Privacy Policy
How we handle the data of businesses that use Miko, and of the visitors who chat on their websites.
Last updated: 18 September 2026
This document is a draft: the company details are not filled in yet and the text has not had a legal review.
Who we are
Miko is customer support software provided by [Şirket unvanı] ([Kayıtlı adres]). "We" in this policy means [Şirket unvanı]. Questions: [email protected].
We have two roles
For the account details of businesses that sign up (our customers), we are the data controller.
For the visitors who chat on our customers' websites, and for our customers' own contacts, we are a processor working on the customer's behalf and instructions. Requests about that data should go to the business first; requests that reach us are passed on to it.
What we collect
- Account data: name, e-mail address, a password hash (never the password), company name, language.
- Usage data: session records, IP address, browser details, security and audit logs.
- Conversation data: messages written by visitors and teams, files sent, the name and e-mail a visitor leaves, page and language details.
- Knowledge sources: documents our customers upload and web pages we crawl for them.
- Payment data: billing details. Card details are handled by the payment provider, not by us.
What we use it for
- Providing the service: delivering conversations, generating AI answers, handing over to people, sending notification e-mails.
- Managing accounts and payments.
- Security: preventing abuse, spam and unauthorised access.
- Meeting legal obligations.
AI
Miko AI answers are generated by sending the relevant parts of a conversation and of the knowledge sources to an AI model provider. Providers do not use that data to train their models, and neither do we.
Who we share it with
We do not sell data. We share it only with the subprocessors needed to run the service (hosting, e-mail, AI models, payments), listed on the Subprocessors page. Some are outside Türkiye; those transfers rely on the safeguards required by KVKK art. 9 and the GDPR.
How long we keep it
- Conversations, contacts and files: until the customer deletes them or closes the workspace.
- Sign-in attempts: 90 days.
- Ended sessions and used e-mail links: 30 days.
- Records of sent e-mails: 90 days.
- Visitors with no name, no e-mail and no conversation: 180 days.
- Uploads that were never sent: 1 day.
- Backups: at most 21 days, after which deleted data is gone from them too.
Your rights
You can exercise your rights under KVKK art. 11 and the GDPR (access, correction, erasure, objection and so on) by writing to [email protected]. You can also delete your account and workspace yourself in Settings.
Security
Traffic is encrypted (HTTPS). Each workspace's data is isolated from every other at the database level. Passwords are hashed and cannot be recovered. Sensitive actions are written to an audit log.
Changes
When this policy changes we update the date above, and we e-mail account owners about significant changes.