Data Processing Terms

Effective September 18, 2026

These Data Processing Terms explain how we process personal data on your behalf when your business uses ZincirX. They cover the personal data inside your content, such as names typed into production steps, the locations captured when steps are recorded, photos and documents, and details of people shown in your passports.

They form part of the Terms of Service (https://zincirx.com/terms). They are accepted on behalf of your business together with the Terms of Service, and that acceptance is recorded.

Where the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) applies, these Data Processing Terms are the contract between a controller and its processor that its Article 28 requires. Where Turkish Law No. 6698 on the Protection of Personal Data (the “KVKK”) applies, they are the agreement between you as data controller and us as data processor under that law.

ZincirX is provided by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. to customers established in Türkiye and by ZincirX Inc. to all other customers. “We”, “us” and “our” mean whichever of the two companies your business contracts with. These Data Processing Terms apply to every customer, whichever company it contracts with.

“You” means the business that uses ZincirX. An “account holder” is a person with their own sign-in who acts for one or more businesses.

A “passport” is a digital product passport we host for you: a unique identifier with its own QR code and public page. You “issue” a passport by assigning it to a production batch, and from then on its public page shows your record of that batch. Its “availability term” is how long it stays online, counted from the day it is issued.

“Your content” means everything your business and its account holders put into ZincirX or record with it, such as templates, batches, steps and the GPS positions recorded with them, photos, documents, passport attributes, certifications and revisions, and the passports built from them, as the Terms of Service define it. In these Data Processing Terms it also includes the records the service keeps for you about your passports, such as scans of their QR codes and reads of their restricted content.

1. Who is the controller and who is the processor

You decide what personal data goes into your content, what you publish in your passports and whom you give access to. You are therefore the controller of the personal data in your content, and we are your processor.

Where you contract with ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., it processes your content for you directly. Where you contract with ZincirX Inc., the platform is operated by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which processes your content as the sub-processor of ZincirX Inc. under a written agreement that binds it to the same obligations as these Data Processing Terms. ZincirX Inc. remains responsible to you for that processing.

Our companies also process some personal data for their own purposes, as controllers, such as account holders' sign-in details and profiles, their messages to the AI assistant, billing and payments, records of the acceptance of our terms, the security of the service, support requests, our marketing to business contacts and website analytics. These Data Processing Terms do not cover that data; the Privacy Policy (https://zincirx.com/privacy) does, and says which of our companies controls it. Section 7 sets out the only uses of passport data beyond the service that you agree to.

2. Subject matter and duration

The subject matter of the processing is the personal data in your content, which we process to provide ZincirX to you under the Terms of Service.

The processing begins when you first put content into ZincirX and lasts for as long as we hold your content: while your contract with us runs, and afterwards until the content is returned or deleted as section 14 describes.

Passports you have issued stay online for their availability term: 10 years, counted from the day each passport is issued, unless the order it came from states a different term; if that order recorded a later end date, the later date applies. Unless erasure was chosen for their order at checkout, or you choose it when your contract ends (section 14), the processing of their content continues until that term ends, even if your contract with us has ended before then.

Records of scans of your QR codes are deleted after 12 months, and records of reads of restricted passport content after 36 months.

3. Nature and purpose of the processing

We process the personal data in your content only to provide the service to you, and use your passport data beyond that only as section 7 allows. Providing the service covers the following.

  • We store your content and keep backups of the database that holds it.
  • We show your content to your account holders according to their roles in your business.
  • We record each production step with the time and with the location captured by the device that records it. When a step is recorded in the mobile app, the app also looks up the address of that location, as section 10 describes.
  • We publish the public content of each issued passport on its public page and in the machine-readable versions of that page. Anyone can open them by scanning the passport's QR code, by following its address or, where a GTIN and lot number are set, by using the GS1 Digital Link address built from them.
  • We show restricted passport content only to the people you give access to, and record each time they read it.
  • We generate QR codes, labels and exports of your content.
  • We record scans of your QR codes, so that you can see how often and when they are scanned.
  • We send the emails the service sends about your business, such as a notice that someone has applied to join it.
  • We help you when you ask for support, and keep the service secure and working.

