ibanchecker.cash

Last updated: June 2026

Data Processing Agreement

This Data Processing Agreement (“DPA”) applies to Enterprise API customers and any organisation using the ibanchecker.cash API to process data on behalf of EU or UK data subjects. It supplements our Terms of Service and Privacy Policy.

Ask AI to explain

Get a plain-language summary of this document without the legal jargon.

Need a countersigned DPA?

Enterprise customers and regulated industries requiring a formal countersigned agreement can request one by email. We aim to respond within 2 business days.

Request Signed DPA →

1. Parties

Data Controller: You (the organisation using the ibanchecker.cash API to process data on behalf of your users).

Data Processor:

KÖYLÜ BİLGİSAYAR ELEKTRONİK GIDA İLETİŞİM SANAYİ VE TİCARET LİMİTED ŞİRKETİ

Trading as ibanchecker.cash

Halaskargazi Mah. Ayla Algan Sok. No:30/A, Nişantaşı, Şişli / İstanbul, Turkey

Tax No

5890453732

Mecidiyeköy V.D.

MERSİS No

0589045373223843

Ticaret Sicil / Dosya No

783228-0 · İstanbul Ticaret Sicili

Authorized Representative

Koray Köylü

[email protected]

Enterprise / DPA Requests

[email protected]

2. Overview

This DPA is entered into between ibanchecker.cash (“Processor”) and the organisation accessing our API (“Controller”). It governs the processing of personal data in accordance with Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent UK legislation.

3. Scope & Roles

The Controller determines the purposes and means of processing (e.g., validating supplier IBANs in a payment workflow). ibanchecker.cash acts as Processor, providing IBAN validation as a technical service only, in accordance with the Controller’s instructions.

Processing activities covered: IBAN format validation via API endpoints (/api/v1/validate, /api/v1/validate/bulk, /api/v1/extract).

4. Data Processed

Critical: IBAN strings are never persisted.

IBAN values passed in API requests are validated in-memory at the edge and immediately discarded. They are never written to disk, databases, or logs.

Data TypePersisted?Retention
IBAN string (API input)NoZero — discarded immediately
API request timestampYes (aggregated)Rolling 13 months
API key (hashed)YesUntil key revocation
Country code of resultYes (aggregated)Rolling 13 months
Response time (ms)Yes (aggregated)Rolling 13 months

5. Sub-processors

ibanchecker.cash engages the following sub-processors. The Controller hereby grants general authorisation for these sub-processors:

Sub-processorRoleDPA / Privacy
Cloudflare, Inc.Edge compute, CDN, KV/D1 storagecloudflare.com/gdpr
Stripe, Inc.Payment processing (paid plans only)stripe.com/privacy
Resend, Inc.Transactional email deliveryresend.com/legal/dpa

We will notify Controllers of any intended changes to sub-processors with at least 14 days’ notice, providing the Controller the opportunity to object.

6. Security Measures

ibanchecker.cash implements appropriate technical and organisational security measures including:

See Security & Trust for the full technical overview.

7. International Transfers & Standard Contractual Clauses

Processing occurs on Cloudflare’s global edge network. Cloudflare relies on EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers of personal data outside the EEA. A copy of the applicable SCCs is available at cloudflare.com/cloudflare-customer-scc.

Enterprise customers requiring Module Two SCCs (Controller-to-Processor) with ibanchecker.cash as named Processor may request these as part of the signed DPA process.

8. KVKK Compliance (Turkey)

The Processor is incorporated in the Republic of Turkey and is subject to Kişisel Verilerin Korunması Kanunu (KVKK) No. 6698 in addition to GDPR. This DPA is consistent with the obligations of both frameworks.

Controllers subject to KVKK who require a Turkish-law DPA addendum may request one via [email protected].

9. Request a Signed DPA

To request a countersigned DPA (PDF format), email [email protected] with the subject line “DPA Request” and include your organisation name, country of incorporation, and API key (if already issued). We respond within 2 business days.