Dazr Identity privacy notice
Last updated 5 October 2026 · For your Dazr Identity account, organisations, organisation verification and Sign in with Dazr Identity.
If a translation of this page differs from the English version, the English version applies.
Who is responsible
Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, is the controller for the personal data described in this notice. For anything about your data, write to privacy@dazr.eu.
What we keep for your account
- Your profile. Email address, name, language, and optionally a profile picture and a personal address. When you first sign in, we suggest a name based on your email address; you can change it.
- How you sign in. The one-time codes we email you (each valid for 10 minutes), the passkeys you add (the public key, the name you give it, and when it was added and last used), and whether you use Google or Microsoft sign-in.
- Your sessions. For each device you are signed in on: the browser and operating system, the country derived from your IP address, and when the session started and was last used. A session ends after 30 days or when you sign out. You can see and end sessions under Security.
- Sign-in times. The times of your last 50 sign-ins, kept for 100 days. Admins of organisations you belong to can see these times from the day you joined, but not your devices or the apps you use.
- Security counters. To stop abuse, we count requests per IP address and per email address. These counters are deleted automatically within 24 hours.
Legal basis: we need this data to provide your account (Article 6(1)(b) GDPR). Sessions, sign-in times and security counters also serve our legitimate interest in protecting accounts against misuse (Article 6(1)(f) GDPR). Showing sign-in times to organisation admins serves the organisation’s legitimate interest in knowing that its members’ accounts are in use (Article 6(1)(f) GDPR).
Signing in with Google or Microsoft
If you choose Google or Microsoft, you sign in on their page and they send us your email address, confirmed as verified, and your name. We receive nothing else from your Google or Microsoft account, and never your password. Google and Microsoft handle your sign-in under their own privacy policies.
Organisations
You can create an organisation or join one when you are invited. An organisation holds its name, country, company number, VAT number, registered address and, optionally, a logo and an email domain, plus its members with their names, email addresses and roles. All members can see the member list. The owner and admins manage the organisation and can see when members signed in.
- When a VAT number is entered, we check it with the European Commission’s VIES service.
- To confirm an email domain, we look up a DNS record of that domain through Cloudflare’s public DNS service.
- Invitations are sent by email and expire after 14 days; invitation links after 7 days.
Legal basis: we keep organisations to provide the service to their members (Article 6(1)(b) GDPR). An organisation stays until its owner deletes it. Deleting your own account does not delete organisations, because other members use them: leave them first, and transfer or delete the ones you own.
Verifying an organisation
An owner or admin of an organisation can ask us to verify it. They name the director or another person who can sign for the organisation, with that person’s name and email address; we email that person a link (and reminders) and tell the requester and the organisation’s admins how the request stands.
- With a qualified electronic signature. The representative signs a declaration we generate. We check the signature and the certificate against the EU trusted lists and the certificate provider’s revocation service. We keep the signer’s name, country and, if present, the organisation identifier from the certificate, and the signed file, encrypted, as evidence for as long as the organisation is verified and 5 years after the verification ends or the organisation is deleted, because regulated businesses that rely on the verification must be able to show it to their auditors.
- With documents. Without a qualified signature, the representative can upload a company register extract and a copy of their passport or ID card. We tell them they may cover the document number and national ID or tax numbers. The files are stored encrypted, are never sent by email, and only Dazr staff who review verifications can open them. We use the ID copy only to verify that organisation and delete it automatically 30 days after the decision; we then keep only the decision, who made it, the date and a fingerprint (hash) of each file. The extract is kept like the signed file above.
- With the organisation’s seal, a sealed register extract or a PEC code. A declaration sealed with the organisation’s qualified electronic seal is checked like a signature. A company register extract that is digitally sealed by the business register (for example a visura camerale or a KvK extract) is checked automatically: we read its text to find the company number, the representative’s name and, in Italy, the PEC address, and keep the extract encrypted as evidence. For a PEC code we send a one-time code to the organisation’s PEC address and keep that address with the verification.
- Paid: letter by post or video call. For a letter we use the organisation’s registered address to print and post a letter with a code; for a video call we keep the booked time, the meeting link and the reviewer’s note on the outcome. We do not record calls. Payments are processed by Mollie B.V. (Amsterdam), which receives the amount, a description and a reference to the request, not the documents; we keep payment and invoice records for as long as tax law requires (10 years in Italy). Refunds are also handled through Mollie.
- Legal basis. The organisation’s request (Article 6(1)(b) GDPR) and our legitimate interest in preventing fraud and impersonation of organisations (Article 6(1)(f) GDPR).
- Verification reports. For the apps’ audits we keep the facts of each verification (organisation details, dates, method, the certificate details of the signature or seal, the register extract check, the VIES result, the checks a reviewer made, file fingerprints) for as long as the signed file above. Never in a report: ID copies or ID numbers, one-time codes, email addresses or addresses other than the registered office; reviewers appear only as an internal ID. ID copies keep their 30-day retention.
- What apps see. Apps the organisation was shared with see its verification status, method and date. Apps that at least one member shared the organisation with can also download its verification report, the signed declaration (for a qualified signature or seal) and the company register extract, a public register document, as evidence for their audits. They never receive ID copies or the representative’s email address. Every download shows in the organisation’s activity for its admins.
Signing in to other apps with Dazr Identity
Other organisations can let you sign in to their website or app with your Dazr Identity account (“Sign in with Dazr Identity”). Nothing is shared until you approve it on the Dazr consent screen, which shows the app, the organisation behind it (legal name, country and company number), its privacy policy and the actual values it will receive.