We do not use your content for any purpose of our own, such as marketing or training AI models, beyond the uses in section 7.

4. Types of personal data and the people concerned

You decide what personal data your content contains. It typically includes the following.

  • Names and other details of people that account holders type into templates, batches, steps, passport attributes or certifications, such as a grower, supplier, inspector or contact person.
  • Which account holder created a template or batch, recorded a step, uploaded a file or made a change recorded in a passport revision, and when.
  • The location captured at the start and at the end of each step by the device that records it, with the time it was captured and, where one was looked up, the address of that location.
  • Photos and documents uploaded as evidence, and whatever they show or contain, such as a person's face, name or signature.
  • The name, address and contact details of a manufacturer, supplier or other business named in a passport, where that business is a person, such as a sole trader, or where a contact person is named.
  • The names, email addresses and organisations of people you give access to restricted passport content, and a record of each time they read it, which keeps their IP address only as a keyed hash.
  • Records of scans of your QR codes: when each scan happened, the browser and device description the scanning device sent, and a keyed hash in place of its IP address.

The people concerned are mainly your account holders and other staff; people in your supply chain, such as growers, suppliers, contractors, inspectors and carriers, and their staff; contact persons of businesses named in your passports; people you give access to restricted passport content; people who scan your QR codes; and anyone else who appears in the photos and documents you upload.

The service is not meant for special categories of personal data, such as data about health, or for data about criminal convictions. Section 6 asks you to keep them out of your content.

5. Your instructions

We process the personal data in your content only on your documented instructions, including instructions about transferring it to other countries.

Your instructions are the Terms of Service, including these Data Processing Terms; what your account holders do in the service within the roles your business has given them, such as what they enter, what they publish, which passports they issue and whom they give access to; and any further instruction an owner or administrator of your business gives us in writing, for example by email to info@zincirx.com, that is consistent with the Terms of Service.

We treat what is done through an account holder's sign-in as done by that account holder. That does not apply where we knew, or should reasonably have noticed, that someone else was using the sign-in, or where that use was made possible by a failure of our own security measures.

Issuing a passport is your instruction to publish its public content and to keep it online for its availability term, including after your contract with us ends, because its QR code may already be printed on products in circulation. You can change that instruction: you can correct personal data in an issued passport or have it removed (section 11), and when your contract ends you can have your issued passports erased (section 14).

An issued passport's identifier is never reassigned to another product or reused, not even on your instruction. Mistakes are corrected in the passport's record, with corrections to its attributes and certifications added as revisions, and a passport can be marked as recalled.

When an account holder's own account is closed, you instruct us to replace the email address that names that person as the creator of a template or batch, as the person responsible for a production step or as the person who uploaded a file with one that identifies nobody, as the Account Closure and Cancellation page (https://zincirx.com/cancellation-policy) describes. What they recorded stays in your records. Passport revisions keep the email address of the person who made each change, as it was at the time; you can have it removed as section 11 describes.

The Terms of Service allow us to disable specific content that is illegal or breaches them, including content in an earlier revision of a passport. When we do, we send a statement of reasons, as the Terms of Service describe.

Beyond that, we process your content other than on your instructions only where a law that applies to us requires it: for example, to comply with an order of a court or public authority, or to inform the competent authorities of information giving rise to a suspicion of a criminal offence that threatens someone's life or safety. Before we act, we tell you of that legal requirement, unless the law or the authority forbids us to.

If we believe that an instruction of yours breaks data protection law, we tell you straight away.

6. Your responsibilities as controller

As controller, you are responsible for the personal data you put into ZincirX and for making sure your instructions to us comply with data protection law. In particular:

  • You need a lawful basis for the personal data in your content, and for everything you publish in the public part of a passport.
  • You tell the people concerned about the processing, as data protection law requires. Make sure the people who record steps know that recording a step captures their device's location and that step locations are shown on the public passport page.
  • Treat everything in the public part of a passport as published to anyone. Keep personal data out of it unless it needs to be there and you have a lawful basis for publishing it. Names, faces in photos and the locations recorded with steps can identify the people who work for you.
  • Where the EU Ecodesign for Sustainable Products Regulation (Regulation (EU) 2024/1781) applies to a product, it does not allow personal data about the product's customers to be stored in its digital product passport without their explicit consent. Do not store personal data about the buyers or users of your products in a passport unless they have explicitly consented.
  • Do not put special categories of personal data, such as data about health, or data about criminal convictions into your content.
  • You answer the requests of people who exercise their rights over personal data in your content. Section 11 describes the help we give.

