Privacy Policy
Information on what personal data is collected, why it is processed, how it is protected, who it is shared with, and the rights you hold while using the BotFront service.
Effective date: June 16, 2026
1. Who We Are and What This Policy Covers
botcu is a third-party integration and software (SaaS) service that connects businesses' product/stock sources (Shopify, PlatinMarket or Google Sheets) and messaging channels (Meta WhatsApp Business and/or Telegram) to provide their end-customers with automated answers about stock, products and order status over those channels. The first module offered is the stock assistant named "Stokçu".
- Operator
- Lumio Studio ("BotFront"); the party operating the BotFront platform. Website: https://botfront.com.tr, E-mail: contact@lumiostudio.co.
- Customer-Firm
- The commercial business that purchases BotFront services and integrates its store and WhatsApp number into the system.
- End-Customer
- The natural person who messages the bot over the Customer-Firm's WhatsApp or Telegram line (the Customer-Firm's own customers).
This policy explains, in plain language, the processing of personal data carried out while providing the BotFront service, within the scope of Law No. 6698 on the Protection of Personal Data ("KVKK").
2. Two Data Flows, Two Roles under KVKK
Under the KVKK, BotFront assumes two distinct legal roles depending on the nature of the data processed. This distinction — which determines which party is responsible for which data — is the foundation of this policy.
- Flow 1 — The Customer-Firm's own data (BotFront is the DATA CONTROLLER)
- For the e-mail address the Customer-Firm uses to log in, its subscription and billing information, and its integration credentials, BotFront acts as the "data controller" and processes that data for purposes and by means it determines.
- Flow 2 — The End-Customer's data (BotFront is the DATA PROCESSOR)
- For the End-Customer data transferred into the system by the Customer-Firm (WhatsApp phone numbers, message content, name-surname information, order and stock/product details), the "data controller" is the Customer-Firm. With respect to this data, BotFront acts solely as a "data processor" on the Customer-Firm's written instructions.
The duty to inform the End-Customers under Flow 2 belongs entirely to the Customer-Firm. BotFront is only obliged to provide the Customer-Firm with technical information such as recipient groups and the locations where data is stored/transferred. The details of this legal relationship are set out in the Data Processing Agreement concluded between the parties.
3. What Data We Collect
Data collected from the Customer-Firm (Flow 1 — where BotFront is the Data Controller):
- Account and Identity Information: Login e-mail address, company title, authorised person's name-surname and contact details.
- Billing and Subscription Information: Subscription status and payment-history records processed through the payment service provider (Polar).
- Integration Credentials: Configuration data such as Shopify/PlatinMarket API keys/tokens, store domain, WhatsApp Business number and "phoneNumberId", Telegram bot token, and Google Sheets access (OAuth) information (secret keys and tokens are kept server-side only; sensitive tokens are stored encrypted).
Data obtained from the End-Customer via the Customer-Firm (Flow 2 — where BotFront is the Data Processor):
- WhatsApp phone number and profile name (display name), or Telegram username/user ID and display name.
- Message content sent to the bot and conversation history (session records).
- Order details and the product/stock information queried.
- Processing logs kept to prevent messages from being handled more than once.
botcu does not offer a service directed at children and does not knowingly process Special Categories of Personal Data (health, religion, biometric data, etc.). Should End-Customers share such data in the messages they send to the bot, responsibility rests entirely with the Customer-Firm in its capacity as Data Controller.
4. Why We Process This Data
- Providing the Service: Setting up the bot, enabling store and WhatsApp integrations, and automatically answering End-Customer messages.
- Message Understanding: Analysing the content of incoming messages to produce accurate answers.
- Stock and Order Operations: Answering product queries and recording stock movements.
- Managing billing and subscription processes.
- Ensuring information security, debugging, and preventing misuse of the service.
- Fulfilling legal obligations in full.
The legal bases for the processing are, under KVKK art. 5, the establishment or performance of a contract, the legitimate interests of the data controller, the fulfilment of legal obligations, and, where necessary, Explicit Consent. The legal basis for processing under Flow 2 is determined by the Customer-Firm in its capacity as Data Controller.
5. How We Protect Your Data
In accordance with KVKK art. 12, we take all necessary technical and administrative measures to ensure the security of the personal data processed:
- Encryption: Data is protected in transit via HTTPS/TLS protocols and at rest within our service providers.
- Secret Key Management: Integration tokens and API keys are not embedded in source code; they are kept only in secure server-side environment variables.
- Multi-tenant Isolation: Every data query is scoped to the relevant firm (tenantId); one Customer-Firm accessing another's data is technically prevented.
- Append-only Stock Ledger: Stock movements are never deleted or overwritten; each change is added as a new, reversible record, preserving data integrity and auditability at the highest level.
- Access Control: Access to the admin panel is restricted via secure session cookies and an authorised-administrator whitelist.
It should be noted that no technical measure can guarantee absolute security on the internet. In the event of a Data Breach, the required notifications are made within the statutory period in accordance with the KVKK and the regulations of the Personal Data Protection Board. Possible breaches under Flow 2 — where we act as Data Processor — are reported without delay to the Customer-Firm as Data Controller.
6. Who We Share With (Sub-processors)
To deliver our services without interruption, we make use of the sub-processors and service providers listed below. Some of these providers process data on servers outside Türkiye (see Section 7 for International Transfer processes):
- Google (Vertex AI · Gemini) — US/EU
- The transcription (speech-to-text) and interpretation of message texts and voice messages is processed via the AI model (Gemini). An international transfer takes place in this context.
