Privacy policy
Last updated: 29 September 2026
Helovo is a service that lets businesses add an AI-powered chat assistant to their websites. It is provided by Burak Tabakoğlu ("Helovo", "we"). This policy explains which personal data is processed when you use the service, why, and what your rights are.
We have two different roles
- For account holders we are the controller. We process the data of the business representatives and team members who sign up to Helovo ourselves, to provide the service.
- For visitor chats we are the processor. Messages written in the chat window on a business's website belong to that business. We process them on the business's behalf and on its instructions; towards visitors, the business is the controller.
What data we process
Account and workspace
- Name, email address and password (the password is stored only as an irreversible hash)
- Your language preference, workspace name, team memberships and roles, invitations sent
- Session data: IP address and browser information
- Activity records: who signed in, changed settings or deleted something, when, and from which IP address
Chatbot content
- Chatbot instructions, business name, contact details, opening hours and appearance settings
Visitor chats (on the business's behalf)
- Messages the visitor writes and the chatbot's answers; visitors may include personal data they choose to share
- A randomly generated visitor ID, the address of the page where the chat was opened, and browser information
Payment
- Your card details never reach us. Payments are taken by Paddle as merchant of record. We only receive the subscription status, billing period, card brand and the last four digits of the card.
Why we process data
- To open your account, manage your session and provide the service
- To answer visitors' questions using the business's information
- To manage your subscription and payments
- To send service emails such as verification, password reset, team invitations and hand-off alerts
- To keep the service secure: preventing abuse, limiting request rates and detecting errors
- To meet our legal obligations and protect our rights in any dispute
The legal bases are the performance of our contract with you, our legitimate interest in running a secure service, and compliance with legal obligations. We don't send you marketing emails and we don't sell your data.
Processing with AI
To let the chatbot answer, visitor messages, the earlier messages in the conversation and the business's instructions are sent to our AI service provider for the purpose of generating the answer. Helovo does not use this data to train models for its own purposes.
Who we share data with
We share data only with the service providers we work with to run the service, and only as far as needed:
| Service provider | Purpose |
|---|---|
| Hosting (server) provider | Running the application and database, backups |
| AI service provider | Generating chatbot answers |
| Resend | Sending service emails |
| Paddle | Taking payments, invoices and subscription management |
| Error monitoring service (when enabled) | Detecting application errors; message contents, cookies and IP addresses are not sent |
Some of these providers may be located outside your country, including in Turkey and the United States, so your data may be transferred internationally. Where the law requires it, we rely on appropriate safeguards for these transfers. We may also share data with competent public authorities when legally required.
How long we keep data
- Account and workspace data: until you delete your account or the workspace
- Visitor chats: until the period the business chose on its Settings page runs out (30 days, 90 days, 6 months, 1 year or forever) or the business deletes the chat
- Sessions: at most 30 days
- Deleted data is removed from the live system immediately and from daily backups within 14 days. Invoice records are kept by Paddle for the periods required by law.
Cookies and browser storage
- On this website and in the dashboard we use only two necessary cookies:
helovo_sessionkeeps you signed in (at most 30 days) andhelovo_localeremembers your language (1 year). We don't use advertising or analytics cookies. - The chat window on businesses' websites uses no cookies. So that a chat can continue after the page reloads, it saves a random visitor ID and the conversation reference in the browser's local storage.
Security
Connections are encrypted with HTTPS, passwords and API keys are stored as irreversible hashes, each workspace's data is kept separate from the others, and important actions are logged. No system is perfect, but we take reasonable technical and organisational measures to protect your data.
Your rights
Depending on where you live, you have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and complain to your data protection authority. You can delete your account and all your data yourself from the Account page; for anything else write to iletisim@ragzeka.com. If your request concerns your chats on a business's website, please contact that business first; we forward requests that reach us to the business concerned. Turkish residents can also read our KVKK notice (in Turkish).
Children
Helovo is a service for businesses; it is not intended for people under 18 to open accounts.
Changes
We may update this policy. We announce important changes by email or in the dashboard before they take effect; the current version is always on this page.
Questions: Burak Tabakoğlu, iletisim@ragzeka.com