Sub-processor List
Last updated: 28 September 2026 · Version 3.15
This is a courtesy translation; in case of conflict the Turkish version prevails. Turkish version: Veri İşleyici Listesi.
This list transparently discloses the sub-processors Sistemiya uses to provide the service. The list is kept up to date to meet the transfer obligations under KVKK Articles 8 and 9.
The full notice on the processing is in the KVKK Privacy Notice, and its plain-language summary and the security measures are in the Privacy and Security Policy.
Controller and Processor Relationship
- Data controller: The business using the platform (clinic, accounting firm, law office, etc.) is the data controller for its own customer data.
- Data processor: Sistemiya is the data processor that processes this data on the business's instructions.
- Sub-processor: Third-party providers that Sistemiya uses to carry out a specific part of the service.
Sub-processors
| Provider | Purpose | Location | Transfer regime |
|---|---|---|---|
| Hostinger | Server, database and file hosting | Germany (EU) | Abroad (under KVKK Art. 9) |
| Anthropic | AI assistant message processing — primary AI provider (AI_PROVIDER=anthropic, the setting in force) | USA | Abroad (under KVKK Art. 9) |
| OpenAI | AI assistant message processing — active only when the primary provider is moved to OpenAI (AI_PROVIDER=openai); listed automatically in the privacy notice once activated | USA | Abroad (under KVKK Art. 9) |
| OpenRouter | Model routing for AI assistant message processing — active only when the primary provider is moved to OpenRouter (AI_PROVIDER=openrouter); requests are routed only to OpenAI and Google endpoints and are not sent to endpoints that use data for model training; listed automatically in the privacy notice once activated | USA | Abroad (under KVKK Art. 9) |
| Google (Gemini models) | AI assistant message processing — only when a Google model is selected as the main or fallback model while AI_PROVIDER=openrouter | USA / global edge locations | Abroad (under KVKK Art. 9) |
| Meta | WhatsApp Business, Instagram DM and Messenger messaging infrastructure | EU | Abroad (under KVKK Art. 9) |
| Resend | E-mail sending and receiving | USA | Abroad (under KVKK Art. 9) |
| Cloudflare R2 | File and image storage | EU | Abroad (under KVKK Art. 9) |
| Cloudflare Turnstile | Bot verification | EU | Abroad (under KVKK Art. 9) |
| Sentry | Error and performance monitoring | EU | Abroad (under KVKK Art. 9) |
| PayTR | Payment infrastructure (iFrame + 3D Secure) | Türkiye | Domestic |
| Enterprise single sign-on (SSO) | USA | Abroad (under KVKK Art. 9) | |
| Google (Places API) | Searching for potential customer businesses — Sistemiya's own sales activity; in this processing Sistemiya acts as data controller on the basis of legitimate interest (KVKK Art. 5/2-f), and no tenant customer data is sent | USA | Abroad (under KVKK Art. 9) |
| Google (Calendar) | Writing the appointment to the staff member's Google Calendar (service, customer name, branch; the customer's e-mail, if any, is added as a guest) — only if the business has connected its calendar; telephone and notes are not sent in the default scope | USA | Abroad (under KVKK Art. 9) |
| Microsoft (Calendar) | Writing the appointment to the staff member's Outlook calendar — same scope as the Google (Calendar) row; only if the business has connected its calendar | EU (Ireland) | Abroad (under KVKK Art. 9) |
| Google (Gmail API) | Reading the connected Gmail mailbox and sending replies — only if the business used "Google ile bağla" ("Connect with Google") | USA | Abroad (under KVKK Art. 9) |
| Microsoft (Graph) | Reading the connected Outlook / Microsoft 365 mailbox and sending replies — only if the business used "Microsoft ile bağla" ("Connect with Microsoft") | EU (Ireland) | Abroad (under KVKK Art. 9) |
| Microsoft | Enterprise single sign-on (Entra ID) | EU (Ireland) | Abroad (under KVKK Art. 9) |
| Mistral AI | Fallback AI model (while the primary provider Anthropic is unreachable) — active only when the AI_FALLBACK_* environment variables are set; listed automatically in the privacy notice once activated | France (EU) | Abroad (under KVKK Art. 9) |
