Acuerdo De Venta
SaaS Service and License Agreement
This Agreement sets forth the terms of use, subscription, data processing, security, intellectual property, service levels, and operational conditions applicable to customers utilizing DigiPestControl software services for commercial or professional business purposes.
Electronic Acceptance of the Agreement
This Agreement enters into full force and effect upon the Customer checking the box stating “I have read and accept the SaaS Service and License Agreement” on the registration, subscription, or purchase screen and completing the electronic confirmation process.
Acceptance of this Agreement does not constitute the granting of explicit consent for personal data processing activities that legally require explicit consent. Where required by applicable law, separate, freely given consent mechanisms are provided independently for relevant data processing activities.
Detailed information regarding cookies and similar tracking technologies is set forth in the separate DigiPestControl Cookie Policy published alongside this Agreement.
| Document Title | DigiPestControl SaaS Service and License Agreement |
| Version | V. 2.0 |
| Publication Date | 18.08.2026 |
| Effective Date | 18.08.2026 |
ARTICLE 1 – Subject Matter, Nature, and Scope of Service
1.1. The subject matter of this SaaS Service and License Agreement (“Agreement”) is to govern the terms and conditions regarding the access and use by the Customer of the cloud-based software services provided under the DigiPestControl brand via the website, web application, mobile applications, APIs, user panels, and other electronic media, as well as the mutual rights and obligations of the Parties.
1.2. DigiPestControl is a software-as-a-service (SaaS) platform that may include modules for pest control business processes, customer and field operations management, service scheduling, user and technician management, regulatory and operational reporting, document and certificate management, bait station and location mapping, chemical product and pesticide application tracking, IoT trap sensor integrations, automated notification systems, analytics tools, and other modules that may be developed by the PROVIDER over time (“Software” or “Service”).
1.3. This Agreement does not transfer ownership, source code, or intellectual property rights of any software to the Customer. The Agreement constitutes a service agreement based on a term-based subscription access model, accompanied by a limited, non-exclusive license to use.
1.4. The Service may be delivered utilizing third-party technical infrastructures, including cloud hosting providers, data centers, internet service providers (ISPs), domain and DNS management services, email delivery gateways, SMS gateways, push notification services, mapping and geocoding providers, licensed payment processors, artificial intelligence tools, analytics platforms, and similar technological sub-providers.
1.5. The PROVIDER may perform system maintenance, software updates, bug fixes, security patches, performance optimizations, and feature enhancements on the Software in order to ensure the continuity, security, and quality of the Service.
1.6. The PROVIDER may enhance, modify, or reorganize the features of the Software, provided that such changes do not breach mandatory applicable law and do not substantially degrade the core functional or economic essence of the Customer's active subscription. For modifications that may substantially and materially affect Customer operations, reasonable advance notice will be provided where practically and commercially feasible.
ARTICLE 2 – Parties, Customer Status, and Electronic Acceptance
PROVIDER / SaaS Service Provider
Commercial Title: Seçkiner Teknoloji ve Kimya San. ve Tic. A.Ş.
Headquarters Address: Adalet Mah. Anadolu Cad. No:41 Megapol Tower 081 BAYRAKLI / İZMİR / Türkiye
Tax Office: Karşıyaka
Tax ID: [TAX NUMBER]
MERSIS No: [MERSIS NUMBER]
General Contact: info@digipestcontrol.com
Support Email: info@digipestcontrol.com
Data Protection Contact: info@digipestcontrol.com
The legal entity specified above shall hereinafter be referred to as the “PROVIDER”, “DigiPestControl”, or “Service Provider”.
2.1. Customer. Any natural or legal person creating an account on the Software and/or utilizing the Service for commercial, industrial, or professional purposes under a paid or free subscription tier is referred to as the “Customer”.
2.2. Authorized Representation. Any individual creating an account or electronically accepting this Agreement on behalf of a legal entity or third party represents and warrants that they possess full legal power and corporate authority to bind the respective Customer.
2.3. Electronic Acceptance. The Customer enters into this Agreement electronically by reviewing the full text of the Agreement, checking the relevant confirmation box, and completing the registration, subscription, or purchase transaction.
2.4. Transaction Logging. The PROVIDER may log and record the date, time, agreement version, user/account identifier, IP address, and necessary technical metadata of the electronic acceptance in accordance with applicable data protection and evidentiary law rules.
2.5. Separation of Privacy and Consent. Acceptance of this Agreement does not constitute explicit consent for marketing, commercial electronic communications, or other data processing activities requiring explicit consent by law. Such activities are governed separately through independent opt-in mechanisms.
2.6. Duty of Accuracy. The Customer is strictly responsible for ensuring that all account, corporate, billing, and contact details provided are accurate, complete, true, and kept up to date.
ARTICLE 3 – Definitions
3.1. Software / Service: Refers collectively to the cloud-based web application, native mobile applications, user and administrative panels, APIs, software integrations, modules, updates, and associated digital services provided under the DigiPestControl brand.
3.2. Account: Refers to the master organizational account created in the name of the Customer and the tenant environment managed under said account.
3.3. User: Refers to employees, technicians, managers, end-client portal users, or other authorized individuals granted access to the Service under the Customer's Account.
3.4. Customer Data: Refers to all information, files, documents, inspection photographs, field visit records, pest audit logs, bait station maps, chemical application amounts, device telemetry, and operational data entered, uploaded, transmitted, or generated within the Software by the Customer or its Users.
3.5. Personal Data: Refers to any information relating to an identified or identifiable natural person.
3.6. Data Controller / Controller: Refers to the natural or legal person who determines the purposes and means of processing personal data.
