Skip to content
Atelyea product of Murat Gözel

Privacy Policy

Version
1
Effective date

Who we are

In this policy, "Atelye", "we", "us" and "our" mean Murat Gözel, trading as Atelye — a sole proprietorship (şahıs şirketi) established in Türkiye. Atelye is a trading name and a product name. There is no company called Atelye, and nothing in this policy should be read as implying one.

Our full legal name, registered address, phone number and country of establishment are published in the operator identity block at the foot of every page on this site, and in full on /about and /contact.

For anything in this policy, write to privacy@atelye.net. That address is monitored, and it is the right first contact for any question, request or complaint about personal data.

About this policy

Atelye is a platform that businesses use to run their content, their commerce and their inbound customer conversations. That means we handle personal data in two different roles, and the law treats them differently. This policy is written in two parts so that you can tell which one applies to you.

  • Part A — information we control. People who visit this website, and the staff of the businesses that use Atelye. Here we decide why and how the data is processed, so we are the controller and you deal with us directly.
  • Part B — information we process for business customers. The data a business puts into its Atelye account, and the data of the people who message that business. Here the business is the controller and we act on its instructions as a processor. If you are a customer of a business that uses Atelye, Part B is the part that concerns you — and the business, not Atelye, is who you ask first.

A third section, Requesting data deletion, applies whichever part you are in.

This policy is written against the EU General Data Protection Regulation (GDPR). It is not a Turkish aydınlatma metni under KVKK and should not be relied on as one.

Part A — information we control

What we collect

If you use Atelye as a member of a business's staff: your name, your email address and your phone number (the last two are also how you sign in — we send you a one-time code rather than asking you to keep a password), your role and permissions within your organisation, your interface preferences, and records of your sessions and sign-ins.

If you contact us: whatever you put in your message, and our reply.

If we bill you: the account and transaction records we need to invoice you and to keep proper business records.

If you simply visit this website: nothing that identifies you. This site sets no cookies, uses no analytics, embeds no third-party content, and has no form other than the confirmation-code box on the deletion-status page, which takes an opaque code and no identity. Your IP address is necessarily processed by our hosting infrastructure in order to deliver and secure the page you asked for; it is not used to build any profile of you and is not combined with anything else.

Operational records: we keep application logs, traces and security events so that we can run the platform and investigate problems. These carry account and request identifiers. They are not allowed to carry message content or the channel identifiers described in Part B.

  • Creating and operating your account, authenticating you, providing the service — performance of a contract.
  • Invoicing you and keeping proper accounting records — performance of a contract, and compliance with a legal obligation.
  • Keeping the platform running, secure and free of abuse — logging, monitoring, rate limiting — our legitimate interests in operating a secure and reliable service.
  • Answering your support messages — performance of a contract, and our legitimate interests in supporting the people who use the platform.
  • Telling you about changes to these documents or to the service — performance of a contract, and compliance with a legal obligation.

We do not rely on consent for any of the processing in Part A, and we do not send marketing email.

How long we keep it

  • Account and staff records — while the account is open. When an account closes we delete or anonymise them, except where we still need records to meet accounting or tax obligations, or to establish, exercise or defend a legal claim.
  • Support correspondence — while it is useful to support you, and afterwards only as long as a related claim could realistically be brought.
  • Audit records — 365 days in the live database, then archived for up to 7 years. Audit records say who did what to which record and when. They deliberately do not contain message content.
  • Database backups — a 30-day point-in-time-recovery window, with base backups kept for up to 90 days. What that means for a deletion request is set out under Requesting data deletion.

Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of service providers, and each of them only receives what it needs to do its job:

  • Hetzner Online GmbH — servers, database and hosting. Processed in Frankfurt, Germany.
  • Cloudflare — object storage for files, media and exports. Processed in the European Union.
  • Postmark (ActiveCampaign) — sends transactional email, including your sign-in codes. Processed in the United States.
  • Twilio — sends SMS, including your sign-in codes. Processed in the United States.
  • GitHub — stores the software builds we deploy. No personal data. United States.

The full and current list, including the providers that appear only in Part B, is published at /legal/subprocessors. We commit to giving our business customers 30 days' notice before we add or replace a provider that processes personal data.

We will also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.

International transfers

We are established in Türkiye, which is not the subject of a European Commission adequacy decision. Most of our infrastructure sits inside the European Union — our servers and database are in Frankfurt and our object storage is in the EU — which is the reverse of the usual arrangement, and it means the flow that needs a safeguard is data reaching us, not where it is stored.

Where personal data is transferred out of the European Economic Area — to us in Türkiye, or to a provider in the United States — the transfer is covered by the European Commission's Standard Contractual Clauses or the provider's equivalent approved safeguard. For business customers, the clauses that apply to their data are in our Data Processing Addendum.

Your rights

If the GDPR applies to you, you have the right to ask us for access to your personal data, and for its rectification or erasure; to ask us to restrict processing or to object to it, including to processing based on our legitimate interests; and to receive certain data in a portable form.

To exercise any of them, write to privacy@atelye.net. We do not charge for this. We will respond within 30 days; if a request is unusually complex we will tell you before that deadline and explain why. We may need to ask you for enough information to be confident you are who you say you are — we will not use anything you send for that purpose for anything else.

Handling of these requests is manual today. That does not change the deadline we commit to.

If you are unhappy with how we have handled your data, please tell us first at privacy@atelye.net. You also have the right to complain to a data protection supervisory authority, normally the one where you live, where you work, or where the problem happened.

Automated decision-making

We do not make decisions about you that produce legal effects, or similarly significantly affect you, solely by automated means. The platform uses AI to draft replies to customer messages, and those drafts are reviewed and approved by a person before anything is sent — that is described in Part B and in our AI transparency notice.

We have not appointed an EU representative

We have not appointed a representative in the European Union under Article 27 GDPR. We are saying so plainly rather than leaving it unsaid: as things stand there is no EU-based representative to contact, and you should contact us directly at privacy@atelye.net.

We will appoint one before we take on our first business customer established in the European Union.

Part B — information we process for business customers

Our role, and who you should ask

When a business uses Atelye, the personal data it puts into its account — its own content, its commerce records, its customer orders, and the conversations its customers have with it — is processed by us on that business's instructions. The business decides why the data is processed and for how long. It is the controller; we are its processor.

The practical consequence matters, so it is worth stating directly:

If you are a customer of a business that uses Atelye and you want your data accessed, corrected or deleted, ask that business. They hold the relationship with you and the law makes them responsible for it. We will help them act on your request, but we are not permitted to make that decision for them.

There is one deliberate exception. If Meta tells us that you have removed a business's access to your Instagram, Facebook or WhatsApp data, we act on that directly, without waiting for the business to instruct us. That is described under Requesting data deletion.

If you have asked a business to delete your data and cannot get a response from them, write to us at privacy@atelye.net anyway. We will not ignore you — we will contact the business, and where we can act ourselves, we will.

What we process on a business's behalf

  • Content and commerce records the business creates — its catalogue, its documents, its media.
  • Records about the business's own customers — for example a buyer's name, contact details and delivery address on an order.
  • Conversations between the business and its customers, where the business has connected a messaging channel. That is described in the next section.

We process all of it only to provide the service, and only as the business instructs. We do not use it for our own purposes.

Each business's data is isolated from every other business's, both by the database's own row-level security and by a second filter in the application — two independent mechanisms, so that one mistake is not enough to cross the boundary.

Connected messaging channels: Instagram, Facebook and WhatsApp

This section describes what the platform does with data from Meta's messaging platforms. It is the part that anyone who has messaged a business through one of those channels — and any platform reviewer — will want to read.

Why we have your data at all

Atelye connects to Instagram, Facebook (Messenger) and WhatsApp on behalf of business customers, using access those businesses have authorised through Meta's own consent screens. We never obtain access to a channel on our own account, and we never see a channel a business has not connected.

We do not contact people who have not contacted the business first. The platform is inbound only: it responds to messages people send to a business, inside the reply windows the messaging platforms allow. It does not send cold outreach, bulk marketing or broadcasts. That is a rule we enforce against our customers as well as ourselves — see our Acceptable Use Policy.