| TypeSafe (Jev) | Classifying the intent of a message (whether a reply is needed, request for a human, opt-out, sensitive topic); it does not generate text, pseudonymised text is sent, accessed through OpenRouter — active only when one of the JEV_MOD_* settings that carries customer messages is activated; listed automatically in the privacy notice once activated | USA | Abroad (under KVKK Art. 9) |
| Cloudflare (network layer) | Domain name resolution, traffic routing, TLS termination and DDoS protection — all web traffic to the system passes through the Cloudflare network | EU / global edge locations | Abroad (under KVKK Art. 9) |
| Apple (APNs) | Push notification delivery in the iOS app — only if the business has turned on notifications in the iOS app; the notification title and short text are delivered via Apple | USA | Abroad (under KVKK Art. 9) |
| Google (FCM), Mozilla, Microsoft (Web push services) | Web push notification delivery — only if the business's staff have turned on notifications in the browser; the notification title and short text pass through the browser vendor's push service | USA / EU | Abroad (under KVKK Art. 9) |
| Twilio | Voice assistant telephone line — carrying the call; the caller number and call audio pass through Twilio, the audio is not stored at Sistemiya — only if the business has enabled the voice assistant | USA | Abroad (under KVKK Art. 9) |
| Deepgram | Voice assistant — real-time transcription of the call audio — only if the business has enabled the voice assistant | USA | Abroad (under KVKK Art. 9) |
| Microsoft (Azure Speech Service) | Voice assistant — voicing the assistant's reply text (default speech engine); only the reply text is sent, not the caller's voice — only if the business has enabled the voice assistant | Sweden (EU) | Abroad (under KVKK Art. 9) |
| ElevenLabs | Voice assistant — voicing the reply text; active instead of Azure only when the speech engine is moved to ElevenLabs | USA | Abroad (under KVKK Art. 9) |
| The business's own mail server (IMAP/SMTP) | Reading the connected mailbox and sending replies — only if the business connected its own server instead of Gmail/Microsoft; the server is with the provider chosen by the business | Depends on the business's provider | Subject to the business's contract |
Single sign-on is enabled only on the Enterprise plan and at the business's choice; when SSO is used, the data transferred to Google and Microsoft is limited to e-mail address, user ID and display name.
Mapping of Data Categories to Processors
| Data category | Processor(s) it is transferred to |
|---|---|
| All application and database content (hosting) | Hostinger |
| Message content (WhatsApp, Instagram DM, Messenger, e-mail) | Primary AI provider (Anthropic; OpenAI if AI_PROVIDER=openai; OpenAI or Google through OpenRouter if AI_PROVIDER=openrouter), Meta, Resend, Google (Gmail API), Microsoft (Graph); TypeSafe for intent classification once activated |
| Connected mailbox content (incoming/outgoing e-mails, attachments) | Hostinger (Frankfurt, Germany — on the business's instructions); the primary AI provider (USA) for AI summaries/replies |
| Knowledge base document content (the relevant sections during reply generation) | Primary AI provider |
| Telephone number | Meta (WhatsApp); Twilio if the voice assistant is on |
| Telephone call audio (real time; not stored) | Twilio, Deepgram |
| Voice assistant reply text | Microsoft (Azure Speech Service) or, if selected, ElevenLabs |
| Appointment calendar entry (service, customer name, branch, customer e-mail if any) | Google (Calendar), Microsoft (Calendar) — only if the business has connected its calendar |
| Instagram / Messenger app-scoped user ID | Meta |
| E-mail address | Resend |
| Files and images | Cloudflare R2 |
| Anonymised IP address | Sentry, Cloudflare Turnstile |
| Payment data (card details do not enter our servers) | PayTR |
For data obtained through Google APIs, Sistemiya complies with the Limited Use requirements of the Google API Services User Data Policy: the data is processed only for the inbox, summary and reply features the business sees in the panel; it is not used for advertising, is not sold to third parties and is not used for AI model training; human access is limited to security, legal necessity or the business's express consent.
