Skip to main content
Data protection

Where your data lives, and who else touches it.

The questions a buyer in Germany or Finland asks before they can sign anything — answered on a page, with the paperwork ready rather than promised.

The short version

  • · This site and the systems we run for clients are hosted in Frankfurt, Germany.
  • · We are a Turkish company, so our engineers access that data from outside the EEA. We cover it with standard contractual clauses, and we say so up front.
  • · A signed DPA and EU SCCs are available before you commit to anything. Ask and you get them the same day.
  • · Analytics data is deleted automatically after 90 days. Not as a policy line — there is a scheduled job that does it.

Where the data is

Our production server is a DigitalOcean machine in Frankfurt. Application data, the database, sessions, queues and uploaded files all sit on it; nothing is farmed out to a third-party queue or object store. The same server runs the checks behind our status page, so you can see it working rather than take our word for it.

For client systems we default to EU hosting as well. When a client's own infrastructure is elsewhere, we work in it rather than moving their data to ours, and that is written into the engagement rather than assumed.

The Türkiye question

The European Commission has not issued an adequacy decision for Türkiye, and we are not going to pretend otherwise: it is the first objection a European buyer raises, and the honest answer is that your data stays in Frankfurt while people in Istanbul access it to do the work.

That access is a transfer, so it needs a legal basis. We use the EU standard contractual clauses — module three where we act as a processor for your processor, module two where you are the controller — together with a transfer impact assessment describing what we can actually see, which systems, and for how long. Access is named, least-privilege and revoked when an engagement ends.

Sub-processors

Everyone who could touch data from this website, and why. We update this list before a new one starts, not after.

Who What for Where
DigitalOcean The server this site and its database run on Frankfurt, Germany
Cloudflare DNS, TLS and protection in front of the site Global edge, EU traffic served in the EU
Resend Delivering the email a form on this site generates Ireland (EU region)
Google Analytics 4 Traffic statistics — loaded only after you accept cookies United States
ipinfo.io Turning a visitor IP into a country, for our own statistics United States

Only two entries above sit outside the EU, and both are avoidable: Google Analytics loads only with consent, and the IP lookup can be switched off for a client engagement. Reject cookies and Google Analytics is never loaded — the script is not on the page until you accept. Our own traffic counter stores no identifier at all: a path and a timestamp, nothing that points back at a person.

How long we keep things

Website analytics 90 days, then deleted by a scheduled job
Uptime checks behind /status 100 days
Enquiries and the emails they generate Until you ask us to delete them, or the conversation is clearly over
Client systems we operate Whatever the engagement says — usually the client sets it

What we do about security

Traffic is TLS-only and the site is sent with HSTS. Every deploy takes a verified database dump before it runs a migration, and we keep the archive of anything a migration deletes. Systems we operate are checked every five minutes and the results are public. Access to servers is by key, per person, and removed when someone stops needing it.

We are not certified against ISO 27001 or SOC 2, and we would rather write that here than let you find out in a procurement call. If your process needs a certificate, tell us early and we will tell you honestly whether it is worth either side's time.

Found a vulnerability?

Write to [email protected]. We answer within two working days, we will not threaten you, and we will credit you if you want the credit. The machine-readable version is at /security.txt.

Need the paperwork to go further?

The DPA, the SCCs and the sub-processor list as a signed pack, plus a transfer impact assessment written for your situation rather than ours. Ask and we send it the same day — you do not need to be a client first.

Request the DPA pack

Company details and the registry entry are on the imprint; what we collect and your rights over it are in the privacy policy. Last reviewed 24 September 2026.

Have something to build — or something that is stuck?

Tell us what you are working on. You will talk to an engineer, not a salesperson.

Before you go — have a system that's stuck, or needs AI?

We build what's missing, put AI where it earns its place, and keep it running.