Telegraf

Telegraf

Telegram automation panel

Privacy Notice (Turkish Data Protection Law – KVKK)

Version: 2026-08-19 · Last updated: 2026-08-20

This is a courtesy translation. The Turkish version is the legally binding text and prevails in the event of any discrepancy.

1) Identity of the data controller

This notice is issued by myeasoft (the “Company”) acting as data controller under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”).

2) Personal data we process

CategoryContent
Identity Name / display name, Telegram username, Telegram user ID.
Contact Phone number (used for Telegram sign-in), e-mail address.
Transaction security Password hash (irreversible), session data, Telegram session key (encrypted), failed-login counters, an irreversible hash of your IP address, browser information, server logs.
Customer transactions Purchase records, credit/balance movements, crypto payment order number, amount paid and currency.
Application content Message texts and images you create, message templates, target Telegram group titles and IDs, sending schedules.

No card data is processed. Payments are collected in cryptocurrency through the payment provider (NOWPayments); the Company has no access to your wallet or private keys.

3) Purposes and legal grounds

  • Providing the service, creating and managing your account, applying the purchased package — KVKK Art. 5/2-c: necessary for the conclusion or performance of a contract.
  • Keeping invoice/accounting records and reporting to competent authorities — KVKK Art. 5/2-a and 5/2-ç: expressly provided for by law and compliance with a legal obligation.
  • Account and infrastructure security, abuse/spam detection, record keeping — KVKK Art. 5/2-f: legitimate interest.
  • Commercial electronic messages (newsletters/campaigns)explicit consent under KVKK Art. 5/1 and Law No. 6563. You may withdraw consent at any time.
  • Non-essential cookiesexplicit consent (see the Cookie Policy).

4) Method of collection

Data is collected electronically through registration and sign-in forms, the Telegram linking flow, in-app usage and automated server logs.

5) Transfers, including transfers abroad

Data is shared, to a limited extent required to run the service, with:

  • Telegram Messenger — connecting to your Telegram account and sending messages (abroad).
  • NOWPayments — crypto payment processing: order number and amount (abroad). No identity or contact details are sent.
  • Hosting provider — the infrastructure where data is stored.
  • E-mail (SMTP) provider — verification and password reset e-mails.
  • Competent public authorities — upon lawful request.

Transfers abroad are made within the framework of KVKK Art. 9 and limited to the minimum data necessary to perform the service. Such transfers are also subject to the respective providers’ own privacy policies.

Our pages also load fonts and interface libraries from third-party content networks (Google Fonts, cdn.tailwindcss.com, unpkg.com); those requests disclose your IP address to the relevant provider.

6) Retention periods

  • Account and application data: for as long as the account is active; immediately upon a deletion request.
  • Invoice/payment and accounting records: 10 years (Turkish Tax Procedure Law / Commercial Code).
  • E-mail verification and password reset tokens: 7 days.
  • Sending/task records: 30 days.
  • Raw payment provider webhook payloads: 90 days.
  • Consent and application records: for the duration of the burden of proof.

Once the period expires, records are automatically deleted or anonymised.

7) Security measures (KVKK Art. 12)

  • All traffic is encrypted with TLS (HTTPS); HSTS is enforced.
  • The Telegram session key is stored encrypted in the database and is never sent to the browser.
  • Passwords are stored as irreversible hashes (PBKDF2).
  • Role separation, session security (HttpOnly/Secure/SameSite cookies), CSRF protection and login rate limiting.
  • IP addresses are stored as irreversible hashes rather than plain text.
  • The database is reachable only from the server’s internal network.

8) Your rights (KVKK Art. 11)

By applying to the Company you have the right to:

  • learn whether your personal data is processed and, if so, request information about it;
  • learn the purpose of processing and whether the data is used accordingly;
  • know the third parties to whom data is transferred domestically or abroad;
  • request rectification if the data is incomplete or inaccurate;
  • request erasure or destruction;
  • request that rectification/erasure be notified to third parties to whom the data was transferred;
  • object to an adverse outcome arising from analysis carried out solely by automated systems;
  • claim compensation for damage arising from unlawful processing.

You can exercise these rights instantly inside the app:

  • Download my data — a machine-readable (JSON) copy of every record linked to your account.
  • Delete my account — your Telegram session key is destroyed, your message/group/template records are deleted and your identifying details are anonymised.

Available under Account → Privacy & my data.

9) How to apply

In line with the Turkish Communiqué on Application Procedures to the Data Controller, you may submit your requests in writing or from your registered e-mail address to info@myeasoft.com. Your request will be concluded within 30 days at the latest. If rejected, you retain the right to complain to the Turkish Personal Data Protection Board.

10) You as a data controller

For the content you send to Telegram groups through the platform, you are the data controller. The lawfulness of that content, obtaining the necessary permissions (e.g. consent for commercial electronic messages) and protecting recipients’ rights are your responsibility. In this respect the Company acts as a data processor providing the technical infrastructure only.

11) Changes

When this notice is updated, its version number changes and your consent is requested again where necessary. Current version: 2026-08-19.