Skip to main content

KVKK Privacy Notice

This English text is provided for convenience only. The legally binding version is the Turkish original at intusell.com/kvkk. In case of any discrepancy, the Turkish version prevails.

Last updated: August 2026

As inTusell AI Solutions, we are preparing this privacy notice in order to inform you about the processing of your personal data within the scope of the Turkish Personal Data Protection Law No. 6698 ("KVKK"). inTusell is a software as a service (SaaS) platform and, depending on the data set it processes, holds two separate capacities: data controller in its relationship with its own SaaS customers, and data processor with respect to the end-customer data that customer organizations collect through the platform. This distinction is defined in section 1 and the entire text is built upon this distinction. This notice has been prepared in accordance with Article 10 of the KVKK and the provisions of the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform.

1. Our Roles: When We Are a Data Controller, When We Are a Data Processor

There are two different data sets on the platform and inTusell does not hold the same capacity in these two sets. The distinction below is based on the definitions of data controller and data processor in KVKK art. 3/1: the data controller is the party that determines the purposes and means of the processing; the data processor is the party that processes the data upon the instruction of the controller.

1.1 Data for which inTusell is the data CONTROLLER

Data for which inTusell itself determines the purposes and means of the processing. In this set your counterparty is directly inTusell:

  • Account data: Name, surname, e-mail address, phone number, password (in encrypted form) and profile information of the organization users registered on the platform
  • Invoice and payment data: Subscription information, payment history, invoice records
  • Support correspondence: Support requests, feedback and e-mail correspondence sent to inTusell
  • Usage and telemetry data: Session records, IP address, device and browser information, platform usage statistics, error logs
  • Marketing communication: Cookie records, campaign preferences, communication consents

The data controller for this set:

  • Title: inTusell AI Solutions
  • E-mail: alikemal@intusell.com
  • Web: intusell.com

1.2 Data for which inTusell is the data PROCESSOR

End-customer data that the customer organization (school, clinic, pharmacy, agency, store, etc.) collects and processes through the platform. In this set the purposes and means of the processing are determined by the customer organization; inTusell processes it only upon that organization's instruction and within the framework of the service agreement:

  • Contact records: The name, phone, e-mail, tags of end customers, parents or patients and the custom fields defined by the organization
  • Conversation and message content: The full text of WhatsApp, Instagram DM, Telegram and web chat correspondence
  • Appointment and session records
  • Sales opportunity, quote and order records
  • Knowledge base content: Documents, price lists, frequently asked questions and product texts uploaded by the organization
  • Voice call data: Call recordings and transcripts — only when the relevant module is enabled by the organization

With respect to the data in this set, the data controller is the customer organization using the service — not inTusell. If, as a data subject (for example a parent, patient or consumer), you wish to exercise your KVKK art. 11 rights set out in section 7, you must direct your request first to the organization that collects your data. inTusell meets such requests that reach it by informing the relevant organization and acting in line with that organization's instruction; it does not make a decision on the request on its own. If you do not know which organization processes your data, you may write to alikemal@intusell.com; we can direct you to the relevant organization.

1.3 Our obligations in our capacity as data processor

With respect to the set in 1.2, we bear the following obligations within the scope of KVKK art. 12 and the service agreement:

  • Processing upon instruction:We process this data only in line with the customer organization's instruction and the purpose of the service agreement; we do not use it for our own purposes
  • Confidentiality: Personnel who can access the data are under a confidentiality obligation; access is limited on a task basis
  • Security measures: Isolation between tenants through row level security (RLS), TLS encryption in transit, encrypted storage of integration credentials, two-step verification support
  • Sub-processor transparency: The sub-processors we use in order to provide the service are listed one by one in section 5
  • Breach notification: When a data breach is detected, we inform the customer organization without delay; the obligation to notify the Personal Data Protection Board and the data subjects belongs to the organization that is the data controller (section 9)
  • Return or destruction:When the service agreement ends, we return the data to the organization or destroy it in accordance with the organization's instruction

2. Personal Data Processed

This section defines the data categories that inTusell processes in its capacity as data controller(1.1). Which data the customer organization collects in the set in 1.2 and for which purpose it processes them is stated in that organization's own privacy notice.

