Privacy Policy
This policy explains how personal data is processed when you use the intordia.com website and the intordia.app platform (together, the “Service”). It is our notice under the Turkish Personal Data Protection Law No. 6698 (KVKK), Article 10, and the EU General Data Protection Regulation (GDPR), Articles 13–14. If the Turkish and English versions differ, the Turkish version prevails.
In short
- Intordia is a brand of Serkan Ceylan, sole proprietorship. We are the controller for our own user accounts.
- Data a business enters into or connects to the platform belongs to that business; we process it only to provide the service.
- We do not sell your data, use it for advertising, or use tracking cookies.
- Data from Google and Meta is used only for the feature you connect and is never used to train any AI model.
- Our servers are in the European Union.
- You can delete your account and data, and write to info@intordia.com about your rights.
1. Data controller
SERKAN CEYLAN (sole proprietorship, Türkiye) — owner of the “Intordia” brand.
Location: Kırıkkale, Türkiye
E-mail: info@intordia.com · Web: https://intordia.com · Platform: https://intordia.app
“We”, “us” and “Intordia” in this policy refer to the data controller above.
2. Our two roles
intordia.app is a platform that businesses (“Customers”) use to manage relationships with their own customers. We therefore act in two roles:
- As controller for the account data of people who use the platform (name, e-mail, login and security records), our correspondence with you, and subscription and billing data.
- As processor for the data a Customer enters into the platform or receives through channels it connects — for example its contact records, WhatsApp/Instagram/Messenger conversations, e-mail archive, calendar entries, forms and bookings. The Customer is the controller of this data; we process it only on the Customer’s instructions and to provide the Service.
If you are a customer of one of our Customers (for example, you messaged a business on WhatsApp), please contact that business first about your data. If you write to us, we will forward your request to the business and help it respond.
3. Data we process
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, e-mail, phone, profile photo, company name, job title | You or the admin who invited you; Google if you use “Sign in with Google” |
| Account security | One-way password hash, two-step verification and passkey data, sessions, IP address, browser details, login attempts | Collected automatically when you use the Service |
| Activity records | Who changed which record and when (audit log); access logs | Automatic |
| Usage information | How often screens are used | Automatic |
| Subscription and billing | Billing name, tax details, address, payment status (we do not store card details) | You |
| Correspondence | Support and contact e-mails | You |
| Customer data (as processor) | The Customer’s contact and lead records, message content and media, e-mail archive, calendar events and attendees, form and booking data, sales and quote records, advertising and web analytics reports | The Customer and the services it connects |
We do not aim to collect special categories of data (health, religion, biometrics, etc.). Customers are responsible for not entering such data, or for meeting the legal conditions if they do.
4. Purposes and legal bases
| Purpose | KVKK Art. 5(2) | GDPR Art. 6(1) |
|---|---|---|
| Creating your account, signing you in, providing the Service, running the channels you connect | (c) performance of a contract | (b) contract |
| Account and system security, abuse prevention, debugging, audit log | (f) legitimate interest | (f) legitimate interest |
| Invoicing, tax and accounting duties, requests from authorities | (ç) legal obligation | (c) legal obligation |
| Establishing, exercising or defending legal claims | (e) establishment or protection of a right | (f) legitimate interest |
| Usage measurement to improve the Service (not for personalised advertising) | (f) legitimate interest | (f) legitimate interest |
| Answering support requests | (c) contract / (f) legitimate interest | (b) / (f) |
We do not sell personal data, we do not share it with third parties for advertising, and we do not make decisions with legal effects about you based solely on automated processing.
5. Meta services (WhatsApp, Instagram, Messenger, Facebook)
A Customer can connect its own WhatsApp Business account, Instagram professional account or Facebook Page to intordia.app. A connection is made only with the approval of the Customer’s authorised person and can be removed at any time.
| Service | What we use it for | What we store |
|---|---|---|
| WhatsApp Business Platform (Cloud API) | Showing messages sent to the business in its inbox, sending the business’s replies and template messages, tracking message status (delivered, read), and handling calls where the business enables them | Phone number or the user ID provided by Meta, profile name, message content, media files, message status. Calls are not recorded. |
| Instagram messaging | Showing and replying to messages sent to the business’s Instagram account | Instagram user ID, username, name, profile picture link, messages and media |
| Messenger and Facebook Pages | Showing and replying to messages sent to the Page; if the business chooses, importing Facebook Lead Ads form submissions into its leads | Page-scoped user ID, name, profile picture link, messages and media; lead form fields and which ad/form they came from |
| Meta ads reporting | Reporting the business’s aggregate ad results such as spend, impressions and clicks (read-only) | Campaign-level aggregate numbers; no person-level data |
The Meta permissions we request are used only for the purposes above: whatsapp_business_management, whatsapp_business_messaging, business_management, instagram_business_basic, instagram_business_manage_messages, pages_show_list, pages_manage_metadata, pages_messaging, pages_read_engagement, leads_retrieval, pages_manage_ads, ads_read. We do not use data received from Meta for ad targeting, we do not sell it, and we do not use it to train any AI model. We share it only with the sub-processors that run the Service (section 10) and, if the Customer has turned on the AI add-on, with our AI provider for the summaries and suggestions the Customer requests by pressing a button (section 9). WhatsApp messages are delivered through Meta’s infrastructure (WhatsApp Cloud API) and are also processed in Meta’s own data centres, under Meta’s own terms. Access tokens are stored encrypted. For deletion requests see Data deletion.