Scope of Data Sent to the AI Provider
The text sent to the primary AI provider (and to the fallback model and the TypeSafe classifier, if active) is pseudonymised: the customer's name, telephone number, e-mail address, Turkish ID number, IBAN and card number are replaced with placeholders (such as TEL_1, MUSTERI_ADI) before sending. The mapping that makes re-identification possible stays only in Sistemiya's own database (Frankfurt, Germany) and is not given to the provider in any form; the mapping is deleted together with the conversation at the end of that conversation's retention period. The same substitution is applied in tool calls: the telephone number needed for the appointment is given to the model as a placeholder, and only the operation on our own server sees the real number.
This is not anonymisation. Because the mapping is in the hands of the controller/processor, the data remains personal data within the meaning of KVKK; the transfer falls under Article 9 and is subject in full to the safeguard procedure described below (standard contract and notification to the Authority). What pseudonymisation provides is not the removal of the obligation but the practical application of the proportionality principle in Article 4, and that content on the provider's side remains unidentifiable in the event of a breach.
Known limits, for transparency: names of third parties written by the customer in free text, numbers written out in words and names in documents the business uploads to its knowledge base are not converted into placeholders. The subject of the conversation (request, complaint, preference) is also sent to the provider.
Transfer Safeguards
All transfers outside Türkiye (including to the EU and the USA) count as transfers abroad within the meaning of KVKK Article 9. Article 9, as amended by Law No. 7499, provides, in order, for an adequacy decision (Art. 9/1), appropriate safeguards (Art. 9/2 — standard contract, binding corporate rules, written undertaking) and, only for non-recurring cases, the incidental case (Art. 9/6).
Because the transfers here are regular and continuous, the incidental-case exception is not relied on; these transfers will be based on the appropriate safeguards under KVKK Art. 9/2, and the signing process for the Board standard contract published by the Personal Data Protection Board is under way. Each signed contract is notified to the Personal Data Protection Authority within the period set by the legislation from the date of signature.
The transfer to the payment infrastructure takes place within Türkiye; it is not subject to the transfer-abroad regime.
In AI processing, the data transferred is kept limited to the purpose of processing. It is recommended not to upload special-category (for example, health) data to the knowledge base; the business concerned is responsible for personal data in the uploaded content and for its legal ground.
AI Transparency
In conversations conducted on behalf of a business, Sistemiya applies the following transparency measures towards customers at software level. These measures cannot be turned off through business settings:
-
Notice: At the first contact via WhatsApp, Instagram DM, Messenger or e-mail and in the first reply after a gap of more than 30 days, the customer is told that they are communicating with an AI assistant. The notice is added by the software independently of the instructions that steer the assistant's behaviour; no instruction given to the assistant can suppress it.
-
Handover to a human: When the customer says they want to speak to a representative, the request is passed to the business and the assistant stops replying in that conversation.
-
Separation from marketing: Appointment notifications (confirmation, reminder, rescheduling, cancellation) are transactional messages; no promotional or campaign content is added to them.
-
Business-specific privacy notice page: For each business, a customer privacy notice template is generated that is filled with the legal identity the business entered in the panel (legal name, address, application e-mail) (
/r/{business}/aydinlatma), and this link is added to the sentence in the first message. Which version was shown to which customer and when is recorded. The business may choose to use its own text.
This template is not legal advice; businesses are themselves responsible for the content of their privacy notices.
Breach Notification
If a personal data breach is detected at a sub-processor or in Sistemiya's infrastructure, the affected businesses are notified without delay and within 24 hours at the latest. So that the business can prepare its 72-hour notification to the Board, the notice includes the nature of the breach, the affected data categories, the approximate number of records, the likely consequences and the measures taken.
The business's notification to the Board as data controller is made through the Data Breach Notification Module at https://ihlalbildirim.kvkk.gov.tr/.
Changes to the List
Businesses are notified by e-mail 30 days before a new sub-processor is added to the list. The business may exercise its right to object; in case of objection, the agreement may be terminated without compensation.
Contact
- Data processing questions: destek@sistemiya.com
- Urgent breach notification: destek@sistemiya.com