Dazr Compliance trust centre
Last updated 6 October 2026
If a translation of this page differs from the English version, the English version applies.
Where your data is stored
All application data and backups are stored in the European Union. Where a sub-processor is headquartered outside the EU, the European Commission’s Standard Contractual Clauses apply; the data processing agreement sets out which clauses apply.
Sub-processors
The sub-processors of Dazr Compliance are listed by category in the sub-processor list of the data processing agreement. We give 30 days’ notice before one is added or changed.
| Provider | Location | Purpose | Data |
|---|---|---|---|
| EU cloud infrastructure | EU | Compute, edge functions and the key-value and file storage that run the portal and the API | Workspace content (records encrypted at the application layer), member identities and billing status |
| Rate-limit counters | EU | Short-lived counters that limit requests to public endpoints and sign-in | IP addresses, email addresses and counter values; no workspace content |
| Payment processor | EU (Netherlands) | Card payments and recurring billing for paid plans | Billing contact, VAT number, invoice address and payment status; card data never reaches our servers |
| Transactional email | EU | Sign-in codes, invitations and notifications | Recipient, subject and message, for the duration of delivery |
| Customer support tooling | EU | Support email and Enterprise enquiries | What the sender writes, kept for 24 months after the last activity |
How we protect your data
- Encryption at rest. Workspace records (controls, risks, incidents, intake reports, the activity log, member and profile data and the other registers) are encrypted with AES-256-GCM at the application layer, on top of the hosting provider’s own encryption. Uploaded evidence files are stored with the storage provider’s encryption under unguessable addresses and are served only through an authenticated download.
- Encryption in transit. All traffic is encrypted with HTTPS. Browsers are told to use only HTTPS for dazr.eu and all its subdomains (HSTS, with the preload directive).
- Sign-in. With Google, Microsoft or a one-time code sent to your work email, on every plan; Dazr stores no passwords. “Sign out everywhere” ends every session of an account.
- Access checks and roles. Every request is checked against current membership and scoped to your workspace, so a removed member loses access at once. Roles: owner, admin, member and auditor.
- Time-limited auditors. External auditors confirm a one-time code on every visit and get read-only access for 1 to 60 days, which an admin can revoke at any time.
- Activity log. Every change is logged, including actions by Dazr support, and the workspace receives an email when support acts in it. The log keeps the latest 2,000 events on Free, 5,000 on Basic, 25,000 on Pro and 50,000 on Enterprise, and you can search and export it.
- Sealed evidence trail for the Cyber Resilience Act. Entries in the CRA module (products, releases, SBOMs, vulnerabilities, reports) are append-only and hash-chained per workspace, and Dazr seals each one with an ES256 signature that anyone can check against the public keys at identity.dazr.eu/oauth/jwks. Corrections are added as new entries.
- Signed webhooks. On Enterprise, outgoing webhooks carry an HMAC-SHA256 signature with a timestamp, made with a secret for each webhook, and go only to HTTPS addresses that resolve to public networks.
- Rate limits. Sign-in, public reporting and the API are rate-limited.
- Deletion schedules. Sign-in codes expire after 10 minutes and public intake submissions are deleted after 365 days. When a subscription ends, workspace content stays available for export for 30 days.
- Content Security Policy. Browsers run only the scripts we list: our own files, inline scripts identified by their hash and one pinned library file. Plugins are blocked, and other websites cannot show our pages in a frame.
Privacy
The privacy policy explains what we process as controller and as processor, the data processing agreement covers Dazr as your processor under the GDPR, and the terms of use set out the rules for using the service.
For data inside a workspace, the organisation that owns the workspace is the controller: contact your workspace owner first. For data we hold as controller, such as your account and billing details, write to privacy@dazr.eu. We reply within 30 days.
You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
Compliance and assessments
- GDPR. For workspace content Dazr is the processor for your organisation, under the data processing agreement; for accounts, billing and the website, Dazr is the controller. Company details: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065.
- CSA STAR Level 1: self-assessment in preparation. Dazr is completing the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ) for the CSA STAR Registry. This page will link to the published entry.
Reporting a vulnerability
If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.
- Scope. The Dazr websites and services on dazr.eu and its subdomains, their APIs, Dazr Browser and the Dazr Suite apps.
- Testing with care. Use your own accounts and test data, access other people’s data only as far as needed to show the problem, and keep the service running for everyone: no denial-of-service tests, spam or social engineering.
- Safe harbour. If you act in good faith and follow this policy, we consider your research authorised and will not take legal action against you. Please give us reasonable time to fix the problem before you share details publicly.
- Our response. We acknowledge your report within 5 working days and keep you informed until the problem is fixed.
Our security contact is also published in security.txt (RFC 9116).
The full policy, including what is out of scope and how we publish fixes, is our vulnerability disclosure policy.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy