Firevibe Customer Data Processing Addendum
Service provider: CREART LLC ("Firevibe")
Address: 364 E MAIN ST STE 1001, MIDDLETOWN, DELAWARE, USA
Support, complaints, cancellation/refund and personal data applications: help@firevibe.ai
Website: https://firevibe.ai
1. Purpose and roles
This addendum governs the activities in which personal data in the customer's project is processed by Firevibe on the customer's behalf. In this context the customer is the data controller and Firevibe the data processor. If the customer itself acts on behalf of another data controller, it provides the sub-processing authorization and the chain of instructions. The operations Firevibe carries out for its own account, payment, security and legal obligation purposes are assessed under its separate data controllership. The actual purpose and decision-making authority take precedence over this classification.
2. Description of the processing
The operations are: hosting the customer's project, file and database storage, authorized access, AI functions started by the customer or enabled in the customer's project, necessary technical support and deletion. The duration is limited to the time required by the customer's instructions and the service relationship; the hosting of project data may continue within this scope even after the subscription has ended. The stopping of publication because of the plan is not automatic data deletion.
| Element | Scope |
|---|---|
| Data subjects | Visitors, end users, customers and employees connected with the customer's project, and the persons included in the customer's lawful instructions |
| Types of data | Depending on the project's function: identity/contact, account, transaction, access logs, prompts and the personal data within the content of uploaded files; only the scope the customer's instructions require |
| Special categories of data | Where the relevant project genuinely includes them, processing limited to the conditions of Article 6 of the KVKK and the necessary additional security measures |
| Purpose | Developing and hosting the web/mobile project the customer has configured, storing its data, and the requested AI functions |
| Authority to instruct | The account holder and the persons they authorize within the project; limited to the scope of their authority |
| Retention and deletion | The duration required by the service and the documented instructions; the deletion instruction, statutory retention and the life cycle of backups are subject to clause 7 of this addendum |
| Processing abroad | Depends on the infrastructure and AI provider used; the conditions of Article 9 of the KVKK are met separately |
The customer's project settings, data schemas, chosen functions and recorded instructions give this scope its concrete form; general descriptions grant no authority for unlimited data collection or processing for other purposes.
3. Instructions and the customer's obligations
Firevibe processes only within documented, lawful customer instructions and the necessary scope of the service. If it concludes that an instruction is unlawful, it notifies the customer and requests an explanation or an appropriate instruction for the relevant operation. In legally mandatory operations, the customer is informed unless this is prohibited.
The customer collects data lawfully; it provides the purpose, the legal basis, the information notice, the data subjects' rights and the necessary permissions. It assesses the additional conditions for special categories of data or children's data. A general file upload statement may not be used in place of the explicit consent of all third parties.
The customer configures appropriately the project authorizations, authentication flows, user roles and file/database visibility under its own control. Responsibility for the security layers Firevibe does not open to the customer is not transferred by this provision.
4. Confidentiality and security
Firevibe does not use data for purposes outside the service or for model training. Data access is limited to persons authorized by reason of their duties; the necessary confidentiality obligations are provided. Technical and administrative measures appropriate to the nature of the processing are applied. The parties are responsible for the risks under their own control and for their statutory obligations.
The parties limit access rights to the duty concerned; they manage account/project separation, the protection of secret values, the security of transfer and storage, the necessary records, backup and deletion in a manner appropriate to the risk of the processing. Additional measures are applied for special categories of data. This clause is not a commitment to a particular certificate or an unverified encryption standard.
API keys are managed from the dedicated secret value area. The customer's own sharing or unnecessary widening of authority, and a security defect in Firevibe's system, are assessed separately.
5. Sub-providers and transfers
Depending on the functions used, Supabase, Amazon Web Services, Modal, Neon and Cloudflare may be used for storage and infrastructure, and Anthropic/OpenAI/xAI and Replicate for processing. Providers receive only the customer data necessary for the function used; no commitment of exclusive storage in a particular region is given. Stripe and marketing tools are not automatically added to this addendum's sub-processor list unless they are genuinely involved in the data processing activity of the customer's project.
Sub-providers receive data limited to the purpose; the necessary security and confidentiality obligations are governed by contract. The customer is given reasonable advance notice of new or changed sub-providers and a channel for a reasoned data protection objection. For an objection that cannot be resolved, the consequences of the alternative provision or the ending of the affected service are determined with mandatory rights protected.
The customer's permission for the use of sub-providers does not replace the transfer safeguard under Article 9 of the KVKK. The standard contract or other appropriate mechanism must match the parties' actual roles; the necessary notifications must be made. Firevibe does not assume the appropriateness of a regular transfer relying solely on the customer's general "may be transferred abroad" approval.
6. Data breaches and data subject requests
When Firevibe learns of a security breach affecting customer data, it informs the customer without delay; it shares the known scope, the affected data, the consequences and the measures taken or planned, and updates the information as it becomes complete. This notification does not remove the customer's and Firevibe's own statutory notification obligations.
Firevibe provides reasonable technical and administrative support appropriate to the scope of the service so that the data controller can fulfil data subject requests and its regulatory obligations. Requests received on the customer's behalf are forwarded to the customer; requests within Firevibe's own role are answered separately.
7. Deletion, access and audit
The customer may delete accounts and projects from the interface. The return of or access to project data and the export of web source code are different matters. The customer may submit data access and return requests through help@firevibe.ai. Once authority is verified, a secure delivery method appropriate to the scope of the request is determined. The code download limit does not remove personal data rights or statutory obligations to provide data.
After a deletion instruction, data is removed from active systems and sub-providers within the determined periods; the backup cycle and statutory retention exceptions are explained. Data to be kept by law is separated, its access is restricted, and it is not used for any other purpose. It is not undertaken that all backups and sub-provider copies are deleted at the same time; records whose retention purpose and legal basis have ceased may not be kept indefinitely.
Firevibe provides appropriate documents for assessing that the obligations have been fulfilled; audits are carried out by a proportionate procedure, protecting the confidentiality of other customers and the security of the system. Audit and assistance terms are not set so as to make statutory rights practically unusable.
8. Liability and precedence
The parties' statutory liabilities are reserved. A clause that "the customer assumes all responsibility" does not remove the data processor's own obligations. Each party's fault, area of control and causation are taken into account. On data processing matters this addendum takes precedence over the general terms of use; the precedence of mandatory provisions and, where applicable, of the standard transfer contract is preserved.
Convenience translation of the Turkish document. The Turkish text prevails. Read the original