3.7. Data Processor / Processor: Refers to the natural or legal person who processes personal data on behalf of and under the documented instructions of the Data Controller.
3.8. Sub-processor: Refers to any third-party infrastructure or service provider engaged by the PROVIDER to perform specific personal data processing activities on behalf of the Customer.
3.9. Personal Data Breach: Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
3.10. Applicable Data Protection Legislation: Refers to the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”); the European Union General Data Protection Regulation (“GDPR”); the UK GDPR; and any other applicable regional data protection laws.
3.11. Subscription: Refers to the Customer's right to access the Service within the scope of a designated plan, user quota, module bundle, capacity tier, and billing period.
ARTICLE 4 – Intellectual Property Rights and License to Use
4.1. Intellectual Property. All worldwide rights, title, and interest in and to the Software, including source code, object code, software architecture, database schemas, algorithms, user interfaces, workflows, report templates, trademarks, trade names, logos, domain names, documentation, and updates, belong exclusively to the PROVIDER or its third-party licensors.
4.2. No Transfer of Ownership. Nothing in this Agreement shall be construed as transferring, assigning, or conveying any title, copyright, intellectual property, or source code ownership in the Software to the Customer.
4.3. Grant of License. Subject to timely payment of applicable subscription fees and full compliance with this Agreement, the Customer is granted a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Service solely for its internal commercial or professional operations during the active subscription period.
4.4. Prohibited Actions. Except where expressly permitted by mandatory statutory law, the Customer shall not:
- copy, reproduce, modify, translate, or distribute the Software or any portion thereof;
- reverse engineer, decompile, disassemble, or attempt to derive the source code of the Software;
- attempt unauthorized access to source code, internal APIs, or security mechanisms;
- rent, lease, sub-license, resell, time-share, or make the Software available as a service bureau to unauthorized third parties;
- systematically scrape, copy, or replicate features of the Software to build a competing product;
- remove, alter, or obscure any proprietary, copyright, trademark, or confidentiality notices.
4.5. Rights in Customer Data. This Agreement does not transfer ownership of Customer Data to the PROVIDER. All rights, title, and proprietary interest in Customer Data remain with the Customer or its licensors.
4.6. Limited Operational License for Hosting. The Customer grants the PROVIDER a worldwide, non-exclusive, royalty-free license to host, copy, process, transmit, back up, and display Customer Data solely to the extent necessary to operate, maintain, support, and secure the Service in accordance with this Agreement.
4.7. Product Feedback. Any feedback, suggestions, feature requests, or enhancement ideas submitted voluntarily by the Customer may be utilized by the PROVIDER to improve its products and services without any obligation of compensation or confidentiality, provided that Customer's confidential information and personal data are not disclosed.
ARTICLE 5 – Terms of Use, Authorization, and Account Security
5.1. User Management. The Customer is solely responsible for authorizing Users created under its Account, assigning appropriate role permissions, maintaining user lists, and supervising User activities within its organization.
5.2. Account Credentials. Safeguarding usernames, passwords, API tokens, two-factor authentication credentials, and session keys is the sole responsibility of the Customer and the respective Users.
5.3. Security Obligations. The Customer shall enforce strong password standards, enable multi-factor authentication where available, restrict access based on need-to-know principles, promptly revoke access for offboarded employees, and maintain endpoint device security.
5.4. Notice of Unauthorized Access. The Customer shall notify the PROVIDER immediately upon becoming aware of, or reasonably suspecting, any unauthorized access, credential compromise, or security incident affecting its Account.
5.5. Prohibited Uses. The Customer and its Users shall not use the Service to:
- conduct unlawful, fraudulent, or tortious activities;
- infringe upon third-party intellectual property, privacy, or trade secret rights;
- distribute malicious software, viruses, phishing payloads, or unsolicited spam;
- bypass software licensing controls, rate limits, or security mechanisms;
- conduct unauthorized vulnerability scanning, penetration testing, or automated load flooding;
- interfere with the integrity, availability, or performance of the Service;
- attempt unauthorized access to data belonging to other customers or tenants.
5.6. Protective Suspension. The PROVIDER reserves the right to temporarily suspend access to the Account or specific features in the event of a security breach, unlawful use, payment default, third-party rights violation, or activities posing a grave threat to system stability or other tenants, strictly proportional to the identified risk.
5.7. Notice of Suspension. Except where emergency security requirements preclude prior notice, the PROVIDER shall notify the Customer of the grounds for suspension and, where remediable, the corrective steps required to restore access.
ARTICLE 6 – Protection of Personal Data and Data Processing Terms
6.1. Applicable Legislation
The Parties undertake to comply with all applicable data protection legislation, including the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”), the European Union General Data Protection Regulation (“GDPR”), the UK GDPR, and relevant secondary regulations.
6.2. Data Protection Roles of the Parties
6.2.1. With respect to personal data relating to employees, technicians, clients, client representatives, and site contacts uploaded by the Customer into the Software where the Customer determines processing purposes and means, the Customer acts as Data Controller and the PROVIDER acts as Data Processor on behalf of the Customer.
6.2.2. With respect to personal data processed for user account creation, credentials, billing, subscription management, payment processing, fraud prevention, information security, customer support, and statutory compliance where the PROVIDER determines purposes and means, the PROVIDER acts as an independent Data Controller.
6.2.3. Processing activities carried out by the PROVIDER as an independent Data Controller are set forth in the separate Privacy Policy published on its website.
