Privacy Policy
Effective Date: September 1, 2026
Last Updated: September 1, 2026
DMRandevu (“we”, “our”, or “us”) is a service operated by Lega Digital Yazılım Anonim Şirketi.
We provide an AI assistant that answers messages and comments for businesses on their own
messaging channels. This Privacy Policy explains how we collect, use, share and store
information, including data received from Meta platforms — Instagram and
WhatsApp — and from other channels a business chooses to connect.
1. Our Role: Controller and Processor
Two different relationships are covered by this policy:
- Businesses that use DMRandevu. For the account data of the business itself
(the connected account, its settings and its billing records) we act as the data controller.
- Customers who message a business. When you message or comment on a business
that uses DMRandevu, we process that data on behalf of that business, as a
processor. The business decides what the assistant does and can switch it off or disconnect
at any time. Requests about your data can be made either to that business or to us.
2. What Information We Collect
a. Instagram
- The Instagram account ID and username of the connected business account
- Direct messages sent to or from that business account
- Comments left on that business account's own posts, and the commenter's username and user ID
- The access token issued when a business connects its account
b. WhatsApp
When a business connects a WhatsApp Business account, we may receive:
- The WhatsApp Business Account ID and business phone number of that business
- The phone number and WhatsApp profile name of customers who message that business
- The content of messages exchanged with that business, including any media sent in the chat
- Message templates created for that business and their approval status
- The access token issued when the business connects its account
We only ever access the WhatsApp account a business has explicitly connected to us. We never
access personal WhatsApp accounts, groups, or any conversation that does not involve the
connected business.
c. Conversation and Appointment Data
- Responses to appointment prompts and date/time preferences
- Booking confirmations
- Conversation history, so a conversation can continue naturally
- Complaint records created when a comment or message is flagged for follow-up
3. How We Use Your Information
- To generate and send replies on behalf of the connected business
- To publish replies to, and hide, comments on that business's own posts
- To identify returning customers and continue existing conversations
- To book appointments where the business has enabled booking
- To show the business its own conversations, complaint tickets and settings
- To maintain security and prevent abuse
We do not use your data for advertising, ad targeting or profiling, and we do
not sell it. We do not use message or comment content to train our own models.
4. Automated Processing by AI Providers
To generate a reply, the text of the conversation is sent to a third-party AI provider
(OpenAI and/or Google) which returns suggested reply text.
Only the content needed to produce that reply is sent. These providers act as our processors
under contract and are not permitted to use the content for their own purposes.
5. How We Share Your Information
We do not sell or share your personal data with third parties for marketing.
We use the following service providers, each processing data only on our behalf and under
confidentiality obligations:
- Meta Platforms – Instagram and WhatsApp messaging infrastructure
- Our hosting provider – application and database servers, located in Türkiye
- OpenAI / Google – generating assistant replies (see section 4)
- iyzico – payment processing for business subscriptions (customer message
data is never shared with the payment provider)
- Google Calendar and Telegram – only where a business
has chosen to connect them for booking or staff notifications
6. Data Retention
Conversation content and comment content are retained for 30 days, after which
they are automatically deleted. Complaint records and appointment records are kept for as long
as the business needs them to serve the customer, and are deleted when the business's account
is closed. Access tokens are deleted immediately when a business disconnects a channel.
You may request deletion at any time by visiting:
https://dmrandevu.com/auth/data-deletion
7. User Rights
Depending on your jurisdiction — including under the Turkish Personal Data Protection Law
(KVKK) and the GDPR — you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion
- Object to or restrict processing
- Withdraw your consent at any time
8. Security Measures
We apply reasonable security measures including HTTPS encryption in transit, access controls,
server-side storage of access tokens (never exposed to a browser), and data minimization.
9. Public Authority Requests
If a public authority requests personal data, we apply the following process:
- We review the legality of the request before disclosing any data
- We challenge unlawful or overly broad requests
- We only disclose the minimum necessary information
- We document such requests, our responses, and the reasoning involved
- Where the request concerns a customer of a business that uses DMRandevu, we direct the
authority to that business as the controller of that data, unless we are legally required
to respond ourselves
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated
to connected businesses by email or through the DMRandevu portal.
11. Contact Us
If you have any questions or requests regarding your privacy, please contact:
Lega Digital Yazılım Anonim Şirketi
Halaskargazi Mah., Şişli, İstanbul, Türkiye
Email: info@lega.digital
Phone: +90 555 400 53 47