DATA PROCESSING

Data Processing Addendum.

How Hookjail processes the personal data inside the webhooks you send through it. It is part of the Terms of Service and applies automatically when you use Hookjail; no signature is needed. If your organisation needs a countersigned copy, write to hello@hookjail.com.

Last updated 1 October 2026.

1. Roles and scope

You are the controller (under the KVKK, the “veri sorumlusu”) of the personal data in your webhooks; Vehbi Emiroğlu (şahıs) is the processor (“veri işleyen”). We process that data only to provide Hookjail to you: receiving, storing, showing (masked), forwarding and replaying webhooks, until your workspace is deleted. This does not cover our own account and website data; see the Privacy notice.

  • Data subjects and categories: whatever your providers send, typically your customers’ contact, order and payment metadata. You decide. Card numbers and special-category data are prohibited by the Terms.
  • Instructions: your configuration and the actions you take in the product. We do not use payloads for any other purpose, do not analyse or sell them, and do not search them (search covers event type and ID only).

2. Security measures

  • Payloads and headers are encrypted at rest (AES-256-GCM) with a key per workspace, bound to the record, with key versioning.
  • Only an allowlist of headers is kept; credentials such as Authorization or cookies are never stored. Previews in the database are masked.
  • Reading an original payload needs a written reason and is rate-limited and recorded in an audit log.
  • Every query is scoped to the workspace, and automated tests check that one workspace cannot reach another’s data.
  • Sign-in uses one-time email links and host-only cookies. Outbound requests are limited to public HTTPS destinations with no redirects.
  • Logs and metrics carry no payload content (checked by automated tests). Retention is enforced by scheduled deletion.

What this does not mean. The master key that protects the workspace keys is held as a secret of the hosting service. The operator could technically use it to decrypt stored payloads; we do not do this, except if you ask us to for support or the law compels us to. Moving the master key to an external key-management service is planned. There is no independent audit or certification yet, and no customer-managed keys.

3. People and confidentiality

Only the operator (and anyone later engaged under a confidentiality obligation) can reach the infrastructure. Reading a payload in the product is limited to members of your workspace.

4. Sub-processors

  • Cloudflare, Inc. (United States, global network): hosting, database, object storage, networking, bot protection on forms, and the sending of sign-in and alert emails. This is the only sub-processor that handles payloads.

We will add or replace a sub-processor only after telling account holders by email at least 30 days ahead. You may object on reasonable data-protection grounds within that time; if we cannot accommodate the objection you may delete your workspace and stop using the service.

5. Where data is processed

The workspace database is created in Cloudflare’s Eastern Europe region; object storage and the network edge are operated by Cloudflare and may process data in other countries. Cloudflare transfers data internationally under the EU Standard Contractual Clauses in its own data processing addendum and, for the United States, its EU-U.S. Data Privacy Framework certification. You cannot choose a data location yet.

6. Helping you meet your obligations

  • Data-subject requests: if someone asks you for access or deletion, you can export metadata and delete deliveries or the workspace yourself; we help with what you cannot do yourself. If a data subject writes to us about your data we refer them to you.
  • Breaches: we tell you without undue delay, and within 72 hours of becoming aware, if a personal-data breach affects your data, with what we know and what we are doing about it.
  • Legal demands: if an authority requests your data from us, we tell you first unless the law forbids it.
  • Compliance: on request we give you the information needed to show these terms are met, including answers to reasonable security questionnaires. On-site audits only by agreement, at your cost, and not more than once a year.

7. Return and deletion

Before leaving you can export your delivery metadata. When you delete the workspace, or when it ends, the workspace key is destroyed first (stored payloads become unreadable at once) and scheduled jobs remove the stored payloads and records. Backups of the database may keep deleted metadata (not payload content) for up to 30 days, the point-in-time recovery window of the database, before they age out.

8. General

Liability under this addendum is governed by the Terms. If this addendum and the Terms conflict on the processing of personal data, this addendum prevails. We may update it as described in the Terms; changes that lower the protection you have are announced 30 days ahead.