KVKK & GDPR
From control to article.
What your compliance team needs is which control answers which obligation. The mapping below is our own reading; it is not legal advice and does not stand in for a certification.
- Controls mapped
- 6
- Data-rights endpoints
- 3
- Regions
- EU-West · TR
- Raw PII in report
- none
Mapping
From control to article.
| control | KVKK | GDPR | ISO 27001 |
|---|---|---|---|
| Data minimisation before transfer (masking) | m.4 · m.12 | Art. 5(1)(c) · Art. 32 | A.8.11 |
| Encryption at rest (pgcrypto columns) | m.12 | Art. 32(1)(a) | A.8.24 |
| Access control and separation of duties | m.12 | Art. 32(1)(b) | A.5.15 · A.8.2 |
| Audit logging and traceability | m.12 | Art. 5(2) | A.8.15 |
| Storage limitation (TTL-bound ephemeral store) | m.7 | Art. 5(1)(e) | A.8.10 |
| Portability and erasure | m.11 | Art. 17 · Art. 20 | A.5.34 |
This table is our own mapping, prepared to speed up your security review. It is not legal advice and does not replace your own compliance team's assessment.
Data rights
What happens when a request arrives.
Portability and erasure requests are served from administrative endpoints.
export
Export
A tenant's data is exported from a single endpoint, scoped to that tenant.
purge-preview
Purge preview
Before deletion, what will go is shown as counts; an irreversible action is never taken blind.
purge
Purge
After confirmation the tenant's data is permanently deleted.
Preview before deletion
We do not perform an irreversible action blind: before a purge, what will go is shown as counts, and confirmation is asked only after that.
See it with your own data.
In a technical session we run your prompts and your policy through it live.