Backups are where most organisations hold the most personal data and apply the least scrutiny. Yedekalma provides part of the technical measures you need there. Let us be clear from the start: compliance cannot be purchased from a product — you are the data controller.
No credit card required · 14-day free trial
"GDPR-compliant backup" gets used like a badge. The accurate statement is this: compliance is a property of the controller, not of a piece of software. A product can only provide the technical measures compliance requires.
This page lists only what we actually do. Producing privacy notices, maintaining records of processing, handling lawful bases and writing a retention and erasure policy remain your obligations. This page is not legal advice.
GDPR Article 32 requires appropriate technical and organisational measures. These are the backup-side equivalents.
Backups are encrypted before leaving your source system. With your own key (BYOK), not even we can open them.
Backups never pass through our servers. Because you choose the destination, you decide where data rests and whether it leaves your jurisdiction.
Role-based permissions, two-factor authentication and read-only or restricted rights for portal users.
Who accessed, downloaded or restored which backup and when is recorded — information typically requested during breach reporting.
You define how many copies of each backup type to keep; the excess is deleted automatically. This is the technical counterpart of a retention and erasure policy.
S3 Object Lock makes a backup undeletable and unmodifiable for a set period, evidencing integrity.
File, database and email backups are scanned, preventing the restoration of code that could cause a breach.
Integrity is verified by checksum, closing the gap between "I have a backup" and "my backup works".
We do not mask or anonymise. A backup is a faithful copy of the source. This is deliberate: a modified backup causes data loss when restored. If you need anonymisation it must be handled in the source system.
We do not make compliance declarations on your behalf. We do not sell certificates or "GDPR approval" — be cautious of anyone who does.
We do not process your data. We do not analyse, index or share the contents of your backups — they do not reside on our servers in the first place.
Encryption, access control, retention and audit logs on every plan. 14 days free.
Create Free Account