in its opinion, an instruction may be in breach of applicable law.
6.5 Special-Category Data
If Client Data includes special categories of personal data (such as health data, biometric data, or data concerning a child's welfare), the Controller accepts sole responsibility for ensuring that the processing of such data is lawful and that all required safeguards, consents, and notifications are in place.
6.6 Data Accuracy
The Controller is responsible for ensuring the accuracy and completeness of Client Data and for rectifying any inaccuracies.
7. Audit
7.1 Information and Compliance Demonstration
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA and applicable data-protection legislation.
7.2 Audit Rights
The Controller (or an independent auditor mandated by the Controller) may conduct audits of the Processor's data-processing activities and security measures, subject to the following conditions:
- The Controller will provide the Processor with at least thirty (30) days' prior written notice of any audit.
- Audits will be conducted during normal business hours and in a manner that minimizes disruption to the Processor's operations.
- The Controller and any auditor will be bound by confidentiality obligations regarding any information obtained during the audit.
- The scope of the audit will be limited to the Processor's processing of Client Data under this DPA.
- Where multiple Controllers request audits, the Processor may propose a consolidated audit or accept a third-party audit report to satisfy audit requests efficiently.
- The Controller will bear the costs of any audit initiated by the Controller, unless the audit reveals a material breach of this DPA by the Processor.
7.3 Regulatory Audits
The Processor will cooperate with any audit or investigation by a supervisory authority or regulatory body with jurisdiction over the processing of Client Data, to the extent required by applicable law.
8. Liability
This DPA does not limit or exclude the liability of either party under the Service Agreement. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Service Agreement, except to the extent that applicable law prohibits such limitations.
9. Term and Termination
This DPA takes effect on the date the Controller accepts the Service Agreement (or, if earlier, the date the Processor first processes Client Data on behalf of the Controller) and remains in effect for the duration of the Service Agreement.
Sections of this DPA that by their nature should survive termination — including Sections 3.6 (Breach Notification), 3.7 (Data Return and Deletion), 7 (Audit), and 8 (Liability) — will survive the termination or expiry of this DPA.
10. Contact
For any questions or requests related to this DPA, please contact:
- Privacy and data-protection requests: privacy@kiipup.com
- General inquiries: hello@kiipup.com
- Support: hello@kiipup.com
wyzmo.ai L.L.C-FZ Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E. Trade License: 2543059.01 | Formation No: 2543059 Manager: Cagatay Guler
This Data Processing Agreement is governed by and construed in accordance with the laws of the United Arab Emirates, without prejudice to the mandatory data-protection rights afforded to data subjects under the laws of their country of residence.
