Last updated: June 2026
Data Processing Agreement
This Data Processing Agreement (“DPA”) applies to Enterprise API customers and any organisation using the ibanchecker.cash API to process data on behalf of EU or UK data subjects. It supplements our Terms of Service and Privacy Policy.
Ask AI to explain
Get a plain-language summary of this document without the legal jargon.
Need a countersigned DPA?
Enterprise customers and regulated industries requiring a formal countersigned agreement can request one by email. We aim to respond within 2 business days.
Request Signed DPA →1. Parties
Data Controller: You (the organisation using the ibanchecker.cash API to process data on behalf of your users).
Data Processor:
KÖYLÜ BİLGİSAYAR ELEKTRONİK GIDA İLETİŞİM SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Trading as ibanchecker.cash
Halaskargazi Mah. Ayla Algan Sok. No:30/A, Nişantaşı, Şişli / İstanbul, Turkey
Tax No
5890453732
Mecidiyeköy V.D.
MERSİS No
0589045373223843
Ticaret Sicil / Dosya No
783228-0 · İstanbul Ticaret Sicili
Enterprise / DPA Requests
[email protected]2. Overview
This DPA is entered into between ibanchecker.cash (“Processor”) and the organisation accessing our API (“Controller”). It governs the processing of personal data in accordance with Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent UK legislation.
3. Scope & Roles
The Controller determines the purposes and means of processing (e.g., validating supplier IBANs in a payment workflow). ibanchecker.cash acts as Processor, providing IBAN validation as a technical service only, in accordance with the Controller’s instructions.
Processing activities covered: IBAN format validation via API endpoints (/api/v1/validate, /api/v1/validate/bulk, /api/v1/extract).
4. Data Processed
Critical: IBAN strings are never persisted.
IBAN values passed in API requests are validated in-memory at the edge and immediately discarded. They are never written to disk, databases, or logs.
| Data Type | Persisted? | Retention |
|---|---|---|
| IBAN string (API input) | No | Zero — discarded immediately |
| API request timestamp | Yes (aggregated) | Rolling 13 months |
| API key (hashed) | Yes | Until key revocation |
| Country code of result | Yes (aggregated) | Rolling 13 months |
| Response time (ms) | Yes (aggregated) | Rolling 13 months |
5. Sub-processors
ibanchecker.cash engages the following sub-processors. The Controller hereby grants general authorisation for these sub-processors:
| Sub-processor | Role | DPA / Privacy |
|---|---|---|
| Cloudflare, Inc. | Edge compute, CDN, KV/D1 storage | cloudflare.com/gdpr |
| Stripe, Inc. | Payment processing (paid plans only) | stripe.com/privacy |
| Resend, Inc. | Transactional email delivery | resend.com/legal/dpa |
We will notify Controllers of any intended changes to sub-processors with at least 14 days’ notice, providing the Controller the opportunity to object.
6. Security Measures
ibanchecker.cash implements appropriate technical and organisational security measures including:
- • TLS 1.3 for all data in transit
- • API keys stored as SHA-256 hashes — never in plaintext
- • Edge-only processing — validation never touches centralised servers
- • Cloudflare DDoS protection and WAF
- • No IBAN data in logs or persistent storage
See Security & Trust for the full technical overview.
7. International Transfers & Standard Contractual Clauses
Processing occurs on Cloudflare’s global edge network. Cloudflare relies on EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) for transfers of personal data outside the EEA. A copy of the applicable SCCs is available at cloudflare.com/cloudflare-customer-scc.
Enterprise customers requiring Module Two SCCs (Controller-to-Processor) with ibanchecker.cash as named Processor may request these as part of the signed DPA process.
8. KVKK Compliance (Turkey)
The Processor is incorporated in the Republic of Turkey and is subject to Kişisel Verilerin Korunması Kanunu (KVKK) No. 6698 in addition to GDPR. This DPA is consistent with the obligations of both frameworks.
- • Processing is limited to what is explicitly requested by the data controller.
- • KVKK Article 12 — technical and administrative measures applied (see Section 6).
- • KVKK Article 13 — data subject requests addressed within 30 days.
- • Processor is registered with the Turkish Data Protection Authority (KVKK Sicil) via MERSİS: 0589045373223843.
Controllers subject to KVKK who require a Turkish-law DPA addendum may request one via [email protected].
9. Request a Signed DPA
To request a countersigned DPA (PDF format), email [email protected] with the subject line “DPA Request” and include your organisation name, country of incorporation, and API key (if already issued). We respond within 2 business days.