7. Limits on the use of passport data

The EU Ecodesign for Sustainable Products Regulation (Regulation (EU) 2024/1781) does not allow a digital product passport service provider to sell passport data, reuse it or process it beyond what is necessary for its storing or processing service, unless that is specifically agreed with the economic operator that places the product on the market.

We apply that rule to every passport we host, whether or not the regulation already applies to the product, and whether or not the passport contains personal data. We do not sell passport data, reuse it for any purpose of our own, or process it, in whole or in part, beyond what is necessary to provide the service to you.

You specifically agree, by accepting these Data Processing Terms, to two uses beyond that, and to no others.

  • We count the templates and batches of all our customers together, including how many batches are in each status, and publish those totals about ZincirX. The totals identify no business, product or person.
  • When an account holder chooses to type passport data into the AI assistant, we send that message to Google, which processes it for us to produce the reply. The assistant is our own feature, not processing we do on your behalf: it never reads your content by itself, the company you contract with is the controller of what is typed into it in ZincirX, and we store none of it, as the Privacy Policy (https://zincirx.com/privacy) describes. Personal data should not be typed into it.

The EU Batteries Regulation (Regulation (EU) 2023/1542) allows no such agreement for battery passports. Each ZincirX passport covers one production batch, and ZincirX passports are not battery passports under that regulation, as the Terms of Service state.

8. Confidentiality

Within our companies, only people who need access to your content to run, support or secure the service are given it, and only as far as that need goes.

Everyone we authorise to process your content is bound by a duty of confidentiality, by contract or by law.

We disclose your content only as these Data Processing Terms allow: to our sub-processors and, for step locations recorded in the mobile app, to the phone's address lookup (section 10); to the people you give access to; to the public in the public part of your passports, as you instruct; and where the law requires it (section 5).

9. Security measures

We take technical and organisational measures to protect your content that are appropriate to the risks of the processing. They include the following.

  • Data travels between browsers or the mobile apps and our servers over encrypted connections (HTTPS).
  • Access to a business's content depends on membership of that business and on the member's role in it. Only its owners and administrators and, for a batch, the person who created it can change a passport's attributes and certifications.
  • Passwords are stored only as hashes, never in readable form. Account holders can turn on two-factor sign-in with a one-time code, and the mobile apps sign in with access tokens that can be revoked.
  • Passport attributes that are not public are left out of public passport pages and of the public machine-readable formats. Restricted attributes are shown only to people you have given access, each read is recorded, and an attribute whose access level is unknown is treated as the most restricted.
  • Each uploaded file is given a SHA-256 fingerprint, so that it can later be shown that the file has not changed.
  • Changes to a passport's attributes, certifications and product group are recorded as append-only revisions: each change is added as a new revision and earlier revisions are kept, apart from content removed or disabled as sections 5 and 11 describe. Changes to step details, and files that are removed, are not kept as revisions.
  • Public passport pages carry no analytics or tracking tools. IP addresses in the records of QR code scans and of reads of restricted content are kept only as keyed hashes, and those records are deleted after 12 and 36 months respectively.
  • QR codes are generated on our own servers, so passport addresses are not sent to outside services to make them.
  • We keep backups of the database.
  • We can suspend an account at once if it appears to have been taken over or misused. A suspension never stops you getting a copy of your content: if you cannot sign in, ask us at info@zincirx.com for an export.

We may change these measures as the service and technology develop, but not in a way that lowers the overall protection they give.

Your own measures matter too. You decide who in your business has an account and with which role, so remove access for people who no longer need it.

10. Sub-processors

You give us general written authorisation to engage sub-processors to help provide the service. We use these sub-processors.

  • ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which operates the platform for both of our companies, where you contract with ZincirX Inc.
  • Hostinger, which provides the servers and storage that the platform runs on and that hold your content, and the mail service through which ZincirX sends its emails. The country where the servers are located is stated on the Data Formats and Infrastructure page (https://zincirx.com/data-formats).
  • MailChannels, through which that mail service relays the emails ZincirX sends. It handles the recipients' addresses and the contents of those emails.

Google, which produces the AI assistant's replies for us, is not a sub-processor for your content. The assistant never reads your content by itself, and what an account holder types into it in ZincirX is handled by the company you contract with as controller (section 7).

When a step is recorded in the mobile app, the app asks the phone's built-in address lookup to turn the captured location into an address, which is saved with the step. The lookup is answered by the provider of the phone's operating system: Apple on an iPhone and, on most Android phones, Google. It receives the coordinates of the location.

We keep this list up to date, with each sub-processor's details and where it processes your content, and send it to you on request: write to info@zincirx.com.

We bind each sub-processor in writing to data protection obligations that are in substance the same as ours under these Data Processing Terms. We remain fully liable to you for how each sub-processor meets them.

Before we add or replace a sub-processor, we tell the owners and administrators of your business by email, in time for you to object before the change takes effect.

You can object on reasonable grounds relating to data protection by writing to info@zincirx.com. We then try to meet your objection, for example by not using the new sub-processor for your content.

If we cannot meet it, you can end your contract without any charge for leaving, as the section of the Terms of Service on switching provider, leaving and erasure describes. Passports you have already issued stay online for their availability term unless erasure was chosen for their order at checkout or you choose it when you leave (section 14), and you can have personal data removed from them as section 11 describes.

11. Requests from the people concerned

People whose personal data is in your content can ask you, as controller, to exercise their rights, such as access, correction or erasure. If one of them sends such a request to us, we pass it to you without undue delay and do not answer it ourselves, except to say that we have passed it on.

You can see, correct and export most of your content yourself, free of charge. Owners and administrators can download all the passports your business has issued in one file in the open zincirx.dpp format, at every access level, with their full revision history and a manifest of SHA-256 fingerprints. Batch lists and the details of a single batch can be exported as CSV or PDF, the public part of each passport is available as JSON-LD and GS1 EPCIS 2.0 events, each uploaded file can be downloaded in its original form, and each account holder can download their own data as JSON. The Data Formats and Infrastructure page (https://zincirx.com/data-formats) describes these formats. Anything you cannot export yourself, such as all original files in a single download, we send you on request: write to info@zincirx.com.

Changes to a passport's attributes, certifications and product group are append-only by design: a correction is added as a new revision, and earlier revisions are kept. That is a choice about how the record is kept, not an inability to delete. Step details, such as notes and locations, can be edited, and uploaded files removed, by those entitled to manage the batch; those changes are not kept as revisions.

Where personal data in your content has to be corrected, erased or restricted, for example because the person concerned has exercised a right you must honour, correct it yourself where the service lets you: edit the step, remove the file, or add a revision that corrects a passport's attributes or certifications. If the data must also go from earlier revisions, or from anything else you cannot change yourself, write to info@zincirx.com. On your instruction our team removes it, or disables access to it, and the passport itself stays online.

Beyond that, we help you as far as we can, with the information and tools we have, to answer requests within the time data protection law allows: one month under the GDPR, which can be extended by two further months where necessary, and 30 days under the KVKK. We act on your instructions under this section without undue delay, so that you can keep to those time limits.

12. Help with your other obligations

Taking into account how the service works and the information available to us, we help you meet your obligations under Articles 32 to 36 of the GDPR: on the security of the processing, on personal data breaches (section 13), on data protection impact assessments and on consulting a supervisory authority before processing that carries a high risk.

In practice, we give you information about how the service processes personal data and about the measures in section 9, and we answer your reasonable questions about them at info@zincirx.com.

13. Personal data breaches

A personal data breach is a breach of security that leads to personal data in your content being accidentally or unlawfully destroyed, lost or altered, or disclosed or accessed without authorisation.

