Service Terms and Liability
Last updated: 17 August 2026
This document sets out in detail who is responsible for what in the software, setup, integration and website services provided by Müşterify. Its purpose is to draw the line of responsibility between the business using the service and Müşterify as the provider clearly and from the outset.
This document applies together with, and supplements, the Terms of Use. The Terms of Use govern how the service may be used; this document governs who owns the consequences of that use. For the processing of personal data, the Privacy Policy and KVKK Disclosure apply.
Roles of the parties
The entire allocation of responsibility rests on this distinction:
- Müşterify — service provider and data processor. We build, host and keep the software running, and we process data on the instructions of the business. We do not decide what data is entered into the platform, who receives which message, or what content is published.
- The business (customer) — data controller and content owner. The business is responsible for the customer, patient and client records entered into the platform, for the messages sent, and for the text and images published. It represents that it has the legal basis required to collect and process that data.
- End user (the business's own customer). The person whose data is processed. Requests should be directed first to the business providing the service; Müşterify acts on that business's instructions.
Obligations a business owes to its own customers do not become obligations that Müşterify owes to that business.
What Müşterify commits to
We set the service up to operate in line with applicable law, and we document that setup. Our standard measures:
- Hosting location. The database is held within the European Union, in Germany's Frankfurt region. Cross-border transfers are made in accordance with Article 9 of the Turkish Data Protection Law and Chapter V of the GDPR.
- Tenant isolation. Each business sees only its own data. Isolation is not left to the application layer; it is enforced at database level through row-level access rules.
- Encryption. All connections are encrypted with TLS. Passwords are stored as irreversible hashes; plain-text passwords are never stored and cannot be seen by us.
- Audit trail. Critical operations are recorded with who did what, and when.
- Access control. Administrative endpoints apply session verification, rate limiting and failed-login lockout.
- Redundancy. Data is held on redundant cloud infrastructure.
- Measurement off by default. Measurement tags on websites write no cookies before consent; the default state is treated as refused.
- Breach notification. If we identify a security breach affecting personal data, we notify the competent authority and the business concerned within the period and in the manner required by law.
These measures correspond to the "appropriate technical and organisational measures" expected of a data processor. No system can promise absolute security; what we commit to is the measure, not the outcome.
How we inform our customers
We give written notice at setup of the points where responsibility remains with the business. Notice is given through the following channels, and the business is deemed to have read them:
- This page and the Terms of Use, Privacy Policy, KVKK Disclosure and Cookie Policy pages.
- The written handover note issued at setup: which modules are enabled, which third-party providers are in use, and which settings the business must complete itself.
- Warning and explanatory texts inside the platform.
- Advance announcement of material changes before they take effect.
A business not having read these notices does not mean it was not informed.
Obligations of the business
The following rest entirely with the business:
- Legal basis and consent. Having the legal basis, and where required the explicit consent and its own disclosure notice, for the personal data entered into the system.
- Commercial electronic messages. Obligations under Turkish Law No. 6563 and the Message Management System (İYS) for promotional, campaign and reminder messages. Obtaining consent, registering it and honouring opt-outs belong to the business. Müşterify provides only the sending mechanism; it does not build the recipient list and does not verify consent status.
- Professional regulation. Advertising, promotion and confidentiality rules applicable in regulated fields such as healthcare, law and finance. Compliance with promotional limits and patient confidentiality in healthcare rests with the business.
- Accuracy and lawfulness of content. All text, images, prices and claims entered, published or sent. Holding the copyright to, or a licence for, the images and text used.
- Account security. Confidentiality of passwords, correctness of the permissions granted to staff, and the actions of team members. Unauthorised access by the business's own staff is the business's responsibility.
- Its own choices. Modules enabled at the business's request, settings it changes, and integration permissions it grants.
Misuse and its consequences
Where the service is used unlawfully, responsibility lies with the business carrying out that use. Misuse includes, by way of example: sending bulk messages without consent, uploading data obtained unlawfully, making misleading or non-compliant promotional claims, infringing third parties' copyright, trademark or personality rights, and attempts to circumvent system security.
In such cases:
- Suspension. If we identify use that threatens system security or the rights of third parties, we may suspend or terminate the account. We give prior warning where possible; where delay would cause harm, notice follows afterwards.
