Privacy Policy

Last updated: July 30, 2026

1. Introduction

This Privacy Policy is issued by Emirhan Yıldırım (Turkish Tax ID: 9551453885), operator of the Deskivy service ("Service") at deskivy.com, acting as "data controller" under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). For our international users, we aim to align our practices, where applicable, with the core principles of the EU General Data Protection Regulation ("GDPR"). This Policy is provided in both Turkish and English; in case of any conflict or inconsistency between the two versions, the Turkish version shall prevail.

2. Information We Collect

Account information: Name, email address, and password (stored hashed with bcrypt).

Company data: The business name, widget configuration, and preferences you provide.

Knowledge base content: Text, PDF, and DOCX files you upload.

Chat data: Conversation content exchanged through the widget, session information, and response latency.

Integration data: Access tokens for channels you connect (Instagram, Telegram, WhatsApp, etc.), stored encrypted, and message content received through those channels.

Payment data: Billing details and transaction records; your card details are not stored by us and are processed directly by PayTR.

Usage/log data: Technical data such as IP address, browser type, and access timestamps.

Cookies: Described in Section 9 below.

3. Purpose and Legal Basis

We process your data on the basis of performance of a contract (KVKK Art. 5/2-c), compliance with legal obligations (Art. 5/2-ç), our legitimate interests (Art. 5/2-f, e.g., security and fraud prevention), and, where required, your explicit consent (e.g., marketing cookies).

4. Channel Integrations and Meta / Instagram Data Usage

When you connect an Instagram account via Meta OAuth, we process your Instagram User ID, username, OAuth access tokens, and direct messages sent to your connected account. This data is used solely to generate AI responses on your behalf and to send those responses via the Instagram Messaging API; it is not used for advertising or sold to third parties. These operations comply with the Meta Platform Terms and Meta Developer Policies.

5. Data Sharing and Sub-processors

We do not sell your personal data. To provide the Service, your data is shared with the following sub-processors, strictly for the purposes stated:
  • Google (Gemini API) and OpenAI — process your message content to generate AI responses
  • PayTR — processes payment transactions
  • Brevo (Sendinblue) — sends verification and notification emails
  • Channel integrations you connect (Telegram, WhatsApp, Slack, Discord, Google Calendar, Shopier, Shopify, etc.) — the current list is available on the Integrations page in your dashboard and may be updated as new channels are added, without requiring a change to this Policy's text

We may also disclose data to competent authorities where required by law or court order.

6. International Data Transfers

Our servers are hosted within the European Union. However, our AI providers (Google, OpenAI) may process data outside the EU (e.g., in the United States). Such transfers are carried out in accordance with KVKK Art. 9 and applicable law, relying on the providers' standard contractual clauses and security commitments.

7. Data Retention

Your account and company data are retained for as long as your account remains active. Chat logs are retained indefinitely while your account is active, for reporting and service-quality purposes. You may request deletion of your account at any time from your dashboard; this starts a 30-day countdown during which you can cancel the request and your account continues to function normally. If the request is not cancelled, your personal data (name, username, email) is anonymized and your account is permanently deactivated at the end of this period. Payment and invoice records are not deleted and are retained for the period required by Turkish tax law (VUK), but are no longer linked to identifiable personal data once your account has been anonymized.

8. Data Security

All integration credentials and access tokens are encrypted at rest using AES-256 (Fernet). Your password is hashed with bcrypt. Data is transmitted over HTTPS/TLS. Access is protected via JWT-based authentication and rate limiting.

9. Cookies

Our website uses the following cookies/tracking tools:
  • lng (essential): Remembers your language preference, stored for 1 year, cannot be disabled
  • Meta Pixel (analytics/marketing): Measures advertising performance; active only on our marketing site (deskivy.com), and only once you consent

Analytics/marketing cookies are only loaded after you give consent via our cookie banner. You can accept, reject, or change your choice at any time using the "Cookie Preferences" link in the footer. No marketing or analytics cookies are used once you are logged into the application dashboard; authentication relies solely on a session token.

10. Your Rights

Under KVKK Art. 11, you have the right to learn whether your data is processed, request information about such processing, learn whether it is used in accordance with its purpose, know the third parties to whom it is transferred domestically or abroad, request correction of incomplete/inaccurate data, request deletion/destruction of your data, and request that these actions be notified to third parties to whom your data was transferred. Users accessing from the EU may exercise equivalent GDPR rights (access, rectification, erasure, portability, objection) by contacting us at info@deskivy.com.

11. Notice to Widget Visitors

Businesses that use Deskivy embed a chat widget on their own websites. When you interact with that widget, you are chatting directly with that business, not with Deskivy. In this context:
  • The business you are chatting with is the "data controller" of your data; Deskivy acts as a "data processor" on that business's behalf, solely to provide the Service
  • Your messages are processed together with that business's knowledge base to generate an AI-powered response, and may be transmitted to AI providers such as Google Gemini or OpenAI
  • To exercise your data rights, we recommend contacting the business you chatted with first; you may also reach us directly at info@deskivy.com

12. Breach Notification

If a security incident affecting your personal data is identified, we will assess the situation under KVKK and applicable law and notify the competent authority and affected users without undue delay.

13. Changes to This Policy

We may update this Policy from time to time. For material changes, we will notify you via your registered email address or an in-dashboard notice that the Policy has been updated; the current text is always available on this page.

14. Contact

For questions about this Privacy Policy or to exercise your data rights:

Email: info@deskivy.com