If we become aware of one, we tell you without undue delay, by email to the owners and administrators of your business, so that you can meet your own obligations to notify supervisory authorities and the people concerned.

We tell you what we know: what happened, the kinds of personal data and roughly how many people and records are affected, the likely consequences, what we have done or propose to do about it, and whom to contact for more information. If we cannot tell you everything at once, we tell you what we have and follow up as we learn more.

We take the steps we reasonably can to contain the breach and limit its effects, and we help you with the notifications you have to make.

14. Return and deletion at the end

When the service ends, you can take your content back, by exporting it or having it moved to another provider or to your own systems, and we then delete it. For passports you have issued, the choice made for each order at checkout decides whether they are erased with the rest or stay online until their availability term ends, and you can change it when you leave. The section of the Terms of Service (https://zincirx.com/terms) on switching provider, leaving and erasure sets out the timetable, following the EU Data Act (Regulation (EU) 2023/2854). In summary:

  • Return: you can export your content at any time while your contract runs, including during the notice period of 30 calendar days from the day we receive your notice and, if you move to another provider or to your own systems, during the transitional period of 30 calendar days that follows it, which you can extend once. Exporting is free of charge.
  • Retrieval period: you then have 30 calendar days to retrieve your content, starting when the transitional period ends if you move, or when your contract ends at the end of the notice period if you chose erasure without a move.
  • Deletion: when the retrieval period ends, we delete your content, including the personal data in it, except as the points below say.
  • Issued passports: passports you have issued stay online until the end of their availability term, even after your contract has ended, unless erasure was chosen for their order at checkout or you ask us, in your notice or by the end of the notice period, to erase them with the rest of your content; those are erased when the retrieval period ends. Their QR codes then no longer lead to a record, so check first whether the rules for your products require their passports to stay available.
  • End of the availability term: when a passport's availability term ends after your contract has ended, we delete that passport's content, except content that a passport still online also uses, such as its template.
  • Personal data in issued passports: at any time, including after your contract has ended, you can instruct us to remove personal data from an issued passport, as section 11 describes.
  • Backups: a copy of deleted content that remains in a backup is kept secure, is not used for anything else and is deleted when that backup is deleted.
  • Legal duties: we keep your content beyond these dates only where Union or Member State law, or Turkish law for customers of ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., requires us to, and only for as long as it does.

However your contract ends, you keep the right to retrieve your content on this timetable.

Records we keep as a controller, such as payment and invoice records and records of your acceptance of our terms, are not your content. The Privacy Policy (https://zincirx.com/privacy) says how long we keep them.

15. Information and audits

We make available to you all the information necessary to show that we meet our obligations under these Data Processing Terms.

You, or an independent auditor you appoint who is bound by confidentiality, may audit our compliance with them, including by inspection. Tell us in writing, reasonably in advance, what you want to examine. We first answer with documents and written answers; if you still want an audit after that, we agree a date for it with you.

An audit must not give access to other customers' data or weaken the security of the service.

16. International transfers

The platform is operated by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., a company established in Türkiye, and ZincirX Inc. is incorporated in the United States. The country where the servers that hold your content are located is stated on the Data Formats and Infrastructure page (https://zincirx.com/data-formats), and other sub-processors may process data in other countries. Neither of our companies is established in the European Union. The European Commission has not adopted an adequacy decision for Türkiye, and its adequacy decision for the United States covers only organisations certified under the EU-US Data Privacy Framework.

If the GDPR applies to your processing of the personal data in your content and you are established in the European Union, these safeguards apply to its transfer to us and onward.

