Dazr Identity trust centre

Where your data is stored

We store personal data in the European Union. Vercel, Upstash, Resend, Amazon Web Services and OpenAI are companies based in the United States; we use Amazon Rekognition only in its European Union region, and OpenAI only through its European data residency. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.

For companies in the United States, that adequacy decision is the EU-US Data Privacy Framework, which covers the companies certified under it.

Sub-processors

These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:

ProviderLocationPurposeData
VercelUnited States; data stored in the EUHosting, server functions, file storage (Vercel Blob) and page statisticsFiles, encrypted at rest, and server logs
UpstashUnited States; data stored in the EUDatabase (key-value store) for accounts and recordsAccounts and records, encrypted at rest
ResendUnited StatesSending emails, such as sign-in codes and notificationsEmail address, name and the content of the email
MollieNetherlands (Amsterdam)Payments for verification by letter or video call and for business verificationAmount, description and a reference to the request, never documents
OpenAIUnited States (OpenAI Ireland Ltd for EEA customers); European data residency: processed in the EU, not storedUsed for business verification: reads the photo of the identity documentPhotos of the identity document, never the selfies
Amazon Web Services (Amazon Rekognition)United States; Rekognition used in its Frankfurt region (EU)Used for business verification: compares the selfies with the document photoSelfies and the document photo; we keep only the similarity scores and head positions
OpenSanctionsGermany (Berlin)Used for business verification: checks names against politically exposed personsName and, when known, date of birth and nationality; for an organisation, its name and country

Business verification becomes available at launch. OpenAI, Amazon Web Services and OpenSanctions take part only in business verifications.

For some checks we contact public services that answer for themselves, not for us: the European Commission’s VIES service for VAT numbers, official business registers for company details and directors, the EU trusted lists and certificate providers for signatures and seals, and Cloudflare’s public DNS service for domain checks. Google and Microsoft are involved only if you choose to sign in with them.

How we protect your data

Privacy

The privacy notice explains what we keep, why and for how long, and the terms of use set out the rules for using the service.

You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.

Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.

You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.

Compliance and assessments

Reporting a vulnerability

If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.

Our security contact is also published in security.txt (RFC 9116).

The full policy, including what is out of scope and how we publish fixes, is our vulnerability disclosure policy.

Contact