Privacy Policy

Last updated: 1 September 2026

MessAI is a platform that helps businesses answer messages received on customer channels (WhatsApp, Instagram, Messenger, email, web chat and social-media post comments) with AI-assisted replies, and manage their social-media publishing. The platform is operated by VDD Teknoloji Hizmetleri A.Ş. (brand: IMGA). This policy explains how personal data processed through the platform is collected, used and protected.

1Parties and our roles

The business using the service ("client business") is the data controller: it decides which data is processed and why. VDD Teknoloji is the data processor, acting only on the client business's instructions. For data you submit through the contact form on this site, VDD Teknoloji is the controller.

2Data processed

  • End-customer identifier: name, phone number or social media user ID.
  • Sent and received message content and media attachments.
  • Comments written on the business's social-media posts and the commenter's public username.
  • When a channel is connected, past conversation records to the extent the platform allows (Meta limit: the 20 most recent messages per conversation) — solely to show conversation history to staff.
  • Technical metadata such as timestamp, channel and language.

3Purpose of processing

Data is processed solely to generate automated or semi-automated replies to customer-service requests and post comments, route conversations to staff, publish social-media content on the business's behalf, and improve service quality. Data is never used for advertising or profiling, and never sold to third parties. Processing complies with the Meta Platform Terms and Developer Policies.

4Knowledge-base improvement and FAQ mining

If the client business explicitly enables it (disabled by default), generalized Q&A suggestions are derived from staff replies in past conversations. During this process, personal data (names, phone numbers, emails, ID/IBAN and order numbers, etc.) is automatically scrubbed from the text; suggestions are never added to the knowledge base without staff approval, and raw end-customer messages are never stored in the knowledge base. The same approval rule applies to learning from individually approved replies.

5Sub-processors

Limited data is shared with the following sub-processors to run the service:

  • Meta Platforms (WhatsApp/Instagram/Messenger message delivery)
  • AI and embedding providers (reply generation and search)
  • Hosting infrastructure (data stored on secure servers)

6International transfer

Meta and some AI/embedding providers may be located abroad (e.g. the United States). In that case personal data may be transferred abroad to the extent necessary to provide the service and under the safeguards required by applicable law.

7Security

Channel access tokens are stored encrypted, the database is closed to external access and backed up regularly. Panel access requires authentication; each business's data is isolated from others.

8Retention

Data is kept for as long as needed to provide the service and according to the client business's retention policy. Closed conversations may be deleted after a configured period (default 180 days).

9Your rights and data deletion

You have the right to access, correct, delete or object to the processing of your data. Requests can be sent to the business you are messaging or to info@vdd-tech.com.tr. When you request deletion, all related message and conversation records are removed from the system, and your request is completed within 30 days.

10Data controller and contact

VDD Teknoloji Hizmetleri A.Ş.
Şehit Muhtar Mah. Mis Sk. No: 24 Suite 28, Beyoğlu/İstanbul, Türkiye
Tax No: 9241146609 · Tel: +90 555 639 03 11
Email: info@vdd-tech.com.tr