Data processing agreement
On this page
- 1. Parties and scope
- 2. Subject matter and duration
- 3. Nature and purpose of the processing
- 4. Types of data and people concerned
- 5. Your duties
- 6. Our duties
- 7. Technical and organisational measures
- 8. Sub-processors
- 9. Transfers to other countries
- 10. Deletion and return
- 11. Information and audits
- 12. Liability and other terms
- 13. Governing law and jurisdiction
- 14. Contact
This agreement sets out how Aphroa handles personal data on your behalf. It applies to Fair Lead Hub and to every service where we can see personal data on your website or systems. You are the controller and Aphroa is your processor under Article 28 of the GDPR. It is part of our terms of service and takes effect when you order or start a trial.
1. Parties and scope
- Controller: the business that orders or starts a trial (“you”).
- Processor: Sedeus, a sole proprietorship, trading as Aphroa (“we”). Business owner: Sercan Uslu. Address and contact data are in the legal notice.
- Services covered: Fair Lead Hub, and Website Fix & Speed, New Website, SEO & AI Visibility, Integrations & Automation and For Agencies when you give us access to systems that hold personal data.
- Personal data that you send us in a request or order form is processed by us as controller. This is described in our privacy policy, not here.
2. Subject matter and duration
The subject is the processing described in section 3. The agreement runs for as long as we provide a service covered by it, plus the time we need to return or delete data under section 9.
3. Nature and purpose of the processing
- Fair Lead Hub: we provide the web app with which you scan business cards, read the data on them, keep and export the contacts, and prepare and send welcome and follow-up e-mails from your own address and SMTP. Follow-up e-mails are personalised with automatic tools.
- Work on your website or systems: we use the access you give us to do the agreed work. We may see personal data that is stored there, for example form entries, orders or user accounts. We use it only to do the work.
- We process data only for these purposes and not for our own. We do not sell it.
4. Types of data and people concerned
- Fair Lead Hub: people whose business cards you scan or whose details you enter; your own staff who use the app. Data: name, title, company, e-mail address, phone number, website, and the content of the follow-up e-mails prepared for them, and the account data of your users.
- Work on your systems: your customers, website visitors, users and staff, as far as their data is on the systems we can reach. Data: contact data, account data, order and form data, technical data.
- Please do not give us special categories of data (Art. 9 GDPR) or data about criminal convictions. If your systems hold such data, tell us before you give us access.
5. Your duties
- You are responsible for the lawfulness of the processing, including a legal basis, information to the people concerned and, where needed, their consent for e-mails.
- You give us instructions in writing (e-mail counts). Our terms, the quote and your use of the service are your complete instructions at the start.
- You tell us without delay if an instruction cannot be followed lawfully or if the data is wrong.
6. Our duties
- We process personal data only on your documented instructions, also for transfers to other countries, unless the law requires otherwise. We tell you if we think an instruction breaks data protection law.
- Everyone who has access to the data for us is bound to confidentiality.
- We take the measures in section 7.
- We use sub-processors only as set out in section 8.
- We help you, as far as possible, to answer requests of the people concerned (access, correction, erasure, restriction, portability, objection). If such a person writes to us directly, we pass the request to you.
- We help you with your duties under Articles 32 to 36 GDPR (security, breach notification, impact assessment, consultation), taking into account what we know.
- We tell you without undue delay, and at the latest within 24 hours, after we learn of a personal data breach that affects your data, and we give you the information we have to help you notify.
- We give you the information needed to show that we meet this agreement (section 10).
7. Technical and organisational measures
These measures apply to our website, forms and mail systems.
- Encrypted connections: our website and forms work over HTTPS only. E-mails are sent from our own mail server over encrypted connections.
- Limited access: access to your data is limited to the people who need it for your job. We ask you to give access through a temporary account made for the job. We use access only for the job, and we ask you to close it when the job ends.
- Data minimisation: we do not store IP addresses in our lead and consent records; we store a hash that changes every day. We ask only for the data a job needs.
- Short retention: records are deleted automatically after their retention period: leads after 24 months, queued e-mails after 30 days, the log of our sending plug-in after 14 days, server logs after 7 days.
- Hardening of our website: file editing in the administration area is off, the XML-RPC interface is off, lists of user names are not exposed, and database access uses prepared statements.
- Abuse protection: forms have a hidden field, a signed time token, Cloudflare Turnstile and a limit on attempts.
- Own mail server: we do not send our e-mails through a third-party mailing service.
8. Sub-processors
You give us a general authorisation to use the sub-processors in the table. We tell you by e-mail or on this page before we add or replace one. You may object for a good data protection reason within 30 days. If we cannot agree, either of us may end the affected service.
| Sub-processor | What for | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of our website, forms and mail server | Germany (provider’s registered country) |
| Hetzner Online GmbH | Hosting of Fair Lead Hub | Finland |
| Anthropic | Business-card reading (OCR) and personalisation of follow-up e-mails in Fair Lead Hub | United States |
| Cloudflare, Inc. | Delivery and protection of our website; Turnstile spam check on forms | United States, global network |
9. Transfers to other countries
Cloudflare, Inc. is based in the United States. For this transfer we rely on the EU–US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses.
Anthropic is based in the United States. Data of Fair Lead Hub that goes to Anthropic for card reading and e-mail personalisation is transferred only with appropriate safeguards.
We are based in Türkiye, for which there is no EU adequacy decision, and we open data from there. If transfer rules require safeguards for your data, we agree on suitable ones with you, for example the Standard Contractual Clauses of the European Commission. Write to legal@aphroa.com and we put them in place.
10. Deletion and return
When the service ends, we delete your personal data or return it to you, as you choose, within 30 days. We return Fair Lead Hub contacts as a CSV file. Access you gave us is no longer used. We keep data only if the law requires it, and then only for that purpose.
11. Information and audits
On request, we give you the information needed to show that we keep this agreement. If this is not enough, you may check our processing, after reasonable notice, during working hours and without disturbing our other customers. Each side bears its own costs. Checks cover only the processing of your data.
12. Liability and other terms
The liability terms of our terms of service apply to this agreement. If this agreement and the terms differ on personal data, this agreement applies.
13. Governing law and jurisdiction
This agreement is governed by the laws of the Republic of Türkiye. The courts and enforcement offices of Eskişehir have jurisdiction, unless mandatory law provides otherwise.
14. Contact
Questions about this agreement: legal@aphroa.com.

