TalkUnify

Privacy Policy

Sürüm v2.1 · Yürürlük: 2026-09-01

PRIVACY POLICY

Version: v2.0

Effective date: 1 September 2026

Supersedes: v1.0 (29 June 2026)

> This is not a translation of our Turkish policy. Turkish law (KVKK) and the

> GDPR differ in legal bases, in the rights they grant and in how transfers

> are justified. Where they differ, this document follows the GDPR.

---

1. WHO WE ARE

| | |

|---|---|

| Controller | Niyazi Öksüz (sole proprietorship) |

| Trading as | Talk Unify |

| Address | Mevlana Mahallesi, Adaçayı Sokak No: 8, İç Kapı No: 1, Sancaktepe / İstanbul, Türkiye |

| Tax ID | 6530253433 |

| Email | kvkk@talkunify.com |

| Website | talkunify.com |

We are established in Türkiye, outside the EEA.

1.1. EU representative — Article 27

TalkUnify is established in Türkiye and directs its services to the Turkish

market. We do not intentionally offer goods or services to, nor monitor the

behaviour of, data subjects in the European Union. Accordingly, Article 3(2)

GDPR does not apply and we are not required to designate an Article 27

representative in the Union. Should this change, we will designate a

representative before offering services to EU data subjects. For all data

protection matters, `kvkk@talkunify.com` remains the contact point.

1.2. Data Protection Officer

We have not appointed a DPO. Our processing does not consist of large-scale

systematic monitoring of data subjects, nor of large-scale processing of

special categories of data, so Article 37(1) does not require one. Data

protection matters are handled directly by the controller.

---

2. TWO DIFFERENT ROLES — read this first

This is the most important section of this policy, because it determines

who you should contact.

| Data | Our role | Who decides |

|---|---|---|

| Your account with Talk Unify (name, email, billing, usage) | Controller | Us |

| Visitors to `talkunify.com` | Controller | Us |

| Messages you send to a business that uses Talk Unify | Processor | That business |

If you contacted a company through WhatsApp, Instagram, Telegram, email,

web chat, SMS or by phone, and that company uses Talk Unify to handle its

conversations, then that company is the controller of your data. We

process it only on their documented instructions. We cannot delete, correct

or disclose it without them.

In that case, please direct your request to that company. If you do not know

who they are, write to `kvkk@talkunify.com` and we will help you identify

them.

**The rest of this policy describes the data for which we are the

controller.**

---

3. WHAT WE COLLECT AND WHY

| Data | Purpose | Legal basis (Art. 6) |

|---|---|---|

| Name, email, phone, password hash | Creating and securing your account | Contract — 6(1)(b) |

| Company name, address, tax details | Invoicing and legal bookkeeping | Legal obligation — 6(1)(c) |

| Payment status, plan, invoices | Managing your subscription | Contract — 6(1)(b) |

| Login records, IP address, device and browser data | Security, fraud and abuse prevention | Legitimate interests — 6(1)(f) |

| Product usage and feature statistics | Keeping the service running and improving it | Legitimate interests — 6(1)(f) |

| Support correspondence | Answering your requests | Contract — 6(1)(b) |

| Analytics data | Understanding how the product is used | Consent — 6(1)(a) |

| Marketing data | Measuring and targeting advertising | Consent — 6(1)(a) |

| Marketing emails to you | Product news and offers | Consent — 6(1)(a) |

3.1. Our legitimate interests

Where we rely on Article 6(1)(f), our interests are keeping the service

secure and available and preventing abuse. We have weighed these against

your rights and consider the processing proportionate: the data is limited

to what security requires, it is not used to profile you, and you may object

at any time (section 8).

3.2. We do not

by automated means alone (Art. 22)

---

4. AI PROCESSING

The service generates replies using AI providers listed in our

Sub-processors document. Only the message content needed to produce a

reply is sent.

**We have contractually excluded the use of this content for model

training**, and we require the same of our providers.

⚠️ Regional data residency has not been selected with these providers;

requests go to their global endpoints. This means content may be processed

in the United States. See section 6.

---

5. HOW LONG WE KEEP DATA

| Data | Retention |

|---|---|

| Account data | Life of the account |

| After account deletion | Permanently erased within 30 days |

| Invoices and accounting records | 10 years (Turkish Commercial Code / Tax Procedure Law) |

| Security and login logs | 12 months |

| Support correspondence | 3 years |

| Consent records (proof) | 3 years after withdrawal |

| Backups | Rolling window, maximum 90 days |

| Data export files | 24 hours, then deleted automatically |

⚠️ Backups cannot be selectively edited. When you delete data it is

removed from live systems immediately, but an encrypted copy may persist in

backups until that backup expires — at most 90 days. We state this plainly

rather than implying instant global erasure.

