Compliance & data protection

Trust centre: how we protect your data – legally, technically, organisationally.

Direct Scouts works as a processor inside your systems. Here you find the legal framework, the technical and organisational measures and the documents your data protection officer needs for the review.

Legal framework

Four building blocks that carry every engagement.

The contracting party is the German entity ([PLATZHALTER: Firmierung der deutschen Gesellschaft, z. B. Direct Scouts GmbH]). The operational work takes place in Istanbul – and that is exactly what the framework is for.

There is no adequacy decision for Turkey – hence SCC, TIA and TOMs.

  • Art. 28 GDPR – data processing agreement

    The basis of every engagement is a data processing agreement (DPA) with the German contracting entity. We process on documented instructions and with the audit rights that Art. 28 provides.

  • Standard contractual clauses (EU) 2021/914, module 2

    Operational processing by our team in Istanbul is covered by the EU standard contractual clauses under Implementing Decision (EU) 2021/914, module 2 (controller → processor), including the annexes on processing and TOMs.

  • Transfer impact assessment (TIA)

    A TIA documents the legal situation in the third country, the concrete access paths and the supplementary measures that safeguard the level of protection. Your DPO receives it before the contract is signed.

  • KVKK – in parallel with the GDPR

    In Turkey the Data Protection Law No. 6698 (KVKK) applies in addition. Both frameworks are complied with side by side; the GDPR requirements remain the yardstick for processing your data.

Technical and organisational measures

Your data stays in your instance.

The most important measures at a glance. The full list of TOMs under Art. 32 GDPR is an annex to the DPA. Direct Scouts is ISO certified; we provide the certificates on request.

  • Access only via VDI/Citrix

    Our agents work in a hosted session on your systems. There is no local installation of your applications and no data held on end devices.

  • No local export

    Download, clipboard, printing and removable media are technically blocked inside the session. Data does not leave your instance.

  • Clean desk and access control

    No notes on paper, no private devices at the workstation, access to the operations floor only with a personal badge.

  • Recording only with consent

    Calls are not recorded by default. Recording takes place only if you want it and the legal requirements (consent of the parties) are met.

  • Access revocation

    Accounts are personal and are revoked immediately on role change, departure or project end. You can end any access yourself at any time – it is your instance.

  • Training and commitment

    All staff are bound to confidentiality and trained on GDPR and KVKK; refreshed at least annually.

Data flow

Three stations. No copy of your data with us.

The agent works in a session on your CRM; appointments land directly in your field team’s calendar. You can revoke access at any time.

No copy of your data in our systems. Access revocable at any time.

Sub-processors

Who we use – and for what.

Every further processor is named in the DPA; we announce changes with a right to object.

  • Telephony / VoIP provider

    Telephony and German phone numbers

  • Hosting provider

    Hosted workstation sessions (VDI/Citrix)

  • Email and calendar service

    Internal communication and scheduling

The full list with company, location and safeguard (DPA/SCC) is an annex to the DPA and is provided to your data protection officer on request.

Documents for your DPO

Four documents that shorten the review.

The documents will be made available here after legal sign-off. Until then we send them on request.

  • DPA template (PDF)

    Data processing agreement under Art. 28 GDPR with the German contracting entity.

  • TOM list (PDF)

    Technical and organisational measures, structured along Art. 32 GDPR.

  • SCC annexes (PDF)

    Annexes I–III to the standard contractual clauses 2021/914, module 2.

  • Pre-filled DPO questionnaire (PDF)

    Pre-filled along the usual Art. 28 checkpoints so your data protection officer does not start from zero.

Site visit

A day in Istanbul – with your DPO.

Whoever has seen the operations has less to take on faith. We organise a visit day in Şişli; we handle travel and scheduling.

  1. 09:00
    Operations tour

    Workstations, access control, clean desk, team structure – you see where and how the work is done.

  2. 11:00
    Live monitoring

    You listen in on live calls of an existing project (with the customer’s consent) and see the documentation in the CRM.

  3. 14:00
    Data protection check

    VDI session, export blocks, permission concept and access revocation – together with your DPO or IT security lead.

Request a site visit
Frequently asked

What data protection officers ask us first.

Where is our data processed?

Your data stays in your systems – CRM, telephony, calendar. Our agents work on them via a VDI or Citrix session; local export is technically blocked. The contracting party is the German entity; operational processing takes place in Istanbul on the basis of the EU standard contractual clauses and a transfer impact assessment.

Is there an adequacy decision for Turkey?

No. That is why we secure the transfer with the EU standard contractual clauses (Implementing Decision 2021/914, module 2), a transfer impact assessment and technical and organisational measures – as Art. 44 ff. GDPR provides for third countries without an adequacy decision.

Are calls recorded?

Not by default. Recording takes place only if you want it and the legal requirements are met, in particular the consent of the parties. Quality assurance runs through live monitoring by the team lead and scoring sheets.

What happens to the accounts after the project ends?

All accounts are revoked at the end of the contract and you receive written confirmation. Since no copies of data sit in our systems, deletion is limited to access credentials and the contract documentation, which we retain for the statutory periods.

Which documents does our data protection officer receive?

DPA template, TOM list, SCC annexes, a summary of the transfer impact assessment and a pre-filled questionnaire – on request before the contract is signed. In addition we offer a site visit with a data protection check.

Legal information without guarantee; the DPA and SCC in the version signed are authoritative. Direct Scouts does not replace legal advice.