6.3. Customer's Obligations as Data Controller
The Customer, within its sphere of responsibility as Data Controller, shall be solely responsible for:
- collecting and processing personal data lawfully, fairly, and transparently for specified, explicit, and legitimate purposes;
- establishing a valid legal processing basis under KVKK, GDPR, or applicable legislation;
- providing required statutory privacy notices to data subjects;
- obtaining and documenting verifiable explicit consent where legally required;
- adhering to data minimization and avoiding excessive data entry into the Software;
- implementing heightened technical and organizational safeguards if processing special categories of personal data;
- determining appropriate data retention and disposal schedules;
- handling and responding to data subject rights requests within statutory deadlines.
6.4. Processor Instructions and Compliance
The PROVIDER processes personal data on behalf of the Customer solely in accordance with documented Customer instructions and to the extent necessary to perform the Service under this Agreement.
Where the PROVIDER is required by applicable law to process data beyond Customer instructions, it shall notify the Customer of that legal requirement prior to processing, unless prohibited by law.
If the PROVIDER reasonably considers that an instruction infringes applicable data protection legislation, it may inform the Customer and suspend execution of that instruction until the legal issue is clarified.
6.5. Subject Matter, Nature, Purpose, and Duration of Processing
| Subject Matter | Provision, hosting, operation, security, support, and technical delivery of the DigiPestControl SaaS platform. |
|---|---|
| Nature of Processing | Collection, recording, organization, structuring, storage, retrieval, consultation, use, transmission, backup, erasure, and anonymization. |
| Purpose of Processing | Delivering software features, role-based authorization, field service & station logging, automated reporting, data exports, diagnostics, backups, and support. |
| Duration | The active term of the Subscription plus the contractual 7-business-day export transition and backup deletion cycles. |
6.6. Categories of Processed Data
Depending on Customer configuration, processed categories may include:
- identity details (name, surname, technician ID, username);
- contact details (email, telephone, work address);
- corporate and organizational details (role, title, access profile);
- customer facility, location, and site contact records;
- service visit schedules, pest inspection logs, and treatment records;
- technician activity and assignment records;
- inspection photographs, digital signatures, and report attachments;
- bait station, trap layout, and IoT telemetry data;
- IP addresses, session tokens, and security event logs;
- other operational data entered by the Customer into the Service.
6.7. Categories of Data Subjects
Data subjects include Customer employees, managers, technicians, end-clients, client site personnel, visitors, and other natural persons whose information is entered into the platform by the Customer.
6.8. Confidentiality
The PROVIDER ensures that all personnel authorized to process Customer personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
6.9. Technical and Organizational Security Measures (TOMs)
Taking into account the state of the art, implementation costs, and the risks presented by processing, the PROVIDER implements appropriate technical and organizational measures as detailed in APPENDIX 3, including:
- role-based access controls and logical tenant isolation;
- secure password hashing and session token protections;
- mandatory TLS/HTTPS encryption in transit;
- security event logging, audit trails, and monitoring;
- vulnerability management and patch deployment processes;
- disaster recovery backups and business continuity measures;
- structured security incident response and breach management protocols.
6.10. Sub-processors
The Customer grants general written authorization to the PROVIDER to engage Sub-processors (such as cloud hosting, data center, email, SMS, and monitoring providers) to support Service delivery.
The PROVIDER imposes data protection obligations on its Sub-processors that are no less restrictive than those set forth in this Agreement.
The current list of Sub-processors is set forth in APPENDIX 2 and maintained online. The PROVIDER shall provide reasonable notice of intended appointments of new Sub-processors where required by law.
6.11. Assistance with Data Subject Rights
Taking into account the nature of processing, the PROVIDER provides reasonable technical assistance to enable the Customer to fulfill its obligations to respond to data subjects' requests to exercise their statutory rights (access, rectification, erasure, portability, objection).
6.12. DPIA and Regulatory Cooperation
The PROVIDER provides reasonable assistance to the Customer with data protection impact assessments (DPIAs) and prior consultations with supervisory authorities, to the extent required by applicable law and based on information available to the PROVIDER.
6.13. Personal Data Breach Notification
The PROVIDER shall notify the Customer without undue delay upon confirming a Personal Data Breach affecting Customer personal data, providing details regarding the nature of the breach, affected categories, and remedial measures taken.
6.14. Audits and Compliance Demonstration
The PROVIDER makes available to the Customer information reasonably necessary to demonstrate compliance with its obligations under this Article 6, subject to reasonable advance notice and without compromising tenant confidentiality or proprietary trade secrets.
6.15. International Data Transfers
Cross-border data transfers shall occur only where adequate safeguards are established through adequacy decisions, Standard Contractual Clauses (EU SCCs, KVKK standard contracts), or other recognized legal transfer mechanisms.
6.16. Return, Export, and Deletion of Data
The Customer is responsible for exporting required copies of its data during the subscription term using platform export tools (.sql, Excel, PDF). Following subscription expiration, a 7 (seven) business days transition export period is provided, after which active Customer Data will be securely deleted or anonymized, subject to statutory retention obligations.
Copies in backup systems will be overwritten during standard backup lifecycle rotations and are not accessible for selective operational retrieval.
6.17. Special Categories of Data
Unless a specific module is explicitly designed therefor, the Customer shall avoid uploading health, biometric, genetic, or criminal conviction data into the Software.
6.18. Data Minimization
The Customer shall ensure that only personal data strictly necessary for its operational purposes is uploaded into the Service.
6.19. Contractual Status of Data Processing Terms
This Article 6 and APPENDIX 1 constitute the baseline Data Processing Agreement (DPA) between the Parties. Where necessary, a dedicated standalone DPA may be executed electronically.
ARTICLE 7 – Service Continuity, Maintenance, Backup, Data Retention, SLA, and Force Majeure
7.1. Nature of SaaS Service and Availability
DigiPestControl is a cloud SaaS platform relying upon internet connectivity, data centers, cloud infrastructure, third-party service providers, and external technological ecosystems. Consequently, scheduled or unscheduled maintenance, updates, access interruptions, network latency, or performance variations may occur from time to time.