6. Google services
Users can sign in with their Google account and, if they choose, connect the Google services below. For each connection Google shows you the permissions we request and asks for your consent. Some connections may not yet be available to everyone on the platform; those that are available are requested only when you choose them.
| Connection and scope | What we use it for | What we store |
|---|---|---|
Sign in with Googleopenid, email, profile | Identifying your account and signing you in | Name, e-mail, Google account ID, profile picture |
Google Calendarcalendar.events, calendar.calendarlist.readonly (optional) | Showing your calendar events in the platform; creating, updating and cancelling the meetings and bookings you schedule in the platform; checking busy times in other calendars you select to find free slots | A copy of events from the last 30 days to the next 120 days (title, description, location, meeting link, time, attendees’ names and e-mails). Events marked “private” are not linked to customer records. |
Google Contactscontacts.readonly, contacts (write optional) | Importing contacts from your address book into the business’s customer records; if you grant write access, sending the customer records you own to your address book | Name, e-mail, phone, company, address; sync mapping |
Google Drivedrive.file | Linking only the file you pick to a record; saving documents such as quotes to your Drive when you ask | The picked file’s name, type, size and link. File content is not stored; no other Drive files are accessed. |
Send with Gmailgmail.send | Sending e-mails you write in the platform from your address | Sender address and name; a copy of the sent e-mail in the business’s archive. Your inbox is never read. |
Google Analyticsanalytics.readonly | Showing website traffic reports for the business | Daily aggregate numbers (visitors, sessions, page views, aggregate age and gender ranges) |
Google Search Consolewebmasters.readonly | Reporting how the business’s website appears in search | Search queries, pages, clicks, impressions, position |
Google Adsadwords | Reporting campaign spend and results and showing keyword ideas. Although this scope is technically broad, we use it read-only; we never change campaigns. | Campaign-level aggregate numbers |
Google Business Profilebusiness.manage | Reporting the business’s profile locations and performance numbers | Location names and daily aggregate numbers |
Google API Services User Data Policy disclosure. Intordia’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve the user-facing features described above.
- We do not sell this data, and we do not use it for serving ads, personalised advertising or credit decisions.
- We do not send this data to AI models, and we do not use it to develop, improve or train generalised AI or machine-learning models.
- We transfer this data to others only on your instruction (for example, a report sharing link your business creates), for security purposes, or to comply with the law.
- Our staff can view this data only with your explicit consent, for security investigations, or where required by law.
You can revoke Google access at any time by removing the connection in the platform or from your Google Account permissions page.
7. Microsoft services
The platform is built to support sign-in with Microsoft, Outlook calendar, Outlook contacts, OneDrive/SharePoint file picking and sending e-mail via Outlook. When these connections are enabled, the same rules as for Google apply: they are requested only when you choose them, with the permissions shown (User.Read, Calendars.ReadWrite, Contacts.Read/Contacts.ReadWrite, Files.Read/Files.ReadWrite, Mail.Send, offline_access), and used only for the related feature. Microsoft data is not sent to AI models.
8. Other services a Customer connects
A Customer can also connect other services with its own credentials: its own mailboxes (sending and reading replies), e-mails forwarded from its mail server for archiving, payments, shipping, SMS and consent management, telephony, marketplaces and e-commerce, LinkedIn, TikTok and Zoom. Data is exchanged with these services on the Customer’s instructions and only to run that feature; credentials are stored encrypted. Those services’ own privacy terms also apply.
9. AI add-on
AI features are off by default. If a Customer’s admin turns on the add-on and accepts its terms, authorised users can press a button to get a summary of a conversation, a reply draft or a sales analysis. In that case:
- The conversation (WhatsApp, Instagram, Messenger or an archived e-mail) is sent to our AI provider, Google’s Gemini service. E-mail addresses, phone numbers, IBANs, national ID and card numbers are masked first.
- Processing happens only when the button is pressed; there is no automatic or background AI processing.
- AI suggestions are never written to records until a person approves them.
- We use Google’s paid Gemini service. Google does not use the text sent or the responses to train its models or improve its products; it keeps these records for a limited time only to detect abuse. We do not use this data to train any AI model either.
- The (masked) text sent and the response are kept for 90 days for audit, then deleted.
- Data received from Google APIs (Calendar, Contacts, Drive, Gmail, Analytics, etc.) is never sent to AI.
- Processing takes place on Google’s infrastructure and is not guaranteed to stay within the EU. This is shown to the Customer when the add-on is turned on.
