Security and procurement pack

At a glance

TopicDazr Identity
ProviderDazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065
Where data is stored, sub-processorsListed in the trust centre
StandardsOpenID Connect 1.0 with the authorization code flow and PKCE, token revocation (RFC 7009) and introspection (RFC 7662), RP-initiated logout, and OpenID Connect for Identity Assurance for business verification
SignaturesES256 for ID tokens, access tokens and verification reports, with public keys at identity.dazr.eu/oauth/jwks
ContractThe Developer Terms, between independent controllers, plus the optional data-sharing addendum below
CertificationsNone yet. The CSA STAR Level 1 self-assessment is in preparation.
AvailabilityWe do our best to keep the service available, but offer no uptime guarantee (SLA) today.
Not available yetSAML, SCIM provisioning and back-channel logout

Security measures

Who is responsible for which data

Dazr is the controller for the Dazr Identity account: the profile, sign-in methods, sessions and verification evidence. When a person signs in to your app, they ask Dazr to give your app the data shown on the consent screen. From then on, your organisation decides what to do with that data, so it is a controller in its own right.

Why no data processing agreement? A processor acts on its customer’s instructions. Dazr does not: it runs the account for the person, under its own privacy notice, and keeps verification evidence for its own legal reasons. Your app does not process data for Dazr either. An Article 28 GDPR agreement would describe a relationship that does not exist, so the Developer Terms set out rules between two controllers instead: purpose limitation, security, breach notification in both directions and deletion requests.

Verification reports work the same way. Dazr keeps the evidence and shares the report with the apps an organisation was shared with, for their audits. Each app then keeps its copy under its own rules.

Optional data-sharing addendum

Some buyers want the cooperation between two controllers in a separate signed document. This text is ready for that. Write to privacy@dazr.eu with your organisation’s legal name, and we send it to you for signature.

  1. Parties. Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, and the organisation named in the signature block (the Recipient).
  2. Shared data. The data a person approves on the Dazr Identity consent screen for the Recipient’s apps: a pairwise identifier and, where approved, name, language, email address, address, and organisations with role and verification status. For organisations shared with those apps, also verification reports and evidence files.
  3. Purpose. Signing people in to the Recipient’s apps, running their accounts, and the purpose shown on the consent screen. For verification reports: the Recipient’s customer due diligence and audits.
  4. Roles. Each party is an independent controller under Article 4(7) GDPR for the data it holds. Neither party processes personal data on behalf of the other, and the parties are not joint controllers.
  5. Lawful basis and transparency. Dazr discloses the data at the person’s request (Article 6(1)(b) GDPR) and says so on the consent screen. The Recipient has its own lawful basis and its own privacy notice, linked on the consent screen.
  6. Security. Each party protects the data with appropriate technical and organisational measures under Article 32 GDPR. The Recipient keeps client secrets on its servers only.
  7. Breaches. Each party tells the other without undue delay, and in any case within 72 hours of becoming aware of it, about a personal data breach that affects shared data, and the parties cooperate on notifying authorities and people where the law requires it.
  8. Requests from people. Each party answers requests about the data it holds. A party that receives a request about data the other party holds passes it on without undue delay.
  9. Transfers. A party that transfers shared data outside the European Economic Area does so only under Chapter V GDPR.
  10. Liability. Each party is liable for its own processing, as set out in the Developer Terms.
  11. Term. This addendum applies while the Recipient has an app registered with Dazr Identity, and for as long as either party still holds shared data.
  12. Law. Italian law applies. Disputes are heard in the courts of Italy.

Breach notification

Liability

Section 15 of the Developer Terms sets the liability. The service is provided as is. To the maximum extent permitted by law, Dazr is not liable for indirect, incidental, special or consequential damages, or for lost profits. Each party is responsible towards people and authorities for its own processing. Nothing limits liability for fraud, gross negligence, wilful misconduct, or anything that cannot be limited under applicable law. We do not offer service credits today.

For marketplaces

Online marketplaces in the EU must know who their business sellers are before those sellers can offer anything. Article 30 of the Digital Services Act calls this trader traceability. Dazr Identity checks the company and the person behind a seller account when they sign up.

Your payment provider checks the people it pays out to. Dazr Identity covers the step before, when a seller signs up, and the evidence stays with you, not with the payment provider.

Article 30 asks for more than company details, such as contact and payment account details. Dazr covers the company and who acts for it; you collect the rest and decide whether it meets your duties.

How Dazr Identity compares

An honest comparison, so you can choose well. Dazr Identity is young: it does a few things well, and some things not yet.

Compared with Auth0 and Clerk

Auth0 and Clerk are sign-in platforms for developers, with many SDKs, ready-made sign-in components and enterprise features.

Compared with Stripe Identity and Sumsub

Stripe Identity and Sumsub are identity verification services: they check ID documents and selfies, and Sumsub also checks companies.

Compared with Microsoft Entra External ID and Okta

Entra External ID and Okta are enterprise identity platforms with broad policy engines and many integrations.

What Dazr Identity doesn’t have yet

Documents for your review

Contact