The PROVIDER exerts commercially and technically reasonable efforts to keep the Service secure and accessible; however, in the absence of a separate written Service Level Agreement (“SLA”), it does not guarantee uninterrupted or 100% continuous availability.
7.2. Scheduled Maintenance and Updates
The PROVIDER may perform scheduled maintenance, software updates, security hardening, capacity enhancements, and bug fixes on the Software.
To the extent reasonably practicable, scheduled maintenance will be conducted during off-peak hours. Emergency security patches or critical infrastructure interventions may be executed without advance notice.
7.3. Absence of Default SLA
Unless a separate written or electronic SLA has been explicitly agreed between the Parties, the PROVIDER provides no commitment regarding specific uptime percentages, response times, bug resolution timelines, data restoration deadlines, Recovery Time Objectives (“RTO”), or Recovery Point Objectives (“RPO”).
Where an explicit SLA has been agreed, only the specific service levels and remedies set forth in that SLA shall apply.
7.4. Third-Party Infrastructure Disruptions
The PROVIDER shall not be liable for service disruptions caused by external telecom providers, cloud data center outages, global DNS failures, or third-party service degradation beyond its direct control.
7.5. Separation of Operational Backups from Customer Archiving
7.6. Customer's Data Backup and Archiving Responsibility
The Customer is solely responsible for exporting and archiving required operational records using the built-in export features:
- raw database records and datasets in .sql format;
- operational lists, visit logs, and tables in Excel / CSV format;
- service certificates, audit documents, and inspection reports in PDF format.
7.7. Customer-Deleted Data
The PROVIDER is under no obligation to recover or restore data deleted, overwritten, or modified by the Customer or its authorized Users.
7.8. Prevention of Data Loss
The Customer must maintain routine local backups of all records required for statutory audit, pest compliance, or commercial purposes.
7.9. Force Majeure
Neither Party shall be liable for delays or failures in performance resulting from natural disasters, earthquakes, fires, floods, war, terrorism, widespread power/telecom failures, major cyber warfare, pandemics, or government restrictions beyond reasonable control.
ARTICLE 8 – Limitation of Liability and Indemnification
8.1. Operational Tool Disclaimer
DigiPestControl is an operational management software tool. Recommendations, dosage calculations, service frequencies, and system outputs do not substitute for certified professional human expertise.
8.2. Exclusion of Consequential Damages
To the maximum extent permitted by applicable law, the PROVIDER shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, loss of revenue, loss of contracts, business interruption, or loss of goodwill.
8.3. Data Loss Liability
The PROVIDER shall not be liable for data loss resulting from Customer credential compromise, failure to export backups, user-initiated deletion, or third-party infrastructure failures.
8.4. Aggregate Cap on Liability
The total aggregate liability of the PROVIDER arising out of or related to this Agreement shall be strictly limited to the total subscription fees actually paid by the Customer to the PROVIDER for the specific Service in the twelve (12) months immediately preceding the incident giving rise to liability.
8.5. Exclusions from Liability Cap
The limitations in this Article 8 shall not apply to damages caused by gross negligence, intentional misconduct, or liabilities that cannot be lawfully limited under mandatory applicable law.
8.6. Indemnification by Customer
The Customer agrees to indemnify, defend, and hold harmless the PROVIDER against any third-party claims, fines, or losses arising from Customer's unlawful use of the Service, violation of third-party intellectual property or privacy rights, or failure to comply with sectoral pest control regulations.
ARTICLE 9 – Fees, Invoicing, Payment, and Refunds
9.1. Subscription Plans and Pricing
Service fees are determined according to the pricing packages, user quotas, modules, and billing cycles published on the DigiPestControl platform or specified in written order forms.
9.2. Taxes
All stated fees are exclusive of VAT, sales taxes, or other statutory levies, which shall be added to the invoice in accordance with applicable tax regulations.
9.3. Payment
The Customer shall pay subscription fees in full upon the designated billing dates. In the event of non-payment or credit card chargeback, the PROVIDER may suspend Service access following reasonable notice.
9.4. Refund Policy
For B2B commercial subscriptions, fees paid for active or commenced subscription periods are non-refundable, except as expressly provided by mandatory statutory law.
9.5. Price Adjustments
The PROVIDER may adjust subscription pricing for future renewal terms, with price adjustments taking effect upon the commencement of the subsequent renewal period.
ARTICLE 10 – Term, Renewal, Termination, Data Export, and Post-Termination Data Deletion
10.1. Term
This Agreement becomes effective upon electronic acceptance by the Customer and remains in force throughout the active Subscription term.
10.2. Renewal
Subscriptions renew in accordance with the selected monthly or annual terms unless cancelled by the Customer prior to the renewal date.
10.3. Cancellation by Customer
The Customer may cancel subscription renewal via the user dashboard. Cancellation takes effect at the conclusion of the prepaid subscription period.
10.4. Termination for Cause by Provider
The PROVIDER may suspend or terminate the Agreement immediately for material breach, payment default, unlawful activities, or severe security violations.
10.5. Obligation to Retrieve Data Prior to Expiration
Prior to expiration or within the transition period below, the Customer must download all needed Customer Data using the supported `.sql`, Excel, PDF, and other export functions.
The provision of these export tools does not imply that the PROVIDER provides a permanent archiving or indefinite backup retention service on behalf of the Customer.
10.6. Contractual 7-Business-Day Data Export Grace Period
Following non-renewal, customer cancellation, or standard subscription expiration, a contractual grace period of 7 (seven) business days is granted to allow limited access solely for exporting data (.sql, Excel, PDF), subject to technical and security feasibility.
This 7 (seven) business day period is not a statutory minimum data retention period, but a contractual transition period defined by DigiPestControl to enable customer data migration.
During this period, account access may be restricted by the PROVIDER solely to data viewing and export functions for security or operational reasons.
10.7. Return or Deletion Option
With respect to personal data processed as a Processor on behalf of the Customer, the Customer may request return or deletion of its data prior to expiration or within the 7-business-day export window.
The standard built-in export features (.sql, Excel, PDF) constitute the default mechanism for data return.
Custom data transformations, migrations, or third-party format adaptations outside standard export tools may be evaluated as separate billable professional services.
10.8. Deletion of Data After Grace Period
Upon the conclusion of the 7-business-day export period, all Customer Data in active production systems that is not legally required to be retained will be permanently deleted, destroyed, or irreversibly anonymized.
The Customer's failure to export its data within this period creates no obligation for the PROVIDER to retain or provide future access to such data.
Following completion of the deletion process, the PROVIDER has no obligation to restore, retrieve, or reconstruct Customer Data.
10.9. Technical Backups
Residual copies in operational backup systems will be overwritten in accordance with standard disaster recovery lifecycle rotations.
Such backup copies are isolated from active operations, not processed for new purposes, and deleted or overwritten in normal rotation cycles.
The presence of a copy in technical backups does not grant the Customer any right to demand selective retrieval or restoration.
10.10. Statutory Records
Tax, billing, corporate, accounting, and legal dispute records required by mandatory law to be retained by the PROVIDER as Data Controller will be stored for statutory retention periods.
Such statutory records are used solely for the specified legal compliance purpose and deleted or anonymized upon expiration of the statutory obligation.
10.11. Previously Deleted Data
Data deleted by the Customer or Users prior to termination is not covered by the 7-day export period and cannot be restored.
ARTICLE 11 – Regulatory Compliance and Pest Control Industry Responsibilities
11.1. Nature of the Software
DigiPestControl is a digital process management tool assisting pest control businesses with administrative and operational workflows.
The Software does not replace official public health, environmental, biocidal, or audit regulatory bodies.
11.2. Local Regulatory Compliance
The Customer is exclusively responsible for ensuring compliance with all local laws, biocidal product regulations, environmental standards, occupational safety rules, and operator licensing requirements in its jurisdiction.
11.3. Chemical Usage and Applications
Selection of biocidal active ingredients, target pest species, application dosages, Safety Data Sheets (SDS), and label compliance remain the sole responsibility of the certified pest control technician and the Customer.
11.4. Audit Reports and Documentation
The Customer must review all generated inspection reports to ensure they meet the specific requirements of national legislation or customer audit standards (e.g., BRCGS, IFS, ISO 22000, AIB, EN 16636).
11.5. International Usage
DigiPestControl may be accessed globally. Technical accessibility in any country does not imply that local chemical registrations or operator permits have been pre-cleared by the PROVIDER.
ARTICLE 12 – Support, Training, and Additional Services
12.1. Standard Support
The PROVIDER provides designated support channels for technical inquiries and bug reporting regarding the Software.
Unless agreed separately in writing, standard support does not include 24/7 continuous emergency coverage or guaranteed response/resolution time commitments.
12.2. Training and User Guides
The PROVIDER may provide educational content, tutorials, knowledge base articles, webinars, or documentation to assist users in onboarding.
12.3. Additional Professional Services
Custom software development, bespoke reporting, data migration, bulk data cleanup, custom API integrations, onsite training, or data conversion are outside standard subscription coverage and subject to separate service fees.
12.4. Data Recovery Disclaimer
Recovery requests for data deleted by the Customer or purged following subscription expiration are outside standard support. If technically feasible, the PROVIDER may conduct a fee-based technical evaluation, but gives no guarantee of successful recovery.
ARTICLE 13 – Agreement Modifications, Electronic Records, and Version Management
13.1. Agreement Modifications
The PROVIDER may update this Agreement due to regulatory changes, security requirements, technical architecture updates, new features, or commercial terms.
13.2. Material Changes
For changes substantially affecting Customer rights and obligations, notice will be provided via email, user panel, or other electronic means to the extent feasible.
Where required by applicable law, re-acceptance of the updated Agreement may be requested electronically.
13.3. Version Records
The PROVIDER records different agreement versions with version numbers and effective dates.
The specific version accepted by the Customer, acceptance timestamp, and technical transaction logs may be evaluated as evidence under applicable procedural law.
13.4. Evidentiary Value of Electronic Records
Electronic acceptance logs, account transactions, audit trails, and system logs constitute admissible evidence in dispute resolution to the extent permitted by procedural law.
This provision does not deprive either Party of statutory rights to introduce evidence or challenge electronic record accuracy.
ARTICLE 14 – Governing Law and Dispute Resolution
14.1. Governing Law
Unless otherwise agreed in writing, this Agreement is governed by and construed in accordance with the laws of the Republic of Türkiye.
Mandatory consumer protection provisions and non-waivable international data protection rules remain reserved.
14.2. Good-Faith Negotiation
The Parties shall first endeavor to resolve any dispute arising from this Agreement through good-faith mutual communication and executive negotiation.
14.3. Competent Courts and Enforcement Offices
Subject to mandatory jurisdictional rules, the Courts and Enforcement Offices of İzmir, Türkiye shall have exclusive jurisdiction over commercial disputes arising out of or in connection with this Agreement.
14.4. International Customers
In international commercial relationships, the Parties may mutually agree in writing to resolve designated disputes through arbitration or alternative dispute resolution mechanisms.
14.5. Mandatory Statutory Rights
Nothing in this Article 14 shall be construed to eliminate statutory non-waivable data protection rights, consumer rights, or judicial remedies under applicable law.
ARTICLE 15 – Entry into Force and Miscellaneous Provisions
15.1. Entry into Force
This Agreement enters into force on the date it is electronically accepted by the Customer.
15.2. Entire Agreement
This Agreement, together with the Privacy Policy, Cookie Policy, Data Processing Agreement (“DPA”), Sub-processors list, SLA, order terms, and other agreed appendices, constitutes the complete understanding between the Parties.
15.3. Order of Precedence
In the event of conflict, terms of a separately executed DPA or custom SLA shall prevail strictly regarding their specific subject matter.
15.4. Severability
If any provision is held invalid, illegal, or unenforceable, the validity and enforceability of the remaining provisions shall not be affected.
15.5. No Waiver
Failure or delay by either Party in exercising any right shall not be construed as a waiver of that right.
15.6. Assignment
The Customer may not assign its rights or obligations without prior written consent. The PROVIDER may assign this Agreement in connection with a corporate reorganization, merger, or asset transfer.
15.7. Notices
Routine contractual notices may be delivered via the Customer's registered email or user dashboard.
15.8. Prevailing Language
This Agreement may be published in Turkish and English. In the event of interpretive discrepancy and unless mandatory local law dictates otherwise, the Turkish version shall prevail.
15.9. Electronic Validity
Electronic check-box acceptance during signup or purchase is legally sufficient to create a binding contract between the Parties.
15.10. Final Declaration
By electronically accepting this Agreement, the Customer confirms having had full opportunity to review, understand, and agree to all terms herein.
COMPLEMENTARY AND BINDING APPENDICES
The following Appendices constitute an integral part of the DigiPestControl SaaS Service and License Agreement and shall be applied together with the main Agreement.
In the event of conflict between an Appendix and the main Agreement, the specific terms of the Appendix shall prevail with respect to its particular subject matter.
All mandatory provisions of applicable data protection legislation remain strictly reserved.
APPENDIX 1 – Data Processing Details and Data Processing Agreement (DPA)
EK-1.1. Roles of the Parties
With respect to personal data where the Customer determines processing purposes and means, the Customer acts as Data Controller / Controller and the PROVIDER acts as Data Processor / Processor.
Party roles are determined strictly based on factual decision-making regarding processing purposes and means.
EK-1.2. Subject Matter of Processing
Technical processing and hosting of personal data entered, uploaded, transmitted, or generated in the Software in connection with the delivery of the DigiPestControl SaaS platform.
EK-1.3. Duration of Processing
Processing continues during the active term of the Customer's subscription.
Post-termination data export, deletion, backup overwriting, and statutory retention processes are governed by Articles 6, 7, and 10 of the main Agreement.
EK-1.4. Nature and Purposes of Processing
The PROVIDER executes the following technical processing operations on behalf of the Customer:
- collection and recording of personal data;
- structuring and organizing datasets;
- hosting data on SaaS cloud infrastructure;
- displaying data to authorized Users;
- executing field, service, and operational workflows;
- generating compliance and audit reports;
- performing PDF, Excel, .sql, and supported format exports;
- facilitating secure third-party system data exchange;
- creating security and operational audit trails;
- performing technical troubleshooting and diagnostic analysis;
- maintaining operational backups and disaster recovery processes;
- executing data deletion in accordance with Customer instructions;
- performing other data operations necessary for technical service delivery.
EK-1.5. Categories of Data Subjects
Data subjects may include:
- Customer employees and managers;
- field technicians and operators;
- authorized platform Users;
- Customer end-clients;
- employees and representatives of end-clients;
- facility managers and site contact persons;
- supplier and partner representatives;
- other natural persons whose details are entered into the platform by the Customer.
EK-1.6. Categories of Processed Personal Data
Depending on active modules, processed categories include:
- name, surname, and identity identifiers;
- telephone, email, and business contact information;
- company, title, role, and department details;
- user authorization and credential records;
- service visit schedules and field inspection logs;
- facility locations and site blueprints;
- bait station, trap, and sensor coordinates;
- technician service action records;
- digital signatures;
- inspection photos and document attachments;
- audit report contents;
- IP addresses and session logs;
- device telemetry and IoT sensor data;
- free-text notes entered by Users.
EK-1.7. Special Categories of Personal Data
DigiPestControl is not intended for the systematic processing of sensitive/special category personal data.
Where sensitive data is uploaded, the Customer is responsible for establishing a valid legal processing basis and implementing heightened safeguards.
EK-1.8. Documented Instructions
The PROVIDER processes personal data solely on documented Customer instructions.
Documented instructions include:
- this Agreement and its Appendices;
- configuration settings applied within the Software;
- actions performed by Users within standard platform use;
- support tickets submitted by authorized persons;
- additional written or electronic DPA documents agreed between the Parties.
The PROVIDER may notify the Customer and suspend execution if an instruction is reasonably considered to violate applicable data protection law.
EK-1.9. Confidentiality
The PROVIDER ensures that all staff authorized to process personal data are bound by formal confidentiality obligations and access is granted strictly on a need-to-know basis.
EK-1.10. Security Measures
The PROVIDER implements risk-appropriate technical and organizational measures as detailed in APPENDIX 3.
EK-1.11. Engagement of Sub-processors
The Customer grants general written authorization to engage Sub-processors for technical service delivery.
Sub-processors are bound by equivalent data protection obligations.
The current Sub-processor list is set forth in APPENDIX 2. Notice will be provided for new Sub-processors where required by law, with reasonable objection procedures.