- What can be shared and only what you approve: a random ID; your name and language; your email address; your personal address, if you saved one; the organisations you tick, with their name, country, company number, VAT number, verification status and your role; and permission for the app to stay connected while you’re away. Dazr never shares your files, your contacts or any compliance data, and there is no password to share.
- A different ID per organisation. Each organisation receives its own random ID for you (a “pairwise” identifier), so unrelated organisations cannot link your accounts with each other.
- Legal basis. We disclose the data because you ask us to sign you in (Article 6(1)(b) GDPR). Once the app has received it, the organisation behind the app is an independent controller for that data, under its own privacy policy. Requests about that data, including deletion, go to that organisation; Dazr shows you its support email.
- What Dazr keeps. Your consent for each app (which data and which organisations you approved, when you first connected and when the app last used it), for as long as the connection exists. An activity log of sign-ins and token refreshes per app, kept for 90 days and deleted when you remove the app. Tokens expire on their own: access tokens after 10 minutes, refresh tokens after 30 days without use.
- Updates to apps. When the verification of an organisation you shared with an app changes, the app is told, with your ID for that app. For each app we keep daily counts of sign-ins and consent decisions, and an estimate of how many people signed in that cannot be turned back into a list of people; these are kept for 400 days.
- Your control. Dazr Identity → Connected apps lists every app with exactly what it received. “Remove access” ends the connection at once: the app’s tokens stop working and your consent and activity log are deleted. Connected apps are part of your data download, and deleting your Dazr account removes all connections.
The rules for the organisations that use Sign in with Dazr Identity are in the Dazr Identity Developer Terms.
Registering an app
If you register an app for your organisation, we keep its details (name, homepage, privacy policy, support email, purpose, logo and redirect addresses), who accepted the Developer Terms and when, its settings, and a log of its webhook deliveries, kept for 30 days. The organisation’s admins see the app’s daily sign-in counts.
Emails we send
We send the emails the service needs: sign-in codes, invitations, updates about organisations and verifications, and notices about your apps. Dazr Identity sends no marketing email.
How long we keep it
- Your account and profile: until you delete your account.
- Sign-in codes: 10 minutes. Sessions: 30 days. Sign-in times: 100 days. Security counters: up to 24 hours.
- Connected apps: as long as the connection exists; their activity log 90 days.
- Organisations: until the owner deletes them. Verification evidence and payment records: as described above.
Visiting our websites
- Server logs. Our hosting provider records each request: IP address, browser (user agent), the address requested, status and time. We use these logs to run our services and keep them secure, and keep them for up to 30 days. Legal basis: our legitimate interest in operating secure websites (Article 6(1)(f) GDPR).
- Page statistics. We count page views with Vercel Web Analytics. It sets no cookies and does not store IP addresses; we only see totals, such as how often a page was viewed. Legal basis: our legitimate interest in knowing which pages people use (Article 6(1)(f) GDPR).
- No advertising or tracking. Our websites show no advertising and contain no third-party trackers, pixels or social media widgets. Fonts and scripts come from our own servers.
- Spam protection. Before a public form is sent, your browser solves a small calculation (proof of work). It runs on your device and sets no cookie.
When you contact us
If you use the contact form or write to one of our addresses, we receive your name, email address, company (optional), the topic, your message and the page you sent it from. The form emails your message to our inbox and a copy to you. We use it only to answer you and follow up on your request, and keep it for up to 24 months after our last contact. Legal basis: steps you ask for before a possible contract (Article 6(1)(b) GDPR) and our legitimate interest in answering questions (Article 6(1)(f) GDPR).
Cookies and storage on your device
We use no advertising or analytics cookies, so there is no cookie banner. What we store is needed for the service or remembers a choice you made, so it needs no consent:
__Secure-dazr_id(cookie): keeps you signed in to Dazr Identity on the dazr.eu sites. It cannot be read by scripts and ends after 30 days, or when you sign out.__Host-dazr_sso(cookie): connects a Google or Microsoft sign-in to your browser while it runs, for at most 10 minutes.dazr_id_hint,dazr_id_ping(local storage): your name, email address and picture, so the page header can show who is signed in straight away, and a signal that keeps your open tabs in step when you sign in or out.dazr_lang(local storage): the language you picked.
Service providers
These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:
- Vercel hosts our websites and server functions, stores files (Vercel Blob) and counts page views.
- Upstash runs the database (a key-value store) that holds accounts and records.
- Resend sends our emails, such as sign-in codes, notifications and replies to the contact form.
- Mollie (Amsterdam) processes payments for verification by letter or video call.
For some checks we contact public services that answer for themselves, not for us: the European Commission’s VIES service for VAT numbers, the EU trusted lists and certificate providers for signatures and seals, and Cloudflare’s public DNS service for domain checks. Google and Microsoft are involved only if you choose to sign in with them.
Where your data is stored
We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.
How we protect your data
All traffic to our services is encrypted (HTTPS). Accounts, documents and files are also encrypted at rest with AES-256-GCM, on top of the encryption our providers apply, using keys held on our servers. This is not end-to-end encryption: our systems can decrypt the data in order to provide the service, and only the few people at Dazr who run it can access them.
Your rights
You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.
Much of this you can do yourself. Your profile shows and lets you correct your data. Under Privacy & data you can download your data as a file (your profile, sign-in devices, organisations, connected apps and the list of your files) and delete your account. Deleting your account at once removes your profile, sign-in methods, sessions, files, the documents you sent with Dazr Sign and your connections to other apps. A Dazr Compliance workspace is separate and has its own settings.
Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.
You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
Changes to this notice
If we change this notice, we update the date at the top. Earlier versions are available on request.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy