Legal document
Data Processing Agreement
The company using GoTeam is the data controller for candidate data and MotiveX Intelligence processes that data on the company's instructions. This text sets out the obligations of both parties.
This text is a translation provided for information; the binding version is the one in Turkish.
1. Division of roles
This agreement is entered into between Motivex Intelligence Bilişim Yazılım Robotik Sanayi ve Ticaret Anonim Şirketi ("MotiveX Intelligence") and the company that opens a GoTeam account ("the Customer") and is an integral part of the Terms of Service. Article 12/2 of Law No. 6698 requires the relationship between a data controller and a data processor to rest on a written agreement. This text meets that requirement.
For candidate data the data controller is the Customer. The Customer opens the posting, the Customer decides which information the application form asks for, the Customer defines the assessment criteria and the Customer makes the hiring decision. MotiveX Intelligence is the party that processes this data on behalf of, and on the instructions of, the Customer.
For the three items below, however, MotiveX Intelligence determines the purpose and the means, so for those items the data controller is MotiveX Intelligence:
- Account data of the Customer's representative: full name, work e-mail, phone, role on the account, login and session records. Processed for opening the account, granting permissions and account security.
- Billing data: invoice title, tax office and tax number, address, the plan purchased, the payment result and the invoice records issued.
- Site usage measurement: browsing, device and browser data on goteamx.app.
The privacy notice for these three items
For the processing in which MotiveX Intelligence is the data controller, which data is processed on which legal ground is set out in the KVKK Privacy Notice. The Customer's obligation to inform candidates about candidate data belongs to the Customer.
2. Subject matter, duration, nature and purpose of the processing
The six headings below draw the boundaries of the processing. Processing outside these headings is not carried out unless the Customer gives a written instruction.
- Subject matter: processing, through the GoTeam software, the candidate data the Customer collects in its recruitment processes.
- Nature: collecting, recording, storing, classifying, analysing with AI, showing to the Customer's representatives and deleting.
- Purpose: collecting applications, scoring candidates against position criteria, corresponding with candidates, collecting the documents requested during the recruitment process and placing the decision taken on record.
- Duration: for as long as the Customer account stays open. What happens after the account is closed is set out in the termination section.
- Data categories: identity (full name, date of birth), contact (e-mail, phone, address), CV content (education, work experience, skills, references), application records (assessment score, stage, notes of the representative) and the documents requested by the Customer.
- Groups of data subjects: candidates who apply to the Customer's postings, people added to the Customer's candidate pool, and employees hired by the Customer for whom the document process has been started.
Special categories of personal data
The Customer may define a field in the application form or in a document set that asks for special categories of personal data (a health report and a criminal record are the typical examples). Where such a field is defined, establishing the legal ground and, where required, obtaining explicit consent are the responsibility of the Customer. MotiveX Intelligence does not open these fields on its own initiative.
3. Processing only on instruction
MotiveX Intelligence processes candidate data only on the instructions of the Customer. Instructions come from two sources: this agreement and the settings the Customer makes in the panel. Posting fields, assessment criteria, document sets, e-mail templates and candidate pool preferences count as instructions; no separate written notice is required for any of them.
Candidate data is not used for any purpose outside the Customer's recruitment process. It is not shown to another customer, not sold to third parties and not used for marketing.
AI models are not trained with the Customer's candidate data. CV analysis goes to our AI provider established outside Türkiye as individual requests, the result returned is used in scoring, and the content of the request is not opened to model training.
The assessment is AI assisted. The score is produced against a fixed, evidence based rubric, and the final decision always belongs to a person. If you believe that an exclusively automated analysis has produced a result to your detriment, you may object under Article 11 of Law No. 6698 (KVKK, the Turkish Data Protection Law).
Each customer's data is bound to its own account. A query is limited by the account of the user making the request; the records of another company cannot enter the result.
If we conclude that an instruction is contrary to Law No. 6698, we do not carry out the instruction and notify the Customer of the reason in writing.
4. Confidentiality and access permissions
MotiveX Intelligence employees who can access candidate data are under the confidentiality obligation in their employment contracts. That obligation continues after the role and the contract come to an end.
Access is granted on the least privilege principle required by the work. What each user can see and do in the panel depends on their role; the Customer defines those permissions through its own administrator and can revoke them at any time.
- MotiveX Intelligence staff look at Customer data in two situations only: to resolve a support request opened by the Customer, and to investigate a reported fault.
- These accesses are written to the audit trail together with who looked at which record and when.