EK-1.12. Assistance with Data Subject Rights
The Customer is responsible for responding to data subject rights requests. The PROVIDER provides reasonable technical assistance to facilitate compliance.
EK-1.13. Personal Data Breach Management
The PROVIDER notifies the Customer without undue delay upon confirming a Personal Data Breach affecting Customer personal data, providing details regarding the incident, affected data, and remedial actions.
EK-1.14. DPIA and Regulatory Support
The PROVIDER provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities.
EK-1.15. Audits and Compliance Verification
The PROVIDER provides reasonable information to demonstrate data processing compliance, prioritizing existing policy and security audit documentation.
EK-1.16. Return or Deletion at End of Processing
The Customer must export required data copies (.sql, Excel, PDF) prior to expiration or within the 7-business-day grace period. Thereafter, active data is deleted or anonymized.
EK-1.17. International Data Transfers
Cross-border transfers utilize adequacy decisions, Standard Contractual Clauses (EU SCCs, KVKK standard contracts), or statutory mechanisms.
EK-1.18. Duration of DPA
This DPA remains in effect until all Customer personal data processed on behalf of the Customer is permanently deleted from active systems.
APPENDIX 2 – Sub-processors
DigiPestControl may engage third-party service providers to deliver the technical infrastructure for the SaaS platform.
The following table identifies the categories of Sub-processors processing personal data on behalf of DigiPestControl:
| Service Category | Service Provider | Processing Purpose | Data Processing / Hosting Region |
|---|---|---|---|
| Server / Hosting / Data Center | [HOSTING PROVIDER DETAILS] | Application and database infrastructure hosting | [COUNTRY / REGION] |
| Email Service | [EMAIL PROVIDER IF APPLICABLE] | System and transactional user notifications | [COUNTRY / REGION] |
| SMS / Notification Service | [SMS PROVIDER IF APPLICABLE] | SMS alerts and 2FA code delivery | [COUNTRY / REGION] |
| Push Notifications | [Apple APNs / Google FCM] | Mobile app technician dispatch and alerts | [COUNTRY / REGION] |
| Payment Infrastructure | [PAYMENT PROVIDER / Iyzico] | Subscription billing and payment execution | [COUNTRY / REGION] |
| Error & Performance Monitoring | [MONITORING PROVIDER IF APPLICABLE] | Technical error and performance analysis | [COUNTRY / REGION] |
| Mapping / Location Services | [MAP PROVIDER IF APPLICABLE] | Location mapping and station geofencing | [COUNTRY / REGION] |
| Artificial Intelligence Services | [AI PROVIDER IF CUSTOMER DATA TRANSFERRED] | [PROCESSING PURPOSE IF UTILIZED] | [COUNTRY / REGION] |
| Other | [IF APPLICABLE] | [PROCESSING PURPOSE] | [COUNTRY / REGION] |
EK-2.1. List Updates
The PROVIDER may update the Sub-processor list as technical architecture evolves.
The current list will be published on the website or user dashboard.
Where required by applicable data protection law, reasonable advance notice will be provided prior to engaging new material Sub-processors.
EK-2.2. Objections to Sub-processor Changes
The Customer may object to a new Sub-processor solely on documented, reasonable data protection grounds. If a mutually acceptable alternative cannot be found, the Parties may evaluate options regarding the specific affected feature.
APPENDIX 3 – Technical and Organizational Measures (TOMs)
The PROVIDER establishes information security measures based on risk analysis and develops them in line with technical advances, data sensitivity, and emerging security threats.
The measures outlined below describe the baseline security approach. Specific controls may be substituted by other measures providing equivalent or higher security.
EK-3.1. Access Control
- User and administrator access managed through authorization profiles.
- Access rights restricted according to job functions and least-privilege principles.
- Immediate revocation of credentials upon employee offboarding.
- Administrative accounts logically segregated from regular user accounts.
- Minimization of unnecessary data access.
EK-3.2. Authentication and Password Security
- User accounts protected by robust authentication controls.
- Passwords hashed using industry-standard algorithms (bcrypt / Argon2).
- Rate-limiting controls to prevent brute-force attacks.
- Multi-factor authentication (MFA) supported where technically enabled.
EK-3.3. Communication Security
- Mandatory TLS/HTTPS encryption for all internet communications.
- Authentication and authorization required for inter-system data flows.
- APIs protected by secure bearer tokens and request validation.
EK-3.4. Application and Infrastructure Security
- Routine security updates and vulnerability patching.
- Firewalls and network access controls to mitigate unauthorized traffic.
- Server and database access restricted to authorized administrators.
- Mitigation of known web vulnerabilities (SQL injection, XSS, CSRF).
- Continuous vulnerability tracking and remediation processes.
EK-3.5. Logging and Monitoring
- Audit logs maintained for security-critical system operations.
- Monitoring mechanisms for anomaly detection.
- Log analysis for security incident investigation.
- Log access strictly restricted to authorized security personnel.
EK-3.6. Operational Backup and Business Continuity
- Automated system snapshots and replication for disaster recovery.
- Restricted administrative access to backup environments.
- Backups rotated and overwritten in standard lifecycle schedules.
- No warranty of selective historical record retrieval for individual customers.
EK-3.7. Data Minimization
System architecture designed to limit personal data collection strictly to what is necessary for Service delivery.
EK-3.8. Data Deletion
Purging, destruction, or anonymization executed when statutory or contractual processing grounds expire.
EK-3.9. Personnel and Organizational Security
- Binding employee non-disclosure agreements.
- Clear organizational policies on roles and responsibilities.
- Internal information security training and awareness.
- Personnel access granted strictly on a business-need basis.
EK-3.10. Security Incident Management
- Structured evaluation and containment procedures for security incidents.
