Joint Controller Arrangement
Joint Controller Arrangement under Article 26 GDPR
Between Navlungo Lojistik ve Teknoloji A.Ş., Istanbul, Turkey, and Navlungo GmbH i. G. (in Gründung), Kreuzberger Ring 24, 65205 Wiesbaden, Germany.
Issued on 14 August 2026 with version 2 of the GDPR and BDSG compliance package prepared by AG Euro Consulting. The text reproduces Annex A of the GDPR and BDSG Compliance Report: German Market Entry and is set out here as a separate instrument, so that the arrangement required by Article 26(1) of Regulation (EU) 2016/679 may be executed without extraction from the report. Bracketed fields require completion before signature, and Appendices 1 to 4, namely the covered processing activities, the retention schedule, the security measures, and the applicable Standard Contractual Clauses, must be prepared and attached. Appendix 1 may be drawn from Section 7 of that report and Appendix 2 from Section 10.2. Review by German counsel before execution is recommended, and the arrangement is signed on the Turkish side by both authorised representatives
Parties
Navlungo Lojistik ve Teknoloji A.Ş., a joint stock company incorporated under the laws of the Republic of Turkey, with its headquarters at [full address], Istanbul, Turkey, represented jointly by İsa Korkmaz, Chief Executive Officer and Founder, and Emrah Arslan, [function], who are jointly authorised to bind the company ("the Turkish Controller"), and Navlungo GmbH, a limited liability company under the laws of the Federal Republic of Germany, in the course of formation at the date of the present instrument and to be registered at the Amtsgericht [registered court] under [HRB number], with its registered office at Kreuzberger Ring 24, 65205 Wiesbaden, Germany, represented by [name and function] ("the German Controller"), together "the Parties".
Clause 1: Subject Matter and Scope
1.1 The Parties jointly determine the purposes and means of the processing of personal data carried out in connection with the operation of the ParkPalet platform for merchants and buyers located in the European Union, and they conclude the present arrangement in order to satisfy Article 26(1) of Regulation (EU) 2016/679.
1.2 The processing activities covered are those listed in Appendix 1, which forms an integral part of the arrangement and reproduces the record maintained under Article 30 of Regulation (EU) 2016/679.
1.3 Processing carried out by either Party exclusively for its own separate purposes falls outside the arrangement, and each Party acts as sole controller for such processing.
Clause 2: Allocation of Responsibilities
2.1 The German Controller is responsible for the relationship with data subjects located in the European Union, including the provision of the information required by Articles 13 and 14, the receipt and handling of requests under Articles 15 to 22, and the publication of the notices required by Regulation (EU) 2016/679 and by § 25 of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz.
2.2 The Turkish Controller is responsible for the operation, maintenance, and security of the platform infrastructure, for the engagement and supervision of processors, and for the technical implementation of erasure, restriction, rectification, and portability instructions transmitted by the German Controller.
2.3 Each Party maintains its own record of processing activities under Article 30 of Regulation (EU) 2016/679 in respect of the activities for which it is responsible under this Clause.
2.4 Determination of retention periods for personal data of data subjects in the European Union rests with the German Controller, which applies the schedule at Appendix 2, and the Turkish Controller implements that schedule in the platform.
Clause 3: Point of Contact for Data Subjects
3.1 The Parties designate [name, function, postal address, and email address] as the contact point within the meaning of Article 26(1) of Regulation (EU) 2016/679, and they publish those details in the privacy notice.
3.2 A request addressed to either Party shall be forwarded to the contact point without delay and in any event within three working days of receipt, so that the period in Article 12(3) of Regulation (EU) 2016/679 can be observed.
3.3 The Parties acknowledge that, under Article 26(3) of Regulation (EU) 2016/679, a data subject may exercise rights in respect of and against each of them irrespective of the allocation in Clause 2.
Clause 4: Information Duties and Essence of the Arrangement
4.1 The German Controller drafts and maintains the information notices required by Articles 13 and 14 of Regulation (EU) 2016/679, and the Turkish Controller supplies the technical particulars required for their accuracy.
4.2 The essence of the present arrangement shall be made available to data subjects in the privacy notice, in a summary identifying the Parties, their respective responsibilities, the contact point, and the right to exercise rights against either Party, in accordance with Article 26(2) of Regulation (EU) 2016/679.
Clause 5: Security and Personal Data Breaches
5.1 Each Party implements the technical and organisational measures required by Article 32 of Regulation (EU) 2016/679 in respect of the systems under its control, and the measures in force at the date of signature are described in Appendix 3.
5.2 A Party becoming aware of a personal data breach shall inform the other Party without undue delay and in any event within twenty-four hours of becoming aware, supplying the information necessary for the assessment required by Article 33 of Regulation (EU) 2016/679.
5.3 Notification to the competent supervisory authority under Article 33 and communication to data subjects under Article 34 of Regulation (EU) 2016/679 are made by the German Controller, which keeps the documentation required by Article 33(5).
Clause 6: Processors and Sub-Processing
6.1 Neither Party shall engage a processor for the processing covered by the arrangement without a contract satisfying Article 28(3) of Regulation (EU) 2016/679.
6.2 The Turkish Controller maintains the list of processors engaged, notifies the German Controller of any intended addition or replacement at least thirty days in advance, and the German Controller may object on reasoned data protection grounds within that period.
Clause 7: International Transfers
7.1 Transfers of personal data to the Republic of Turkey are governed by the Standard Contractual Clauses annexed at Appendix 4, concluded pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 using the module corresponding to the roles of the Parties.
7.2 The transfer impact assessment supporting those clauses is maintained by the German Controller and reviewed at least annually, and each Party shall inform the other of any change in the law or practice of its jurisdiction affecting the assessment.
Clause 8: Records, Audit, and Cooperationar, Denetim ve İş Birliği
8.1 Each Party shall provide the other, on reasonable request, with the information necessary to demonstrate compliance with Regulation (EU) 2016/679 in respect of the processing covered by the arrangement.
8.2 The Parties shall cooperate with the competent supervisory authority under Article 31 of Regulation (EU) 2016/679, and shall inform one another of any contact from an authority relating to the covered processing within two working days.
Clause 9: Liability
9.1 The Parties acknowledge that, under Article 82(4) of Regulation (EU) 2016/679, each controller involved in the same processing is liable for the entire damage caused, and that a controller having paid full compensation may claim back from the other the part corresponding to its responsibility under Article 82(5).
9.2 As between the Parties, responsibility for damage follows the allocation in Clause 2, and each Party shall indemnify the other for damage arising from a failure attributable to it.
Clause 10: Term, Amendment, and Governing Law
10.1 The arrangement enters into force on the date of the last signature and continues for as long as the covered processing continues.
10.2 Amendments require the written form, and the Appendices may be updated by written agreement of the designated contacts without amendment to the body of the arrangement.
10.3 The arrangement is governed by the law of the Federal Republic of Germany, and the place of jurisdiction is [Wiesbaden or as agreed], without prejudice to the rights of data subjects under Article 79 of Regulation (EU) 2016/679.
Signatures
For Navlungo Lojistik ve Teknoloji A.Ş., first authorised signatory: name İsa Korkmaz, function Chief Executive Officer and Founder, place ______________________, date ______________________, signature ______________________.
For Navlungo Lojistik ve Teknoloji A.Ş., second authorised signatory: name Emrah Arslan, function ______________________, place ______________________, date ______________________, signature ______________________. Both signatures are required, the two representatives being jointly authorised.
For Navlungo GmbH: name and function ______________________, place ______________________, date ______________________, signature ______________________.