- Outside support and fault investigation, production data is not copied and not moved to a development environment.
5. Security measures
The technical and organisational measures taken under Article 12/1 of Law No. 6698 are below. The list describes the measures applied, not the ones aimed at.
- All traffic is carried encrypted with TLS. Files are held in storage protected by an access key and are served only over a signed, time limited link.
- Authorisation is role based. On every request the account the session belongs to is verified.
- Passwords are stored hashed in a non-reversible form. Sessions expire after 24 hours.
- Critical operations such as creating and deleting records and changing permissions are written to the audit trail.
- On public endpoints a limit of 30 requests per minute and a third party bot protection check are applied.
- Uploaded files go through type and size checks; in the application flow only PDF is accepted.
- Unverified CV records are deleted at the end of 7 days, so that incomplete applications do not accumulate in the system.
6. Sub-processors
By this agreement the Customer consents to the use of the sub-processors below. Each sub-processor is used only for the work stated next to it; candidate data is not transferred for any purpose outside that work.
MotiveX Intelligence is liable to the Customer for an act of a sub-processor that breaches this agreement. The source of that liability is the undertaking MotiveX Intelligence gives here; it does not rest on an undertaking the sub-processor gives to its own customer.
- Cloud file storage provider established outside Türkiye: Storing the CV and document files that are uploaded. Data transferred: CV and document files. The processing takes place outside Türkiye.
- AI analysis provider established outside Türkiye: Analysing and scoring CV content. Data transferred: CV text and position criteria. The processing takes place outside Türkiye.
- Site usage measurement provider established outside Türkiye: Measuring how the site is used. Data transferred: Device, browser and browsing data. The processing takes place outside Türkiye.
- Bot protection provider established outside Türkiye: Verifying that forms are filled in by a person. Data transferred: IP address and browser verification record. The processing takes place outside Türkiye.
- PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş.: Collecting the payment. Data transferred: Full name, e-mail, transaction amount and payment result. The processing takes place within Türkiye.
- ePlatform Bulut Bilişim A.Ş. (Turkcell e-Şirket): Issuing the official e-Arşiv invoice. Data transferred: Invoice title, tax details, address, e-mail and amount. The processing takes place within Türkiye.
The scope of the list
This list is the complete set of providers that touch candidate and customer data. Candidate data is not transferred to any third party that is not on the list. The processing operations in which the transfer goes abroad are shown separately on the list; the legal ground is set out in the transfer abroad section.
Sub-processors are identified on the page by the work they do and the place of processing, not by their trade name. The Customer may request the trade names of the sub-processors at any time, and when the request is sent to [email protected] the list is provided in writing together with the trade names. You need that information when you prepare your own privacy notice or when you object to a sub-processor; the absence of the trade name on the page does not limit that right.
For sub-processors that process data abroad there is no standard contract signed and notified to the Personal Data Protection Board. That is why no reference to a standard contract was made as a legal ground: writing a safeguard that does not exist would be worse than not writing about the transfer at all. The ground written is the one that actually operates.
7. Notice of a change of sub-processor
If a new sub-processor is to be added to the list or an existing one is to change, the change is notified in advance. The notice is sent to the e-mail address of the representative on the Customer account at least 30 days before the change takes effect, and the list on this page is updated.
If the Customer does not accept the change, it sends its objection in writing to [email protected] within the same 30 days. If the objection cannot be resolved, the Customer may terminate its subscription before the effective date of the change; on termination the Cancellation and Refund Policy applies.
This page is the only place where the sub-processor list is published. The other legal texts do not repeat the list, they link here, so that two different lists never appear in two places.
8. Transfer abroad
CV files are hosted by our cloud file storage provider established outside Türkiye and are sent to our AI provider established outside Türkiye for analysis. These two providers are the places where the data is processed outside Türkiye. The transfer falls within Article 9 of Law No. 6698 (KVKK, the Turkish Data Protection Law) and is necessary for the service to be provided; for the analysis service your explicit consent is obtained in addition. You can learn the identity of the providers through the channel described on the Data Subject Request page. If you do not give consent, no analysis can be carried out; on its own this leads to no other consequence.
Because the data controller for candidate data is the Customer, showing this transfer in its own privacy notice and obtaining the necessary explicit consent belong to the Customer. MotiveX Intelligence provides ready made fields that allow a link to the privacy notice in the application form and that keep the consent record together with the application.
9. Data breach notification
When a security breach affecting candidate data comes to our knowledge, the Customer is notified without delay. The notice reaches the Customer within 24 hours in any event.
