Last updated: August 3, 2026
Privacy Policy
This Privacy Policy explains what data Melih Erdem Koçoğlu ("we"), operator of Subsdiary, collects through the Service at subsdiary.online, why, and how. Users located in Türkiye should also read our KVKK Disclosure Notice (in Turkish), which describes your rights under Turkish data protection law in full.
1. Data We Collect
| Type | Examples |
|---|---|
| Account information | Name, email, business name, password (stored hashed with bcrypt) |
| Conversation content | Customer messages received via WhatsApp and the web widget, and AI-generated replies |
| Usage / technical data | IP address (used only for language routing, cached for 24 hours), browser info, session/access logs |
| Payment-related data | Only which plan you purchased and billing status — your card details never reach us, they are processed directly by Paddle |
2. Why We Process Your Data
- To provide the Service: generating AI replies to customer messages, keeping appointment/lead records, running your dashboard.
- To authenticate and secure your account.
- For billing and subscription management.
- To show visitors the site in the right language (Turkish/English).
- To comply with our legal obligations.
3. Who We Share Your Data With
We do not sell your data. To provide the Service, data is shared, only to the extent necessary, with:
- OpenAI / OpenRouter — conversation content is processed to generate AI replies to customer messages.
- Meta (WhatsApp Business Platform) — to send and receive messages via WhatsApp.
- Paddle.com Market Ltd — for payment processing, acting as our Merchant of Record.
- Railway — for server hosting and database infrastructure.
Some of these providers are located outside Türkiye (e.g. the US, EU); in that case your data may be transferred abroad. Each provider is subject to its own privacy and data-security obligations.
4. Data Retention
Your account and conversation data is retained for as long as your account is active. When you close your account, data not subject to a legal retention obligation is deleted or anonymized within a reasonable period.
5. Security
Your data is protected by technical measures including encrypted (HTTPS) communication, bcrypt-hashed passwords, JWT-based session management, and tenant isolation (each business's data is kept separate from every other business's).
6. Cookies
The Service uses only technically necessary cookies/local storage to keep you signed in and make the dashboard work; we do not use third-party advertising tracking cookies.
7. Your Rights
For users located in Türkiye, the full list of rights under Turkish Law No. 6698 (KVKK) is set out in our KVKK Disclosure Notice. In general, you have the right to learn whether your data is being processed, request correction or deletion, and object to processing. To exercise any of these rights, contact us using the details below.
8. Contact
Privacy questions: erdemkocoglu04@gmail.com