Last updated · 24 July 2026
KVKK Disclosure Notice
This notice is prepared under article 10 of Turkish Personal Data Protection Law no. 6698 (KVKK) to inform you about the personal data processed by Eagvio.
Identity of the data controller
The data controller under the law is Eagvio. For applications and questions: [email protected]
The data controller's registered trade name, address and tax details appear on the invoice issued for the subscription and in the contract documents.
Allocation of roles
Eagvio is the data controller for the account and subscription data of the businesses that are its own customers.
For the data of end customers a business messages on WhatsApp, the business itself is the data controller; Eagvio processes that data on the business's behalf and instructions.
In practice this means the business decides the purpose and means of processing end-customer data, while Eagvio only provides the software infrastructure.
Categories of personal data processed
Identity and contact data: name, business name, email address, phone number.
Customer transaction data: subscription plan, order and invoice records, support requests.
Transaction security data: IP address, session and login records, device and browser information.
Communication content: the content of WhatsApp messages between the business and its end customers, including any images sent, as needed to run the sales assistant.
Request and feedback data: information shared through the demo form and support correspondence.
Processing of special categories of personal data is not intended. Businesses are expected not to share such data in message content.
Purposes of processing
Conclusion and performance of the service agreement: opening accounts, managing subscriptions, invoicing and providing support.
Running the features of the software: generating replies to incoming messages, recording orders, matching catalog items and preparing payment links.
Ensuring information security: preventing unauthorized access, misuse and fraud, and keeping the associated records.
Improving the service: debugging, performance measurement and reviewing usage statistics.
Meeting legal obligations: record-keeping and retention duties under tax and commercial legislation, and responding to requests from competent authorities.
Method of collection
Data is collected electronically, by automated and partly automated means, through the sign-up and demo forms on the website, entries made in the panel, messages arriving over the WhatsApp integration, and support correspondence.
Legal grounds for processing
Processing is necessary for the conclusion or performance of a contract (KVKK art. 5/2-c): account, subscription, invoicing and service operation data.
Processing is mandatory for the data controller to fulfil a legal obligation (KVKK art. 5/2-ç): retention of financial records, responding to authorities.
Processing is necessary for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject (KVKK art. 5/2-f): information security, preventing misuse, improving the service.
Processing is mandatory for the establishment, exercise or protection of a right (KVKK art. 5/2-e): keeping records that may serve as evidence in a dispute.
Explicit consent (KVKK art. 5/1): non-essential cookies and commercial electronic messages, where separate consent is obtained. Consent can be withdrawn at any time.
Special categories of personal data are not intended to be processed; if such data must exceptionally be processed, the conditions in KVKK art. 6 are observed.
Transfer of personal data
Domestic transfers (KVKK art. 8): to payment institutions, accounting and invoicing providers, and hosting and infrastructure providers, to the extent needed to deliver the service; and to competent public authorities where legislation requires it.
International transfers (KVKK art. 9): to WhatsApp / Meta for the messaging infrastructure and to AI model providers for reply generation. These transfers are limited to the minimum data needed to deliver the service.
For transfers to countries without an adequacy decision, one of the appropriate safeguards provided by the law is relied on; where that is not possible, the explicit consent of the data subject is sought.
Personal data is never sold to third parties for advertising or marketing.
Retention
Personal data is kept for as long as necessary for the purpose it was processed for, and for the limitation and retention periods set out in applicable legislation.
When a subscription ends, account and content data is deleted, destroyed or anonymized within a reasonable time, except where a legal retention obligation applies.
Financial records are retained for the period required by tax legislation.
Data security
Technical and organizational measures such as access authorization, encryption in transit, logging and regular review are applied to prevent unlawful processing of and unlawful access to personal data.
No system offers absolute security, but we take reasonable care to keep the risk as low as possible.
Your rights as a data subject
Under KVKK art. 11, everyone may apply to the data controller to learn whether their personal data is being processed and, if so, to request information about it.
To learn the purpose of processing and whether the data is used in line with that purpose, and to know the third parties to whom data is transferred in Türkiye or abroad.
To request correction of incomplete or inaccurate data, and to request deletion or destruction under the conditions in article 7 of the law.
To request that correction, deletion and destruction be notified to the third parties the data was transferred to.
To object to an outcome against the data subject arising from analysis carried out solely by automated systems.
To claim compensation for damage suffered as a result of unlawful processing of personal data.
How to apply
To exercise your rights, send your request to [email protected]. Please state your name, contact details and the subject of your request clearly.
Applications are concluded within thirty days at the latest, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller. If the process incurs a cost, the fee set by the Board's tariff may be charged.
If an application is rejected, the response is found insufficient, or no response is given in time, a complaint may be filed with the Personal Data Protection Board.
Changes
This notice may be updated as legislation and the service evolve. The current version is always published on this page.
Contact
Questions: [email protected]
