Terms of Use (Service Agreement)

Terms of use between BotFront (Lumio Studio) and the firm purchasing the service: description of the service, fees, the firm's obligations, liability and termination.

Effective date: June 16, 2026

1. Parties and Definitions

These Terms of Use (the "Agreement") are concluded between, on one side, Lumio Studio (e-mail: contact@lumiostudio.co) ("Lumio Studio" or "BotFront"), which operates the BotFront platform, and, on the other side, the legal entity or firm that creates an account to use the service (the "Customer" or "Firm"), and take effect upon use of the service at https://botfront.com.tr.

botcu
The multi-tenant WhatsApp-bot SaaS platform operated by Lumio Studio and offered in modules.
Module
A separately priced functional unit. The first module is "Stokçu" (a stock/order assistant over WhatsApp and/or Telegram). The Customer may add or remove any module at will.
Bot
A paid bot instance allocated to the Customer, integrated with a product/stock source (Shopify, PlatinMarket or Google Sheets) and one or more messaging channels (Meta WhatsApp Business and/or Telegram). A Firm may have multiple bots.
End-Customer
The natural persons who are the Firm's own customers and who interact with the bot by contacting it over the Firm's WhatsApp or Telegram line.
Applicable Legislation
Law No. 6698 (KVKK), Law No. 6563 on the Regulation of Electronic Commerce, Law No. 6502 on Consumer Protection, and the secondary regulations enacted thereunder.

2. Description of the Service

botcu is a third-party integration and SaaS (software service) provider. It allocates the Firm a bot on a per-module basis; this bot integrates with the Firm's product/stock source (Shopify, PlatinMarket or Google Sheets) and one or more messaging channels (Meta WhatsApp Business and/or Telegram) to give the Firm's End-Customers automated answers about stock, product and order processes over those channels.

  • The service is offered in modules; each module is purchased separately and can be added or removed independently.
  • Bots analyse incoming text and voice messages via an AI model (LLM) and deterministic (rule-based) handlers; critical operations such as stock and orders run under user-confirmed, deterministic controls. The default response language is Turkish, and responses may also be given in other supported languages.
  • botcu is not the owner, partner or representative of third-party platforms such as Meta/WhatsApp, Shopify or PlatinMarket; it cannot be held responsible for the uninterrupted availability, policies or changes of those platforms.
  • botcu reserves the right to develop, change or update the scope of the service, the modules and the technical infrastructure; material changes are notified to the Customer a reasonable time in advance.

Google Sheets integration: When the Firm chooses to connect a Google Sheet, BotFront accesses only the spreadsheet the Firm selects itself via Google Picker, with the granted Google OAuth permission (drive.file and spreadsheets scopes), and solely for the purpose of stock synchronisation. BotFront's use and transfer of information received from Google adheres to the Google API Services User Data Policy, including the Limited Use requirements; details are in the "Google User Data and Limited Use" section of the Privacy Policy. The Firm represents that it is authorised to operate on the connected Google account and spreadsheet.

emlakçı portfolio folder: In the emlakçı module the Firm itself shares its Google Drive portfolio folder with BotFront's service-account address as "Viewer" (read-only); no Google OAuth permission is requested. BotFront only READS that folder and the photo/document files inside it and copies them to import the portfolio into the bot; it writes nothing to Drive and never deletes or modifies a file. Access ends when the Firm removes the share in Drive. The Firm represents that it is authorised to operate on the content of the folder it shares.

3. Account and Onboarding

The Firm record is created by the system administrator; an admin-panel login (authentication via e-mail link) and a firm account are defined for each Firm. Bots are assigned to the Firm as slots and become active by default from the moment of assignment.

  • The Firm is solely responsible for the confidentiality and security of its panel login credentials and for all operations carried out under its account.
  • The integration credentials required for each bot (e.g. Shopify store domain and Admin API access key, or PlatinMarket credentials) are entered into the system by the Firm; data synchronisation (sync) is then started.
  • When synchronisation completes successfully, the bot-specific WhatsApp webhook URL is shown to the Firm and the Meta WhatsApp setup guide is provided.
  • The Firm represents that the integration credentials it enters are accurate, current and its own, and that it is fully authorised to use them.

