Data Processing Agreement
Effective date: January 1, 2025 · Last updated: June 2026
Ask AI to explain
Get a plain-language summary of this document without the legal jargon.
هذا المستند متاح باللغة الإنجليزية فقط.
Summary
whatsmy.fyi processes IP addresses solely to return them to the requesting party in real-time. No IP addresses, request data, or geolocation data is stored, logged, or retained after the HTTP response is sent. The zero-retention architecture minimises breach exposure; processor obligations under GDPR Art. 28, 32, and 33 are acknowledged and addressed in the sections below.
1. Parties
Data Controller: You (the operator using the whatsmy.fyi API or website to process data on behalf of your users).
KÖYLÜ BİLGİSAYAR ELEKTRONİK GIDA İLETİŞİM SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Trading as whatsmy.fyi
Halaskargazi Mah. Ayla Algan Sok. No:30/A, Nişantaşı, Şişli / İstanbul, Turkey
Tax No
5890453732
Mecidiyeköy V.D.
MERSİS No
0589045373223843
Ticaret Sicil / Dosya No
783228-0 · İstanbul Ticaret Sicili
Enterprise Contact
enterprise@whatsmy.fyiThe Data Processor processes personal data solely as instructed by the Data Controller and as described in this agreement.
2. Nature and purpose of processing
whatsmy.fyi receives an IP address as part of an inbound HTTP request and returns geolocation, network, and connection metadata associated with that IP address in the HTTP response. The processing is instantaneous and transient — it is completed the moment the response is sent.
Purpose: Returning geolocation and connection metadata to the data controller in real-time, for use in their own application.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — the data controller requests the processing, receives the result immediately, and no data is retained by whatsmy.fyi thereafter.
3. Zero retention policy
whatsmy.fyi retains zero user data after an API response is sent. Specifically:
- ✓No IP addresses are written to any database, log file, or persistent store.
- ✓No geolocation data is retained beyond the in-flight HTTP response.
- ✓No User-Agent strings, request headers, or metadata are logged.
- ✓Cloudflare KV stores API key hashes and usage counters — never IP addresses or PII.
- ✓Cloudflare D1 stores account data provided voluntarily by registered users only.
This architecture means there is no personal data to be breached, no retention period to comply with, and no data subject access requests that require retrieval of IP history.
4. Sub-processors
whatsmy.fyi uses a single sub-processor for infrastructure:
| Sub-processor | Purpose | Location | DPA |
|---|---|---|---|
| Cloudflare, Inc. | Network infrastructure, Workers runtime, KV, D1 | Global (300+ PoPs) | cloudflare.com/gdpr → |
| Resend, Inc. | Transactional email (account registration only) | United States | resend.com/legal/dpa → |
Resend only receives email addresses for registered dashboard users — it never processes IP addresses or end-user data.
5. Data subject rights (GDPR Art. 15–22)
Because whatsmy.fyi retains zero personal data beyond the HTTP response, most data subject rights are satisfied by design:
- ·Right of access (Art. 15): No data retained — nothing to return.
- ·Right to erasure (Art. 17): No data retained — nothing to delete.
- ·Right to portability (Art. 20): No data retained — nothing to export.
- ·Right to rectification (Art. 16): No data retained — nothing to correct.
- ·Registered account data: Email, name, OAuth provider — deletable via Dashboard → Settings → Delete account.
6. Security measures
Technical and organisational measures in place:
- 🔒All traffic encrypted with TLS 1.3 — older protocols rejected.
- 🔒API keys stored as SHA-256 hashes only — plaintext never persisted.
- 🔒Cloudflare Workers runtime provides process-level isolation per request.
- 🔒Cloudflare's infrastructure is ISO 27001, SOC 2 Type II, and PCI DSS Level 1 certified.
- 🔒No credentials stored in code — environment variables via Cloudflare secrets.
7. International transfers
Cloudflare routes requests to the nearest Point of Presence globally. For EEA data subjects, this typically means processing within Europe. Cloudflare participates in the EU-U.S. Data Privacy Framework and provides Standard Contractual Clauses (SCCs) for international transfers.
Because whatsmy.fyi retains zero data after the response, there is no ongoing international transfer of personal data by whatsmy.fyi itself.
8. Breach notification (Art. 33 GDPR)
The Processor shall notify the Controller without undue delay — and in any case within 72 hours — of becoming aware of a personal data breach that may have affected processing carried out under this agreement.
Notification shall include, to the extent known at the time: (a) the nature of the breach; (b) the categories and approximate number of data subjects affected; (c) the likely consequences; and (d) the measures taken or proposed to address the breach.
Given the zero-retention architecture, the practical breach surface is limited to in-flight HTTP requests and Cloudflare infrastructure. Cloudflare's own breach notification obligations to the Processor are governed by Cloudflare's DPA.
Breach notifications should be sent to: enterprise@whatsmy.fyi
9. Audit rights (Art. 28(3)(h) GDPR)
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations in Art. 28 GDPR and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller.
Given the zero-retention architecture, audit compliance is typically demonstrated by:
- →Review of this DPA and the accompanying Privacy Policy.
- →Cloudflare's publicly available SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certifications.
- →On-request architectural review call with the Processor (enterprise customers).
Audit requests should be submitted to enterprise@whatsmy.fyi.
10. Termination and data return (Art. 28(3)(g) GDPR)
Upon termination of the agreement or at the Controller's request, the Processor shall — at the Controller's choice — delete or return all personal data processed under this agreement, and delete existing copies unless retention is required by applicable law.
End-user IP data: No deletion or return action is required upon termination — zero-retention by design means no end-user IP addresses, geolocation data, or request metadata is held by the Processor at any point after the HTTP response is sent.
Registered account data (name, email, API key hashes): Deleted automatically when the Controller's account is deleted via Dashboard → Settings → Delete account, or upon written request to enterprise@whatsmy.fyi. Deletion is completed within 30 days.
11. KVKK compliance (Turkey)
The Processor is incorporated in the Republic of Turkey and is subject to Kişisel Verilerin Korunması Kanunu (KVKK) No. 6698 in addition to GDPR. This DPA is consistent with the obligations of both frameworks.
- ✓Processing is limited to what is explicitly requested by the data controller.
- ✓KVKK Article 12 — technical and administrative measures applied (see Section 6).
- ✓KVKK Article 13 — data subject requests addressed within 30 days.
- ✓Processor is registered with the Turkish Data Protection Authority (KVKK Sicil) via MERSİS: 0589045373223843.
Controllers subject to KVKK who require a Turkish-law DPA addendum may request one via enterprise@whatsmy.fyi.
12. Limitation of liability
The Processor's liability under this agreement is limited as follows:
- ·The Processor is liable only for damages caused by processing that does not comply with the specific obligations of this agreement or with applicable law.
- ·The Processor shall not be liable for any damages resulting from lawful processing carried out on the documented instructions of the Controller.
- ·Because no personal data is retained beyond the HTTP response, the Processor's liability surface is limited to the in-flight processing window of each individual request.
- ·In no event shall the Processor's total liability exceed the amount paid by the Controller for the service in the twelve (12) months preceding the event giving rise to the claim.
- ·Nothing in this section limits a party's liability for fraud, gross negligence, or wilful misconduct.
13. Enterprise DPA signing
For enterprise customers who require a signed DPA as part of their vendor onboarding process, contact us at:
enterprise@whatsmy.fyi →We respond within 1 business day for enterprise DPA requests.
14. Changes to this agreement
Material changes to this DPA will be announced via the changelog at least 30 days before they take effect. The effective date at the top of this page is updated on every revision.