Legal documents

Data Residency

Shows where each category of data physically lives. We run a mixed setup and we write it down as it is.

Last updated: 28 July 2026 · Data controller / service provider: Bildirim.io service operator

This English text is an informational translation. The agreement is concluded in Turkish and governed by Turkish law; in case of any discrepancy, the Turkish version prevails.
We do not say “your data is entirely in Türkiye”, because that would not be true. Application data is kept in Türkiye; but services established abroad are involved in getting a notification to a device and in taking payment. The table below shows this category by category.

Residency by component

ComponentLocationDetail
Application databaseTürkiyeAccounts, projects, subscribers, campaigns, statistics
Database backupsTürkiyeEncrypted backups
Application and worker serversTürkiyeAPI and queue workers
Application logsTürkiyeKept on the server; sensitive fields are redacted from logs
Web/mobile push deliveryAbroadGoogle, Mozilla, Apple, Microsoft push services — technically unavoidable, content is delivered encrypted
Payments and billingAbroad (UK/EU)Paddle; card data never reaches us
SDK distribution (CDN)GlobalA static JavaScript file only; carries no personal data
Email deliveryAbroad (EU)Transactional email (address verification, password reset, alerts) is sent through Brevo
Support requestsTürkiyeMessages from the panel and the site’s help box are stored in the database on our own server (email address + the text you write); the notification email goes through Brevo. Closed requests are deleted after 12 months.
Visit measurement (basic)TürkiyeCookie-free Umami hosted on our own server; requires no consent
Visit measurement (detailed)Abroad (EU/US)Google Analytics 4 — on the marketing site only; runs in cookieless mode and writes no cookie unless consent is given

Transfers abroad

Transfer to push services is required to perform the service and is technically unavoidable: a notification can only reach a device through the browser vendor’s service. The data transferred consists of the endpoint address and the encrypted notification payload. Transfer to the payment provider is limited to carrying out the payment. Transfer to Google Analytics, by contrast, is not required to perform the service: it is done to measure visit statistics on the marketing site. Without consent the data transferred is limited to a cookieless page-view signal (including a truncated IP address); with consent a cookie identifier is added.

Retention periods

DataPurposeRetention period
Account record (name, email, password hash)Providing the service, authenticationUntil the account is deleted; within 30 days of a deletion request
Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone)Sending and targeting notificationsUntil the subscription ends or the project is deleted
Campaign content and send recordsReporting, debuggingUntil the project is deleted
Delivery and click eventsPerformance statistics12 months (deleted automatically as monthly partitions)
Outgoing webhook delivery recordsIntegration debugging90 days (deleted automatically)
Session refresh tokensSession continuity30 days (invalid once expired)
Invoice and payment recordsObligation under financial legislationThe period required by financial legislation (10 years)
Bildirim

For questions about this document, write to [email protected] .

All legal documents