Privacy Notice and Privacy Policy (KVKK)
This notice is issued by Sahatek Bilişim Teknolojileri Tic. Ltd. Şti. ("Sahatek" or "we"), the data controller of the WappNeo software (the "Application") and the wappneo.com website (the "Site"), under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and related legislation. It informs natural persons who install the Application, visit the Site or receive messages sent through the Application.
1. Identity of the data controller
Sahatek Bilişim Teknolojileri Tic. Ltd. Şti.
Konya, Türkiye
Phone: 0850 532 7690 · 0553 240 16 90
E-mail: [email protected]
Web: wappneo.com
2. How WappNeo works and where data flows
WappNeo is Windows software that lets businesses manage their own WhatsApp accounts from their own computers. This architecture determines where each piece of data is kept:
- Kept on your computer: your WhatsApp session, chat contents, phone book, saved message templates, send logs and user activity records are stored only on the computer where the Application is installed. They are never sent to Sahatek servers.
- Kept on the WappNeo server: licence and user account details, company profile (name, contact details, logo), transaction notifications queued for the ERP integration, reconciliation records and customer answers, the blacklist (numbers that opted out), API key records and administration logs.
- WhatsApp: messages are delivered from your own WhatsApp account through the infrastructure of Meta Platforms. WhatsApp's own privacy policy applies separately; Sahatek is not responsible for WhatsApp's processing.
3. Personal data processed
3.1 Application users (business staff)
- Identity and contact: name, e-mail, phone number, company name.
- Account and licence: user ID, password hash (the password itself is not stored), licence period, device fingerprint (to bind the licence to a device), application version.
- Transaction security: sign-in times, IP address, API request logs, error logs.
- Usage records: screen changes and actions inside the Application (on your computer only, 60 days).
3.2 The business's customers (message recipients)
- Name, company name, phone number and, where provided, address, tax office and tax number.
- Transaction data from the ERP: transaction type, document number, amount, previous and current balance, transaction date.
- Reconciliation answers: the answer given (accept / reject / request details), explanation, date and time, IP address, digital signature record number.
- Notification preference: opt-out requests and their dates.
This data is entered into the Application by the business (which is itself the data controller) or transferred from its ERP. For this data Sahatek acts as a data processor and does not process it beyond the business's instructions.
3.3 Site visitors
- Server access logs: IP address, browser type, time of visit and requested page (for security and error detection).
- The Site does not use third-party analytics or advertising cookies.
4. Purposes of processing
- Installing, licensing, updating the Application and providing technical support.
- Delivering accounting and commercial notifications (invoice, collection, payment, statement, reconciliation etc.) to the business's customers.
- Running the digital account reconciliation process and keeping answers as evidence.
- Honouring the requests of persons who do not wish to receive notifications (blacklist).
- Ensuring information security, preventing abuse, detecting errors and attacks.
- Meeting legal obligations and requests from competent authorities.
- Concluding and performing the contract, invoicing and bookkeeping.
5. Legal grounds
Personal data is processed on the grounds listed in Article 5 of the KVKK: (a) necessity for concluding or performing a contract, (b) compliance with a legal obligation of the controller, (c) the controller's legitimate interest provided it does not harm the fundamental rights and freedoms of the data subject, (d) establishing, exercising or protecting a right. Where none of these applies your explicit consent is obtained; consent can be withdrawn at any time.
6. Transfers
- Hosting: WappNeo servers are located in Türkiye. Site and API traffic may pass through Cloudflare infrastructure for security and acceleration; only connection metadata (IP, request details) is processed in that transfer.
- WhatsApp / Meta: message content is delivered to the recipient through WhatsApp's infrastructure, from the business's own WhatsApp account.
- Your ERP vendor: the ERP software authorised by your business sends transaction notifications through the API and may read their results.
- Authorities: to legally competent public bodies when required by law.
Beyond these, personal data is never sold, rented or shared for marketing purposes.
7. Retention periods
- Account and licence data: for the term of the contract and 10 years after it ends (Turkish Code of Obligations and Tax Procedure Law).
- ERP queue records and send results: 12 months.
- Reconciliation records and digital signature data: 10 years, as evidence.
- Blacklist records: as long as the person does not wish to receive notifications.
- Server access and security logs: 6 months.
- Send logs and user activity on your computer: 60 days (deleted automatically by the Application).
When a period ends, data is deleted, destroyed or anonymised.
8. Data security
- All communication between the Application and the server is encrypted with TLS and every request is signed.
- Passwords are stored as one-way hashes; only a hash of ERP API secrets is kept.
- Server access is limited to authorised staff; administrative actions are logged.
- Regular backups are made and protected with the same safeguards.
- Application data on your computer is tied to your operating-system user account; device security is the business's responsibility.
9. Rights of message recipients and opting out
Persons who receive messages from a business through WappNeo can leave the notification list by tapping the link at the end of the message or by contacting the business. The opt-out is recorded with date and time, and no message is sent to that number through the Application until the business re-adds it. Requests about recipients' personal data are addressed first to the business as data controller; Sahatek, as processor, provides the business with the necessary support.
10. Cookies
The Site may use only strictly necessary technical cookies for security and session continuity. No analytics, advertising or tracking cookies are used. Web views inside the Application (e.g. WhatsApp Web) keep the cookies of those services on your computer; Sahatek does not read them.
11. Your rights under the KVKK
Under Article 11 of the KVKK you have the right to:
- Learn whether your personal data is processed and request information about it.
- Learn the purpose of processing and whether data is used accordingly.
- Know the third parties to whom data is transferred in Türkiye or abroad.
- Request correction of incomplete or inaccurate data.
- Request deletion or destruction under the conditions of Article 7 of the KVKK.
- Request that corrections, deletions and destructions be notified to third parties.
- Object to a result against you produced exclusively by automated analysis.
- Claim compensation for damage caused by unlawful processing.
12. How to apply
Send your requests, with information verifying your identity, to [email protected] or in writing to Sahatek's address in Konya. Applications are concluded free of charge within 30 days at the latest; where the process entails additional cost, the tariff set by the Personal Data Protection Board applies. If your application is rejected, the answer is insufficient or no answer is given in time, you may lodge a complaint with the Personal Data Protection Board.
13. Changes
This notice may be updated according to changes in legislation or our services. The current version is always published at wappneo.com/en/kvkk.html; material changes are announced inside the Application. The Turkish version is the legally binding text.