4. Fees and Payment

  • The service is priced per module (approximately ₺2,000 per module). Current fees and per-module pricing are communicated to the Customer at the point of sale or via the admin panel.
  • Collection is carried out outside the platform (externally and manually between botcu/Lumio Studio and the Firm); payment history may be shown in the admin panel for informational purposes only.
  • Bot assignment is not subject to any prepayment condition or integrated payment gateway; an assigned bot is active by default. Payment obligations are tracked externally by the parties.
  • Unless expressly stated otherwise, fees are exclusive of applicable taxes (VAT, etc.); statutory taxes are invoiced separately as required by law.
  • If a payment obligation is not met on time, BotFront reserves the right to deactivate (suspend) the relevant bot(s).

5. The Firm's Obligations and the Two KVKK Roles

Two distinct data flows take place within the service, and the roles assumed by the parties under the KVKK differ accordingly. This distinction is essential for determining the Firm's legal obligations:

Flow 1 — The Firm's own data
For the Firm's login e-mail address, subscription/billing information and integration credentials, BotFront (Lumio Studio) acts as the DATA CONTROLLER.
Flow 2 — End-Customer data
For the End-Customers' personal data the Firm transfers into the system (WhatsApp phone number, message content, name-surname, order and product/stock information), the FIRM IS THE DATA CONTROLLER; BotFront acts solely as a DATA PROCESSOR on the Firm's written and documented instructions.

Under Flow 2, the Firm, as data controller, undertakes to fulfil the following obligations on its own:

  • Fulfil in full the duty to inform End-Customers under KVKK art. 10, and base the processing on an appropriate legal ground under KVKK art. 5 and art. 6 (explicit consent where required).
  • Obtain lawful and provable opt-ins from End-Customers in order to communicate over WhatsApp; comply with all applicable legal rules including Meta/WhatsApp Business policies and the İYS (Message Management System) legislation.
  • Transfer into the system only personal data that has been lawfully obtained, is accurate and current, and over which it is authorised; avoid entering unnecessary or excessive data contrary to the purpose-limitation principle.
  • Keep integration credentials secure, accurate and current; immediately notify BotFront when a suspicion of unauthorised access arises.
  • Provide BotFront with the instructions and legal bases necessary to process the Flow 2 data; comply with the provisions of the Data Processing Agreement (DPA) governing the controller-processor relationship.

The duty to inform End-Customers and obtain explicit consent belongs exclusively to the Firm; BotFront, as data processor, is only obliged to provide the Firm with technical information such as recipient groups and data-transfer locations.

International data transfer: The service is provided through sub-processors established abroad (LLM/AI providers, hosting/cloud infrastructure, messaging and payment providers), which requires the continuous transfer of personal data abroad.

Under KVKK art. 9 (the new regime amended by Law No. 7499 and in force since 01.06.2024), explicit consent alone does not constitute a sufficient or appropriate basis for continuous transfers such as cloud/SaaS (explicit consent is an exceptional basis only for occasional/one-off cases). International transfers are conducted in line with this tiered regime: transfer to countries covered by an adequacy decision, or the provision of the appropriate safeguards prescribed by law (including the Standard Contract published by the Board). Onward transfers and the sub-processor chain are addressed under the Data Processing Agreement (DPA). The categories of data transferred, recipient groups and destination countries are listed in the Privacy Policy.

6. Acceptable Use

The Firm agrees, declares and undertakes to abide by the following while using the service:

  • Not to use the service for unlawful purposes, for sending unsolicited bulk messages (spam), with misleading content, or in a manner that infringes the rights of third parties.
  • To fully comply with the terms of use and policies of the integrated third-party platforms, in particular Meta/WhatsApp Business, Shopify and PlatinMarket.
  • To refrain from acts (reverse engineering, unauthorised access attempts, overloading, etc.) that would jeopardise the security or integrity of the service or the per-tenant isolation of its multi-tenant structure.
  • Not to transfer into the system data that does not belong to it or that it is not authorised to process.

