Skip to content

Last updated: October 7, 2026

Data Processing Addendum

Data processing terms for the chat, email, ticket and visitor data we process on our customers’ behalf (KVKK Article 12 and GDPR Article 28).

This document is also available in Turkish. If the two versions differ, the Turkish version prevails.

1. Parties, roles and precedence

This addendum forms part of the Terms of Service and takes effect when the Customer accepts the Terms; it does not need to be signed separately.

The Customer is the controller of personal data entered into the Service; Layvchat is the processor acting on the Customer’s behalf and instructions.

On personal data matters, this addendum prevails if it conflicts with the Terms of Service.

2. Subject, nature and duration

Subject: providing software that lets the Customer communicate with its visitors through live chat, email, tickets and a help center.

Nature: collecting, recording, storing, organizing, displaying, transmitting, exporting and deleting data.

Duration: the term of the agreement plus the deletion period in section 10 after it ends.

3. Data subjects and data types

Data subjects: people who visit the Customer’s sites and use the chat widget; people who send the Customer emails or tickets; people who read and rate help center articles; the Customer’s agents.

Data types:

  • Chat content, emails and attachments, tickets and their correspondence, uploaded files, satisfaction ratings and comments
  • Information visitors give in forms (name, email, phone and other fields the Customer defines)
  • Technical data: IP address, country and city, browser, operating system and device details, pages viewed, referral source and the site written from
  • If the Customer enables the integration: the identity of members signed in on its site and member details sent from the Customer’s system
  • Agent data: name, email, role, availability status and performance statistics

The Customer undertakes not to collect special categories of personal data (health, beliefs, biometrics and similar) through the Service or, if it does, to have the necessary legal basis and additional safeguards in place.

4. Instructions

Layvchat processes data only to provide the Service, keep it secure, fix problems and follow the Customer’s documented instructions. The Terms of Service, this addendum and the Customer’s console settings (retention period, IP masking, file uploads, the email channel, integrations, Telegram and webhook notifications) count as written instructions.

If we believe an instruction breaches data protection law, we tell the Customer without delay.

Layvchat does not sell data, use it for its own purposes or for advertising, share it with other customers or send it to any external AI service. AI features run only on Layvchat’s servers and only with the data of the Customer concerned.

If a legal obligation requires us to process data beyond the instructions, we tell the Customer first unless the law prevents it.

5. Customer obligations

  • informing data subjects and obtaining their explicit consent where required
  • entering into the Service only data that was lawfully obtained
  • keeping agent accounts, roles and access permissions current and secure
  • setting retention periods in the console that suit its own activities

6. Confidentiality and personnel

Only people who need access to run the Service, and who are under a written confidentiality obligation, can access the data.

We access a chat or other Customer Data only at the Customer’s support request, during a security incident or where the law requires, and only as far as necessary.

7. Security measures

Layvchat takes appropriate technical and organizational measures to protect the confidentiality, integrity and availability of the data. The main ones are:

  • TLS encryption on all connections; AES-256 encryption for backups
  • separation between workspaces at application and database level
  • two-factor authentication, role-based permissions and an IP restriction option for agents
  • virus scanning of uploaded files
  • a tamper-proof activity log; retention period and IP masking settings
  • daily encrypted backups and regular restore tests

Details are on the Security page. Layvchat may update these measures as long as the level of protection does not decrease.

8. Sub-processors

The Customer gives general authorization for the sub-processors listed on the Sub-processors page.

Layvchat imposes data protection obligations on its sub-processors equivalent to those in this addendum and remains responsible to the Customer for their performance.

We notify the Customer by email at least 30 days before adding a new sub-processor. If the Customer objects on reasonable data protection grounds, we first try to resolve the issue together; if we cannot, the Customer may terminate the agreement without penalty and the amount for the unused period is refunded.

9. Data subject requests

The console provides tools to find, export and delete a visitor’s data (Settings → Personal data); they cover chats, emails and tickets together.

For requests these tools cannot handle, Layvchat provides reasonable help. We forward data subject requests that reach Layvchat directly to the Customer concerned without answering them ourselves.

10. Return and deletion of data

The Customer can export its data from the console at any time.

When the agreement ends or the workspace is closed, the data is deleted within 30 days at the latest; removal from encrypted backups can take up to 30 more days. Legal retention obligations are not affected.

11. Breach notification

If we learn of a security breach affecting Customer Data, we notify the Customer without undue delay and within 48 hours at the latest. The notice includes, as far as is known at the time, the nature of the breach, the categories of data and people affected, its likely consequences and the measures we have taken or propose.

As controller, the Customer is responsible for notifying the authority and data subjects; Layvchat provides the information needed and reasonable help.

12. International transfers

The database and files are stored in security-certified data centers. International transfers through sub-processors are protected by standard contracts and the providers’ data processing commitments in line with KVKK Article 9 and the GDPR.

13. Audits and information

The Customer may request reasonable information and documents to show compliance with this addendum, and Layvchat will respond.

Where documents are not enough, an on-site audit may be carried out with at least 30 days’ written notice, no more than once a year, during business hours, under a confidentiality undertaking and without access to other customers’ data. The Customer bears the cost of the audit.