  • The standard contractual clauses for the transfer of personal data to third countries, adopted by the European Commission in Implementing Decision (EU) 2021/914, apply in their Module Two (controller to processor), with you as the data exporter and the company you contract with, which for a customer established in the European Union is ZincirX Inc., as the data importer. They form part of these Data Processing Terms by this reference.
  • For the clauses' annexes, the parties are you and that company, with the details in your account and in the Legal Notice (https://zincirx.com/legal-notice). Sections 2 to 4, 10 and 14 of these Data Processing Terms describe the transfer, which takes place continuously while you use the service, and section 9 sets out the technical and organisational measures.
  • The clauses' option of general written authorisation for sub-processors applies, with the notice and the right to object in section 10.
  • The clauses are governed by the law of the EU Member State in which you are established, disputes arising from them are for the courts of that Member State, and the competent supervisory authority is the one responsible for you as data exporter.
  • Where you contract with ZincirX Inc., the written agreement under which ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. processes your content binds it to the same data protection obligations as the clauses place on ZincirX Inc., including the rights they give the people concerned.
  • We transfer your content to any other sub-processor outside the European Economic Area only where the European Commission has decided that the recipient's country ensures an adequate level of protection, or with a safeguard the GDPR recognises: the same standard contractual clauses, in the module that fits, or, for a recipient in the United States certified under the EU-US Data Privacy Framework, the European Commission's adequacy decision for that framework (Implementing Decision (EU) 2023/1795). If that decision stops applying, we rely on the standard contractual clauses instead.
  • We give you the information you reasonably need to assess, as Clause 14 of the clauses requires, the laws and practices of the countries your content goes to.

The clauses are published in the Official Journal of the European Union. Ask us at info@zincirx.com for a copy with the annexes completed.

Section 17 covers transfers out of Türkiye for customers of ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş.

17. Customers in Türkiye

For customers of ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., Law No. 6698 on the Protection of Personal Data (the KVKK) applies to the personal data in your content. Under that law you are the data controller (veri sorumlusu) and ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş. is your data processor (veri işleyen). These Data Processing Terms are the agreement between us for that processing, and the points below apply in addition.

Under Article 12(2) of the KVKK, you and we are jointly responsible for taking the technical and organisational measures that keep the personal data secure. We take the measures in section 9.

We do not disclose the personal data we process for you in breach of the KVKK, and we do not use it for any purpose other than processing it for you as these Data Processing Terms set out. This duty continues after your contract ends.

Apart from the phone's address lookup described in section 10, the personal data goes abroad only to the sub-processors in section 10 that process it outside Türkiye, and only for what that section says each of them does: email delivery and, where the servers are outside Türkiye, hosting. We make those transfers only on a basis that Article 9 of the KVKK allows, such as a standard contract announced by the Personal Data Protection Board and notified to the Personal Data Protection Authority within five business days of its signature. We do not rely on consent for them.

When someone applies to you under Article 11 of the KVKK about personal data in your content, we help you conclude the application within the 30 days that Article 13 allows. If they apply to us instead, we pass the application to you without undue delay.

If personal data we process for you is obtained by others unlawfully, we tell you without undue delay, as section 13 describes, so that you can notify the people concerned and the Personal Data Protection Board.

At the end, the personal data is deleted, destroyed or anonymised as section 14 describes.

18. Liability, changes and precedence

The limits of liability in the Terms of Service apply to these Data Processing Terms, except where the law does not allow liability to be limited, including liability for intent or gross negligence. Nothing in the Terms of Service limits the rights that data protection law or the standard contractual clauses give the people whose personal data is in your content.

We tell you about every change to these Data Processing Terms by email and in the service, not only by publishing a new version here. A new version applies to you once it has been accepted on behalf of your business, which you are asked to do before you continue using the web app, and the acceptance is recorded. Until then, the version last accepted for your business applies.

If you do not accept a new version, the version last accepted for your business continues to apply, and you can still obtain an export of your content and end your contract as section 14 describes.

If these Data Processing Terms and the rest of the Terms of Service differ on how we process personal data on your behalf, these Data Processing Terms prevail. Where the standard contractual clauses apply, they prevail over both.

These Data Processing Terms are governed by the same law, and disputes about them go to the same courts, as the Terms of Service provide, except that section 16 says how the standard contractual clauses are governed.

19. Contact

For anything about these Data Processing Terms, including instructions, objections to a sub-processor, audit requests and requests to remove personal data from a passport, write to info@zincirx.com or call +90 536 587 41 81. Both are also listed on our contact page (https://zincirx.com/contact).

Our company details, including our representatives and their contact details, are listed in the Legal Notice (https://zincirx.com/legal-notice), and info@zincirx.com is always open to you.