Dazr Compliance trust centre

Where your data is stored

All application data and backups are stored in the European Union. Where a sub-processor is headquartered outside the EU, the European Commission’s Standard Contractual Clauses apply; the data processing agreement sets out which clauses apply.

Sub-processors

The sub-processors of Dazr Compliance are listed by category in the sub-processor list of the data processing agreement. We give 30 days’ notice before one is added or changed.

ProviderLocationPurposeData
EU cloud infrastructureEUCompute, edge functions and the key-value and file storage that run the portal and the APIWorkspace content (records encrypted at the application layer), member identities and billing status
Rate-limit countersEUShort-lived counters that limit requests to public endpoints and sign-inIP addresses, email addresses and counter values; no workspace content
Payment processorEU (Netherlands)Card payments and recurring billing for paid plansBilling contact, VAT number, invoice address and payment status; card data never reaches our servers
Transactional emailEUSign-in codes, invitations and notificationsRecipient, subject and message, for the duration of delivery
Customer support toolingEUSupport email and Enterprise enquiriesWhat the sender writes, kept for 24 months after the last activity

How we protect your data

Privacy

The privacy policy explains what we process as controller and as processor, the data processing agreement covers Dazr as your processor under the GDPR, and the terms of use set out the rules for using the service.

For data inside a workspace, the organisation that owns the workspace is the controller: contact your workspace owner first. For data we hold as controller, such as your account and billing details, write to privacy@dazr.eu. We reply within 30 days.

You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.

Compliance and assessments

Reporting a vulnerability

If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.

Our security contact is also published in security.txt (RFC 9116).

The full policy, including what is out of scope and how we publish fixes, is our vulnerability disclosure policy.

Contact