Law No. 6698 & GDPR Compliance

Privacy Policy & Data Protection Notice

An information notice on the collection, processing and protection of your personal data on the Ayla Generative AI-powered customer service platform, and on your legal rights.

📅 Last updated: 15 August 2026•🏛️ Compliant with Board decisions 2020/71 & 2023/1041•🏢 Harby Digital

Summary (Quick Overview)

Fundamental principles regarding Ayla Generative data protection and compliance:

The Data Controller is the business you interact with; Ayla Generative acts as a data processor on their behalf.
Your data is only processed based on lawful processing grounds under KVKK and GDPR.
Access to core customer service is not conditional upon consent to marketing or secondary purposes.
Your personal data is never sold, leased, or commercially traded.
AI model training is conducted strictly with irreversibly anonymised data.
Personal data whose retention schedule has expired is permanently erased, destroyed, or anonymised.

1. Data Controller and Data Processor Roles

Definitions of parties and their roles under applicable data protection regulations (KVKK / GDPR):

The Business You ContactData Controller

Determines the purposes and means of processing your personal data; responsible for establishing and managing the filing system.

Ayla Generative (Harby Digital)Data Processor

Processes your personal data on behalf of the business, strictly within authorized scope and documented instructions.

📌 This privacy notice is provided by Ayla Generative on behalf of and/or under authorization from the data controller business. Proof of fulfilling notification obligations lies with the data controller.

2. Processed Personal Data

The categories of personal data that may be processed to deliver our services:

Identity & Contact Data

  • Full name
  • Phone number
  • Email address

Social Media Data

  • Instagram username
  • Messenger account details
  • Platform profile

Communication Content

  • Message contents
  • Inquiries and requests
  • Voice notes (if applicable)

Transaction Data

  • Order details
  • Appointment and quote requests
  • Preferences

Technical Data

  • Platform information (WhatsApp, Instagram, Web)
  • Communication timestamps
  • Session / metadata logs
🔒 Special categories of data: Special categories of personal data (health, religion, ethnicity, etc.) are processed strictly when required conditions are met and only to the minimal necessary extent.

3. Processing Purposes and Legal Grounds

Your personal data is processed based on lawful processing grounds:

Customer Service & Inquiries

Contract Performance & Legitimate Interests

Answering your inquiries, processing requests, and providing automated customer assistance.

Orders, Appointments & Quotes

Performance of Contract

Order tracking, appointment scheduling, and quotation preparation.

Invoicing & Statutory Books

Legal Obligation

Fulfilling accounting, commercial books, taxation, and legal retention duties.

Official Authority Inquiries

Legal Obligation

Responding to lawful requests from authorized public authorities.

Service Quality Improvements

Legitimate Interests

Improving service quality through aggregated statistics (strictly anonymised data).

Marketing & Promotional Outreach

Explicit Consent

Newsletters, updates, and campaigns (strictly with separate opt-in consent).

Cross-Border Infrastructure

Explicit Consent or Statutory Safeguards

Hosting across secure global cloud servers as needed for uptime and performance.

Core service delivery (answering inquiries, scheduling appointments) is never conditional upon consent. Explicit consent is requested solely for optional purposes like marketing.

4. Transfer of Personal Data

Personal data is transferred only to the extent necessary and in compliance with legal standards:

The Business You Contact (Data Controller)

Has access to communication history and data for the purposes of serving your request.

Sub-processors (Service Providers)

Cloud infrastructure, hosting, and security providers acting under strict confidentiality and data protection obligations.

Authorized Public Authorities

Only when required by applicable laws or binding lawful judicial requests.

5. Cross-Border Data Transfers

Ayla Generative utilizes secure cloud infrastructures on behalf of data controller businesses. Certain infrastructure components may be located abroad.

Transfers to jurisdictions with recognized adequacy decisions, or
Transfers supported by appropriate standard contractual clauses and safeguards, or
Transfers based on explicit consent where legally permitted.
🛡️ If you do not wish for your data to be processed via global cloud infrastructure, alternative communication channels will be provided by the business.

6. Artificial Intelligence and Model Training

Principles regarding how data is used within our AI systems: your business data is never used to train third-party public models.

Your conversations and personal data are irreversibly anonymised prior to any model evaluation.
Anonymised data cannot be linked back to you and ceases to constitute personal data.
Identifiable customer data is never used to train external public foundation models.
Aggregated anonymous metrics are utilized solely to ensure response accuracy and platform security.
Irreversible Anonymisation Guarantee

No raw data directly or indirectly matching your identity is transferred to external AI model training.

7. Data Retention Periods

Data is retained only as long as required by processing purposes or statutory retention schedules, and safely deleted or anonymized thereafter.

Data typeStatutory retention period
Message contentsDuration of service and statutory retention; permanently erased or anonymised thereafter
Identity & contact detailsDuration of service and statutory retention; erased thereafter
Order & appointment recordsDuration of service + statutory accounting/tax retention requirements
Anonymised dataIndefinite (excluded from personal data regulations as it cannot identify individuals)
⏱️ Personal message logs are permanently purged within 7 days after anonymisation is complete.

8. Data Security Measures

Technical and administrative measures implemented to ensure the confidentiality, integrity, and security of personal data:

Industry-standard encryption (TLS/HTTPS in transit, AES-256 at rest)
Secure data centres and strict access control authorization
Role-based access controls and Least Privilege enforcement
Regular security vulnerability assessments and audits
Mandatory breach notification protocols in compliance with regulations

9. Your Rights and Application Process

You may exercise your data subject rights by applying directly to the data controller:

Learn whether your personal data is being processed
Request information regarding processing if processed
Learn the purpose of processing and verify compliance
Know third parties to whom data is transferred domestically or abroad
Request rectification of incomplete or inaccurate data
Request erasure or destruction subject to statutory conditions
Request notification of rectification or erasure to third parties
Object to outcomes detrimental to you arising exclusively from automated processing
Claim compensation for damages arising from unlawful processing
📬 Application procedure: Applications are concluded free of charge within 30 days pursuant to relevant legal regulations.
Data Deletion and Destruction Requests

Erasure requests are processed promptly, excluding statutory accounting and tax records that must be retained by law.

10. Separation of Information Notice and Explicit Consent

Information disclosure and explicit consent are distinct legal requirements; consent may be withdrawn at any time:

Privacy notice is a unilateral notification and does not require consent.
Explicit consent relates to a specific subject, is informed, and freely given. You may revoke consent at any time without stating grounds.
Revoking consent does not affect the lawfulness of processing carried out prior to withdrawal.

11. Children's Data

Ayla Generative does not knowingly target or collect personal data from individuals under the age of 18 without parental or guardian consent.

12. GDPR / EU Data Subjects Information

Although established in Türkiye, Ayla Generative adheres to GDPR (2016/679) standards for data subjects in the EU/EEA:

Right of access & rectification
Right to erasure (\"Right to be forgotten\")
Right to restriction of processing
Right to data portability
Right to object
Right of access & rectification
Right to erasure (\"Right to be forgotten\")
Right to restriction of processing
Right to data portability
Right to object
🌐 International transfers comply with standard contractual clauses and adequacy safeguards under GDPR Articles 45-49.

13. Contact & Data Protection Officer Communication

For any inquiries, requests or applications regarding privacy and personal data:

Email application[email protected]
Phone+90 501 486 80 54
Address / HeadquartersIstanbul, Turkey

14. Effective Date and Policy Updates

This policy may be updated in line with regulatory changes and service enhancements. Current version is always published on the Ayla Generative platform.

Last edited: 15 August 2026v2.4 (KVKK & GDPR Compliant)