In the event of a breach of these rules, BotFront reserves the right to suspend the relevant bot or account or to unilaterally terminate the agreement.

7. Availability and Disclaimer of Warranties

  • The service is provided "as is" and "as available"; BotFront gives no express or implied warranty as to uninterrupted availability, error-free operation, or fitness for a particular purpose.
  • The accuracy of bot responses depends on the data fed into the system and on the availability of the integrated third-party platforms (Meta/WhatsApp, Shopify, PlatinMarket, LLM provider); automated responses do not constitute a final and binding commercial commitment.
  • Access to the service may be temporarily suspended during planned maintenance, third-party outages or force-majeure events.
  • Stock movements are kept under an append-only ledger logic (no direct deletion/editing), and current stock is calculated as the sum of those movements. Nevertheless, the final verification and monitoring of data accuracy is solely the Firm's responsibility.

8. Limitation of Liability

  • botcu shall in no event be liable for indirect, incidental, special or consequential damages (loss of profit, loss of business, loss of data, loss of reputation, etc.).
  • botcu's total liability for any claim under this Agreement is limited to the total service fee actually paid by the Firm to BotFront in the twelve (12) months preceding the event giving rise to the claim.
  • botcu is not responsible for damages arising from outages, technical errors or policy changes of third-party platforms (Meta/WhatsApp, Shopify, PlatinMarket, LLM and hosting providers).
  • The Firm, as data controller, is the addressee of any administrative and legal claim arising from the lawful collection of Flow 2 data, the fulfilment of the duty to inform and the obtaining of the necessary consents; accordingly, the Firm shall indemnify BotFront against all claims directed at BotFront in this respect.
  • These limitations of liability apply without prejudice to the mandatory provisions of the applicable legislation (such as cases of intent and gross negligence).

9. Term and Termination

  • This Agreement remains in force for as long as the Firm continues to use the service.
  • The parties may terminate the agreement at any time upon reasonable prior written notice; since payment obligations are tracked externally, payment obligations that have already accrued before termination are not affected by it.
  • If the Firm breaches this Agreement or the acceptable-use rules, BotFront may deactivate the relevant bots or terminate the agreement immediately and without compensation.
  • Upon termination of the agreement, the Firm's access to the relevant bots and the admin panel ends.

10. Data Deletion on Exit

Upon termination of the agreement, BotFront — as data processor — deletes or returns to the Firm the personal data it processed under Flow 2 (End-Customer), in line with the Firm's written and documented instruction; statutory retention obligations arising from applicable legislation are reserved.

  • Data held in BotFront's Postgres infrastructure (product information, the append-only stock ledger, conversation sessions, chat messages, processed-message records and the derived tenant configuration snapshot) is deleted or anonymised within the scope of the relevant Firm account.
  • Data that must be retained due to statutory retention periods or an ongoing legal dispute may be kept for the limited purpose until the relevant retention period or dispute ends.
  • For data-deletion requests and details of the process, you may contact contact@lumiostudio.co.

11. Governing Law and Jurisdiction

This Agreement is governed by Turkish law. The courts and enforcement offices of the Republic of Türkiye have jurisdiction over disputes arising from the Agreement; the competent court is determined under the applicable procedural rules.

This Agreement is a B2B (business-to-business) service relationship between parties that are merchants. As the Customer acts for commercial or professional purposes, it does not qualify as a "consumer" under Law No. 6502 on Consumer Protection; accordingly, consumer-protective provisions on distance contracts (e.g. the right of withdrawal) do not apply to this relationship. The relationship between the parties is subject to Law No. 6563 and the relevant secondary legislation in respect of commercial electronic-commerce activities.

12. Changes to the Terms

botcu may update these Terms of Use from time to time in line with applicable legislation, service updates or business requirements. Material changes are notified a reasonable time in advance, stating the effective date, via the admin panel or the contact@lumiostudio.co e-mail address. Continued use of the service after such notice constitutes acceptance of the updated terms.

For your questions: contact@lumiostudio.co.