This document is also available in Turkish. If the two versions differ, the Turkish version prevails.
1. Scope and roles
This policy covers three groups: customers who open a Layvchat account, the agents who use our customers’ consoles, and visitors to layvchat.com. Layvchat is the controller of their data.
For people who use the chat widget on our customers’ sites, send them emails or tickets, or read their help centers, the controller is the business concerned; we only process that data on the business’s behalf and instructions. These people should direct requests about their data to the business they contacted first. This relationship is governed by the Data Processing Addendum.
Contact: [email protected]
2. Data we collect
- Account data: name, username, email address, password (stored only as a one-way hash), two-factor secret (encrypted), language and notification preferences, profile photo; if you use Sign in with Google, your Google account ID and email address
- Mobile app data: push notification token, device platform (Android / iOS) and app language. The session key is kept only in the phone’s secure storage (Keychain / Keystore)
- Workspace data: business name, site addresses, brand settings, team, role and department information, plan
- Payment data: plan, amount, the address created for the payment, the sending wallet address and the blockchain transaction ID. We never have access to your wallet’s private key or to card details
- Usage and security data: sign-in times, IP address, browser and device details, sessions, failed sign-in attempts and a log of significant actions in the console
- Communication data: support messages, emails and feedback you send us
- Website data: your language choice on layvchat.com and the technical access logs kept by the server (IP address, date, requested page). We use no advertising or tracking tools
Customer Data (chats, emails, tickets, files, visitor information) is processed on our customers’ behalf; see the Data Processing Addendum.
3. How we collect data
We collect data electronically from you directly (sign-up form, console, mobile app, support conversations), from Google if you use Sign in with Google, from public blockchain records during payment, and from the Service’s automatic logs.
4. Purposes and legal bases
- Opening your account, providing the Service, verifying payments and giving support: entering into and performing the contract
- Keeping accounts secure, notifying you of sign-ins from new devices, preventing abuse and unauthorized access: legitimate interest and legal obligation
- Sending necessary service messages (verification, password reset, invitations, security alerts, trial and renewal reminders): performing the contract
- Keeping payment records and responding to requests from authorities: legal obligation
- Producing aggregated, anonymous statistics to improve the Service: legitimate interest
- Marketing emails: only with your separate, explicit consent, which you can withdraw using the link in every email
5. AI
Smart reply suggestions and similar AI features run only on Layvchat’s own servers. Your account data and Customer Data are never sent to an external AI provider, and one customer’s data is never used in another customer’s suggestions.
6. Sharing
We do not sell data or share it with advertising networks. We share it only with the service providers we use to run the Service, and only as far as each needs for its job. The current list is on the Sub-processors page.
If authorities make a lawful request, we disclose only what is required and, unless the law prevents it, inform the customer concerned.
In a merger, acquisition or business transfer, data may pass to our successor together with the protections in this policy; we will tell you in advance.
7. International transfers
The database and files are stored on our servers in security-certified data centers. Some of our service providers are based abroad, so some data is transferred internationally. These transfers are made under standard contracts and the providers’ data processing commitments, in line with Article 9 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and the relevant provisions of the GDPR.
8. Retention
- Account and workspace data: while the account is open; deleted within 30 days after the workspace is closed
- Chats, emails, tickets and files: for the retention period our customer sets in the console
- Activity and security logs: while the workspace is open; deleted together with the other data when it is closed
- Payment records: for the period required by applicable law
- Backups: encrypted, for up to 30 days; deleted data leaves the backups by the end of this period at the latest
9. Security
We protect data with measures such as encrypted connections, one-way password hashing, two-factor authentication, encrypted backups, file scanning and a tamper-proof activity log. Details are on the Security page. No system is completely risk-free; if we learn of a data breach, we notify those affected and the competent authority within the legal deadline.
10. Cookies
We use no advertising or tracking cookies. The cookies and browser storage we use are only for the Service to work; see the Cookie Policy.
11. Your rights
Under Article 11 of the KVKK and the GDPR, you have the right to know whether your data is processed, to request information and a copy, to have it corrected or deleted, to restrict processing, to object to processing, to receive your data in a portable format, to withdraw consent and to seek compensation for any damage.
You can correct most account details, export your data and close your workspace yourself in the console. Send other requests to [email protected]; once we verify your identity, we reply free of charge within 30 days at the latest.
You can also complain to the Turkish Personal Data Protection Board or the data protection authority in your country. For processing in Türkiye, see the Turkish Data Protection Notice.
12. Automated decisions
We do not make decisions about you that are based solely on automated processing and have legal effects. Our security systems may temporarily block suspicious sign-in attempts; you can write to us to ask for a review.
13. Children
The Service is intended for businesses; we do not allow people under 18 to open accounts and do not knowingly collect children’s data.
14. Changes
We may update this policy. We announce significant changes by email and in the console. The date at the top of the page shows the latest update.