10. Who we share data with
We use the following service providers (sub-processors) to run the Service. Each can access only the data it needs for its task.
| Provider | Purpose | Data location |
|---|---|---|
| netcup GmbH | Server running the platform (database, files, e-mail archive) | European Union |
| Cloudflare, Inc. | Storing encrypted database backups; hosting intordia.com and e-mail forwarding | Backups in the EU; website traffic on Cloudflare’s global network |
| Google LLC / Google Ireland Ltd. | Sign in with Google; Gemini if the AI add-on is on | Google infrastructure |
Beyond these, data may be transferred to services the Customer connects on its own instructions (Meta, Google, e-mail, payments, shipping, etc.), to competent authorities where legally required, and to lawyers and courts in legal disputes. If we change our server provider, we will update this list.
11. International transfers
The platform’s servers are in the European Union, and some of the providers above are based in the United States. Personal data is therefore transferred outside Türkiye. These transfers rely on the appropriate safeguards provided in KVKK Article 9 (standard contracts) and, under the GDPR, on the European Commission’s standard contractual clauses. Signing the standard contracts with our providers and notifying the Turkish Personal Data Protection Authority is in progress; we will update this section when it is complete.
12. Retention
| Data | Period |
|---|---|
| User account | While the account exists. When you delete your account, your login data, sessions and personal connections are deleted immediately; business records you created stay with the business they belong to. |
| Customer data | While the Customer’s account exists, or as long as the Customer sets (Customers can set automatic deletion between 30 days and 10 years for messages, e-mail archive, activity logs and similar data). When a Customer asks to delete its account, all of its data, including the audit log, is permanently deleted after a 14-day grace period; only a record proving the deletion took place remains. |
| Login attempts | 180 days |
| Audit log | At least 365 days while the Customer’s account exists (Customers can choose longer); deleted with the Customer’s account |
| AI request logs | 90 days |
| API and webhook delivery logs | 30 days |
| Usage metrics | 25 months |
| Export files | 7 days |
| Quarantined e-mails | 30 days |
| Backups | Encrypted daily backups 40 days, monthly backups 190 days; nightly backups on the server 14 days. Deleted data leaves the backups when these periods end. |
| Invoices and accounting records | As required by tax law (at least 5 years) |
When a person’s data is deleted, we keep an encrypted record proving the deletion took place, which does not directly identify the person.
13. Security
- All connections are encrypted (HTTPS/TLS).
- Access tokens and passwords for connected services are stored encrypted (AES-256-GCM).
- The e-mail archive is encrypted with a separate key for each Customer.
- Each Customer’s data is separated from other Customers at database level; one Customer cannot see another’s data.
- Passwords are stored as one-way hashes, and known breached passwords are rejected. Two-step verification and passkeys are supported.
- Important actions are written to a tamper-evident audit log.
- We access a Customer’s data only at the Customer’s request for support, for security investigations or where required by law, and only as much as needed.
- Database backups are encrypted and stored in a separate location in the EU, and restores are tested regularly.
No system is perfectly secure. If a personal data breach occurs, we will notify the competent authority and affected people or Customers within the time limits required by KVKK and the GDPR.
14. Cookies
intordia.com uses no cookies. intordia.app uses only strictly necessary cookies; we do not use analytics, advertising or tracking cookies, so no cookie consent is requested.
| Cookie | Purpose | Duration |
|---|---|---|
__Secure-better-auth.session_token | Keeps you signed in | 30 days (renewed while you use it) |
__Secure-better-auth.dont_remember | Marks that “remember me” was not chosen | Until the browser closes |
__Secure-better-auth.two_factor, __Secure-better-auth.trust_device | Completes two-step sign-in; remembers “trust this device” | During sign-in / 30 days |
__Secure-better-auth-passkey | One-time check during passkey sign-in | A few minutes |
predator_fb_pages | Completes the page selection step when connecting a Facebook Page (encrypted) | 15 minutes |
NEXT_LOCALE, ui_look, predator-acik-menuler, predator_firmasiz | Language, appearance and menu preferences; company setup step | 1 year |
Your browser’s local storage also keeps preferences such as theme and screen settings; these are not sent to our servers.
15. Your rights
Under KVKK Article 11 you have the right to learn whether your personal data is processed and to request information about it; to learn the purpose of processing and whether it is used accordingly; to know the third parties in Türkiye or abroad to whom it is transferred; to request correction of incomplete or inaccurate data; to request deletion or destruction when the conditions of KVKK Article 7 are met, and to have these actions notified to third parties; to object to an outcome against you resulting solely from automated analysis; and to claim compensation for damage caused by unlawful processing.
If the GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability and objection.
How to make a request: e-mail info@intordia.com from the address registered to your account. We may ask for additional information to verify your identity. We will respond free of charge within 30 days at the latest. You can also delete your account or your company account inside the platform.
If you are not satisfied with our response, you can complain to the Turkish Personal Data Protection Board (KVKK) or, if you live in the EU, to the data protection authority of your country.
16. Children
The Service is designed for businesses and is not directed at anyone under 18. If we learn that someone under 18 has opened an account, we will close it.
17. Changes
We update this policy when the Service or the law changes. The current version is always on this page; we announce important changes inside the platform or by e-mail.