Erasure runs on automated schedules, not on request-by-request manual

action.

---

6. INTERNATIONAL TRANSFERS

Our servers are in Germany (Düsseldorf) — inside the EEA. However, some

of our sub-processors are outside the EEA, primarily in the United States.

| Destination | Safeguard |

|---|---|

| Germany (hosting) | Within the EEA — no transfer safeguard needed |

| United States | Standard Contractual Clauses (Art. 46(2)(c)), with supplementary measures where appropriate |

| Other third countries | Standard Contractual Clauses |

⚠️ We rely on Article 46 safeguards, not on adequacy decisions or on

derogations under Article 49. Where a provider participates in the EU–US

Data Privacy Framework, that participation is treated as an additional

safeguard and not as a substitute for the clauses.

The full list of recipients, their countries and what is transferred is in

our Sub-processors document.

You may request a copy of the relevant safeguards by writing to

`kvkk@talkunify.com`.

---

7. SECURITY

We apply: TLS in transit, encryption of stored credentials, encrypted

backups, role- and tenant-based access control, audit logging,

multi-factor authentication for administrators, bot protection, and

automated erasure schedules.

7.1. What we have not yet implemented — stated openly

These are on our roadmap. We list them because a security section that

implies protections we do not have is worse than no section at all.

---

8. YOUR RIGHTS

Under Articles 15–22 GDPR you have the right to:

| Right | Article |

|---|---|

| Access your data and receive a copy | 15 |

| Rectification of inaccurate or incomplete data | 16 |

| Erasure ("right to be forgotten") | 17 |

| Restriction of processing | 18 |

| Data portability — receive your data in a structured, machine-readable format and have it transmitted to another controller | 20 |

| Object to processing based on legitimate interests | 21 |

| Object to direct marketing — absolute, no balancing | 21(2) |

| Not be subject to solely automated decisions with legal effect | 22 |

| Withdraw consent at any time, without affecting prior lawfulness | 7(3) |

⚠️ Articles 20 and 21 have no direct equivalent under Turkish law. They

are granted here because the GDPR grants them — this is one of the reasons

this document is written separately rather than translated.

8.1. Exercising your rights

Many rights can be exercised immediately in the app, without contacting

us:

| Action | Where |

|---|---|

| Export your data | Profile → Data Management |

| Delete your account and data | Profile → Delete Account |

| Change cookie preferences | Footer → Cookie Preferences |

| Withdraw marketing consent | Profile → Communication Preferences |

| Correct your details | Profile → Account |

Otherwise write to `kvkk@talkunify.com`. We respond within one month,

extendable by two further months for complex requests — we will tell you if

we extend, and why.

Exercising your rights is free of charge. We may charge a reasonable fee,

or refuse, only where a request is manifestly unfounded or excessive, and we

will explain why.

We may ask you to confirm your identity. This protects you: it prevents

someone else obtaining your data.

---

9. COMPLAINTS

You may lodge a complaint with the supervisory authority in your EU or EEA

country of residence, work, or where the alleged infringement occurred

(Art. 77).

⚠️ Because we have no establishment in the Union, the one-stop-shop

mechanism does not apply; your local supervisory authority is competent.

If you are in Türkiye, you may also apply to the Turkish Personal Data

Protection Authority (KVKK). Under Turkish law you must contact us first.

We would appreciate the chance to resolve the matter directly, but this is

not a precondition to your right to complain under the GDPR.

---

10. COOKIES

Analytics and marketing technologies run only with your consent, and

are switched off by default. Details, categories and how to change your

choice are in our Cookie Policy.

---

11. CHILDREN

The service is not directed at children and we do not knowingly collect

data from children under 16. If you believe a child has provided us with

data, write to `kvkk@talkunify.com` and we will delete it.

---

12. CHANGES

We publish the current version at `talkunify.com` with a version number and

effective date. For material changes we notify you in advance, and where the

change affects processing based on consent we ask for your consent again.

---

13. CONTACT

| | |

|---|---|

| Data protection | kvkk@talkunify.com |

| Security incidents | [BREACH ADDRESS TO BE ADDED] |

| General support | destek@talkunify.com |