Chatinbox KVKK Privacy Notice
Effective date: 15.12.2025 • Last updated: 15.12.2025
Language note: The Turkish text is the binding version; this English text is provided for convenience. The binding notice is published at chatinbox.net/kvkk. In case of any difference, the Turkish text prevails. KVKK is the Turkish Personal Data Protection Law No. 6698.
In short
- Data controller: Inbox Limited (Chatinbox).
- Where your data comes from: the website, the application, integrations, support channels and similar means of communication.
- How long it is kept: within the periods set by legislation and statutes of limitation — message and log records 2 years, finance and accounting records 10 years, health data 20 years. Where no period is set, for as long as the processing purpose requires (section 6).
- Your rights: 9 rights, including learning whether your data is processed and requesting correction and erasure.
- How to apply: from the email address registered in our system to hello@chatinbox.net, by post with a wet-signed petition, or by other methods set by the Board. Reply within 30 days at the latest; for requests that incur a cost, the fee in the Board's tariff may be charged (section 8).
This summary is here to make reading easier. The binding text is the full notice below.
Introduction
This notice has been prepared by Inbox Limited ("Chatinbox" or the "Company") in its capacity as data controller, pursuant to Article 10 of the Personal Data Protection Law No. 6698 ("KVKK").
1. Identity of the Data Controller
1.1. Under KVKK, your personal data is processed, within the scope and on the terms described below, by the data controller:
- Company: Inbox Limited
- Address: Istanbul, Türkiye
- Email: hello@chatinbox.net
- Phone: +90 216 372 9400
as set out in this notice.
2. How and on Which Legal Grounds Is Your Personal Data Collected?
2.1. Your personal data is obtained through the Chatinbox website, web application, mobile applications, integrations, support channels, email and other means of communication, by fully or partly automated means, or by non-automated means provided that it forms part of a data filing system.
2.2. In this process your personal data is processed on the basis of one or more of the following legal grounds set out in Articles 5 and 6 of KVKK:
- It is expressly provided for by law,
- It is directly related to the conclusion or performance of a contract,
- It is necessary for the data controller to fulfil a legal obligation,
- It is necessary for the establishment, exercise or protection of a right,
- It is necessary for the legitimate interests of the data controller, provided that this does not harm your fundamental rights and freedoms,
- You have given your explicit consent.
2.3. Your special categories of personal data (for example, health data, political opinions and similar content that you collect from your own users through integration channels) may be processed only in the limited cases provided by law or with your explicit consent, and by taking the additional measures set by the Personal Data Protection Board.
3. Categories of Personal Data Processed
3.1. Depending on the nature of our activities, the following categories of personal data may be processed:
- Identity data (such as name, surname, role and title within the company),
- Contact data (such as email, phone, address),
- Customer transaction data (subscription details, invoice and payment data, contract data),
- User transaction data (in-platform transaction and usage records, logs, support requests),
- Transaction security data (session records, access logs, IP address, device data),
- Data relating to integrations and message content (customer/end-user messages you record, attachments and metadata),
- Marketing and preference data (newsletter subscription and campaign preferences, if you give explicit consent).
3.2. The categories of data processed may vary according to the contract you are party to, the products and services you choose and the subject of the activity.
4. For What Purposes Is Your Personal Data Processed?
4.1. Your personal data is processed, in line with the principles set out in Articles 4, 5 and 6 of KVKK, for the following purposes:
- Carrying out the membership, authentication and account management steps needed for you to use Chatinbox services,
- Providing the software infrastructure that lets you manage your CRM processes, and operating messaging and integration channels,
- Running sales, invoicing and collection processes; carrying out finance and accounting operations,
- Receiving, assessing and resolving your support requests,
- Performing anonymous or statistical analysis, using as little data as possible, to raise service quality and improve the service,
- Running information security processes; ensuring system and application security, preventing unauthorised access, misuse and fraud,
- Conducting Company activities in accordance with legislation, and providing the necessary information and documents to authorised persons, institutions and organisations on request,
- If you give explicit consent, sending you newsletters, campaigns, announcements and similar commercial communications as part of marketing activities,
- Resolving legal disputes and protecting our rights,
- Preventing fraud, misuse and unauthorised access,
- Meeting the medical confidentiality requirements specific to healthcare services.
