Skip to the text
ErrorHub
Why ErrorHub How it works Features Pricing FAQ
Sign in Start free
Menu
Why ErrorHub How it works Features Pricing FAQ Sign in
ErrorHub / Data Processing Agreement

Legal

Data Processing Agreement

The errors your applications send can contain personal data of your users. For that data you are the controller and we are your processor. This agreement is what Article 28 of the GDPR requires between us.

In force from 29 September 2026 · Privacy · Terms · Data processing

On this page

  1. When this agreement applies
  2. What is processed
  3. Your instructions
  4. The people who work with the data
  5. Security measures
  6. Subprocessors
  7. Transfers outside the European Economic Area
  8. Requests from the people concerned
  9. If something goes wrong
  10. Helping you meet your duties
  11. Deleting the data
  12. Showing that we keep to this
  13. Liability, law and order of documents

When this agreement applies

This agreement is part of the Terms of Service. It applies from the moment your applications send an error event that contains personal data, and for as long as we hold such data for you. It needs no signature. If you need a signed copy for your records, write to hello@errorhub.dev.

You are the controller: you decide which applications report to ErrorHub and what an event contains. We, Autrady EOOD (UIC 206828616, Varna, Bulgaria), are the processor. If you process the data for someone else, you are their processor and we are yours.

The data of your own account, such as your login and your invoices, is not covered here. For that we are the controller, and the Privacy Policy applies.

What is processed

Subject Receiving, storing, grouping and showing the error events of your applications, and alerting you
Duration As long as your account exists. Events are deleted after the event history of your plan: 7 days on Free, 30 days on Indie, as agreed on Scale.
Purpose So that you can find and fix errors in your software
Kinds of data Whatever your events contain. Usually: error messages, stack traces, the method and path of a request, a request identifier, a user identifier, the environment and release, tags and context you add.
People concerned The users of your applications, and your staff where their actions cause an error
Special categories None intended. The Terms of Service forbid sending health data, payment card data and other special categories.

Your instructions

We process the data only on your documented instructions. Your instructions are these terms, the settings you choose in the dashboard and the requests your applications and users send to the API. If the law of the European Union or of Bulgaria requires us to process the data in another way, we tell you before we do, unless that law forbids telling you.

If we think an instruction breaks data protection law, we tell you and can wait with carrying it out until you confirm or change it.

The people who work with the data

Only people who need the data to run and support ErrorHub can reach it. They are bound to confidentiality, by contract or by law, also after their work for us ends. We look into the events of an account only to keep the service running, to investigate abuse, or when you ask us for help.

Security measures

We take the following technical and organisational measures (Article 32 GDPR).

Area Measure
Transport Every connection to the website, the dashboard and the API is encrypted with TLS.
Separation Every project belongs to one account. Every query names the account it is for, and automated tests check that an account cannot read or change what belongs to another.
Credentials Passwords are stored as salted PBKDF2 hashes. Secret server keys are stored as keyed hashes and shown once. Links sent by mail are stored as hashes, expire and work once.
Access Roles (owner, administrator, member) limit who manages projects, keys, people and billing. A role change or the removal of a person takes effect with their next request. Changing a password ends every other session.
Data minimisation Query strings are removed from request paths. Fields named like secrets and credentials recognised inside text are replaced with a marker before storage. Every field and every event has a maximum size.
Abuse Sign-in, sign-up, password reset and event ingestion are rate limited. An ingestion key can submit events and nothing else.
Retention Events are deleted automatically after the event history of the plan. Closing an account deletes its data from the database at once.
Untrusted content Error data is shown as text and never run as code. The dashboard loads no scripts from other origins.

We can change measures as technology moves on, as long as the level of protection does not go down.

Subprocessors

You agree that we use the subprocessors listed here. Each is bound by a contract that protects the data at least as well as this agreement. We stay responsible to you for what they do.

Subprocessor Task Data of your events it handles Where
Hetzner Online GmbH Provides the server and the data centre the application and its database run on All of them, as data at rest on the disk of that server. Hetzner does not access it. Germany

The events themselves are stored only on that server in Germany. Stripe handles payments and receives no event data; it is listed in the Privacy Policy.

Before we add or replace a subprocessor, we update this list and write to the owner of every account at least 30 days before. If you object for a reason that concerns data protection and we cannot find another way, you can end the agreement and we refund what you paid for the time after the end.

Transfers outside the European Economic Area

We store the data in Germany, and no subprocessor of event data is outside the European Economic Area. Your applications send events straight to our server; Cloudflare, which runs the DNS of errorhub.dev, does not handle them.

Requests from the people concerned

If someone asks us about data in your events, we pass the request to you and do not answer it ourselves, unless the law requires that. You can find, show and delete events and issues in the dashboard. Where that is not enough, we help you answer the request within a reasonable time.

If something goes wrong

If we learn of a breach of security that affects personal data in your events, we tell the owner of the account without undue delay, and no later than 72 hours after we learned of it. We say what happened, which data and how many people are likely affected, what we did about it, and who to talk to. If we do not know everything yet, we tell you what we know and follow up.

Helping you meet your duties

Taking into account what we process and what we know, we help you with the security of processing, with notifications of breaches, with data protection impact assessments and with consulting a supervisory authority (Articles 32 to 36 GDPR).

Deleting the data

Events are deleted automatically when the event history of your plan ends. You can delete projects, and with them their issues and events, at any time. When you close the account, its data is deleted from the database at once. Copies in backups disappear as the backups are overwritten. We keep data longer only where the law requires it.

You can read your issues and events through the dashboard and the API for as long as the account exists. If you need them in another form before you leave, ask us.

Showing that we keep to this

On request we give you the information you need to check that we keep to this agreement. If that is not enough, you or an auditor you appoint can carry out an audit once a year, and after a breach. Ask at least 30 days before, keep what you learn confidential, and do it during working hours without disturbing the service. An audit never includes the data of other accounts. Each side bears its own costs. If an audit takes more than one working day of our time, we can charge the further time at a reasonable rate.

Liability, law and order of documents

The limits of liability, the law and the courts in the Terms of Service apply to this agreement too. Where this agreement and the Terms of Service say different things about personal data in your events, this agreement wins.

ErrorHub

Error tracking for every app you run. Nothing else.

Product

Why ErrorHub How it works Features Pricing FAQ

Developers

OpenAPI document Pricing as Markdown llms.txt

Account

Sign in Start free hello@errorhub.dev

Legal

Privacy Policy Terms of Service Data Processing Agreement

© 2026 Autrady EOOD, Varna, Bulgaria. UIC 206828616. This page sets no cookies and loads no third-party scripts.

Page updated 29 September 2026