KVKK and the data processing agreement

KVKK is Turkey's Personal Data Protection Law (Law No. 6698). When you use Errorbird, you are the data controller and Errorbird is the data processor. This page brings together the answers to the questions asked in a corporate audit.

Where is the data kept?

All data is hosted in Turkey: PostgreSQL/TimescaleDB, Redis and all backups. No data is transferred abroad; this is also a written commitment in the signed data processing agreement, and it can be verified through the dataResidency: "TR" field in the API response.

Which personal data is processed?

Data Source Purpose
Name, email Sign-up form Account management, notifications
IP address Request headers Security, audit trail
Log content The events you send Error tracking

Log content is under your control. To reduce personal data leaks, Errorbird scrubs incoming events by default: the values of fields such as passwords and tokens are never stored, and TCKN/card/IBAN/phone/email patterns are masked. Details: PII scrubbing.

The data processing agreement

The agreement is signed in the dashboard: Compliance and security → Data processing agreement.

curl -X POST https://api.errorbird.com/api/v1/organizations/<org-id>/dpa \
  -H "Authorization: Bearer <access-token>" \
  -H "content-type: application/json" \
  -d '{"signedByName":"Jane Doe","signedByTitle":"IT Manager","signedByEmail":"[email protected]"}'

The signature record stores the version of the text that was signed. When the template is updated, earlier signatures remain valid, and "which text was signed?" is never ambiguous in an audit.

Only the organization owner (Owner) can sign.

Audit trail

Critical actions are written to the audit trail in the same transaction as the change: an unaudited change cannot happen.

Action Record
project.created / project.deleted Project lifecycle
api_key.created / api_key.revoked Key management
member.invited / member.joined / member.removed / member.role_changed Team changes
plan.changed / billing.updated Subscription
client_workspace.* Agency layer
monitor.created / monitor.deleted Monitoring
sso_connection.* / sso.sign_in Corporate identity
dpa.signed Agreement signature
curl "https://api.errorbird.com/api/v1/organizations/<org-id>/audit-logs?action=api_key.created" \
  -H "Authorization: Bearer <access-token>"

Every record carries who did it (actorEmail), when, and the request's IP address. The list is paginated with a cursor; over time the audit trail becomes one of the largest tables.

Retention and deletion

Raw events and check records are dropped at the chunk level in TimescaleDB when your plan's retention period expires. The audit trail and billing records are kept independently of that: they are legal records and cannot be tied to the log retention period.

When you close your account, you can request deletion of all your data; the request is recorded in the audit trail.

Subprocessors

The infrastructure providers Errorbird uses to process data (hosting, email delivery, payments) are listed in an annex to the agreement. Any change to the subprocessor list is announced before it takes effect.