🔐 AES-256 + BYOK 🌍 You Choose the Location 📋 Audit Logs 🗓 Retention Management 🔐 AES-256 + BYOK 🌍 You Choose the Location 📋 Audit Logs 🗓 Retention Management
Data Protection

How We Support Your GDPR Obligations
Encryption · Access Control · Retention · Audit Logs

Backups are where most organisations hold the most personal data and apply the least scrutiny. Yedekalma provides part of the technical measures you need there. Let us be clear from the start: compliance cannot be purchased from a product — you are the data controller.

No credit card required · 14-day free trial

An honest framing first

"GDPR-compliant backup" gets used like a badge. The accurate statement is this: compliance is a property of the controller, not of a piece of software. A product can only provide the technical measures compliance requires.

This page lists only what we actually do. Producing privacy notices, maintaining records of processing, handling lawful bases and writing a retention and erasure policy remain your obligations. This page is not legal advice.

Technical Measures We Provide

Where We Fit in Article 32

GDPR Article 32 requires appropriate technical and organisational measures. These are the backup-side equivalents.

🔐

Encryption (AES-256)

Backups are encrypted before leaving your source system. With your own key (BYOK), not even we can open them.

🌍

Data location control

Backups never pass through our servers. Because you choose the destination, you decide where data rests and whether it leaves your jurisdiction.

👤

Access control

Role-based permissions, two-factor authentication and read-only or restricted rights for portal users.

📋

Audit logs

Who accessed, downloaded or restored which backup and when is recorded — information typically requested during breach reporting.

🗓

Retention management

You define how many copies of each backup type to keep; the excess is deleted automatically. This is the technical counterpart of a retention and erasure policy.

🔒

Immutability (WORM)

S3 Object Lock makes a backup undeletable and unmodifiable for a set period, evidencing integrity.

🦠

Malware scanning

File, database and email backups are scanned, preventing the restoration of code that could cause a breach.

Backup verification

Integrity is verified by checksum, closing the gap between "I have a backup" and "my backup works".

Things we do not do

We do not mask or anonymise. A backup is a faithful copy of the source. This is deliberate: a modified backup causes data loss when restored. If you need anonymisation it must be handled in the source system.

We do not make compliance declarations on your behalf. We do not sell certificates or "GDPR approval" — be cautious of anyone who does.

We do not process your data. We do not analyse, index or share the contents of your backups — they do not reside on our servers in the first place.

FAQ

GDPR and Backup — Frequently Asked Questions

No, and we want to say that plainly. Compliance cannot be bought from a product; you are the data controller. Yedekalma supplies part of the technical measures compliance requires: encryption, access control, retention management and audit logs. Privacy notices, records of processing, lawful bases and your retention and erasure policy remain your responsibility.
Not on our servers. They go directly to the destination you choose, and you determine that destination's geographic location. Whether data is transferred outside your jurisdiction therefore stays under your control.
No. The backup system never alters data — no masking, truncation or anonymisation is applied. This is a deliberate design decision: a backup exists to hold a faithful copy of the source, and an altered backup causes data loss when restored. If you need anonymisation it has to be addressed in the source system.
Yes. You can define how many copies of each backup type to keep; once the count is exceeded the oldest backups are deleted automatically. This helps you implement a retention and erasure policy technically.
Yes, in two ways. A clean restore point limits the impact of the breach. And audit logs let you show who accessed which backup and when — information typically requested during breach notification.
As long as you hold the encryption key (BYOK) only you can open the contents. On the panel side there is role-based authorisation, two-factor authentication and access logging, and you can grant portal users read-only or restricted rights.

Strengthen Your Technical Measures

Encryption, access control, retention and audit logs on every plan. 14 days free.

Create Free Account

Read our data protection notice →