What this policy covers
This Privacy Policy explains which personal data we process when you use the Yardimo service (yardimo.com), why we process it, who we share it with and what rights you have.
It concerns two groups: the business customers who open a Yardimo account, and the visitors who reach us through the Yardimo chat window on those businesses' websites.
There is a third case: visitors who type into the chat window on the Yardimo website (yardimo.com). There we are the business that installed the chat window, so for those messages Yardimo is the data controller itself.
The service is operated by Sevim Oğuztürk, registered at Memurevleri Mah. 208. Sok. No: 14, Muratpaşa/Antalya.
Controller and processor: the split
This distinction shapes everything else, so we state it first.
For our customers' account details, billing data and website usage records, Yardimo acts as the data controller.
For the chat messages of visitors on our customers' own websites, the controller is the business that installed the chat window. Yardimo processes that data only on that business's instructions in order to provide the service, which makes us a data processor.
On the chat window on the Yardimo website, Yardimo is the data controller itself. In that channel we process your message, your IP address, the address of the page you are on, your browser details, the full name, email address and phone number you type into the contact form in the chat window, and the rating and comment you leave at the end of a chat; to answer your question the text of your message is transferred to OpenAI. You can bring any request about that chat directly to us.
If your request concerns a message you typed into a chat window on a business's website, you need to contact that business first. When such a request reaches us we forward it to the business and support them technically.
Data we collect
We collect the minimum data the service needs to work. The categories are:
- Account details
- Name, email address, an irreversible hash of your password, and your company name and contact details if provided.
- Knowledge base content
- The pages we crawl from your site, the documents you upload and the question and answer records you write in the panel.
- Visitor chat data
- Messages typed into the chat window, the answers the assistant gives, the date of the conversation and any contact details the visitor writes.
- Visitor contact details
- The full name, email address and (optionally) phone number a visitor types into the offline contact form in the chat window. The form is only shown when a chat is handed over while the team is offline, and only with the visitor’s explicit consent. For this data the business that installed the chat window is the data controller; we are the processor (for details left in the chat window on the Yardimo website, Yardimo is the data controller itself).
- Technical records
- IP address, browser and operating system information, request timestamps, error records and access logs kept for security.
- Usage data
- Counters such as message volume and number of crawled pages, used to track plan limits.
- Payment data
- Invoice details and payment status. Your card number never reaches us; the payment screen is served by the payment provider.
- Contact form
- The name, email address, subject and message text you submit through the form.
Why we process data
We process personal data only for the following purposes and no further:
- Creating your account, keeping your session secure and giving you access to the service.
- Allowing the chat assistant to answer visitor questions.
- Measuring plan limits, billing the subscription and tracking payments.
- Answering your support requests and fixing faults.
- Detecting and preventing abuse, unsolicited bulk messaging and security attacks.
- Measuring service quality and resolving errors and performance problems.
- Meeting our statutory retention, disclosure and invoicing obligations.
Legal grounds
We process personal data only where we have a legal ground for it.
- Performance of a contract
- Account creation, delivery of the service, limit tracking and billing data.
- Legal obligation
- Records that tax and commercial legislation requires us to keep for a set period.
- Legitimate interest
- Security logs, abuse detection and service improvement. When we rely on this ground we take care not to harm your fundamental rights and freedoms.
- Explicit consent
- Situations where none of the grounds above apply, such as sending marketing email. You can withdraw your consent at any time.
Who we share data with
We do not sell your personal data. We share only what is necessary, and only with the providers the service depends on.
- OpenAI
- To let the assistant produce an answer, the visitor question and the relevant text passages selected from your knowledge base are sent to the OpenAI interface. This is a transfer abroad; details are in the next section.
- Our server and infrastructure provider
- The application and the database are hosted in the location where our servers are based. That location is: Türkiye.
- Our email provider
- To deliver password reset, notification and support emails to you.
- Competent public authorities
- Where legislation requires it, after checking the legal basis of the request and limited to what is requested.
Transfers abroad
We want to be clear about this: we use OpenAI servers located outside Türkiye to generate chat answers.
The visitor question and the relevant text passages selected from your knowledge base are sent to OpenAI for the sole purpose of generating an answer. Your password, your payment details and any data unrelated to the conversation are not sent.
This is a transfer abroad within the meaning of article 9 of Turkish Law no. 6698, and it is necessary for the service to work; the chat assistant cannot operate without it.
OpenAI states that data sent through its interface is not used to train its general purpose models. You can follow the provider's current terms on its own website.
If you prefer to avoid this transfer, you can switch off AI answers and run the chat with your human agents only.
How long we keep data
We do not keep data longer than the purpose requires. Once the period ends, data is deleted, destroyed or anonymised.
- Account data
- For as long as your account is open. It is deleted or anonymised within 30 days of the account being closed.
- Chat records
- Until deleted from the panel. They are removed together with account data when the account is closed.
- Visitor contact details
- Stored together with the chat record: until the customer deletes it, and deleted with the account data when the account is closed.
- Knowledge base content
- Until you delete it or the account is closed.
- Invoice and payment records
- 10 years, as required by tax legislation.
- Security and access logs
- 12 months at most.
- Contact form messages
- 24 months at most after the request is resolved.
Cookies
We use strictly necessary cookies only; there are no analytics or advertising cookies. The name, purpose and lifetime of every cookie we set are listed in a table on the Cookie Policy page.
Security measures
Some of the technical and organisational measures we take to protect your data:
- All traffic is encrypted with HTTPS.
- Passwords are stored as irreversible hashes; we never keep plain text passwords.
- Database queries are parameterised and form submissions are verified with CSRF protection.
- Authorisation is account scoped; one customer cannot reach another customer's data.
- Server access is limited to a small number of people and every access is logged.
- Rate limiting blocks automated abuse.
We know no system is one hundred percent secure. If we detect that personal data has been accessed unlawfully, we notify the affected individuals and the Turkish Personal Data Protection Board within the period the law prescribes.
Your rights
Article 11 of Law no. 6698 gives you rights such as accessing your data, having it corrected, requesting its deletion and objecting to processing. The full list, the application channels and the thirty day response period are set out in our Data Protection Notice.
Children's data
Our service is aimed at businesses; we do not intend to serve anyone under 18 directly. If we learn that we have processed a child's personal data without the required consent, we delete it without delay.
Changes to this policy
We may update this policy as the service evolves. The current version is always published on this page and the last update date is shown at the bottom. For significant changes we notify registered customers by email.
Contact
Write to us with any privacy question. Legal name: Sevim Oğuztürk. Address: Memurevleri Mah. 208. Sok. No: 14, Muratpaşa/Antalya. Registered electronic mail (KEP): [to be confirmed].
Last updated: