Agreement overview
Part of the agreement between Customer and GenderAPI
This Data Processing Agreement ("DPA") forms part of the agreement governing Customer's use of GenderAPI when GenderAPI processes Customer Personal Data on Customer's behalf. If a conflict concerns the protection of Customer Personal Data, this DPA prevails over the conflicting provision of the main agreement.
Scope and Roles
Customer is the controller and Onur Öztürk, a sole proprietor trading as Ozan Soft ("GenderAPI"), is the processor for Customer Personal Data submitted through the API, file-processing tools or connected spreadsheet functions. Each party remains independently responsible for personal data it processes as a controller, including account, billing and business-contact administration by GenderAPI.
Customer determines whether submitted data is personal data and is responsible for its legal basis, notices, permissions and instructions. Customer must not submit data that the Service is not designed to process or use inference results as the sole basis for a decision producing legal or similarly significant effects about a person.
Processing Instructions
GenderAPI will process Customer Personal Data only to provide, secure and support the Service in accordance with the agreement, this DPA, Customer's documented use of the Service and applicable law. GenderAPI will inform Customer if, in its reasonable opinion, an instruction infringes applicable data-protection law, unless the law prohibits that notice.
GenderAPI will not sell Customer Personal Data, use it for cross-context behavioral advertising, use it to train the private inference model, or retain it in AI logs. The retention rules in the Privacy Policy form part of these documented processing instructions.
Confidentiality and Security
GenderAPI will ensure that persons authorized to process Customer Personal Data are subject to an appropriate duty of confidentiality and may access the data only as necessary for their assigned work. GenderAPI will maintain technical and organizational measures appropriate to the nature of the Service and the processing risks.
- TLS-protected transmission for data exchanged with the Service.
- Access restrictions for production systems, customer data and access-restricted backups.
- Separation and protection of account credentials and production API keys.
- Security-event and technical logging subject to the published retention schedule.
- Rolling backups with a standard overwrite period of up to 15 days.
- Private AI processing without customer-data training or AI prompt/result logging.
- Data-minimization and deletion procedures aligned with the Service's retention schedule.
Subprocessors
Customer gives GenderAPI general written authorization to use the providers identified as DPA subprocessors on the Subprocessors page. GenderAPI will require each such subprocessor to protect Customer Personal Data under obligations materially consistent with this DPA, as applicable to the services the subprocessor performs. GenderAPI remains responsible for its obligations under this DPA. Providers used only for GenderAPI's controller activities, such as billing or account communications, are identified separately and are not treated as Customer's processors merely because they appear in the provider register.
GenderAPI will provide at least 30 days' advance notice through the Subprocessors page, the Service or the Customer's account email before adding or replacing a subprocessor that will process Customer Personal Data. Customer may raise a reasonable, documented data-protection objection during that period. The parties will work in good faith on a commercially reasonable solution; if none is available, Customer may stop using the affected feature.
Assistance and Personal Data Incidents
Taking into account the nature of the processing and information available to it, GenderAPI will provide reasonable assistance with data-subject requests, security obligations, personal-data-breach notifications, data-protection impact assessments and consultations required by applicable data-protection law. If a data subject contacts GenderAPI about Customer Personal Data, GenderAPI may refer the request to Customer unless applicable law requires a direct response.
GenderAPI will notify Customer without undue delay and, where reasonably possible, within 48 hours after becoming aware of a confirmed personal data breach affecting Customer Personal Data. The notice will provide available information reasonably needed for Customer's assessment and notification obligations. Notification is not an admission of fault or liability.
Return and Deletion
During the Service term, Customer may retrieve available results through the supported Service functions. On account closure, termination of the relevant processing or a valid deletion request, GenderAPI will delete or irreversibly anonymize Customer Personal Data remaining in active systems within 30 days, unless applicable law requires retention. Data removed from active systems may remain in access-restricted rolling backups for up to 15 additional days before automatic overwrite.
Legal retention of billing, transaction, fraud-prevention or dispute records does not authorize continued use of Customer query or uploaded-file content. The category-specific schedule in thePrivacy Policy continues to apply where it provides a shorter period.
Information and Audits
GenderAPI will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, initially through current policies, documentation and a reasonable security questionnaire. If that information is insufficient for a legal obligation, Customer may request a proportionate audit no more than once per year, except following a confirmed breach or a binding regulator request.
An audit must be conducted on reasonable advance notice, during normal business hours, without exposing another customer's data or compromising security. Customer bears its audit costs unless the audit identifies a material breach by GenderAPI. The parties will agree appropriate confidentiality and scope terms first.
International Transfers
Customer Personal Data may be processed in Türkiye and, through contracted infrastructure, in the United States. GenderAPI will use a legally recognized transfer mechanism where applicable. If the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are required, the applicable controller-to-processor module is incorporated into this DPA and prevails over conflicting terms for that transfer. The parties will complete any selections or annex details legally required for their specific transfer when executing the DPA.
Processing Details
Subject matter and duration
Processing needed to provide GenderAPI during Customer's use of the Service and for the limited deletion, backup, security and legal-retention periods described in this DPA and the Privacy Policy.
Nature and purpose
Receiving, transmitting, analyzing and returning results for API queries, uploaded Excel or CSV files, and connected spreadsheet operations; plus related hosting, security, troubleshooting and support.
Categories of data subjects
Individuals whose names, email addresses, usernames or related records Customer submits; Customer's users, personnel, contacts or end users; and persons represented in uploaded or connected spreadsheet data.
Types of personal data
Names, email addresses, usernames, country or localization context, customer-provided spreadsheet fields, inferred gender result and confidence information, and limited request, device, authentication and security metadata needed to operate the Service. Customer must not submit special-category data unless expressly agreed in writing and lawfully permitted.
Acceptance and Contact
This DPA becomes binding when Customer accepts it as part of the Service agreement or when it is signed by both parties. Requests for an execution copy, transfer annex or data-processing information may be sent tosupport@genderapi.io.
Onur Öztürk, trading as Ozan Soft · Tax identification number: 7140188422 · Etimesgut Tax Office · Ankara Chamber of Tradesmen registration: 4522 · Tradesmen Registry number: 354342
Şehit Osman Avcı Mah. Kaplan Cad. No:11B/4, Etimesgut, Ankara, Türkiye