  • Identity Information: Name, surname
  • Contact Information: E-mail address, phone number
  • Account Information: Username, password (in encrypted form), profile information
  • Customer Transaction Information: Subscription information, payment history, invoice information
  • Transaction Security Information: IP address, session information, log records, access times
  • Marketing Information: Cookie records, campaign preferences, communication consents
  • Visual/Audio Data: Profile photos
  • Digital Trace Information: Browser information, device information, platform usage data

3. Purposes of Processing

The processing purposes determined by inTusell in its capacity as data controller (1.1) are as follows:

  • Carrying out membership procedures and account management
  • Providing and improving platform services
  • Providing the artificial intelligence powered sales automation service
  • Operating WhatsApp, Instagram and web widget integrations
  • Carrying out subscription and payment transactions
  • Customer relationship management and the provision of support services
  • Providing analytics and reporting services
  • Carrying out information security processes
  • Fulfilling legal obligations
  • Carrying out marketing and communication activities (within your consent)

In the set in 1.2 the purpose of the processing is determined by the customer organization; inTusell does not carry out processing for its own purpose in that set. We do not use the data in this set for any purpose other than the provision of the service (delivering the message, generating the response, recording the appointment).

4. Legal Grounds

The data that inTusell processes in its capacity as data controller (1.1) is processed on the basis of the following legal grounds within the scope of Article 5/2 of the KVKK. In the set in 1.2, determining the legal ground and, where required, obtaining explicit consent belongs to the customer organization that is the data controller:

  • Establishment and performance of a contract (art. 5/2-c): Provision of platform services, account creation, subscription management
  • Legal obligation (art. 5/2-ç): Requirements of tax legislation and electronic commerce legislation
  • Legitimate interest (art. 5/2-f): Ensuring platform security, increasing service quality, preventing fraud
  • Explicit consent (art. 5/1): Marketing communications, use of cookies, profiling activities
  • Establishment, exercise or protection of a right (art. 5/2-e): Use as evidence in legal disputes

5. Transfer

Your personal data may be transferred to the following recipients within the scope of Articles 8 and 9 of the KVKK:

Domestic transfer: Legal authorities, audit bodies and the business partners that are indispensable for the provision of the service.

5.1 Sub-processors used in every deployment

The following service providers are necessarily involved while the platform is running:

  • Supabase Inc. (EU - Frankfurt): Database, file storage and authentication — all data on the platform
  • Vercel Inc. (USA): Application hosting; server functions run in the Frankfurt region. Also page view and performance telemetry
  • Anthropic PBC (USA): AI response generation, document and image analysis, call transcript evaluation — the conversation text that goes into the prompt content
  • OpenAI Inc. (USA): AI response generation, knowledge base and conversation vectors (embedding), voice note transcription, text-to-speech generation — conversation text and audio files
  • Google LLC (USA): AI response generation (Gemini) and temporary caching of system prompts. In the voice demo on the website, the microphone audio is transmitted directly from your browser to Google infrastructure; this feature works only when you approve the disclosure and grant microphone permission
  • Resend Inc. (USA): E-mail delivery — recipient address, subject and e-mail body
  • Upstash Inc. (EU - Frankfurt): Scheduled job queue — only record identifiers and job type; message content is not transferred
  • Fly.io Inc. (EU - Frankfurt): WhatsApp (QR-connected) channel bridge — WhatsApp message content, phone number and session keys
  • Telegram: Delivery of Telegram channel messages; also platform management notifications (support request and alert content)
  • iyzico (Türkiye):Payment and subscription transactions — name, e-mail, amount; card details are processed on iyzico's own payment form

5.2 Only when the relevant integration is enabled

The following transfers take place when the customer organization connects the relevant channel or integration with its own account; as long as it is not connected, no data is transferred:

  • Meta Platforms Inc. (USA):Delivery and receipt of WhatsApp Business, Instagram DM and Messenger messages, advertising form (Lead Ads) records. If the organization defines its own advertising pixel, sales/appointment events are reported to the organization's advertising account together with the cryptographically hashed (SHA-256) phone number and e-mail
  • Twilio Inc. (USA):Voice calls and global SMS — phone number, message text, call audio and recordings (the organization's own Twilio account)
  • NetGSM (Türkiye): SMS and voice service to Turkish numbers — phone number and message text
  • Google LLC (USA) - Google Calendar: Appointment synchronization — the appointment holder's name, appointment note, date and time
  • Bitrix24:CRM synchronization — contact name, phone, e-mail, channel information and opportunity records (the organization's own portal)
  • E-commerce and marketplace platforms: Order and message synchronization — buyer name, phone, e-mail and delivery address; if the organization has enabled automatic replies, the AI response text is sent to the marketplace message channel. Examples: Shopify, Amazon, eBay, Etsy, TikTok Shop, Trendyol, Hepsiburada, n11
  • Kolayturum (Türkiye): Transfer of tour and accommodation pre-registrations — guest information
  • Webhook addresses defined by the organization itself: If the organization defines an automation address (for example Zapier, Make, n8n or its own server), order/contact/appointment events are sent to that address. In this case, the party determining who the recipient is and in which country it is located is the customer organization

In cross-border data transfers, the necessary technical and administrative measures are taken within the scope of Article 9 of the KVKK, and data processing agreements containing standard contractual clauses are applied with the providers. In the set in 1.2, the final authority regarding the use of sub-processors belongs to the customer organization that is the data controller; in the event of a change to this list, organizations are informed in advance.

