Identity of the data controller
Under article 10 of Turkish Law no. 6698 on the Protection of Personal Data, we inform you as the data controller.
- Legal name
- Sevim Oğuztürk
- Brand and website
- Yardimo (yardimo.com)
- Address
- Memurevleri Mah. 208. Sok. No: 14, Muratpaşa/Antalya
- Tax office and number
- [to be confirmed] / [to be confirmed]
- MERSIS number
- [to be confirmed]
- Registered electronic mail (KEP)
- [to be confirmed]
- destek@yardimo.com
Where we are controller and where we are processor
Yardimo is the data controller for its customers' account, billing and website usage data.
For the data of visitors who type into the chat window on our customers' websites, the controller is the business that installed the chat window. Yardimo processes that data solely on that business's instructions.
For visitors who type into the chat window on the Yardimo website (yardimo.com), however, Yardimo is the data controller itself; there is no other business in between. This covers the chat message and technical records as well as the full name, email address and phone number typed into the contact form and the chat rating and comment.
For that reason, a request about a message you typed into a chat window on a business's website should be addressed to that business first.
Categories of personal data processed
The following categories of data are processed as part of the service:
- Identity: first name, last name.
- Contact: email address, postal address.
- Customer transactions: subscription plan, usage counters, support requests.
- Financial: invoice details and payment status. We do not process card data.
- Transaction security: IP address, session records, access and error logs, password hash.
- Chat content: messages sent through the chat window and the answers given.
- Visitor contact details: the full name, email and optional phone number entered in the offline contact form, plus the rating and comment left at the end of a chat.
Purposes of processing
Your personal data is processed for the following purposes:
- Creating the membership record and managing the account.
- Delivering the service, generating assistant answers and displaying chat history.
- Collecting subscription fees, invoicing and keeping accounting records.
- Handling support requests and fixing faults.
- Ensuring information security, preventing abuse and keeping audit trails.
- Measuring service quality and making technical improvements.
- Meeting statutory obligations and responding to requests from competent authorities.
How personal data is collected
Personal data is collected electronically, by wholly or partly automated means, through the following channels:
- Sign up and sign in forms and the customer panel.
- The contact form on the website and support emails.
- The chat window installed on customer websites.
- The offline contact form in the chat window: collected only when a chat is handed over while the team is offline, and only after the visitor ticks the consent box. The business that installed the chat window is the data controller for this data; Yardimo is only the processor (for details left in the chat window on the Yardimo website, Yardimo is the data controller itself).
- The chat window on the Yardimo website: the visitor's message, IP address and the address of the page they are on, the full name, email address and phone number they type into the contact form, and the rating and comment they leave at the end of a chat are collected; the message text is transferred to OpenAI to generate an answer.
- Server and application records and strictly necessary cookies.
- Transaction results returned by the payment provider.
Legal grounds for processing
Data is processed on the legal grounds listed in article 5 of the Law:
- Processing is directly related to the conclusion or performance of a contract (article 5/2-c).
- Processing is necessary for the controller to fulfil a legal obligation (article 5/2-ç).
- Processing is necessary for the establishment, exercise or protection of a right (article 5/2-e).
- Processing is necessary for the legitimate interests of the controller, provided it does not harm the fundamental rights and freedoms of the data subject (article 5/2-f).
- Where none of these grounds apply, the explicit consent of the data subject (article 5/1).
Recipients and purposes of transfer
In line with articles 8 and 9 of the Law, your personal data is transferred to the following parties for the purposes stated next to each:
- OpenAI
- To generate the chat answer; the question text and the relevant passages selected from the knowledge base.
- Server and infrastructure provider
- To host the data. The location where our servers are based is: Türkiye.
- Email provider
- To deliver notification and transactional email.
- Competent public authorities
- In cases prescribed by law, after checking the legal basis of the request and limited to what is requested.
Beyond these parties your personal data is not sold to third parties and is not transferred for marketing purposes.
Transfers abroad (article 9)
To let the assistant generate an answer, the visitor question and the relevant passages selected from the knowledge base are transferred to OpenAI servers located abroad.
This constitutes a transfer abroad under article 9 of the Law and is necessary for the service to be provided.
Transfers rely on the appropriate safeguards set out in Article 9 of the Law, primarily the standard contract notified to the Board.
The transferred data is limited to the minimum needed to produce the answer. Your password and payment details are never transferred.
When AI answers are switched off in the customer panel, this transfer does not take place.
Retention and destruction
Personal data is kept for as long as the purpose of processing requires and for the limitation periods prescribed by legislation. Once the period ends, data is deleted, destroyed or anonymised.
- Account data: at most 30 days after the account is closed.
- Chat records: until the customer deletes them, and together with account data when the account closes.
- Visitor contact details: together with the chat record; until the customer deletes it, and with the account data when the account is closed.
- Knowledge base content: until the customer deletes it or the account is closed.
- Invoice and payment records: 10 years.
- Security and access logs: 12 months at most.
- Contact form messages: 24 months at most after the request is resolved.
Your rights as a data subject (article 11)
Under article 11 of the Law you may apply to us and request the following:
- To learn whether your personal data is being processed.
- To request information if your personal data has been processed.
- To learn the purpose of processing and whether the data is used in line with that purpose.
- To know the third parties in Türkiye or abroad to whom your personal data has been transferred.
- To request correction if your personal data is incomplete or inaccurate.
- To request erasure or destruction under the conditions set out in article 7 of the Law.
- To request that correction, erasure or destruction be notified to the third parties the data was transferred to.
- To object to a result reached against you through analysis carried out exclusively by automated systems.
- To claim compensation if you suffer damage due to unlawful processing.
How to apply and our response time
To exercise your rights, send us your application in Turkish, together with information that lets us verify your identity and a clear statement of your request.
You can apply through our registered electronic mail address [to be confirmed], by writing from the email address registered in our system to destek@yardimo.com, or by sending a signed letter to Memurevleri Mah. 208. Sok. No: 14, Muratpaşa/Antalya in person or through a notary.
We conclude applications free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request. Where the process incurs a cost, the fee set in the tariff published by the Personal Data Protection Board may be charged.
If your application is rejected, if you find our answer insufficient or if we do not answer in time, you may file a complaint with the Personal Data Protection Board within thirty days of learning our answer and in any case within sixty days of the application date.
Changes to this notice
We may update this notice in line with changes in legislation or in our service. The current version is always published on this page and the last update date is shown at the bottom.
Last updated: