Last updated: 30.06.2026
This notice describes how Reply Flows, operated by [Şirket Ünvanı], handles personal data under the EU General Data Protection Regulation (GDPR). It supplements our Privacy Policy.
[Şirket Ünvanı] is the controller for personal data of its own account holders and website visitors. For personal data our customers process about their end users through Reply Flows, we act as a processor on their behalf under a data processing agreement.
We process account data, usage and log data, conversation content, and cookie data to provide and secure the service, process payments, support you, and (with consent) measure and improve our marketing. See the Privacy Policy for details.
We share data with sub-processors (AI providers, hosting, Paddle for payments, email, and analytics/advertising providers). Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
We keep personal data for as long as necessary to provide the service and to meet legal obligations, after which it is deleted or anonymized. When an account is deleted, operational data is kept frozen for 30 days (so the deletion can be undone by the account owner) and then permanently erased; invoice and payment records are retained for the statutory period required by tax law. See the Privacy Policy for details.
You have the right to access, rectify, erase, restrict, and object to processing, and the right to data portability and to withdraw consent at any time. To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you use Reply Flows to process personal data about your own end users, we act as your processor. A data processing agreement (DPA) is available on request via [email protected].
For any GDPR request, email [email protected].