CREATIVES DATA SAAS PERSONAL DATA PROTECTION AND PRIVACY POLICY
PERSONAL DATA PROTECTION AND PRIVACY POLICY
Last Updated: [29/03/2026]
1. IDENTITY OF THE DATA CONTROLLER
This Personal Data Protection and Privacy Policy (“Policy”) has been prepared by the data controller identified below, in accordance with the Turkish Law on the Protection of Personal Data No. 6698 (“KVKK” or “the Law”).
Data Controller: Talha Çoruh (Creatives Data) Tax Office / Tax ID: Göztepe Tax Office / 2610618364 Address: Fikirtepe Mah. Rüzgar Sok. No:29/1K Kadıköy, Istanbul, Turkey Phone: +90 533 375 25 77 Email: contact@creativesdata.com Website: https://creativesdata.com Contact Person: Talha Çoruh — contact@creativesdata.com
This Policy has been prepared for the purpose of fulfilling the obligation of disclosure in connection with personal data collected, processed, and stored through the WhatsApp Business communication management platform (“Platform”) operated by Creatives Data, within the framework of Article 10 of the KVKK and the Communiqué on Procedures and Principles to Be Observed in Fulfilling the Obligation of Disclosure.
2. DEFINITIONS
The following terms used in this Policy carry the meanings set forth below:
Personal Data: Any information relating to an identified or identifiable natural person.
Data Controller: The natural or legal person who determines the purposes and means of the processing of personal data and is responsible for the establishment and management of the data filing system.
Data Processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
Data Subject: The natural person whose personal data is processed.
Platform: The web-based software service operated by Creatives Data that enables businesses to communicate with their customers via WhatsApp Business API.
Platform User: Business owners, employees, and authorized representatives who register for and use the services of our Platform.
End User: The customers, recipients, and relevant individuals that a Platform User (business) communicates with via WhatsApp.
WABA: WhatsApp Business Account; the business account provided by Meta.
Meta: Meta Platforms, Inc. and its subsidiary WhatsApp LLC.
3. SCOPE OF THE POLICY AND THE COMPANY’S DUAL ROLE
Creatives Data processes personal data in two distinct capacities through the Platform:
a) As Data Controller: With respect to Platform Users’ account information, payment information, team member information, and data relating to Platform usage, Creatives Data holds the status of data controller under the KVKK. The purposes and methods for processing these data are determined directly by Creatives Data.
b) As Data Processor: With respect to the personal data of End Users belonging to the businesses that are Platform Users (WhatsApp message content, phone numbers, conversation histories, etc.), Creatives Data operates in the capacity of data processor, acting in accordance with the instructions of the relevant business. The data controller status for these data belongs to the business using the Platform.
This Policy covers data processing activities conducted by Creatives Data in both capacities.
4. CATEGORIES OF PERSONAL DATA PROCESSED
4.1. Data Belonging to Platform Users (In the Capacity of Data Controller)
Identity Information: First name, last name, company name, tax identification number, tax office.
Contact Information: Email address, phone number, business address.
Account Information: Username, password (in encrypted form), account creation date, account status, user role (administrator, agent, etc.).
Financial Information: Billing address, payment method details (credit card information is processed directly by iyzico and is not stored by Creatives Data), subscription plan, invoice history.
WhatsApp Account Information: WABA ID, Phone Number ID, business profile information (business name, description, address, logo), Meta Business Portfolio information, quality rating status, messaging tier.
Transaction Security Information: IP address, session data, browser type and version, operating system, access date and time, pages accessed, error logs.
Marketing Information: Communication preferences, notification settings, email open and click data (only if explicit consent has been provided).
4.2. Data Belonging to End Users (In the Capacity of Data Processor)
The following End User data is processed in accordance with the instructions and directions of the Platform User (business):
Contact Information: Phone number, WhatsApp profile name.
Messaging Data: Content of sent and received messages (text, images, video, documents, audio, location, contact shares), message send/delivery/read timestamps, message status information (sent, delivered, read, error).
Tag and Segmentation Data: Tags, groups, and notes assigned to End Users by the Platform User.