What we receive

  • Channel-scoped identifiers — the Instagram-scoped ID (IGSID), the page-scoped ID (PSID), other business-scoped identifiers, and — on WhatsApp — the phone number you messaged from.
  • Message content — the text you send to the business, and the replies it sends you.
  • Media — images, audio, video, documents and other attachments in the conversation.
  • Timestamps — when each message was sent and received.
  • Conversation metadata — which channel and surface it came from, the state of the reply window, whether the conversation was handed to a person, and the disclosure the business gave you.

The identifiers Meta gives us are scoped to that business. They are not your Instagram username, your Facebook account or a general-purpose identity, and they cannot be used to find you anywhere else. We do not enrich them, we do not buy data about you, we do not build a profile of you, and we do not link the same person across different businesses or different channels.

Why we process it

To receive the messages you send a business, to draft a reply for that business, and to send the reply once a member of that business's staff has approved it. Nothing else.

AI providers that process message content

Message content is sent to third-party AI providers so that a reply can be drafted. We state this plainly because it is the sort of thing you are entitled to know without having to dig for it.

The providers we use for this are Anthropic, OpenAI and Mistral AI. What is sent is the conversation content and the context needed to answer it — the business's own instructions, its business information, and the relevant part of the conversation.

Where a business chooses EU-resident processing for its account, we route generation to an EU-eligible endpoint; Mistral AI's EU service is the first such endpoint. Otherwise, generation may be processed in the United States, under the transfer safeguards described above.

The draft that comes back is not sent to you automatically. A person at the business reads it, edits it if they want to, and approves it. Where a conversation involves a complaint, a legal matter, safety, a minor, or a request to speak to a human, the platform escalates it to a person rather than drafting a reply at all.

What we do not do with it — and what we do

We do not sell platform data. We do not use it for advertising, ours or anyone else's. We do not use it to train AI models — not our own, and not our providers'. We use AI providers on terms that do not permit them to train their models on the content we send them, and we will not use a provider for this purpose that cannot offer such terms.

Stating only what we do not do would leave out something you should know, so here is what we do do: within a single business's own account, the platform learns from that business's own conversation history to improve the instructions and business context it uses when drafting that business's replies. It is how the drafts get better at sounding like the business and following its policies.

That refinement is fenced in two ways. It never crosses from one business to another — nothing learned from one business's conversations can reach another's. And what it produces never carries your message text, your name, your contact details, your order numbers or your channel identifier; where something could only be learned by keeping your words, it is summarised or discarded rather than copied.

How long we keep it

  • Messages, media and conversation content5 years from the last message received in that conversation, then destroyed.
  • Reply drafts, and the record of any edits a person made to them — destroyed with the conversation.
  • The content an AI provider was sent, and what it returned — destroyed with the conversation.
  • Channel-scoped identifiers — destroyed and replaced with a meaningless token when the conversation is erased.
  • Cost and usage records for AI generation — the model used, token counts and cost, with no content — kept as part of the audit record: 365 days live, then archived for up to 7 years.
  • Audit records — who did what and when, with no message content — 365 days live, then archived for up to 7 years.

Five years is a default, not a floor. A business can instruct us to delete a conversation, a date range, or everything in its account at any time, and we will do it — the controller's instruction always wins over our default. If you want your conversation deleted sooner, that is the route: ask the business, or use one of the routes in the next section.

How we protect it

Every business's data is separated by row-level security in the database and by a second filter in the application. Access is checked against a policy engine on every request. Secrets are encrypted and never committed to our source code. All traffic runs over TLS. Our servers and database are in Frankfurt and our object storage is in the EU. Every change to a record is written to an append-only audit log — one that, by design, records that something happened and to which record, and never the content of a conversation. That last rule is what allows a deletion to actually delete: if message text were copied into an immutable audit row, erasing it would be impossible.

We have no SOC 2 report, no ISO 27001 certification and no third-party penetration test or security attestation. We would rather say so than let their absence be assumed away. The fuller picture is at /legal/security. To report a vulnerability, write to security@atelye.net.

Requesting data deletion

There are three ways your data gets deleted from Atelye. All of them are free — we never charge for a deletion request, and we never require an account or a payment to make one. A step-by-step version of this section, written for someone who has never used Atelye, is at /legal/data-deletion.

1. Through Instagram, Facebook or WhatsApp

If you remove a business's access to your data in your Instagram, Facebook or WhatsApp settings, Meta notifies us. We act on that notification directly, without waiting for the business, and we erase the data we hold about you across every business on the platform you have messaged. We return a confirmation code so you can check the outcome — see below.

2. Through the business you messaged

Ask the business. They are the controller and they can instruct us to erase your data at any time — for one conversation, for a date range, or for everything. We act on that instruction; we do not overrule it and we do not charge for it.

3. By writing to us

Email privacy@atelye.net. If you are a customer of a business that uses Atelye, we will normally pass your request to that business, because it is their decision to make and not ours — but we will tell you that we have done it, and we will help them carry it out. If they do not respond, we will follow up rather than let your request go quiet. If you are a member of a business's staff, or your request concerns data we control under Part A, we act on it ourselves.

What is deleted

When an erasure runs, we destroy — not hide, not flag, not soft-delete:

  • every message you sent and every reply sent to you, including the message text;
  • every image, audio file, video, document or other attachment in the conversation;
  • every reply draft, and the record of any edits a person made to it;
  • everything sent to an AI provider on your behalf, and everything it sent back;
  • the raw data we received from the messaging platform;
  • your entry in our search index;
  • anything queued to be sent that mentions you.

Your channel identifier is destroyed and replaced with a meaningless token. The conversation record survives only as evidence that a conversation happened — no longer whose. It cannot be traced back to you from anything we keep, including by combining it with our audit records.

What is not deleted, and why

We would rather tell you the exceptions than let you find them:

  • A content-free audit skeleton. We keep the record that an action was taken on a record, by whom, and when. It contains no message content, no media and no identifier of yours — after an erasure it says that a conversation existed and was erased, not what was in it. We keep it because we have to be able to account for what the platform did, and because we may need it to establish or defend a legal claim.

  • Aggregate counters. Totals — how many messages were processed in a month, what the AI cost. These are numbers, not personal data, and nothing in them points at you.

  • Backups, for a limited and fixed period. Our database backups run on a 30-day point-in-time-recovery window, with base backups retained for up to 90 days. A backup is a sealed copy of the whole database at a moment in time; it is not possible to reach into one and edit a single record out of it without destroying the integrity of the entire backup, which would leave us unable to recover from a disaster. So your data may persist in a backup for up to 90 days after it has been erased from the live system.

    What we commit to instead: backups are never used except to recover from a disaster, they age out on the schedule above and are then gone, and if we ever do restore from one, we re-apply every completed erasure to the restored system before it serves any traffic. An erasure you asked for does not come back to life because we had an outage.

How long it takes

We commit to completing an erasure within 30 days. In practice it runs in minutes. Requests that reach us by email are handled by a person, which is why the commitment is 30 days rather than minutes.

If an erasure fails, it is reported as failed. It is never quietly reported as complete.

Your confirmation code

A deletion request that reaches us through Meta gets an opaque confirmation code — a random string that identifies the request and says nothing about you. You can enter it at /legal/data-deletion/status to see whether the request is received, in progress, completed or failed. That page asks for nothing else: no login, no name, no email. We keep the code working for 12 months after the request completes.

Changes to this policy

If we make a material change to this policy we will publish the new version with a new version number and a new effective date, keep the version it replaces published in our archive — every document and its superseded versions are listed on the legal documents index — and, for business customers, notify them at their registered contact address at least 30 days before it takes effect. Corrections that do not change meaning, such as fixing a typo or a broken link, do not get a new version.

Every version we have published stays published. A document that cannot be produced as it stood on a given date is a document nobody can rely on.

How to contact us

Our legal name, registered address, phone number and country of establishment are in the operator identity block at the foot of this page, and in full at /contact.