In force · listed organization processor terms

Data processing agreement

When a listed organization uses the CONCILERA workbench, that organization is the controller of the personal data in its files. CONCILERA, operated by SMARTEDTECH SL, is the processor. These terms are in force.

Last updated: 9 September 2026 · Version 1.0 · In force. Approved 9 September 2026 by SMARTEDTECH SL (owner and chief architect).

In force for listed organizations. SMARTEDTECH SL appoints the live sub-processors on this page and adopts the KVKK standard contract for Ireland hosting under company file CONCILERA-KVKK-SC-2026-09-09. An AI model provider is not on the schedule.

1. Scope

These terms apply to personal data a listed organization uploads, receives or generates in the CONCILERA workbench (cases, claims, statements, invites, evidence metadata, obligations, grants).

Party (complainant) accounts remain invited-only. CONCILERA is controller for its own platform accounts, as described in the GDPR / KVKK notice. This DPA does not rewrite that notice.

VRIZMA owns dispute process. VeriChain owns proof. Veruma owns verification. Those rails are not CONCILERA processor services.

2. Nature of processing

Purpose: host the case file, send claim-first invites, store evidence metadata, run the organization workbench, and produce portability packs on request.

Types of data: names and emails of invited mailboxes, case and claim text, evidence filenames/hashes/states, obligation text, grants, audit event names.

Data subjects: complainants, organization agents, and other people named in a file. Evidence bytes stay quarantined until accepted and are never placed in a DSAR zip.

Duration: while the case is active, then according to the retention policy (closed cases default five years, legal hold can extend).

3. Processor obligations

CONCILERA processes workbench data for the listed organization only as needed to run the product: case scope, explicit grant, and documented support or DSAR actions.

Access is host tenant, case scope and an explicit grant. There is no org_admin mint from the organization team page.

Personnel who can reach production systems are bound to keep case content closed outside that scope.

A personal-data breach affecting controller data is a founder/legal duty to notify without undue delay, targeting 72 hours where GDPR or KVKK require it. That is not a vendor SLA invented here.

On a valid erasure request, deletion is legal-hold-aware: a hold returns a reason, never a silent denial.

4. Security measures

Transport is TLS. Database access uses row-level security. Application APIs require a session. Direct database access from the browser Data API stays off.

Evidence objects stay in quarantine until accepted. AV scanning is fail-closed: an unscanned file is not treated as clean.

Billing cannot change queue order, rank, moderation or case state.

5. International transfers

Production database is in AWS eu-west-1 (Ireland). Users in Türkiye sending data there is a KVKK overseas transfer.

SMARTEDTECH SL adopts the KVKK standard contract as its transfer instrument for that hosting, company file CONCILERA-KVKK-SC-2026-09-09, approved 9 September 2026. That is the operator’s transfer record. A Kurul protocol number is printed here only when Kurul issues one.

The sub-processors below are appointed under this DPA. Their own vendor paper is not copied here; SMARTEDTECH SL’s instruction to them is this schedule.

6. AI and human desks

No AI model provider is on this schedule. Binding a model is done by adding that provider here with training_allowed=false first (D-27). Until then, CONCILERA does not send case text to a model provider as a live bind.

AI does not produce a responsibility share, a finding of who is right, or an official outcome. A settlement proposal is not mediator minutes. SMARTEDTECH SL’s human-desk engagement terms are in force; a legal-title document still needs a named licensed practitioner on the file.

7. Return, deletion and DSAR

The listed organization can export through the same DSAR path as any signed-in actor: /app/exports, JSON and markdown zip, no evidence bytes.

Closed-case retention defaults to five years unless a jurisdiction or legal hold says otherwise. Public case projection is off.

Questions: privacy@concilera.com and legal@concilera.com.

8. Governing text

Operator: SMARTEDTECH SL. Trade name: CONCILERA (concilera.com). VAT/NIF: B66970831. Sole administrator: Mustafa Yurteri.

Correspondence: Carrer Agricultura, 16, 1º, 9ª, 08320 El Masnou, Barcelona, Spain. Registered office: Av. Portal de l'Àngel, 42, 3º, 08002 Barcelona, Spain.

Registry: Registro Mercantil de Barcelona · T 45858 · F 103 · S 8 · H B-501172 · capital 6000 €. Constituted: 2017-03-10.

Public contact: privacy@concilera.com, legal@concilera.com, dpo@concilera.com. A separate telephone number is not published.

These terms are in force. They were approved on 9 September 2026 by SMARTEDTECH SL, acting through its owner and chief architect. GDPR and Spanish data-protection law apply to the operator. KVKK applies for residents of Türkiye.

The lead supervisory authority for GDPR, given the Spanish establishment, is the Agencia Española de Protección de Datos (AEPD): https://www.aepd.es. This document is not legal advice.

Sub-processors in production use

SMARTEDTECH SL appoints this live stack under this DPA. An AI provider is absent on purpose until it is added here with training_allowed=false.

  • Supabase

    Database, auth, object storage · EU (Ireland, eu-west-1)

    Case rows, grants, evidence objects

  • Vercel

    Web application · Edge + application hosting

    Request logs, rendered pages

  • Railway

    Background worker · Worker environment

    Outbox, scans, retention jobs

  • Resend

    Transactional email · Email provider

    Recipient address, invite and notice copy (claim-first: no claim body on the invite)

  • Cloudflare

    DNS · DNS only on this deploy

    DNS queries; not used here as a case store

GDPR / KVKKEmail legal@concilera.comLegal hub

Data processing agreement · CONCILERA