TurnaMesh Privacy Policy
TurnaMesh is AZINTECO's shared connection layer for business messaging products, including TurnaMessage and TurnaMed. This policy explains what the layer processes when a customer connects its own Meta business assets.
Operator and roles
TurnaMesh is operated by AZINTECO MAHDUD MASULIYYATLI CAMIYYATI (AZINTECO MMC), Baku, Azerbaijan. The customer normally controls its business account, customer relationships and message purposes. AZINTECO processes that data only to provide, secure and support the contracted service, except where AZINTECO has a separate legal obligation.
Data we may process
Depending on the connected channel, we may process business account and page identifiers, WhatsApp Business Account and phone-number identifiers, Instagram or Messenger account identifiers, user-scoped identifiers, access credentials, connection status, webhook events, message metadata and message content. We also process limited administrator, diagnostic, security and audit data needed to operate the service.
Why we process it
We use the data to connect channels, route inbound and outbound messages to the correct customer tenant, provide inbox and automation features, prevent abuse, troubleshoot delivery, maintain auditability and comply with lawful obligations. We do not sell channel data or use sensitive message content to build advertising profiles.
Meta platform data
WhatsApp, Instagram and Messenger data is handled only for the functionality requested by the customer and in accordance with the applicable Meta platform terms. The customer retains ownership and administrative control of its Page, Instagram account, WhatsApp Business Account and phone number. Disconnecting a channel does not transfer those assets to AZINTECO.
Sensitive and health-related content
TurnaMesh is a technical transport and control layer, not a medical service. TurnaMed customers may handle appointment or health-context messages. Such content is not used for advertising, unrelated profiling or general model training. Customers must minimise sensitive content and apply their own legal notices, permissions and clinical controls.
Service providers and transfers
Data may be processed by contracted infrastructure, hosting, database, security, email and channel providers only as needed to deliver the service. Depending on the product configuration, these can include Meta, Cloudflare, Vercel, Railway, Supabase and approved communications providers. Cross-border processing is protected through contractual, technical and organisational safeguards appropriate to the service.
Retention
Connection credentials are revoked or removed when a channel is disconnected, subject to technical completion and legal obligations. Customer content is retained only for the configured product and contract. After service termination, an export window of up to 30 days may be provided, after which active data is deleted or anonymised. Backup copies expire within at most 90 days. Security and audit records are retained for at most 12 months unless law requires longer.
Security
We use tenant separation, role-based access, encryption in transit, secret management, signed-webhook verification, logging and access reviews. No internet service can guarantee absolute security. Suspected security issues should be reported to security@azinteco.com.
Your choices and rights
You may request access, correction, deletion, restriction or other rights available under applicable law. If your data belongs to a customer's conversation, we may need to coordinate with that customer as the responsible business. Instructions are available on the TurnaMesh Data Deletion page.
Privacy requests: privacy@azinteco.com · Security reports: security@azinteco.com