Campaign Data: Inclusion in broadcast campaigns, message delivery and read information.
Media Files: Photo, video, audio recording, and document files sent or received via WhatsApp.
5. PURPOSES OF PROCESSING PERSONAL DATA
5.1. Processing Purposes in the Capacity of Data Controller
Creatives Data processes the personal data of Platform Users for the following purposes:
a) Conducting Platform membership and account creation processes.
b) Providing, operating, and maintaining the Platform; ensuring WhatsApp Business API integration.
c) Managing the WhatsApp Business Account creation process through the Meta Embedded Signup flow.
d) Delivering message sending, receiving, template management, broadcast campaign, and conversation inbox services.
e) Managing subscriptions, processing payment transactions, and conducting billing processes.
f) Addressing user support requests and resolving technical issues.
g) Ensuring Platform security, detecting and preventing unauthorized access attempts.
h) Fulfilling legal obligations (tax legislation, commercial law, electronic commerce regulations).
i) Monitoring Platform performance, generating usage statistics, and improving service quality.
j) Conducting marketing communications regarding new features, updates, and promotions, provided that your explicit consent has been obtained.
5.2. Processing Purposes in the Capacity of Data Processor
Personal data belonging to End Users is processed solely for the purposes determined by the business that is the Platform User and within the framework of their instructions. These purposes generally include:
a) Technically facilitating the sending and receiving of messages via WhatsApp Cloud API.
b) Submitting message templates to Meta and tracking the approval process.
c) Storing and displaying conversation histories.
d) Technically executing broadcast campaigns.
e) Generating message delivery status and analytics reports.
f) Temporarily storing and transmitting media files.
6. METHOD AND LEGAL BASIS FOR COLLECTING PERSONAL DATA
6.1. Collection Methods
Your personal data is collected through the following methods:
a) Automatically through the registration, login, and account management operations you perform on the Platform.
b) Automatically from your Facebook account during the Meta Embedded Signup flow.
c) Automatically through WhatsApp Cloud API webhook notifications.
d) Automatically through the iyzico payment infrastructure during payment transactions.
e) Partially automatically through customer support channels (email, live chat).
f) Automatically through cookies and similar technologies during your visit to our website.
6.2. Legal Bases
Your personal data is processed on the following legal bases:
KVKK Article 5/2(a) — Being explicitly prescribed by laws: Invoice information, transaction records, and data subject to statutory retention periods for the purpose of fulfilling our obligations under the Tax Procedure Law, the Turkish Commercial Code, and related legislation.
KVKK Article 5/2(c) — Being directly related to the formation or performance of a contract: Formation of the Platform service agreement, account creation, linking a WhatsApp Business Account, delivering messaging services, managing subscriptions, and processing payment transactions.
KVKK Article 5/2(ç) — Being necessary for the data controller to fulfill its legal obligations: Issuing e-invoices and e-archive invoices, tax declarations, statutory notification obligations.
KVKK Article 5/2(e) — Being necessary for the establishment, exercise, or protection of a right: Creating evidence in potential legal disputes, responding to legal claims.
KVKK Article 5/2(f) — Being necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject: Ensuring Platform security, detecting unauthorized access attempts, maintaining error logs, using essential cookies, fraud prevention.
KVKK Article 5/1 — Explicit consent: Marketing communications, analytics and advertising cookies, Facebook SDK tracking technologies. These processing activities are only carried out if your explicit consent has been obtained; you may withdraw your consent at any time.
7. DATA SHARING WITH WHATSAPP BUSINESS API AND META
7.1. Use of Meta/WhatsApp Infrastructure
Our Platform utilizes the WhatsApp Cloud API infrastructure provided by Meta. In this context:
a) Messages sent and received via WhatsApp Business API are temporarily processed on Meta’s global infrastructure (primarily in data centers in the United States and the European Union).
b) Meta retains undelivered messages on its servers for a maximum of 30 (thirty) days and automatically deletes them at the end of this period.
c) Data transferred to Meta includes: sender and recipient phone numbers, message content (text, images, video, documents, audio, location), message metadata (send time, delivery time, read time), message status information, message template content, and WhatsApp business profile information.
