Privacy and Security Policy
Last updated: 17 September 2026 · Version 1.9
This is a courtesy translation; in case of conflict the Turkish version prevails. Turkish version: Gizlilik ve Güvenlik Politikası.
This policy explains in plain language what happens to your data when you use Sistemiya. The detailed notice required by law is set out in the KVKK Privacy Notice; where the two conflict, the KVKK Privacy Notice prevails.
Who This Policy Covers
Sistemiya comes into contact with the data of two different groups, and its role is different for each:
| Who | Sistemiya's role | What it means |
|---|---|---|
| Businesses that sign up to Sistemiya and their employees | Data controller | We determine and protect your account, subscription and billing data |
| End customers who write to that business (for example, a clinic's patient) | Data processor | We process the data only on the business's instructions; the business is the controller |
If you have written to a business via WhatsApp, Instagram or Messenger, the controller of your data is the business you wrote to. You should direct your requests to it first; Sistemiya fulfils those requests on the business's behalf.
What Data We Collect
- Account information: first name, last name, e-mail, telephone, user role.
- Business and billing information: trade name, tax information, subscription plan, billing records.
- Conversation data: the content of messages received via WhatsApp, Instagram DM, Facebook Messenger and e-mail; your app-scoped user ID on those channels.
- Appointment data: date, time, selected service, staff member and any notes.
- Knowledge base content: documents the business uploads to teach the assistant.
- Technical data: IP address, session cookie, browser and device information, error and security logs.
What we do not collect: card numbers (processed in the payment provider's own secure environment; they never enter our servers), advertising tracking IDs, cross-site tracking data, location data.
Why We Process It
Every processing activity has a legal basis; all of them are listed in a table in the KVKK Privacy Notice. In short: opening your account and providing the service (contract), billing and tax records (legal obligation), security and abuse prevention (legitimate interest), optional promotional messages (explicit consent).
We do not profile or score you. The AI assistant books appointments, answers questions and provides information; it does not produce any automated decision that has legal effects on you.
Who We Share Data With
Data is transferred only to the providers needed for the service to work, and only to the extent needed. The full list, with the processing purpose and location, is on the Sub-processor List page.
We do not sell your data. No personal data is transferred to advertising networks, data brokers or third-party marketers.
Where Data Is Hosted
Sistemiya's application servers, database and file storage are hosted in the European Union (Frankfurt, Germany). Payments are processed on the infrastructure of a payment institution in Türkiye.
Every transfer outside Türkiye — hosting included — is a transfer abroad within the meaning of KVKK Article 9 and is subject to the safeguards under the "Transfers Abroad" heading below. To avoid any misleading statement, we say it plainly: data is not kept in Türkiye. The application servers, database and file storage are in the EU; AI processing (primary provider Anthropic; OpenAI if the main model is moved to OpenAI; OpenAI or Google through OpenRouter if it is moved to OpenRouter) and the e-mail sending and receiving infrastructure (Resend) are in the USA — e-mail content and delivery logs are kept by Resend for 30 days. The list of recipients and their locations is on the Sub-processor List page.
When a business connects its own mailbox with a Google or Microsoft account, e-mails are read directly from that provider's API and replies are sent from there; for this access Sistemiya requests only read and send permissions and does not obtain permission to delete or modify the mailbox. Our Limited Use statement for Google data: we comply with the Limited Use requirements of the Google API Services User Data Policy — data is processed only for the user-facing feature, is not used for advertising or sale, is not used for model training, and human access is limited to security, legal and user-consent cases.
Transfers Abroad
Article 9 of Law No. 6698, as amended by Law No. 7499, sets out a three-step order for transfers abroad:
- Adequacy decision (Art. 9/1) — transfer to a country the Board has declared to provide adequate protection.
- Appropriate safeguards (Art. 9/2) — where there is no adequacy decision; a standard contract, binding corporate rules, a written undertaking or an international agreement.
- Incidental cases (Art. 9/6) — only one-off cases that are not recurring.
Sistemiya's transfers are regular and continuous; the incidental-case exception is therefore not relied on. These transfers will be based on the appropriate safeguards under KVKK Art. 9/2; the signing process for the standard contracts published by the Board is under way. Under Article 9/5 of the Law, each signed contract is notified to the Personal Data Protection Authority within the period set by the legislation from the date of signature.
Security Measures
The technical and administrative measures we take:
- Tenant isolation: each business's data is separated at database level with Row-Level Security; one business's query technically cannot reach another's rows.
- Encryption in transit: all traffic is encrypted with TLS; the site is served over HTTPS only.
- Encryption of secrets: messaging and calendar access keys are stored encrypted (Fernet) in the database; they are not kept in plain text or written to logs. Passwords are stored as one-way hashes. Message content is not encrypted in the database; it is protected by isolation between businesses, role-based access and deletion at the end of the retention period.
- Session security: session cookies are issued with the HttpOnly, Secure and SameSite flags; a separate check is applied against cross-site request forgery.
- Verification of incoming requests: notifications from messaging providers are verified by signature (HMAC-SHA256); a request whose signature does not match is not processed.
- Separation of privileges: the platform administration screen and customer data run under separate database roles; the administration screen cannot read businesses' customer records and messages, every access is written to a separate audit log with who–what–when details; there is no feature for the administration side to log in to a customer account (impersonation).
- Audit log: critical operations on accounts and data are recorded with who–what–when details.
- Least privilege: employee access is role-based and granted only for as long as needed.
No system offers absolute security. If you notice a security vulnerability, report it to destek@sistemiya.com; we will not take legal action against researchers who report in good faith.
What We Do in Case of a Breach
If a personal data breach is detected:
- The breach is contained immediately and its scope is determined.
- Affected businesses are notified without delay and within 24 hours at the latest, together with the nature of the breach, the affected data categories, the approximate number of records, the likely consequences and the measures taken. This period is set so that the business can prepare its 72-hour notification to the Board; details are in the Sub-processor List.
- For data of which Sistemiya is the controller (business accounts, site visitors), the Personal Data Protection Board is notified within 72 hours of our becoming aware of the breach; affected persons are informed as soon as reasonably possible. For businesses' customer data, notification to the Board is the responsibility of the business as controller.
How Long We Keep It
Retention periods vary by data type, and all of them are in the table in the KVKK Privacy Notice. For example: messaging content is deleted after the period chosen by the business, at the latest after 12 months (the contact record is kept for the duration of the relationship), application error logs are kept for at most 90 days, and financial records are kept for the period required by tax legislation.
Your Rights
Under KVKK Article 11 you have the right to learn whether your data is processed, to request information, to have it corrected or deleted, to learn the persons to whom it has been transferred, to object to automated processing and to claim compensation for your damage.
You can do it yourself: from Ayarlar → KVKK (Settings → KVKK) in the panel you can download your data in machine-readable form or start a deletion request. For written applications: destek@sistemiya.com. Applications are concluded within 30 days at the latest.
Children's Data
Sistemiya does not provide services directly to persons under 18 and does not knowingly collect data from them. If you believe a child's data has been processed without consent, report it to destek@sistemiya.com; the data is deleted after verification.
Cookies
No advertising or tracking cookies are used on the site. For details see the Cookie Policy.
Changes to This Policy
When the policy is updated, the date and version at the top of the page change. Significant changes are announced by e-mail or panel notification before they take effect.
Contact
- Data protection and applications: destek@sistemiya.com
- Security reports: destek@sistemiya.com
- General support: destek@sistemiya.com
If you are not satisfied with the outcome of your application, your right to lodge a complaint with the Personal Data Protection Authority is reserved.