- Indemnity. If a claim, lawsuit, administrative fine or loss arises against Müşterify because of the business's use in breach of this document or of the law, the business agrees to cover the resulting amount together with defence costs and legal fees.
- Requests from authorities. Where a competent authority so requests, we provide information to the extent required by law. Unless legally prevented, we inform the business concerned.
Where Müşterify is not liable
Müşterify cannot be held liable for loss arising from:
- The content, accuracy and lawfulness of the data entered by the business.
- Messages the business sends, content it publishes and commercial claims it makes.
- Incorrect, incomplete or unauthorised use by the business or its staff; shared or weak passwords.
- Problems originating from the business's own devices, network, email account or domain management.
- Outages, policy changes, account closures or pricing changes at third-party services.
- Changes made at the business's request after we notified it in writing that we did not consider them advisable.
- The business's professional or commercial decisions, and its interpretation of output from the platform.
Third-party services
The service may work with third-party providers for messaging, email, measurement, telephony and hosting. Those providers' own terms and privacy policies apply; which providers are in use is set out in writing at setup.
If such a provider stops its service, changes its rules or closes an account, Müşterify will make reasonable efforts to offer an alternative, but is not responsible for the provider's decision.
AI-assisted features
Automated reply and assistant features generate text from the information supplied. The accuracy, completeness and situational appropriateness of that output is not guaranteed.
This output is not a substitute for diagnosis, treatment, or legal or financial advice; responsibility for professional decisions rests entirely with the business. The business is responsible for defining the scope and limits of automated replies and for adding human review where needed.
Website and design services
For websites produced by Müşterify:
- The delivered site is built in line with the law and accessibility principles applicable at the date of delivery.
- The content of text, images, prices and promotional claims published on the site belongs to the business. Müşterify is not responsible for content the business later adds or changes.
- Domain, email and hosting accounts are opened in the business's name and belong to the business.
- The "Powered by Müşterify" line in the footer is a maker's signature only; it places no responsibility on Müşterify for the site's content, commercial activity or obligations.
- Outcomes such as search ranking, advertising performance and conversion rate depend on third parties' algorithms and are not guaranteed.
Continuity of service
We make reasonable efforts to provide the service without interruption; uninterrupted access is not guaranteed. We try to announce planned maintenance in advance. Current operational status can be followed on the status page.
Limitation of liability
The service is provided "as is". To the maximum extent permitted by law, we are not liable for indirect loss, loss of profit, loss of data, loss of reputation or business interruption.
In any event our total liability is limited to the amount paid to us in the twelve months before the claim arose.
These limitations do not affect liability for intent or gross negligence, damage to life or physical integrity, or rights under consumer law that cannot be excluded by contract.
Force majeure
Neither party is liable for delay or non-performance caused by events beyond its reasonable control, such as natural disaster, war, epidemic, cyber-attack, general failure of electricity or internet infrastructure, and decisions of competent authorities. If the impediment lasts beyond a reasonable period, either party may terminate without compensation.
Assignment, severability and notices
- Assignment. The business may not assign its rights and obligations under this document without our written consent. Müşterify may assign the agreement to a group company or a successor, provided continuity of service is preserved.
- Severability. If a provision is held invalid, the remainder is unaffected; the invalid provision is deemed replaced by the valid provision closest to its purpose.
- Waiver. Failure to exercise a right does not constitute a waiver of it.
- Notices. Notices are sent to the email address registered for the business in the platform, and to us at info@musterify.com. Keeping that address current is the business's responsibility.
Order of precedence
Where the documents differ on the same point, the order is: (1) any specific agreement signed between the parties, (2) this Service Terms and Liability document, (3) the Terms of Use, (4) other informational texts. For the processing of personal data, the Privacy Policy and KVKK Disclosure prevail.
Changes
We may update this document. We notify material changes before they take effect; continuing to use the service after notice means the current version is accepted.
Governing law and disputes
This document is governed by the laws of the Republic of Türkiye. The courts and enforcement offices of the Republic of Türkiye have jurisdiction. If you are acting as a consumer, your right to apply to the courts of your place of residence is reserved.
Contact
For questions about this document, you can write to info@musterify.com.
If you have questions about this text, you can reach us at info@musterify.com.