- Corrective action plans to limit incident impact.
- Temporary isolation of affected systems where necessary.
- Breach notification procedures executed pursuant to applicable law.
EK-3.11. Continuous Updates
Security controls are updated continuously in response to technical developments, emerging threats, and regulatory changes without degrading overall security levels.
APPENDIX 4 – Data Retention, Export, and Disposal Policy for Customer Data
EK-4.1. Active Subscription Period
Customer Data is processed during the active subscription period.
The Customer should perform periodic self-service data exports during active subscription terms.
EK-4.2. Supported Export Formats
The Customer may generate data copies using:
- .sql raw dataset and database exports;
- Excel or CSV tabular datasets;
- PDF service certificates and audit reports;
- other built-in export utilities;
- independent local backups created by the Customer.
EK-4.3. Customer's Backup Responsibility
The Customer is solely responsible for maintaining local copies of records required for commercial, contractual, or regulatory compliance.
Failure to export data creates no duty for the PROVIDER to preserve data indefinitely.
EK-4.4. Customer-Deleted Data
The Customer is responsible for consequences of deletions initiated by its Users.
The PROVIDER has no duty to reconstruct data purged from active production databases.
The existence of temporary backup snapshots grants no restoration rights.
EK-4.5. Subscription Expiration
Upon subscription non-renewal or cancellation, active service access ceases.
EK-4.6. 7-Business-Day Data Export Transition Period
A contractual grace period of 7 (seven) business days following expiration is provided to allow limited access for exporting data (.sql, Excel, PDF).
This 7-business-day window is a contractual transition period provided by DigiPestControl, not a statutory retention period.
All needed data must be retrieved prior to the end of this transition window.
EK-4.7. Deletion After 7 Business Days
Following the 7-business-day window, active Customer Data not legally required to be retained will be permanently deleted, destroyed, or anonymized.
Failure to export within this period creates no ongoing retention duty for the PROVIDER.
Completed deletion is final and data cannot be reconstructed.
EK-4.8. Copies in Technical Backups
Residual copies in operational backup systems exist temporarily due to disaster recovery architecture.
Such copies are inaccessible for routine operations and overwritten during normal rotation cycles.
Presence in backups grants no selective retrieval rights to the Customer.
EK-4.9. Statutory Provider Records
Statutory accounting, invoice, and legal dispute records processed by the PROVIDER as Data Controller will be retained for mandatory statutory periods.
Retention of statutory records does not mean customer SaaS operational records will be retained.
EK-4.10. Deletion Methods
Applicable methods include:
- application-level database record deletion;
- purging database tables and files;
- revoking access tokens and permissions;
- overwriting in backup rotation cycles;
- secure digital destruction;
- irreversible statistical anonymization.
EK-4.11. No Data Recovery Warranty
APPENDIX 5 – Electronic Acceptance, Agreement Versioning, and Logging Mechanism
EK-5.1. Electronic Acceptance Mechanism
During signup or subscription purchase, access to the current Agreement text is provided.
The Customer accepts the Agreement by checking the confirmation box and completing the transaction.
EK-5.2. Separation of Agreement Acceptance from Explicit Consent
Accepting the SaaS Agreement does not constitute explicit consent for personal data processing.
Activities requiring explicit consent are managed through independent opt-in mechanisms.
EK-5.3. Marketing Communication Permissions
Marketing permissions are collected separately from Agreement acceptance where required by law.
EK-5.4. Privacy Notices
The separate Privacy Policy describing Data Controller processing activities is accessible independently.
Presenting privacy disclosures is distinct from obtaining explicit consent.
EK-5.5. Logged Acceptance Metadata
To prove electronic acceptance and maintain security, the following metadata may be recorded:
- Customer ID or account identifier;
- User ID performing acceptance;
- Agreement version number;
- Agreement effective date;
- Electronic acceptance timestamp (UTC / local);
- Signer IP address;
- Session identifier;
- Language version accepted;
- Technical checksum and integrity verification hashes.
EK-5.6. Agreement Versioning
Each substantial agreement update is assigned a version number and effective date.
| Version | Publication Date | Effective Date | Description |
|---|---|---|---|
| V. 2.0 | 18.08.2026 | 18.08.2026 | Comprehensive update of SaaS terms, KVKK/GDPR compliance, DPA integration, backup/export policies, and international use provisions. |
EK-5.7. Archiving Prior Versions
The PROVIDER archives historical agreement versions to identify the terms in effect for each customer.
This archive serves as evidentiary proof of past agreement terms.
EK-5.8. Material Modifications
Material modifications affecting customer rights are notified in advance.
Re-acceptance may be requested where required by law.
EK-5.9. Language Versions
Turkish and English versions may be published independently.
Accepted language versions are recorded in transaction logs.
Pursuant to Article 15.8, the Turkish text prevails in the event of interpretive discrepancy, subject to mandatory law.
EK-5.10. Evidentiary Value of Electronic Records
Electronic acceptance records, timestamps, account IDs, and version logs constitute admissible evidence under applicable procedural law.
This provision does not deprive either Party of statutory rights to challenge electronic record accuracy.
Integrality of the Agreement
This APPENDIX 1, APPENDIX 2, APPENDIX 3, APPENDIX 4, and APPENDIX 5 constitute an inseparable, integral part of the DigiPestControl SaaS Service and License Agreement. Electronic acceptance of the main Agreement by the Customer incorporates and confirms acceptance of all attached Appendices, provided that clear access to these Appendices has been granted during signup or purchase. Official statutory transfer contracts and separate agreements requiring handwritten or qualified electronic signatures under mandatory local law remain outside the scope of this electronic provision.