7.2. Meta Embedded Signup
Meta’s Embedded Signup flow is used during the WhatsApp Business Account creation process. During this process:
a) Identity verification is performed through your Facebook account.
b) Business name, phone number, business category, and Meta Business Portfolio information are shared with Meta.
c) Temporary session cookies are created in your browser using the Facebook JavaScript SDK.
d) The WhatsApp Business Account ID and access tokens created are stored in encrypted form by our Platform.
7.3. Meta Business Tools
The Platform uses Facebook Login and the Facebook JavaScript SDK. These tools may collect or receive certain information through cookies and web beacons belonging to Meta. Meta may use this information for measurement and ad targeting purposes. For Meta’s own privacy policy, please visit: https://www.facebook.com/privacy/policy/
7.4. Artificial Intelligence Restriction
Pursuant to the WhatsApp Business Solution Terms, data obtained through WhatsApp Business API is not used for the purpose of creating, developing, training, or improving any machine learning or artificial intelligence system. The sole exception to this restriction is the fine-tuning of an AI model exclusively for the use of the relevant business.
8. DOMESTIC TRANSFER OF PERSONAL DATA
Your personal data may be transferred to the following domestic recipients within the scope of Article 8 of the KVKK:
iyzico Ödeme Hizmetleri A.Ş. ??????? — For the purpose of processing payment transactions. iyzico is a payment institution licensed by the Central Bank of the Republic of Turkey (BDDK) and certified at PCI DSS Level 1. Your credit card information is processed directly by iyzico and is not stored by Creatives Data.
Paraşüt Yazılım Teknolojileri A.Ş ?????? . — For the purpose of issuing e-invoices and e-archive invoices within the scope of invoicing and accounting management services.
Authorized Public Institutions and Organizations — Upon the request of authorized courts, prosecutors’ offices, tax offices, the Personal Data Protection Authority, and other regulatory bodies, within the framework of our statutory obligations.
9. CROSS-BORDER TRANSFER OF PERSONAL DATA
A portion of your personal data is transferred abroad within the scope of Article 9 of the KVKK in order to provide our Platform services. These transfers are carried out within the framework of the Standard Contractual Clauses (Type 2: Controller to Processor) published by the Personal Data Protection Board on July 10, 2024, and each signed Standard Contract is notified to the Personal Data Protection Authority within 5 (five) business days.
The recipients to which data is transferred abroad, the categories of data transferred, and the purposes of transfer are set forth below:
9.1. Meta Platforms, Inc. / WhatsApp LLC (United States of America)
Data Transferred: Phone numbers, message content, media files, message metadata, WhatsApp business profile information, message template content.
Purpose of Transfer: Technical provision of WhatsApp Business API messaging services.
Transfer Mechanism: KVKK Standard Contractual Clauses (Type 2).
9.2. Supabase Pte. Ltd. (Singapore / European Union — Frankfurt Region)
Data Transferred: Account information, authentication data, all platform data stored in the database.
Purpose of Transfer: Provision of database hosting, authentication, and real-time data synchronization services.
Transfer Mechanism: KVKK Standard Contractual Clauses (Type 2). Our database project is located in the European Union region (Frankfurt, Germany).
9.3. Vercel Inc. (United States of America)
Data Transferred: Transaction security information (IP address, browser information), application data, data temporarily accessed during server-side processing.
Purpose of Transfer: Provision of web application hosting, server-side function execution, and content delivery network (CDN) services.
Transfer Mechanism: KVKK Standard Contractual Clauses (Type 2). Our server-side functions are executed in the European Union region (Frankfurt).
10. PROCESSING OF PAYMENT AND INVOICE DATA
10.1. Payment Transactions
Platform subscription payments are processed through the infrastructure provided by iyzico Ödeme Hizmetleri A.Ş. In this context:
a) Your credit card number, expiration date, and CVV information are processed directly on iyzico’s PCI DSS Level 1 certified secure servers. This information is not stored on Creatives Data servers in any manner whatsoever.
b) Information transferred to iyzico includes: billing name and surname, billing address, email address, phone number, order amount, and payment result information.
c) iyzico processes recurring payment transactions within the scope of subscription management and transmits webhook notifications regarding payment status to our Platform.
10.2. Invoicing
In accordance with our legal obligations, e-invoices and e-archive invoices are issued using the infrastructure of Paraşüt Yazılım Teknolojileri A.Ş. Information appearing on invoices (name-surname or trade name, tax identification number/Turkish ID number, address) is retained for 5 (five) years pursuant to Tax Procedure Law No. 213.
11. RETENTION PERIODS FOR PERSONAL DATA
Your personal data is retained for the duration required by the processing purposes and for the statute of limitations periods stipulated in the relevant legislation. When the processing purpose ceases to exist and the statutory retention period expires, your personal data is deleted, destroyed, or anonymized.
Account information: For the duration the account is active and 1 (one) year from the date of account deletion.
Messaging data (End User data): For the period determined by the Platform User; deleted within 30 (thirty) days at the latest following the deletion of the Platform User’s account.
Payment and invoice information: 5 (five) years pursuant to Tax Procedure Law No. 213.
Transaction security information (log records): 2 (two) years pursuant to Law No. 5651.
Marketing communication records: Until the withdrawal of explicit consent; deleted within 30 (thirty) days at the latest following withdrawal.
Cookie data: Varies by cookie type; session cookies expire when the browser is closed, and persistent cookies expire after a maximum of 13 (thirteen) months.
WhatsApp Business Account information (WABA ID, tokens): For the duration the account is active; immediately destroyed upon account deletion.
Periodic destruction of personal data is carried out at intervals of no more than 6 (six) months in accordance with the Regulation on Deletion, Destruction, or Anonymization of Personal Data.
12. MEASURES RELATING TO PERSONAL DATA SECURITY
Pursuant to Article 12 of the KVKK, Creatives Data takes the following technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure the safekeeping of personal data:
12.1. Technical Measures
a) All data transmissions are protected with TLS 1.2 and above encryption protocols.
b) User passwords are stored using one-way cryptographic hash functions and are never stored in plain text.
c) WhatsApp API access tokens are stored in the database with AES-256 encryption.
d) Database access is controlled through Row Level Security (RLS) policies, ensuring that each tenant can only access its own data.
e) WhatsApp webhook requests are subjected to identity verification through HMAC-SHA256 signature validation.
f) Regular security scans and vulnerability assessments are conducted.
g) Access logs are maintained and audited on a regular basis.
h) Database backups are performed in encrypted form.
12.2. Administrative Measures
a) Access to personal data is restricted in accordance with an authorization matrix aligned with job descriptions.
b) Regular training on personal data processing activities is provided to employees.
c) Written data processing agreements have been executed with data processors (iyzico, Paraşüt, Supabase, Vercel, Meta).
d) A Personal Data Retention and Destruction Policy has been established and is being implemented.
e) A procedure has been established to notify the Personal Data Protection Board and the affected data subjects in the shortest possible time and in any case within 72 (seventy-two) hours of becoming aware of a data breach, pursuant to Article 12, paragraph 5 of the KVKK.
13. COOKIE POLICY
13.1. What Are Cookies?
Cookies are small text files placed on your device through your browser when you visit our website. Cookies are used to ensure the proper functioning of our site, to implement security measures, and to improve the user experience.
13.2. Types of Cookies Used
Essential Cookies (Legal Basis: Legitimate Interest — KVKK Art. 5/2(f)): These are cookies necessary for the basic functions of the Platform to operate. They include session management, authentication, and security cookies. Without these cookies, Platform services cannot be provided. They do not require separate consent.
Analytics Cookies (Legal Basis: Explicit Consent — KVKK Art. 5/1): These are cookies that help us understand how the Platform is being used. They collect information such as page view counts, visit durations, and error reports. These cookies are only activated with your explicit consent.
Facebook/Meta Cookies (Legal Basis: Explicit Consent — KVKK Art. 5/1): These are cookies placed by Meta during the Embedded Signup and Facebook Login processes (such as _js_datr, _fbp). Meta may use these cookies for measurement and ad targeting purposes. These cookies are only activated with your explicit consent.
13.3. Cookie Preferences
A cookie consent notification is presented to you upon your first visit to our Platform. All cookies other than essential cookies are not activated without your explicit consent being obtained. You can change your cookie preferences at any time through the cookie settings panel on the Platform or through your browser settings.
14. RIGHTS OF THE DATA SUBJECT
Pursuant to Article 11 of the KVKK, you have the following rights as a data subject whose personal data is processed:
a) The right to learn whether your personal data is being processed.
b) The right to request information if your personal data has been processed.
c) The right to learn the purpose of the processing of your personal data and whether it is used in accordance with its purpose.
d) The right to know the third parties to whom your personal data is transferred, domestically or abroad.
e) The right to request the rectification of your personal data if it has been processed incompletely or inaccurately.
f) The right to request the deletion or destruction of your personal data within the framework of the conditions stipulated in Article 7 of the KVKK.
g) The right to request that the operations carried out pursuant to paragraphs (e) and (f) be notified to third parties to whom your personal data has been transferred.
h) The right to object to the emergence of a result against you through the exclusive analysis of your processed data by automated systems.
i) The right to claim compensation for damages arising from the unlawful processing of your personal data.
15. APPLICATION METHOD
You may submit your requests regarding the rights set forth above through the following methods, in compliance with the conditions specified in the Communiqué on the Procedures and Principles of Application to the Data Controller:
Written Application: By sending a wet-signed petition together with documents verifying your identity to the address Fikirtepe Mah. Rüzgar Sok. No:29/1K Kadıköy, Istanbul, Turkey.
Application via Email: To the address contact@creativesdata.com, by using a registered electronic mail (KEP) address, secure electronic signature, or mobile signature, or through the email address you have previously communicated to our Company and which is registered in our system.
Your application must include: your first name, last name, your signature if the application is in writing, your Turkish ID number (for foreign nationals, passport number or identification number if available), your residential or business address for notification purposes, your electronic mail address if available for notification, phone and fax number, and the subject of your request.
Your applications will be concluded free of charge in the shortest time possible and within 30 (thirty) days at the latest, depending on the nature of the request. In cases where the transaction requires an additional cost, the fee determined by the Personal Data Protection Board’s tariff may be charged.
In the event that your application is rejected, the response given is deemed insufficient, or no response is given within the prescribed period, you retain the right to file a complaint with the Personal Data Protection Board within 30 (thirty) days following the notification of the response to you and in any case within 60 (sixty) days from the date of application.
16. INFORMATION FOR END USERS
This section contains information directed at the End Users with whom Platform User businesses communicate via WhatsApp.
Creatives Data holds the position of data processor with respect to the personal data of End Users. The data controller with respect to the personal data of End Users is the relevant business using our Platform. End Users’ rights under the KVKK should be directed to the relevant business that holds the status of data controller.
Nonetheless, as Creatives Data, we apply all technical and administrative measures set forth in Section 12 of this Policy for the purpose of ensuring the security of End User data. Upon the termination of the account of the business that is the Platform User, the relevant End User data is deleted from our systems within 30 (thirty) days at the latest.
17. CHANGES TO THE POLICY
Creatives Data reserves the right to update this Policy in line with changes in legal regulations, updates to Platform features, or changes in data processing activities.
Material changes made to the Policy will be communicated to you through the notification system on the Platform and via your registered email address. The updated Policy enters into force on the date of its publication. You can review the current version of the Policy on this page at any time.
18. CONTACT INFORMATION
For any questions, opinions, and requests regarding the processing of your personal data, you may reach us through the following communication channels:
Data Controller: Talha Çoruh (Creatives Data) Address: Fikirtepe Mah. Rüzgar Sok. No:29/1K Kadıköy, Istanbul, Turkey Phone: +90 533 375 25 77 Email: contact@creativesdata.com Website: https://creativesdata.com
This Personal Data Protection and Privacy Policy entered into force on [29/03/2026].