That period is deliberately short: as the data controller, the Customer must notify the Personal Data Protection Board of the breach within 72 hours, and a notice that arrives late burns the Customer's time.
The notice carries the following information:
- When the breach occurred and when it was noticed.
- The number of data subjects and records affected, and the categories of data affected.
- The likely consequences of the breach.
- The measures taken and to be taken.
- The contact person and contact details on the MotiveX Intelligence side.
Who makes the notification
The notification to the Board and to the data subjects is made by the Customer; MotiveX Intelligence provides the information, records and investigation needed to prepare it. If the breach affects the items for which MotiveX Intelligence is the data controller under the division of roles section, MotiveX Intelligence makes the notification directly.
10. Right of audit
The Customer may audit compliance with the obligations in this agreement once a year. The audit request is sent in writing to [email protected] at least 15 days in advance.
An audit is first answered with a written list of questions. If the answers given are not sufficient, an on-site audit may be carried out during working hours.
- The audit is limited to the Customer's own data and to the obligations in this agreement.
- The data of other customers, the security configuration of the infrastructure and personnel records are outside the scope of an audit.
- The cost of the audit belongs to the Customer. If the audit finds a shortcoming that breaches this agreement, the cost of remedying it belongs to MotiveX Intelligence.
- These limits do not apply to audits carried out by the Board or by a competent public authority.
11. Support for data subject requests
If a candidate applies directly to MotiveX Intelligence about their data, the request is not answered and not decided. The candidate is told which company is the data controller, the request is directed to the Customer and the Customer makes the decision.
On the Customer's request, MotiveX Intelligence provides the record, export, correction and deletion needed to answer the request, within a time that does not exceed the Customer's 30 day response period.
Viewing, exporting, correcting and deleting a candidate's data can be done directly in the panel by the Customer's representatives. No support request needs to be opened for those operations.
You may send your requests under Article 11 of Law No. 6698 (KVKK, the Turkish Data Protection Law) to [email protected]. Your request is concluded within 30 days at the latest. How the request is made and which information it must carry is set out on the Data Subject Request page.
12. Return and destruction on termination
This agreement ends when the Customer subscription ends or the account is closed. Termination also determines what happens to the data.
After the account is closed, candidate data is kept unchanged for 30 days. That period is for the Customer to export the data; if the Customer requests it in writing, the data is delivered in a machine readable format.
At the end of the period, candidate data and uploaded documents are permanently deleted. Copies remaining in backups fall away when the retention period of the backup expires; throughout that period the backup is accessed only in order to restore the system.
If the Customer does not want to wait for the 30 day period, it can ask for deletion earlier. In that case the data is deleted within the business day on which the request is received and the deletion cannot be undone.
Your data is kept for the duration of the relationship between us and throughout the limitation periods set out in the legislation. Payment and invoice records are kept for 10 years under Article 82 of the Turkish Commercial Code (at least 5 years under Article 253 of the Tax Procedure Law); even if you delete your account, these records are held for that period and are then anonymised by severing the links to you.
13. Entry into force and competent court
This agreement enters into force the moment the Customer opens its GoTeam account and is valid for as long as the account stays open. When the text is amended, the representative on the Customer account is notified by e-mail.
Disputes arising from this agreement shall be subject to the Courts and Enforcement Offices of Manisa.
You can send your questions about this agreement to [email protected] or to 0551 406 11 90. Registered office: Muradiye Mah. Celal Bayar Üniversitesi Kampüsü Küme Evleri Teknokent No: 22 Ofis No: Z-27, 45140 Yunusemre / Manisa.
Other legal documents
- Terms of ServiceWho opens the account, how the service may be used and where liability stops.
- Transaction GuideThe steps an order goes through, how to correct a mistake, where the contract is kept.
- AI Transparency NoticeWhat the AI does, what it does not do and how to object to a decision.
- KVKK Privacy NoticeWhich personal data is processed, for what purpose and on what legal ground.
- Privacy PolicyWhere data is stored, who it is shared with and how it is protected.
- Cookie PolicyWhich cookies are used and which of them need your permission.
- Pre-Contract Information FormThe price, term and conditions to know before ordering a subscription.
- Business Subscription AgreementThe parties, delivery, renewal and termination of a subscription sale.
- Cancellation and Refund PolicyRefund conditions for subscriptions, credit packs and CV Analysis purchases.
- Data Subject RequestHow to file a request in order to exercise your KVKK rights.
- GDPR NoticeA data protection summary for users reaching the service from the European Union.