Privacy Policy

Last updated: 17 August 2026

Müşterify ("we") operates this website and a cloud-based customer management platform for businesses. This policy explains two separate relationships: people who visit the site or contact us, and businesses that use the platform together with their own customers. Anyone who accesses the site or starts using our products and services is deemed to have read this policy. Use of the platform is also subject to our Terms of Use.

Two distinct roles: controller and processor

This distinction matters because it determines who you exercise your rights against.

We are the CONTROLLER for data about site visitors, people who submit the contact form, and platform account holders. We decide why that data is processed.

We are a PROCESSOR for the customer, patient or client records that a business enters into the platform. The business is the controller of that data; we process it only on that business's instructions and only to provide the service. We do not use it for our own purposes, we do not sell it, and we never expose it to other customers.

If you are a patient or client recorded in the platform, please direct your request to the business you deal with; we act on that business's instructions.

What data we process

Contact form: your name, email address, phone number and message.

Platform account: name, email address, an irreversible hash of your password, workspace and permission details, and session records.

Usage and technical data: IP address, browser information, error logs and audit records, kept for security and service continuity.

Content entered by the business: customer, patient or client records, appointments, notes and messages. The processor rules above apply to this content.

Special category data such as health information exists in the system only to the extent a business enters it, and is processed solely to deliver the service.

Our legal bases

Performance of a contract: opening your account, delivering the service, billing.

Legitimate interests: system security, prevention of abuse, and improving service quality.

Consent: non-essential cookies and marketing messages. You can withdraw consent at any time.

Legal obligation: retention and notification duties imposed by law.

These correspond to Article 6 of the EU General Data Protection Regulation (GDPR) and Articles 5 and 6 of Turkish Law No. 6698 (KVKK).

Where your data is stored

Our database is hosted inside the European Union, in the Frankfurt region of Germany.

The web application is served through a global delivery network; that network distributes page content and does not carry database records.

Where data is transferred outside the country of origin, the transfer is made only to jurisdictions offering adequate protection or under appropriate safeguards such as standard contractual clauses.

Who we share it with

We do not sell your data and we do not share it for advertising. We work only with the service providers needed to deliver the service, and only to the extent needed:

Database and file infrastructure: a cloud database provider hosted in the European Union.

Application hosting and delivery network: a cloud application platform.

Email delivery: an email infrastructure provider used for notification and correspondence emails.

Availability monitoring: a service that checks whether the site is up. It processes no personal data.

Measurement and tag management: Google Analytics 4 and Google Tag Manager (Google Ireland Limited / Google LLC). These run on marketing pages only and according to your cookie choice; nothing is loaded once you sign in to the platform. See our Cookie Policy for details.

For businesses that enable the WhatsApp or phone assistant modules, the relevant messaging and telephony providers are also involved. These modules are activated only at the business's request, and the providers used are disclosed in writing during setup.

We may also disclose data where required by law or by a lawful request from a competent authority, to the extent required.

How long we keep it

Contact form records: up to 2 years after the request is resolved.

Platform account and business content: for as long as the account is active. After closure, data is deleted or anonymised within 30 days; that window exists so you can retrieve your data.

Security and audit logs: up to 12 months.

Records for which the law requires longer retention are kept for the period prescribed.

How we protect your data

All connections are encrypted with TLS.

Passwords are stored as irreversible hashes; we do not keep and cannot read plaintext passwords.

Each business sees only its own data; isolation is enforced at the database level with row-level access rules.

Critical actions are written to an audit log recording who did what and when.

Administrative endpoints are protected with session controls, rate limiting and failed-login lockout.

Data is held on redundant cloud infrastructure.

No system can promise absolute security. If we identify a breach affecting your personal data, we will notify the competent authority and you within the period and manner required by applicable law.

Your rights

Under GDPR Articles 15 to 22 and Article 11 of Law No. 6698 you have the right to: learn whether your data is processed and access it; have inaccurate or incomplete data corrected; request erasure; request restriction of processing; receive your data in a structured format and port it to another controller; object to processing and withdraw consent; object to a decision produced solely by automated analysis that affects you adversely; claim compensation for damage; and lodge a complaint with a supervisory authority.

Send requests to info@musterify.com. We respond within 30 days at the latest. We may ask for additional information to verify your identity.

In Türkiye the competent authority is the Personal Data Protection Authority. If you reside in the European Union you may also complain to the data protection authority of your own country.

Children's data

Our service is not directed at people under 18 and we do not knowingly collect data from them.

If a business using the platform enters data about a minor client, obtaining the necessary parental consent is that business's responsibility.

Changes

If we change this policy we publish the current version on this page and update the date above. We notify platform users separately about significant changes.

If you have questions about this text, you can reach us at info@musterify.com.