Privacy Policy
This English text is provided for convenience only. The legally binding version is the Turkish original at intusell.com/gizlilik. In case of any discrepancy, the Turkish version prevails.
Last updated: August 2026
At inTusell AI Solutions, we attach great importance to the protection of your personal data. This privacy policy has been prepared to inform you about how your personal data is collected, processed, stored and protected under the Turkish Personal Data Protection Law No. 6698 (KVKK) and the European Union General Data Protection Regulation (GDPR). inTusell is a software-as-a-service (SaaS) platform and, depending on the data set it processes, holds two separate capacities: for some data it is the data controller (veri sorumlusu, KVKK) / controller (GDPR), and for some data it is the data processor (veri işleyen, KVKK) / processor (GDPR). This distinction is defined in section 1.
1. Our Roles: When We Are a Data Controller and When We Are a Data Processor
There are two different data sets on the platform, and inTusell does not hold the same capacity in both. The data controller is the party that determines the purposes and means of the processing; the data processor is the party that processes the data on the controller's instructions.
1.1 Data for which inTusell is the data CONTROLLER
Data whose purposes and means inTusell itself determines, relating to its relationship with its own SaaS customer:
- Account data:Name, e-mail address, phone number, password (in encrypted form) and profile information of the organisation's users
- Invoicing and payment data: Subscription information, payment history, invoice records
- Support correspondence: Support requests, feedback, e-mail correspondence with inTusell
- Usage and telemetry data: Session records, IP address, device and browser information, usage statistics, error logs
- Marketing communication: Cookie records, campaign preferences, communication consents
The data controller for this set is:
- Company: inTusell AI Solutions
- E-mail: alikemal@intusell.com
- Web: intusell.com
1.2 Data for which inTusell is the data PROCESSOR
End-customer data collected and processed by the customer organisation (school, clinic, pharmacy, agency, store, etc.) through the platform. In this set the purposes and means are determined by the customer organisation; inTusell processes the data solely on its instructions and within the framework of the service agreement:
- Person records: The name, phone number, e-mail address, tags of end customers, parents or patients, and the custom fields defined by the organisation
- Conversation and message content: The full text of WhatsApp, Instagram DM, Telegram and web chat correspondence
- Appointment and session records
- Sales opportunity, quotation and order records
- Knowledge base content: Documents, price lists, frequently asked questions and product texts uploaded by the organisation
- Voice call data: Call recordings and transcripts — only where the relevant module has been enabled by the organisation
For the data in this set, the data controller is the customer organisation using the service — not inTusell. If, as a data subject (for example a parent, a patient or a consumer), you wish to exercise your rights set out in section 8, you must address your request first to the organisation that collects your data. inTusell responds to such requests that reach it by informing the relevant organisation and acting on that organisation's instructions; it does not decide on the request on its own. If you do not know which organisation processes your data, you may write to alikemal@intusell.com; we can direct you to the relevant organisation.
1.3 Our obligations in our capacity as data processor
- Processing on instructions:We process this data solely on the customer organisation's instructions and for the purpose of the service agreement; we do not use it for our own purposes
- Confidentiality: Personnel who can access the data are under a confidentiality obligation; access is limited on a duty-by-duty basis
- Security measures: The technical and administrative measures set out in section 10 (isolation between tenants via RLS, TLS, encrypted storage of credentials)
- Sub-processor transparency: The sub-processors we use are listed one by one in section 5
- Breach notification: We notify the customer organisation of a data breach without delay; the obligation to notify the competent authority and the data subjects rests with the organisation acting as data controller (section 11)
- Return or destruction:When the service agreement ends, we return the data to the organisation or destroy it in accordance with the organisation's instructions
2. Data Collected
The list below defines the data that inTusell collects in its capacity as data controller(1.1). Which data an organisation collects within the set described in 1.2 is set out in that organisation's own privacy notice:
- Identity Information: First name, last name, e-mail address, phone number
- Account Information: Username, password (encrypted), profile information
- Transaction Information: Subscription information, payment history, invoice information
- Usage Data: Platform usage statistics, session information, log records
- Communication Data: Support requests, feedback
- Integration Data: Connected social media accounts, Google Calendar data
- Technical Data: IP address, browser information, device information, cookie data
- Customer Communication Data: Messaging content exchanged through the platform
3. Purposes of Processing
Your personal data is processed for the following purposes:
- Providing and improving the platform services
- Account creation and identity verification
- Carrying out subscription and payment transactions
- Providing the AI-powered sales automation service
- Providing customer support services
- Fulfilling legal obligations
- Ensuring the security of the platform
- Providing analytics and reporting services
- Sending marketing communications (with consent)
4. Legal Basis
Your personal data is processed on the following legal bases:
- Performance of a contract: Data processing necessary for the provision of the platform services
- Legal obligation: Tax, accounting and other legal obligations
- Legitimate interest: Ensuring the security of the platform, service improvement
- Explicit consent: Marketing communications and the use of cookies
5. Data Sharing
Your personal data may be shared with the following parties:
5.1 Service providers active in every installation (sub-processors)
- Supabase (EU - Frankfurt): Database, file storage and authentication
- Vercel (USA): Application hosting (server functions run in the Frankfurt region) and performance telemetry
- Anthropic (USA): AI response generation, document and image analysis
- OpenAI (USA): AI response generation, vector (embedding) creation, voice note transcription, text-to-speech generation
- Google (USA):AI response generation (Gemini) and temporary caching of system prompts. In the voice demo on the website, microphone audio is transmitted from your browser directly to Google's infrastructure
- Resend (USA): E-mail delivery
- Upstash (EU - Frankfurt): Scheduled job queue — record identifiers only
- Fly.io (EU - Frankfurt): WhatsApp channel bridge connected via QR
- Telegram: Telegram channel messages and platform administration notifications
- iyzico (Türkiye): Payment and subscription transactions
5.2 Only when the relevant integration is connected
- Meta (USA): WhatsApp Business, Instagram DM and Messenger messages, lead ad form records; if the organisation defines its own advertising pixel, conversion notification with hashed (SHA-256) phone number/e-mail
- Twilio (USA): Voice calls and global SMS
- NetGSM (Türkiye): SMS and voice service to Turkish numbers
- Google Calendar (USA): Appointment synchronisation — name, appointment note, date
- Bitrix24: CRM synchronisation
- E-commerce and marketplace platforms: Order and message synchronisation (Shopify, Amazon, Trendyol, Hepsiburada, etc.)
- Kolayturum (Türkiye): Transfer of tour and accommodation pre-registrations
- Webhook addresses defined by the organisation: If the organisation defines an automation address, event data is sent to that address; the party that determines who the recipient is, is the customer organisation
5.3 Other disclosures
- Legal Authorities: Competent courts and public authorities where legally required
Your personal data is under no circumstances sold to third parties for commercial purposes. The providers listed above are sub-processors that act to the extent necessary for the provision of the service and on the instructions of inTusell (within the scope of 1.2: of the customer organisation).
6. Cookies
Our platform uses cookies and similar technologies. For detailed information about the use of cookies, please review our Cookie Policy.
7. Data Retention Period
In this section we declare only the destruction and anonymisation jobs that actually run on the platform and the statutory retention obligations.
Time-based automatic destruction/anonymisation:
- Integration request records: 30 days (daily destruction job)
- Webhook event records: 60 days (daily destruction job)
- Customer memory summaries: For records with no activity for 6 months, summaries and topic headings are anonymised by a weekly job
Statutory retention obligations: Invoices and financial records are retained for 10 years (Tax Procedure Law / Turkish Commercial Code) and electronic communication records for 3 years (Law No. 5651), even if a deletion request is received.
Destruction upon request: Data that does not fall within the scope of the automatic jobs above is retained for as long as the service relationship continues and is destroyed upon a deletion request. Because the request is handled by a job that runs daily, the start of destruction may take up to 24 hours. In an organisation-wide request, records are permanently deleted; in a person-specific request, the name, phone number, e-mail address, custom fields and message bodies are masked, while statistical aggregates that cannot be linked to the person are retained. Once consent is withdrawn, marketing data is no longer used for marketing purposes.
For the set described in 1.2, determining the retention period is within the authority of the customer organisation acting as data controller; when the service agreement ends, this data is returned to the organisation or destroyed in accordance with its instructions.
8. Your Rights
Under Article 11 of the KVKK and under the GDPR you have the following rights. For the set described in 1.1 you must address your request directly to inTusell; for the set described in 1.2 you must address it first to the organisation that collects your data:
- To learn whether your personal data is being processed
- To request information about it if your personal data has been processed
- To learn the purpose of the processing of the personal data and whether it is used in accordance with that purpose
- To know the third parties within Türkiye or abroad to whom the personal data is transferred
- To request the rectification of the personal data if it has been processed incompletely or inaccurately
- To request the erasure or destruction of the personal data
- To request that the rectification/erasure operations be notified to the third parties to whom the processed data has been transferred
- To object to a result to your detriment arising from the analysis of the processed data exclusively by automated systems
- To claim compensation for the damage if you suffer damage due to the unlawful processing of the personal data
9. International Data Transfers
Some of our service providers are located abroad. Your personal data may be transferred to countries that provide an adequate level of protection under the KVKK and the GDPR, or under appropriate safeguards (standard contractual clauses). The countries to which data is transferred in respect of the providers listed in section 5 are:
- USA: Anthropic, OpenAI, Google, Vercel, Resend, Meta, Twilio
- European Union: Supabase (Frankfurt), Upstash and Fly.io (Frankfurt); Vercel server functions also run in the Frankfurt region
- Türkiye: iyzico, NetGSM, Kolayturum and marketplace platforms based in Türkiye
- Other:Telegram, Bitrix24 and the marketplace/automation services connected by the organisation — the country in which they are located varies according to the relevant provider and the organisation's choice
Technical and administrative measures ensuring data security are taken in all international data transfers.
10. Security
We apply the following security measures to protect your personal data:
- Data transmission with SSL/TLS encryption
- Row level security (RLS) at the database level
- Data isolation through a multi-tenant architecture
- Regular security audits and penetration tests
- Access control and authorisation mechanisms
- Data backup and disaster recovery plans
11. Data Breach Notification Procedure
If a data breach affecting the security of your personal data is detected, the following procedure applies. These steps are carried out directly by inTusell for the set described in 1.1. For the set described in 1.2, inTusell notifies the customer organisation of the breach without delay; the obligation to notify the competent authority and the data subjects rests with the organisation acting as data controller:
- Detection and Assessment: Within 24 hours at the latest after the breach is detected, the incident is investigated and its impact is assessed
- Notification to the Competent Authority: Under the KVKK, the data breach is notified to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 72 hours at the latest
- Notification to Users: Users affected by the breach are informed as soon as possible, depending on the nature of the breach, by e-mail and in-platform notification
- Content of the Notification: The date and scope of the breach, the categories of data affected, its possible consequences and the measures taken/to be taken are clearly stated
- Corrective Measures: The technical and administrative measures necessary to prevent a recurrence of the breach are taken immediately
12. Changes
This privacy policy may be updated whenever deemed necessary. Material changes are notified through our platform and by e-mail at least 30 days before they take effect. You can review the current policy on our website at any time.
13. Contact
For any questions, requests and complaints regarding the privacy policy and your personal data:
- Company: inTusell AI Solutions
- E-mail: alikemal@intusell.com
- Web: intusell.com