This notice is issued under the disclosure obligation in Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK). It explains for what purpose and on what legal basis personal data is processed, who it is shared with, how long it is kept, and what rights data subjects have. For the general privacy approach of the service, see the Privacy Policy.
Identity of the data controller
The data controller is the person whose name, location and contact address appear in the identity block at the top of this page. Wherever this notice says “merter.app”, it means the service operated by that person.
merter.app acts in two distinct capacities, and this distinction matters for the rest of the notice:
- For account data it is the data controller. Data relating to the account of a business that signs up for the panel is processed for purposes merter.app determines itself.
- For the data of the tenant’s customers it is a data processor. There, the data controller is the business that opened the account; merter.app acts only on that business’s behalf and on its instructions. The terms of that relationship are set out in the Data Processing Addendum.
Personal data processed
(a) Data of the account-holding business and its representative — here merter.app is the controller
- Identity and contact: business name, name of the account representative, email address.
- Transaction security: not the password itself but a hash derived from it; panel session records (session identifier and the time the session was opened); the IP address used in the counters that limit abuse of sign-up and login attempts.
- Sign-up source: if present in the sign-up link, the UTM parameters identifying the advertising campaign (
utm_source,utm_medium,utm_campaign,utm_content,utm_term) and the Meta click identifier (fbclid). No browser fingerprint or other identifying trace is kept in this field. - If Google sign-in is used: the email address verified by Google and the account identifier.
- Subscription: subscription status and billing details. Full payment card details are not stored on merter.app servers; payment is taken through the payment service provider named on the Subscriptions, Billing and Refunds page.
- If a callback request is submitted: company name, name of the representative, phone number and number of WhatsApp numbers to connect.
(b) Data of the tenant’s customers — here the tenant is the controller
Phone number or platform profile identifier, profile name, message content, images and voice messages shared, and conversation timestamps.
In this group merter.app is not the controller but the processor: the business that opened the account decides for what purpose the data is processed, and the duty to inform its own customers rests with that business. The full list of data categories, the processor’s obligations and the technical measures applied are set out in the Data Processing Addendum.
Purposes of processing
- Creating, verifying and administering the account,
- Providing the service; receiving, delivering and displaying in the panel the messages that arrive on connected channels,
- Running the automations the tenant enables in the panel and managing the product catalogue,
- Operating the subscription relationship, pricing and billing,
- Securing the service, preventing abuse and fraud, and troubleshooting faults,
- Meeting obligations arising from legislation and responding to requests from competent authorities,
- Sending commercial electronic messages (promotions, campaign announcements) where separate explicit consent has been given.
Transactional emails such as verification codes, account notices and billing information are part of running the service; they are not commercial electronic messages and do not depend on separate consent.
Legal bases
- Establishment or performance of a contract — KVKK Art. 5/2-c. Opening the account, providing the service, delivering messages, subscription and billing rest on this basis.
- Legal obligation — KVKK Art. 5/2-ç. Retention and reporting duties imposed by legislation, and responding to properly issued requests from competent public authorities.
- Legitimate interest — KVKK Art. 5/2-f. Securing the service, preventing abuse, fixing faults and improving the service. Processing on this basis stays within limits that do not harm the fundamental rights and freedoms of the data subject.
- Explicit consent — KVKK Art. 5/1. Required only for sending commercial electronic messages. Consent may be withdrawn at any time; withdrawal does not affect processing lawfully carried out until then.
How the data is collected
Personal data is collected electronically, by automated and partly automated means, through the following channels:
- The sign-up form and the email verification step,
- The Google sign-in flow,
- Records created while the panel is used,
- Webhook notifications from the connected messaging platforms (WhatsApp, Instagram, Telegram),
- The callback request form on the marketing site,
- Cookies and similar measurement tools: cookies strictly necessary to maintain the session, plus the measurement and marketing scripts running on the marketing site. Details are on the Cookie Policy page.
Who the data is shared with
- Providers used to deliver the service. Which provider handles which task, what data it touches and where it is located are kept in the subprocessor table in the Data Processing Addendum. That list lives in one place; it is not repeated here — when it changes, that table is updated and the change is notified to the account email.
- Competent public authorities. Where a properly issued request based on legislation is received, limited to the scope of that request.
- Measurement and advertising platforms. Visit and conversion events are passed to the relevant platform through the measurement cookies running on the marketing site; details are on the Cookie Policy page.
Personal data is not sold and is not transferred to third parties for marketing purposes.
International transfers
Some of the providers used to deliver the service are located outside Türkiye. Personal data is therefore transferred abroad within the framework of Article 9 of the KVKK, to the extent strictly necessary for performance of the service and limited to the task the relevant provider carries out.
Where each provider is located and which data category it touches is shown in the table in the Data Processing Addendum.
Retention periods
- Email verification code: 10 minutes. The record is deleted when the code is used or when the period expires.
- Panel session records: 30 days at most. Sessions older than that are treated as invalid and their records are deleted.
- Account data: kept for as long as the account remains open. Data is not deleted automatically when a subscription ends; it stays in place so that the catalogue and history are intact if the account is reactivated.
- Message and conversation records: until the tenant requests deletion. The tenant is the controller for these records and sets their retention period.
- When a deletion request is received, data is deleted or irreversibly anonymised in line with the process on the Data Deletion page.
- Limited records that legislation requires to be kept are retained until the relevant period expires and are used during that period only for that obligation.
Your rights as a data subject
Under Article 11 of the KVKK you may apply to the data controller and exercise the following rights:
- To learn whether your personal data is being processed,
- To request information if it has been processed,
- To learn the purpose of processing and whether the data is used in line with that purpose,
- To know the third parties in Türkiye or abroad to whom the data is transferred,
- To request correction where the data has been processed incompletely or inaccurately,
- To request erasure or destruction within the conditions laid down in the law,
- To request that correction, erasure and destruction be notified to the third parties to whom the data was transferred,
- To object to a result reached against you through analysis carried out solely by automated systems,
- To claim compensation for damage suffered because personal data was processed unlawfully.
Requests concerning the data of a tenant’s customers must be addressed directly to that business, because it is the controller for that data. If such a request reaches merter.app it is not decided here; it is forwarded to the relevant controller and the applicant is informed.
How to make a request
Send your request to [email protected], with information that allows your identity to be established and with your request stated clearly. If you are an account holder, writing from the email address linked to the account speeds up the match.
The request is concluded free of charge and within 30 days at the latest, depending on its nature. If a request is refused, the reason for refusal is given in writing.
If your request is refused, if you find the response inadequate, or if no response is given within the period, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board.