6. Retention Period

In this section we declare only the destruction and anonymization jobs that actually run on the platform and the statutory retention obligations.

6.1 Time-based automatic destruction and anonymization

In the following categories, destruction or anonymization is applied automatically by scheduled jobs:

  • Integration request records: Deleted after 30 days (destruction job running daily)
  • Webhook event records: Deleted after 60 days (destruction job running daily)
  • Customer memory summaries: For records with no activity for 6 months, the summary and topic headings are anonymized by a job running weekly

6.2 Statutory retention obligations

The following records are retained for the period stipulated by the relevant legislation even if a deletion request is made (KVKK art. 7/1 and art. 28):

  • Commercial books and documents: 10 years (Turkish Commercial Code)
  • Invoices and financial records: 10 years (Tax Procedure Law)
  • Electronic communication records: 3 years (Law No. 5651)

6.3 Destruction upon request

Data that does not fall within the scope of 6.1 is retained for as long as the service relationship continues and is destroyed upon a deletion request. The request is processed by a job running daily; for this reason the start of the destruction process may take up to 24 hours. In an organization-wide deletion request, the relevant records are permanently deleted from the database; in a contact-level deletion request, the name, phone, e-mail and custom fields as well as the message bodies are masked (statistical totals that cannot be linked to a person are preserved). Marketing data is not used for marketing purposes once consent is withdrawn.

In the set in 1.2, determining the retention period is within the authority of the customer organization that is the data controller; inTusell destroys the data upon the organization's instruction. When the service agreement ends, the data in this set is returned or destroyed in accordance with the organization's instruction.

7. Your Rights (KVKK Article 11)

Within the scope of Article 11 of the KVKK you have the following rights:

  • a) To learn whether your personal data is being processed
  • b) To request information if your personal data has been processed
  • c) To learn the purpose of the processing of your personal data and whether they are used in accordance with their purpose
  • ç) To know the third parties to whom your personal data is transferred domestically or abroad
  • d) To request the rectification of your personal data in the event that they have been processed incompletely or inaccurately
  • e) To request the erasure or destruction of your personal data within the framework of the conditions stipulated in Article 7 of the KVKK
  • f) To request that the operations carried out pursuant to subparagraphs (d) and (e) be notified to the third parties to whom your personal data has been transferred
  • g) To object to a result arising against you through the analysis of your processed data exclusively by means of automated systems
  • h) To claim compensation for the damage in the event that you suffer damage due to the unlawful processing of your personal data

8. Application Methods

For the set for which inTusell is the data controller (1.1), you may apply to us directly through the following methods in order to exercise your rights. For the set in 1.2, you must direct your application first to the organization that collects your data; we forward such requests that reach us to the relevant organization and act upon that organization's instruction:

  • E-mail:You may send an e-mail with the subject "KVKK Information Request" to alikemal@intusell.com
  • Through the Platform: With the Download My Data (JSON)function on the Panel > Settings screen you can instantly download a copy of your data, and with the Delete tenant function you can create a deletion request

Your application must include information verifying your identity and must state your request clearly and comprehensibly. Your application will be concluded free of charge as soon as possible and within 30 days at the latest, depending on the nature of your request. However, in the event that the process requires an additional cost, the fee in the tariff determined by the Personal Data Protection Board may be charged.

In the event that your application is rejected, the response given is found insufficient or no response is given to the application within the time limit; you have the right to file a complaint with the Personal Data Protection Board within 30 days from the date on which you learn of the response and in any case within 60 days from the date of the application.

9. Data Breach Notification Procedure

In the event that a data breach affecting the security of your personal data is detected, the following procedure is applied. The steps below are carried out directly by inTusell for the set for which inTusell is the data controller (1.1). In the set in 1.2, inTusell notifies the customer organization of the breach without delay; the obligation to notify the Board and the data subjects belongs to the organization that is the data controller, and inTusell provides technical support to the organization in these notifications:

  • Detection and Assessment: The incident is examined within 24 hours at the latest after the breach is detected
  • Notification to the Board: Pursuant to KVKK art. 12/5, the data breach is notified to the Personal Data Protection Board within 72 hours at the latest
  • Notification to Data Subjects: The data subjects affected by the breach are informed as soon as possible by e-mail and by in-platform notification
  • Content of the Notification: The date and scope of the breach, the affected data categories, the possible consequences and the measures taken are clearly stated
  • Corrective Measures: The necessary technical and administrative measures are immediately implemented in order to prevent a recurrence of the breach