5. For What Purposes and to Whom May Your Personal Data Be Transferred?
5.1. For the purposes stated above and within the conditions set out in Articles 8 and 9 of KVKK, your personal data may be transferred to:
- Our business partners and suppliers we work with in customer relations, call centre and support activities,
- Authorised financial institutions and payment service providers within the scope of payment transactions,
- Authorised public institutions and organisations, in particular regulatory and supervisory authorities, as required by legal obligations,
- Our lawyers, consultants and other relevant third parties for the purpose of resolving legal disputes and protecting our rights,
- Persons and organisations to whom rights and interests are transferred, or from whom they are taken over, in the transfer of Company shares or assets, mergers, demergers and similar restructuring processes,
- Meta Platforms Inc. (WhatsApp/Instagram API), cloud hosting service providers (e.g. AWS), payment service providers and call centre infrastructure providers
within the limits set by the relevant legislation.
Chatinbox does not hold or store critical financial data such as full card numbers or CVV.
5.2. Where your personal data is transferred abroad, legal mechanisms under Article 9 of KVKK are used, such as the countries announced by the Personal Data Protection Board, undertakings approved by the Board, or your explicit consent.
6. Retention Period of Your Personal Data
6.1. Your personal data is retained for the retention periods set out in the relevant legislation and the statutes of limitation arising from contracts (message content and log records two years, finance and accounting records ten years, health data twenty years); where no such period is set, for as long as the processing purposes require. After these periods end, your personal data is deleted, destroyed or anonymised in accordance with our Company's personal data retention and destruction policy.
7. Your Rights Under KVKK
7.1. Under Article 11 of KVKK, as a data subject you have the right, by applying to Chatinbox, to:
- Learn whether your personal data is processed,
- Request information if your personal data has been processed,
- Learn the purpose of processing your personal data and whether it is used in line with that purpose,
- Know the third parties to whom your personal data is transferred, in Türkiye or abroad,
- Request correction of your personal data if it is incomplete or inaccurately processed,
- Request erasure or destruction of your personal data if the reasons requiring processing no longer exist, even though it was processed in accordance with KVKK and other relevant laws,
- Request that the operations carried out in this context be notified to the third parties to whom your personal data has been transferred,
- Object to a result to your detriment arising from analysis of your processed data exclusively by automated systems,
- Claim compensation for damage if you suffer damage due to unlawful processing of your personal data.
These are your rights.
8. How Can You Exercise Your Rights?
8.1. You may submit your requests under KVKK to our Company in writing or by other methods set by the Personal Data Protection Board. In this context you may apply:
- To hello@chatinbox.net, using the email address you previously notified to Chatinbox and which is registered in our systems,
- By post to our Company address with a wet-signed petition.
8.2. Your applications will be concluded as soon as possible and within thirty days at the latest, depending on the nature of your request. If fulfilling your request also requires a cost, the fees in the tariff set by the Personal Data Protection Board may be charged.
9. Limitation of Liability
9.1. Informational Nature and Legal Framework: This notice has been drawn up to inform data subjects pursuant to Article 10 of KVKK and is not, on its own, intended to create any further contractual rights or obligations between the parties.
9.2. Cases Where Customers Are the Data Controller: With respect to the personal data of its corporate customers' own customers and users, Chatinbox is in most cases in the position of data processor. In this framework, the data controller towards the relevant data subjects is the customer that uses Chatinbox as a tool within its own commercial activity.
Customers are deemed personally responsible for fulfilling the duty to inform the relevant data subjects, obtaining explicit consent where necessary, lawfully determining the purposes and means of data processing, the compliance with legislation of the instructions given to Chatinbox, and the lawfulness of the content and data transferred into the system through integration channels.
Chatinbox, in its capacity as data processor, cannot be held directly liable towards data subjects for breaches arising from its customers' unlawful instructions, incomplete or incorrect notifications, or failure to fulfil their own obligations.
9.3. Security Measures: While Chatinbox takes the reasonable technical and administrative measures required under KVKK and the relevant legislation to protect personal data, it notes that, given the nature of internet infrastructure and technological systems, absolute security cannot be guaranteed.
Notwithstanding the mandatory provisions in force, liability for damage that may arise from attacks, leaks, outages or similar events that develop outside Chatinbox's reasonable control and cannot be prevented, despite Chatinbox having taken the necessary minimum security measures, exists only where Chatinbox acted with intent or gross negligence.
9.4. Indirect Damages and Liability Cap: Subject to mandatory legislation in force, Chatinbox cannot be held liable for indirect damages, loss of profit, loss of data, loss of reputation and consequential damages that may arise from the processing of personal data and the processes covered by this notice.
Even where Chatinbox is directly liable, this liability shall not exceed the total service fees paid to Chatinbox by the relevant customer in the last twelve (12) months before the date on which the relevant claim arose.
9.5. Reservation of Mandatory Law: The limitations in this section do not remove rights and obligations arising from KVKK and other mandatory legislation that cannot be waived or limited in advance. This notice cannot be interpreted in a way that conflicts with the legislation in force; in the event of such a conflict, the mandatory rules of law always apply to the relevant dispute.