- Google Firebase / Google Cloud (Cloud Run, Cloud SQL) — US/EU
- Admin-panel configuration/authorisation data (Firestore) and bot runtime and operational data (the service hosted on Cloud Run and Cloud SQL/Postgres) are processed on this infrastructure. An international transfer may take place in this context.
- Vercel — US
- Provides hosting for the admin panel (dashboard). An international transfer takes place in this context.
- Meta / WhatsApp Business API and Telegram Bot API
- Provide the infrastructure for delivering (transporting) WhatsApp and Telegram messages.
- Polar
- Enables the management of subscription and billing processes.
Other than the infrastructure providers listed, your personal data is not sold to third parties and is not shared for marketing purposes, save for a legal obligation or the requests of authorised public authorities.
7. International Data Transfers
Some of the sub-processors listed above (Google, Vercel, Meta and, in certain cases, other infrastructure providers) process data outside the borders of Türkiye. These transfers are carried out within the tiered regime set out in KVKK art. 9: transfer to countries covered by an adequacy decision, or — where no adequacy decision exists — by providing the appropriate safeguards prescribed by law (including the Board's Standard Contract) or relying on the exceptions in the law.
For continuous SaaS services, explicit consent is not the sole legal basis for international transfer; transfer processes are conducted in line with the tiered regime under KVKK art. 9 (adequacy decision → appropriate safeguards/Standard Contract and notification to the Board → occasional cases).
8. How Long We Retain Data
- Account, Subscription and Integration Data: Retained for as long as the membership and service relationship continues and, following its termination, throughout the applicable statutory limitation and retention periods.
- End-Customer Messages, Conversation Sessions and Order/Stock Data: Retained in line with the instructions of the Customer-Firm (Data Controller) and the requirements of the service. Upon termination of the agreement, the data is returned or securely deleted at the Customer-Firm's choice.
- Append-only Stock Ledger Records: For data integrity, these are not retroactively deleted or altered; corrections are added to the system as new records.
Personal data whose retention period has expired is deleted, destroyed or anonymised in accordance with the KVKK and the relevant legislation.
9. Your Rights (Data Subject)
Under KVKK art. 11, as a Data Subject whose personal data is processed, you have the right to:
- Learn whether your personal data is processed and, if so, request information about it,
- Learn the purpose of processing and whether the data is used in accordance with that purpose,
- Know the third parties to whom personal data is transferred at home or abroad,
- Request rectification of personal data that is incomplete or inaccurate,
- Request the erasure or destruction of personal data within the conditions set out in the KVKK,
- Object to a result against you arising from the analysis of processed data solely by automated systems,
- Claim compensation for damage suffered due to the unlawful processing of personal data.
Requests under Flow 2 — where BotFront acts as Data Processor — should be directed first to the Customer-Firm as Data Controller. Such requests reaching BotFront directly will be forwarded to the relevant Customer-Firm within a reasonable time, in accordance with the contractual provisions between the parties.
10. Contact and Requests
You may send us any request or application regarding this policy or the processing of your personal data through the following channels:
- contact@lumiostudio.co
- Web
- https://botfront.com.tr
Your applications will be assessed and concluded within the statutory periods set out in the KVKK and the relevant Board regulations (no later than 30 days).
11. Google User Data and Limited Use
When the Customer-Firm chooses to manage its product/stock data via a Google Sheet, BotFront accesses your Google account only with the Google OAuth permission you grant and only the spreadsheet you select yourself through Google Picker. The permission scopes used are: "drive.file" (access only to files you select or that are created via the app) and "spreadsheets" (reading and writing the selected spreadsheet).
The emlakçı (real-estate) portfolio folder connection works DIFFERENTLY: no Google OAuth permission is requested. The Customer-Firm itself shares its Google Drive portfolio folder with BotFront's service-account address as "Viewer" (read-only). BotFront only READS that shared folder and the files inside it (photos and information documents) and copies them to import the portfolio into the bot once; it writes nothing to Drive and never deletes or modifies a file. Photos are copied into BotFront's own storage so the bot can send them in messages. Access ends the moment the Customer-Firm removes the share in Drive.
This access is used solely to provide the stock-synchronisation feature: reading product/stock rows, writing bot-confirmed stock movements back to the sheet, and updating product image links.
- Data received from Google is used only to provide and improve this user-facing feature.
- This data is not used for advertising and is not sold or transferred to third parties.
- Data is not read by humans; the only exceptions are (a) your explicit consent, (b) security purposes (investigating abuse or a breach), (c) applicable legal obligations, and (d) aggregating and anonymising the data.
- The Google OAuth refresh token is stored encrypted server-side with AES-256-GCM; it is never sent to the browser or client and is never written to logs.
- You can revoke the connection at any time from your Google Account security settings (Third-party access) or via the admin panel.
botcu's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Policy: https://developers.google.com/terms/api-services-user-data-policy
12. Related Documents
This policy should be read together with the following complementary documents:
- KVKK Disclosure Notice (Aydınlatma Metni) — contains detailed information about the processing carried out under KVKK art. 10.
- Data Processing Agreement (DPA) — governs the parties' mutual obligations under Flow 2, where BotFront acts as Data Processor, including breach-notification procedures, sub-processor approval mechanisms and international-transfer safeguards.
13. Changes to This Policy
This Privacy Policy may be revised in line with updates to legislation or changes to the services offered. The current version will always be published at https://botfront.com.tr, and the effective date will be the date stated at the top of the text.