ANES Technology

Privacy Policy

Last updated: 8 September 2026

1. Data controller

This policy explains how personal data is processed by ANES Teknoloji ("ANES", "we") in connection with the website anesteknoloji.com and the ANES Operations Panel software that ANES develops and provides to its business customers. It is based on the Turkish Personal Data Protection Law No. 6698 ("KVKK") and related regulations.

Address: Esentepe Mah. Ecza Sk. Pol Center C Blok No: 4/6, 34394 Sisli/Istanbul
E-mail: contact@anesteknoloji.com

2. Scope and roles

For the website, ANES is the data controller.

The ANES Operations Panel is software used by e-commerce businesses (our customers) to run their own order and customer-service processes. For end-customer data processed in the panel, the business using the software is the data controller; ANES acts as a data processor, processing that data on the business's instructions and only to provide the service. End customers should direct requests about their data to the business they purchased from; ANES supports the business in fulfilling such requests.

3. Data we process

3.1 Website

  • Name, e-mail address and message content submitted through the contact form.
  • Server logs: IP address, browser type, time of visit (for security and troubleshooting).

3.2 ANES Operations Panel

  • Panel users (business staff): name, username, role, team/department, sign-in and activity logs (date, IP).
  • Order data received from marketplaces (Trendyol, ikas): order number, items, buyer name, delivery address, phone number, shipping details.
  • Packing records: photos of items/packages taken during packing and their timestamps.
  • WhatsApp messaging data (detailed below).

4. WhatsApp Business Platform data

The ANES Operations Panel integrates with Meta Platforms' WhatsApp Business Platform (Cloud API). The integration operates in accordance with the Meta Platform Terms and the WhatsApp Business Terms.

  • Connection: The business connects its own WhatsApp Business account to the panel through Meta's official onboarding flow (Embedded Signup). The account, phone number and message templates remain in the business's own Meta Business Portfolio. The business can remove the connection at any time from its Meta Business settings or by contacting us.
  • Data processed: the customer's phone number and WhatsApp profile name, message text, images/documents/audio sent, message identifiers and delivery status (sent/delivered/read), message timestamps.
  • Purpose: to display messages to the business's support team, route them to the right department, assign an agent, send replies and track delivery status. No other purpose.
  • Prohibited uses: the data is not used for advertising, building marketing lists, profiling, training AI/ML models or sale to third parties.
  • Access tokens: tokens obtained from Meta are stored encrypted on the server and used only for the corresponding business's account.
  • Media: images and documents remain on Meta's servers; the panel fetches them only when an agent views them and does not keep a permanent copy.
  • Coexistence with the phone app: if the business also uses the number in the WhatsApp Business app, copies of messages sent from the phone are delivered to the panel by Meta and shown for the same purpose.

5. Sharing

Personal data is shared only with the following parties and only to provide the service:

  • Hosting and infrastructure providers (servers, database, file storage — including Amazon Web Services S3).
  • Meta Platforms (for the transmission of WhatsApp messages, inherent to the integration).
  • Marketplace platforms (Trendyol, ikas) — to receive and update order data.
  • Public authorities where legally required.

Data is not otherwise shared with, sold to or rented to any third party.

6. Retention

  • Website contact form: up to 1 year after the request is resolved.
  • Panel activity logs: for the periods required by law.
  • Order and packing records: according to the business's commercial and legal retention policy.
  • WhatsApp messages: for the period set by the business; deleted when the business requests it or removes the connection. Personal-data payloads of marketplace notification records are purged automatically after 30 days.
  • Access tokens: deleted immediately when the business removes the connection.

7. Security

Data is encrypted in transit with TLS. Access is role-based; each user sees only the data they are authorised for. Incoming webhooks are verified by signature and secret. Access tokens and API keys are never stored in source code.

8. Your rights

Under Article 11 of the KVKK you have the right to learn whether your data is processed, request information, learn whether it is used for its purpose, request correction, deletion or destruction of incomplete or inaccurate data, and claim compensation for damages. Send requests to contact@anesteknoloji.com; we respond within 30 days. Requests concerning end-customer data processed in the panel are forwarded to the relevant business and resolved together.

For deletion requests see also Data Deletion Request.

9. Cookies

The website uses only technically necessary cookies; no tracking or advertising cookies. The panel uses a mandatory session cookie for sign-in.

10. Changes

This policy is updated when necessary; the current version is published on this page with the "last updated" date.