Skip to content
← Back to all articles

July 11, 2026 · 7 min read

WhatsApp Chatbots and KVKK: Compliance Guide for Businesses

One of the most justified questions of businesses wanting to set up an AI-powered customer assistant is: 'Will my customers' messages and information cause issues under KVKK?' The short answer: a properly configured chatbot does not violate KVKK—but there are obligations businesses must be aware of. This article is not legal advice; it provides a general framework and we recommend consulting an expert for your specific situation.

Which Personal Data Does a Chatbot Process?

  • Identity and contact: name-surname, phone number (by the very nature of WhatsApp).
  • Message content: what the customer writes—appointment requests, address, or other shared details.
  • Transaction data: appointment date, requested service, conversation history.

Under KVKK, your business is the 'data controller' for this data; the chatbot provider acts as the 'data processor' on your behalf. This means the chain of responsibility is no different from using WhatsApp without a bot—it just becomes more organized and auditable.

Your Business's Core Obligations

ObligationWhat does it mean in practice?
Information DisclosureInforming customers about the purpose of processing their data—adding a short disclosure and a link to the privacy policy to the bot's first message is a common solution.
Purpose LimitationNot using phone numbers collected for appointments for unauthorized bulk marketing.
Data MinimizationNot requesting data that is not necessary for the bot's function (e.g., Turkish ID number).
SecurityEncrypting stored data and restricting access to authorized personnel.
Retention PeriodKeeping conversation records for a reasonable period, not indefinitely, and deleting them upon request.

AI-specific questions: 'Are customer messages used to train the AI model?'—this is the right question to ask. At BozLat AI, your customer conversations are not used to train third-party models; the bot generates responses solely from the business knowledge base you provide. Data is isolated on a business basis: one business's data never leaks into another's bot.

'Who is responsible if the bot provides fabricated information?'—Instead of guessing on topics not in your knowledge base, the bot should hand the question over to you; this is the default behavior in our installations. Nevertheless, we recommend testing the bot with your own questions during the trial period before going live.

5 Questions to Ask When Choosing a Provider

  • Where is the data stored and is it encrypted?
  • Are my conversations used for model training?
  • Do you offer a data processing agreement/confidentiality commitment?
  • What is the process if my customer requests their data to be deleted?
  • Who has access to the conversation records?

Avoid any provider that cannot give a clear answer to these questions. We have clearly outlined BozLat AI's data approach in our privacy policy; you can find industry-specific setups on our industry pages and rates on our pricing page. We highly recommend that businesses processing special categories of personal data, such as health data (clinics, dietitians, etc.), proceed with their own KVKK consultant.

Frequently Asked Questions

Is using a WhatsApp chatbot on its own a KVKK violation?
No. Like any tool that processes personal data, it is subject to obligations: when rules of disclosure, purpose limitation, security, and retention periods are followed, using a chatbot is fully compliant with KVKK.
Do I have to tell my customers they are talking to a bot?
Transparency is recommended for both trust and compliance. E.g., adding a brief disclosure and a privacy policy link to the bot's first message is a common and practical solution.
How long are conversation records kept?
They should be kept for a reasonable period necessary for the purpose. You can view your conversation history on the BozLat AI panel and submit your deletion requests.
Is my data used for AI training?
No, not with BozLat AI—your conversations are not sent for third-party model training, the bot only generates answers from your knowledge base, and business data is completely isolated from one another.
I am in the healthcare sector, is there anything extra I should pay attention to?
Yes. Health data is classified as a special category of personal data under KVKK and is subject to stricter rules. It is necessary to limit the bot to scheduling and general inquiries, keep diagnosis/treatment details out of the correspondence, and proceed with a KVKK consultant.

Ready to set up an AI assistant for your business?

View Pricing
24/7 access