Where your data lives, and who else touches it.
The questions a buyer in Germany or Finland asks before they can sign anything — answered on a page, with the paperwork ready rather than promised.
The short version
- · This site and the systems we run for clients are hosted in Frankfurt, Germany.
- · We are a Turkish company, so our engineers access that data from outside the EEA. We cover it with standard contractual clauses, and we say so up front.
- · A signed DPA and EU SCCs are available before you commit to anything. Ask and you get them the same day.
- · Analytics data is deleted automatically after 90 days. Not as a policy line — there is a scheduled job that does it.
Where the data is
Our production server is a DigitalOcean machine in Frankfurt. Application data, the database, sessions, queues and uploaded files all sit on it; nothing is farmed out to a third-party queue or object store. The same server runs the checks behind our status page, so you can see it working rather than take our word for it.
For client systems we default to EU hosting as well. When a client's own infrastructure is elsewhere, we work in it rather than moving their data to ours, and that is written into the engagement rather than assumed.
The Türkiye question
The European Commission has not issued an adequacy decision for Türkiye, and we are not going to pretend otherwise: it is the first objection a European buyer raises, and the honest answer is that your data stays in Frankfurt while people in Istanbul access it to do the work.
That access is a transfer, so it needs a legal basis. We use the EU standard contractual clauses — module three where we act as a processor for your processor, module two where you are the controller — together with a transfer impact assessment describing what we can actually see, which systems, and for how long. Access is named, least-privilege and revoked when an engagement ends.
Sub-processors
Everyone who could touch data from this website, and why. We update this list before a new one starts, not after.
| Who | What for | Where |
|---|---|---|
| DigitalOcean | The server this site and its database run on | Frankfurt, Germany |
| Cloudflare | DNS, TLS and protection in front of the site | Global edge, EU traffic served in the EU |
| Resend | Delivering the email a form on this site generates | Ireland (EU region) |
| Google Analytics 4 | Traffic statistics — loaded only after you accept cookies | United States |
| ipinfo.io | Turning a visitor IP into a country, for our own statistics | United States |
Only two entries above sit outside the EU, and both are avoidable: Google Analytics loads only with consent, and the IP lookup can be switched off for a client engagement. Reject cookies and Google Analytics is never loaded — the script is not on the page until you accept. Our own traffic counter stores no identifier at all: a path and a timestamp, nothing that points back at a person.
How long we keep things
| Website analytics | 90 days, then deleted by a scheduled job |
| Uptime checks behind /status | 100 days |
| Enquiries and the emails they generate | Until you ask us to delete them, or the conversation is clearly over |
| Client systems we operate | Whatever the engagement says — usually the client sets it |
What we do about security
Traffic is TLS-only and the site is sent with HSTS. Every deploy takes a verified database dump before it runs a migration, and we keep the archive of anything a migration deletes. Systems we operate are checked every five minutes and the results are public. Access to servers is by key, per person, and removed when someone stops needing it.
We are not certified against ISO 27001 or SOC 2, and we would rather write that here than let you find out in a procurement call. If your process needs a certificate, tell us early and we will tell you honestly whether it is worth either side's time.
Found a vulnerability?
Write to [email protected]. We answer within two working days, we will not threaten you, and we will credit you if you want the credit. The machine-readable version is at /security.txt.
Need the paperwork to go further?
The DPA, the SCCs and the sub-processor list as a signed pack, plus a transfer impact assessment written for your situation rather than ours. Ask and we send it the same day — you do not need to be a client first.
Request the DPA packCompany details and the registry entry are on the imprint; what we collect and your rights over it are in the privacy policy. Last reviewed 24 September 2026.