Dazr Identity trust centre
Last updated 6 October 2026
If a translation of this page differs from the English version, the English version applies.
Where your data is stored
We store personal data in the European Union. Vercel, Upstash, Resend, Amazon Web Services and OpenAI are companies based in the United States; we use Amazon Rekognition only in its European Union region, and OpenAI only through its European data residency. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.
For companies in the United States, that adequacy decision is the EU-US Data Privacy Framework, which covers the companies certified under it.
Sub-processors
These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:
| Provider | Location | Purpose | Data |
|---|---|---|---|
| Vercel | United States; data stored in the EU | Hosting, server functions, file storage (Vercel Blob) and page statistics | Files, encrypted at rest, and server logs |
| Upstash | United States; data stored in the EU | Database (key-value store) for accounts and records | Accounts and records, encrypted at rest |
| Resend | United States | Sending emails, such as sign-in codes and notifications | Email address, name and the content of the email |
| Mollie | Netherlands (Amsterdam) | Payments for verification by letter or video call and for business verification | Amount, description and a reference to the request, never documents |
| OpenAI | United States (OpenAI Ireland Ltd for EEA customers); European data residency: processed in the EU, not stored | Used for business verification: reads the photo of the identity document | Photos of the identity document, never the selfies |
| Amazon Web Services (Amazon Rekognition) | United States; Rekognition used in its Frankfurt region (EU) | Used for business verification: compares the selfies with the document photo | Selfies and the document photo; we keep only the similarity scores and head positions |
| OpenSanctions | Germany (Berlin) | Used for business verification: checks names against politically exposed persons | Name and, when known, date of birth and nationality; for an organisation, its name and country |
Business verification becomes available at launch. OpenAI, Amazon Web Services and OpenSanctions take part only in business verifications.
For some checks we contact public services that answer for themselves, not for us: the European Commission’s VIES service for VAT numbers, official business registers for company details and directors, the EU trusted lists and certificate providers for signatures and seals, and Cloudflare’s public DNS service for domain checks. Google and Microsoft are involved only if you choose to sign in with them.
How we protect your data
- Encryption in transit. All traffic is encrypted with HTTPS. Browsers are told to use only HTTPS for dazr.eu and all its subdomains (HSTS, with the preload directive).
- Encryption at rest. Accounts, documents and files are encrypted with AES-256-GCM at the application layer, on top of our providers’ own encryption, with keys held on our servers. The master key can be rotated without downtime: a background job re-encrypts the stored data with the new key.
- Passkeys. Sign in with a passkey (WebAuthn) on your device, with up to 20 per account. Each sign-in challenge is valid for 5 minutes and can be used once.
- One-time codes instead of passwords. A sign-in code is valid for 10 minutes and allows 5 attempts; after 10 failed attempts in an hour, sign-in with codes pauses for that account until the hour is over. Code requests are limited per IP address and per email address.
- Sessions. The session cookie cannot be read by scripts and ends after 30 days. Under Security you see every signed-in device and can end one session or all of them.
- Rate limits and request checks. Sign-in, account and organisation requests are rate-limited per IP address or account, and requests that change data are accepted only from Dazr websites.
- Apps get only what you approve. Each organisation receives a different ID for you. Access tokens expire after 10 minutes and refresh tokens after 30 days without use.
- Signed reports and webhooks. Verification reports are signed (JWS) with keys published at identity.dazr.eu/oauth/jwks. Webhooks to apps carry an HMAC-SHA256 signature with a timestamp and go only to HTTPS addresses on public networks.
- Audit logs. Organisation admins see when members signed in and every download of verification evidence. Each time a reviewer opens the photos of a business verification, it is logged.
- Deletion schedules. Sign-in codes expire after 10 minutes, sessions after 30 days and sign-in times after 100 days; security counters are deleted within 24 hours. ID copies and business verification photos are deleted 30 days after the decision.
- Content Security Policy. Browsers run only the scripts we list: our own files, inline scripts identified by their hash and one pinned library file. Plugins are blocked, and other websites cannot show our pages in a frame.
Privacy
The privacy notice explains what we keep, why and for how long, and the terms of use set out the rules for using the service.
You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.
Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.
You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
Compliance and assessments
- GDPR. Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, is the controller for the personal data described in the privacy notice, under the General Data Protection Regulation (GDPR).
- CSA STAR Level 1: self-assessment in preparation. Dazr is completing the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire (CAIQ) for the CSA STAR Registry. This page will link to the published entry.
Reporting a vulnerability
If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.
- Scope. The Dazr websites and services on dazr.eu and its subdomains, their APIs, Dazr Browser and the Dazr Suite apps.
- Testing with care. Use your own accounts and test data, access other people’s data only as far as needed to show the problem, and keep the service running for everyone: no denial-of-service tests, spam or social engineering.
- Safe harbour. If you act in good faith and follow this policy, we consider your research authorised and will not take legal action against you. Please give us reasonable time to fix the problem before you share details publicly.
- Our response. We acknowledge your report within 5 working days and keep you informed until the problem is fixed.
Our security contact is also published in security.txt (RFC 9116).
The full policy, including what is out of scope and how we publish fixes, is our vulnerability disclosure policy.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy