This addendum governs how personal data belonging to the tenant’s own customers is processed on merter.app. Under Turkish Law No. 6698 on the Protection of Personal Data (KVKK), the Personal Data Protection Board expects a written agreement between a data controller and a data processor; this document is that agreement. When preparing its own privacy notice and consent processes, the tenant may rely on the information set out here — in particular on the subprocessor list.
Parties and capacities
In this addendum the data controller is the business that opens and uses the merter.app account (the tenant). The data processor is the service provider identified in the identity block at the top of this page.
What those capacities mean: the tenant decides for what purpose and by what means personal data of end users is processed; the service provider processes that data only on the tenant’s behalf, on the tenant’s instructions, and only in order to provide the service.
The identity block describes the service provider as a data controller in respect of its own services; the two capacities do not conflict, they relate to different sets of data. For the tenant’s own account details the data controller is the service provider, and that processing is explained on the Privacy Policy page. For the data of the tenant’s end users the same person is a processor, and this addendum applies.
This addendum forms an integral part of the Terms of Use; a business that opens an account accepts this addendum together with those terms. Matters not covered here — including the limitation of liability, suspension and termination — are governed by those terms. This addendum does not create a separate enforcement regime.
Subject matter, duration and purpose of the processing
Subject matter: the tenant’s management of its messaging channels (WhatsApp, Instagram, Telegram) and of its product catalogue through merter.app. This covers receiving and answering incoming messages, sending product images, displaying conversation records in the panel, and publishing products in the public showroom if the tenant chooses to.
Duration: for as long as the subscription relationship continues. After the subscription ends, the data continues to be kept as described in the “When the agreement ends” section, until the data controller asks for it to be deleted.
Purpose: solely the provision of the service. The processor does not use the data of the tenant’s end users for its own commercial purposes, for its own promotion, or to serve another tenant; it does not sell that data and does not transfer it to third parties for marketing.
Categories of data
Two separate sets of data are processed under this addendum.
The tenant’s account data: business name, name of the authorised person, e-mail address, panel user accounts, session records and the IP address a session was opened from, subscription and billing details.
Data belonging to the tenant’s end users: phone number or platform profile identifier, profile name, message content, images sent and received, any voice message recording and its transcript, location data where it has been shared, conversation timestamps, and the state kept for the conversation in the panel.
Data belonging to the carriers the tenant works with: the business card image uploaded through the registration link the tenant shares, together with the company name, phone number and service note read from that image.
Categories of data subject
Three groups of people are affected by the processing:
- The tenant’s customers — end users who write to the WhatsApp, Instagram or Telegram account the tenant has connected, who browse the catalogue, or who arrive through the public showroom.
- The tenant’s panel users — employees, agencies or consultants who access the panel on the tenant’s behalf.
- Representatives of carriers and freight companies who upload a business card — people who upload their own card through the registration link the tenant shares.
Acting on instructions
The processor processes personal data only on the written instructions of the data controller and within the framework set out in this addendum. The settings made in the panel, the channels connected and the configuration the tenant enters count as instructions in this sense.
Where a processing operation follows from a legal obligation the processor may carry it out; but unless the applicable law forbids such notice, it informs the data controller before doing so.
If the processor takes the view that an instruction it has received breaches the law, it informs the data controller.
Confidentiality
Everyone with access to personal data — the service provider and the people working on its behalf — is bound by a duty of confidentiality. That duty continues after the person’s role or contract has ended.
Access is limited to the people the work requires and to the extent the work requires.
Technical and organisational measures
To ensure a level of security appropriate to the nature of the processing, the processor applies the following measures:
- Encryption in transit — traffic coming from the panel and from the messaging platforms is carried over TLS across the internet.
- Session security — the panel session runs on a signed cookie and can be revoked; when the session counter kept for an account (
session_epoch) is incremented, every open session for that account becomes invalid. - Tenant isolation — every record belonging to a tenant is separated by
tenant_idand queries are constrained by that identifier; one tenant’s data is not visible to another. - Media access — new media links carry an unpredictable signature generated by the server. Un-banded original images and carrier business cards do not open with a sequential identifier; they are not served without the unpredictable part of the link. So that Meta’s cache and messages already sent are not broken, the older unsigned link format is kept open during a transition period; only the visible product images the bot has already sent to customers are served over that path.
- Authorisation boundary — a panel session can reach only its own tenant’s data; the platform-wide administration endpoints are protected by a separate authorisation check and are not open to a tenant session.
- Password storage — tenant account passwords are not kept in plain text; they are stored as a digest derived with scrypt.
- Secret handling — the access keys of connected channels are held against the tenant record; no panel or API endpoint returns those values, only whether a connection exists. Telegram personal-account session credentials are additionally stored encrypted with AES-256-GCM.
Subprocessors
By accepting this addendum the data controller consents to the use of the subprocessors below. Each of them is engaged only for the work listed against it and only with the data that work requires.
| Subprocessor | Service | Data touched | Location |
|---|---|---|---|
| Meta Platforms (WhatsApp Business Platform, Instagram) | Messaging infrastructure and ad measurement | End-user phone number/profile identifier, message content, media, conversion events | USA / EU |
| Telegram | Messaging and channel broadcasting | End-user profile identifier, message content, media | EU / international |
| Cloudflare (R2, CDN, DNS) | Storage and delivery of product images | Catalogue images, access logs, IP | International |
| Hetzner (via Coolify) | Application and database hosting | All service data | Germany |
| iyzico | Payment processing and refund intermediation | Tenant billing details, transaction identifiers and subscription status. Full card details are not stored on merter.app servers. | Türkiye |
| Google (OAuth, Ads, Places) | Sign-in with Google; ad management; business directory | Tenant e-mail and account identifier; business details in directory lookups | International |
| OpenAI | Voice message transcription; incoming and outgoing message translation | End-user voice recordings; message text and recent conversation context when needed for translation | USA |
| Anthropic | AI-assisted replies and business card reading | The message text being processed; when a business card is uploaded, the card image and the contact details in it; classification of business photos. Not used for model training. | USA |
| Brevo | Transactional e-mail (verification code, notifications) | Tenant e-mail address | EU (France) |
| OpenStreetMap (Nominatim, Overpass) | Address and business lookup | Search text entered in the panel. No end-user personal data is sent. | International |
The OpenAI row deserves particular attention: when an end user sends a voice message over a connected channel, that recording is passed to OpenAI to be transcribed. This happens outside Türkiye and does not depend on a separate setting — it runs automatically whenever a voice message arrives. The data controller should state this transfer in its own privacy notice.
Transfers abroad
Some of the subprocessors above are located outside Türkiye. Personal data is therefore transferred abroad only to the extent necessary for the performance of the service and only within the scope of the work the subprocessor concerned carries out. Transfers are made within the framework of Article 9 of the KVKK.
Determining the legal ground a transfer rests on, and stating it in its own privacy notice, is the data controller’s responsibility. The processor keeps the information needed for that — recipient, category of data transferred and purpose — up to date on this page.
Notification of a data breach
If the processor becomes aware that personal data has been unlawfully obtained by others, it notifies the data controller without undue delay and within 24 hours at the latest. The notification is sent to the account e-mail and covers the scope known at the time, the categories of data affected and the measures taken. It is completed as further details become clear.
The obligation to notify the Personal Data Protection Board and the data subjects lies with the data controller, that is, the tenant. The processor provides, to a reasonable extent, the information needed to prepare those notifications.
Data subject requests
If a data subject — for example a customer of the tenant — brings a request about their own data directly to the processor, the processor does not resolve it on its own initiative; it refers the request to the data controller concerned and informs the person who made it.
Meeting requests for access, rectification, erasure and objection to processing is the data controller’s obligation. The processor assists to a reasonable extent in meeting it, through the tools available in the panel and, where needed, with technical support.
Audit
The data controller may request written information once a year to verify that the measures listed in this addendum are applied. Requests go to [email protected] and are answered within a reasonable time.
The information given does not include other tenants’ data or any detail that would put the security of the service at risk.
When the agreement ends
Data is not deleted automatically when a subscription ends: it continues to be kept so that the tenant’s catalogue and conversation history are still in place if the account is reactivated.
When the data controller asks for deletion, the data is deleted or irreversibly anonymised in accordance with the process on the Data Deletion page. The limited records subject to a statutory retention obligation are kept until the relevant period expires, and during that period they are used only for that obligation.
Changes to subprocessors
Before a new subprocessor is brought into use, the table on this page is updated and the change is notified to the account e-mail. This lets the data controller update its own privacy notice before the change takes effect.
The table is updated in the same way when a subprocessor is removed from the list.