Privacy Policy
PRIVACY POLICY
Version: v2.0
Effective date: 1 September 2026
Supersedes: v1.0 (29 June 2026)
> This is not a translation of our Turkish policy. Turkish law (KVKK) and the
> GDPR differ in legal bases, in the rights they grant and in how transfers
> are justified. Where they differ, this document follows the GDPR.
---
1. WHO WE ARE
| | |
|---|---|
| Controller | Niyazi Öksüz (sole proprietorship) |
| Trading as | Talk Unify |
| Address | Mevlana Mahallesi, Adaçayı Sokak No: 8, İç Kapı No: 1, Sancaktepe / İstanbul, Türkiye |
| Tax ID | 6530253433 |
| Email | kvkk@talkunify.com |
| Website | talkunify.com |
We are established in Türkiye, outside the EEA.
1.1. EU representative — Article 27
TalkUnify is established in Türkiye and directs its services to the Turkish
market. We do not intentionally offer goods or services to, nor monitor the
behaviour of, data subjects in the European Union. Accordingly, Article 3(2)
GDPR does not apply and we are not required to designate an Article 27
representative in the Union. Should this change, we will designate a
representative before offering services to EU data subjects. For all data
protection matters, `kvkk@talkunify.com` remains the contact point.
1.2. Data Protection Officer
We have not appointed a DPO. Our processing does not consist of large-scale
systematic monitoring of data subjects, nor of large-scale processing of
special categories of data, so Article 37(1) does not require one. Data
protection matters are handled directly by the controller.
---
2. TWO DIFFERENT ROLES — read this first
This is the most important section of this policy, because it determines
who you should contact.
| Data | Our role | Who decides |
|---|---|---|
| Your account with Talk Unify (name, email, billing, usage) | Controller | Us |
| Visitors to `talkunify.com` | Controller | Us |
| Messages you send to a business that uses Talk Unify | Processor | That business |
If you contacted a company through WhatsApp, Instagram, Telegram, email,
web chat, SMS or by phone, and that company uses Talk Unify to handle its
conversations, then that company is the controller of your data. We
process it only on their documented instructions. We cannot delete, correct
or disclose it without them.
In that case, please direct your request to that company. If you do not know
who they are, write to `kvkk@talkunify.com` and we will help you identify
them.
**The rest of this policy describes the data for which we are the
controller.**
---
3. WHAT WE COLLECT AND WHY
| Data | Purpose | Legal basis (Art. 6) |
|---|---|---|
| Name, email, phone, password hash | Creating and securing your account | Contract — 6(1)(b) |
| Company name, address, tax details | Invoicing and legal bookkeeping | Legal obligation — 6(1)(c) |
| Payment status, plan, invoices | Managing your subscription | Contract — 6(1)(b) |
| Login records, IP address, device and browser data | Security, fraud and abuse prevention | Legitimate interests — 6(1)(f) |
| Product usage and feature statistics | Keeping the service running and improving it | Legitimate interests — 6(1)(f) |
| Support correspondence | Answering your requests | Contract — 6(1)(b) |
| Analytics data | Understanding how the product is used | Consent — 6(1)(a) |
| Marketing data | Measuring and targeting advertising | Consent — 6(1)(a) |
| Marketing emails to you | Product news and offers | Consent — 6(1)(a) |
3.1. Our legitimate interests
Where we rely on Article 6(1)(f), our interests are keeping the service
secure and available and preventing abuse. We have weighed these against
your rights and consider the processing proportionate: the data is limited
to what security requires, it is not used to profile you, and you may object
at any time (section 8).
3.2. We do not
- Sell your personal data
- Use your content, or your customers' messages, to train AI models
- Make decisions producing legal or similarly significant effects about you
by automated means alone (Art. 22)
---
4. AI PROCESSING
The service generates replies using AI providers listed in our
Sub-processors document. Only the message content needed to produce a
reply is sent.
**We have contractually excluded the use of this content for model
training**, and we require the same of our providers.
⚠️ Regional data residency has not been selected with these providers;
requests go to their global endpoints. This means content may be processed
in the United States. See section 6.
---
5. HOW LONG WE KEEP DATA
| Data | Retention |
|---|---|
| Account data | Life of the account |
| After account deletion | Permanently erased within 30 days |
| Invoices and accounting records | 10 years (Turkish Commercial Code / Tax Procedure Law) |
| Security and login logs | 12 months |
| Support correspondence | 3 years |
| Consent records (proof) | 3 years after withdrawal |
| Backups | Rolling window, maximum 90 days |
| Data export files | 24 hours, then deleted automatically |
⚠️ Backups cannot be selectively edited. When you delete data it is
removed from live systems immediately, but an encrypted copy may persist in
backups until that backup expires — at most 90 days. We state this plainly
rather than implying instant global erasure.
Erasure runs on automated schedules, not on request-by-request manual
action.
---
6. INTERNATIONAL TRANSFERS
Our servers are in Germany (Düsseldorf) — inside the EEA. However, some
of our sub-processors are outside the EEA, primarily in the United States.
| Destination | Safeguard |
|---|---|
| Germany (hosting) | Within the EEA — no transfer safeguard needed |
| United States | Standard Contractual Clauses (Art. 46(2)(c)), with supplementary measures where appropriate |
| Other third countries | Standard Contractual Clauses |
⚠️ We rely on Article 46 safeguards, not on adequacy decisions or on
derogations under Article 49. Where a provider participates in the EU–US
Data Privacy Framework, that participation is treated as an additional
safeguard and not as a substitute for the clauses.
The full list of recipients, their countries and what is transferred is in
our Sub-processors document.
You may request a copy of the relevant safeguards by writing to
`kvkk@talkunify.com`.
---
7. SECURITY
We apply: TLS in transit, encryption of stored credentials, encrypted
backups, role- and tenant-based access control, audit logging,
multi-factor authentication for administrators, bot protection, and
automated erasure schedules.
7.1. What we have not yet implemented — stated openly
- Application-level encryption at rest for message content and transcripts
- Full disk encryption
- Point-in-time recovery
- Real-time security alerting
These are on our roadmap. We list them because a security section that
implies protections we do not have is worse than no section at all.
---
8. YOUR RIGHTS
Under Articles 15–22 GDPR you have the right to:
| Right | Article |
|---|---|
| Access your data and receive a copy | 15 |
| Rectification of inaccurate or incomplete data | 16 |
| Erasure ("right to be forgotten") | 17 |
| Restriction of processing | 18 |
| Data portability — receive your data in a structured, machine-readable format and have it transmitted to another controller | 20 |
| Object to processing based on legitimate interests | 21 |
| Object to direct marketing — absolute, no balancing | 21(2) |
| Not be subject to solely automated decisions with legal effect | 22 |
| Withdraw consent at any time, without affecting prior lawfulness | 7(3) |
⚠️ Articles 20 and 21 have no direct equivalent under Turkish law. They
are granted here because the GDPR grants them — this is one of the reasons
this document is written separately rather than translated.
8.1. Exercising your rights
Many rights can be exercised immediately in the app, without contacting
us:
| Action | Where |
|---|---|
| Export your data | Profile → Data Management |
| Delete your account and data | Profile → Delete Account |
| Change cookie preferences | Footer → Cookie Preferences |
| Withdraw marketing consent | Profile → Communication Preferences |
| Correct your details | Profile → Account |
Otherwise write to `kvkk@talkunify.com`. We respond within one month,
extendable by two further months for complex requests — we will tell you if
we extend, and why.
Exercising your rights is free of charge. We may charge a reasonable fee,
or refuse, only where a request is manifestly unfounded or excessive, and we
will explain why.
We may ask you to confirm your identity. This protects you: it prevents
someone else obtaining your data.
---
9. COMPLAINTS
You may lodge a complaint with the supervisory authority in your EU or EEA
country of residence, work, or where the alleged infringement occurred
(Art. 77).
⚠️ Because we have no establishment in the Union, the one-stop-shop
mechanism does not apply; your local supervisory authority is competent.
If you are in Türkiye, you may also apply to the Turkish Personal Data
Protection Authority (KVKK). Under Turkish law you must contact us first.
We would appreciate the chance to resolve the matter directly, but this is
not a precondition to your right to complain under the GDPR.
---
10. COOKIES
Analytics and marketing technologies run only with your consent, and
are switched off by default. Details, categories and how to change your
choice are in our Cookie Policy.
---
11. CHILDREN
The service is not directed at children and we do not knowingly collect
data from children under 16. If you believe a child has provided us with
data, write to `kvkk@talkunify.com` and we will delete it.
---
12. CHANGES
We publish the current version at `talkunify.com` with a version number and
effective date. For material changes we notify you in advance, and where the
change affects processing based on consent we ask for your consent again.
---
13. CONTACT
| | |
|---|---|
| Data protection | kvkk@talkunify.com |
| Security incidents | [BREACH ADDRESS TO BE ADDED] |
| General support | destek@talkunify.com |