Trust centre: how we protect your data – legally, technically, organisationally.
Direct Scouts works as a processor inside your systems. Here you find the legal framework, the technical and organisational measures and the documents your data protection officer needs for the review.
Four building blocks that carry every engagement.
The contracting party is the German entity ([PLATZHALTER: Firmierung der deutschen Gesellschaft, z. B. Direct Scouts GmbH]). The operational work takes place in Istanbul – and that is exactly what the framework is for.
There is no adequacy decision for Turkey – hence SCC, TIA and TOMs.
Art. 28 GDPR – data processing agreement
The basis of every engagement is a data processing agreement (DPA) with the German contracting entity. We process on documented instructions and with the audit rights that Art. 28 provides.
Standard contractual clauses (EU) 2021/914, module 2
Operational processing by our team in Istanbul is covered by the EU standard contractual clauses under Implementing Decision (EU) 2021/914, module 2 (controller → processor), including the annexes on processing and TOMs.
Transfer impact assessment (TIA)
A TIA documents the legal situation in the third country, the concrete access paths and the supplementary measures that safeguard the level of protection. Your DPO receives it before the contract is signed.
KVKK – in parallel with the GDPR
In Turkey the Data Protection Law No. 6698 (KVKK) applies in addition. Both frameworks are complied with side by side; the GDPR requirements remain the yardstick for processing your data.
Your data stays in your instance.
The most important measures at a glance. The full list of TOMs under Art. 32 GDPR is an annex to the DPA. Direct Scouts is ISO certified; we provide the certificates on request.
- Access only via VDI/Citrix
Our agents work in a hosted session on your systems. There is no local installation of your applications and no data held on end devices.
- No local export
Download, clipboard, printing and removable media are technically blocked inside the session. Data does not leave your instance.
- Clean desk and access control
No notes on paper, no private devices at the workstation, access to the operations floor only with a personal badge.
- Recording only with consent
Calls are not recorded by default. Recording takes place only if you want it and the legal requirements (consent of the parties) are met.
- Access revocation
Accounts are personal and are revoked immediately on role change, departure or project end. You can end any access yourself at any time – it is your instance.
- Training and commitment
All staff are bound to confidentiality and trained on GDPR and KVKK; refreshed at least annually.
Three stations. No copy of your data with us.
The agent works in a session on your CRM; appointments land directly in your field team’s calendar. You can revoke access at any time.
No copy of your data in our systems. Access revocable at any time.
Who we use – and for what.
Every further processor is named in the DPA; we announce changes with a right to object.
- Telephony / VoIP provider
Telephony and German phone numbers
- Hosting provider
Hosted workstation sessions (VDI/Citrix)
- Email and calendar service
Internal communication and scheduling
The full list with company, location and safeguard (DPA/SCC) is an annex to the DPA and is provided to your data protection officer on request.
Four documents that shorten the review.
The documents will be made available here after legal sign-off. Until then we send them on request.
- DPA template (PDF)
Data processing agreement under Art. 28 GDPR with the German contracting entity.
- TOM list (PDF)
Technical and organisational measures, structured along Art. 32 GDPR.
- SCC annexes (PDF)
Annexes I–III to the standard contractual clauses 2021/914, module 2.
- Pre-filled DPO questionnaire (PDF)
Pre-filled along the usual Art. 28 checkpoints so your data protection officer does not start from zero.
A day in Istanbul – with your DPO.
Whoever has seen the operations has less to take on faith. We organise a visit day in Şişli; we handle travel and scheduling.
- 09:00Operations tour
Workstations, access control, clean desk, team structure – you see where and how the work is done.
- 11:00Live monitoring
You listen in on live calls of an existing project (with the customer’s consent) and see the documentation in the CRM.
- 14:00Data protection check
VDI session, export blocks, permission concept and access revocation – together with your DPO or IT security lead.
What data protection officers ask us first.
Where is our data processed?
Your data stays in your systems – CRM, telephony, calendar. Our agents work on them via a VDI or Citrix session; local export is technically blocked. The contracting party is the German entity; operational processing takes place in Istanbul on the basis of the EU standard contractual clauses and a transfer impact assessment.
Is there an adequacy decision for Turkey?
No. That is why we secure the transfer with the EU standard contractual clauses (Implementing Decision 2021/914, module 2), a transfer impact assessment and technical and organisational measures – as Art. 44 ff. GDPR provides for third countries without an adequacy decision.
Are calls recorded?
Not by default. Recording takes place only if you want it and the legal requirements are met, in particular the consent of the parties. Quality assurance runs through live monitoring by the team lead and scoring sheets.
What happens to the accounts after the project ends?
All accounts are revoked at the end of the contract and you receive written confirmation. Since no copies of data sit in our systems, deletion is limited to access credentials and the contract documentation, which we retain for the statutory periods.
Which documents does our data protection officer receive?
DPA template, TOM list, SCC annexes, a summary of the transfer impact assessment and a pre-filled questionnaire – on request before the contract is signed. In addition we offer a site visit with a data protection check.
Legal information without guarantee; the DPA and SCC in the version signed are authoritative. Direct Scouts does not replace legal advice.