Security & Trust

Hazonlive was built for European businesses. EU hosting, GDPR-compliant, AI transparency and an approval workflow that keeps you in control.

As of: 2026-07-03 · Reviewed quarterly

EU hosting, Frankfurt

Database, storage and web app run on AWS Frankfurt eu-central-1. All storage stays in the EU; AI processing is handled by the providers listed below.

GDPR-compliant

Data processing under Art. 28 GDPR. No data is shared with third parties without a processing agreement.

AI transparency

Every AI-generated item carries an AI label. EU AI Act ready.

Zero-training

Your data is never used to train AI models — contractually guaranteed with every LLM provider.

Where and how your data is processed

Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database connections run exclusively over encrypted channels.

Multi-tenant isolation: Every workspace is strictly separated from every other one through Supabase Row Level Security (RLS) — enforced in the database, not just in the application. A customer account cannot see another workspace's data. The one documented exception is our support access: we can open a time-limited customer view to help with problems. Every such access is cryptographically signed, logged and expires automatically — and email content from connected mailboxes stays hidden throughout.

No training on your data: We use zero-retention endpoints exclusively at Anthropic (Claude) and OpenAI (GPT, gpt-image-2). Processing takes place in the USA — safeguarded by EU Standard Contractual Clauses. Your prompts and generated content are never used to train AI models — contractually safeguarded in our DPAs.

Authentication: Passwords are stored only as bcrypt hashes, never in plain text. Session cookies are HttpOnly + Secure + SameSite=Lax. Rate limits against brute-force attacks are active.

Backups & disaster recovery

Point-in-time recovery

Supabase PITR. Seven days of granularity, down to the second.

RPO ≤ 24 hours

Recovery Point Objective: the maximum data loss in a worst-case scenario.

RTO ≤ 4 hours

Recovery Time Objective: the maximum downtime during disaster recovery.

Our processors (sub-processors)

A complete list of all services that process data on our behalf. A DPA is in place with each service.

ProviderPurposeRegionSafeguards

Supabase, Inc.

DPA available at supabase.com/privacy/dpa

Database (PostgreSQL), auth, storage, edge functionsEU (AWS Frankfurt, eu-central-1)Servers in the EU, encryption at rest (AES-256) and in transit (TLS 1.3)

Anthropic PBC

DPA and SCCs in place (anthropic.com/legal/dpa)

Claude LLM — text generation and document analysisUSA (US → EU: Standard Contractual Clauses under EU Decision 2021/914)Zero-retention API (prompts are NOT used for training purposes)

OpenAI, L.L.C.

DPA in place

GPT text models and gpt-image-2 image generationUSA (SCCs)No training use, zero data retention for API usage

Resend, Inc.

DPA under Art. 28 GDPR

Transactional email delivery (sign-up, notifications)EU (AWS eu-west-1, Ireland)Sending strictly task-related, TLS encryption

Twilio Inc.

DPA and SCCs in place

Phone reception — only when the phone feature is enabledUSA (SCCs)Call metadata and transcripts only, no workspace data

Tavily Inc. / Brave Software Inc.

DPA and SCCs in place

Web research for the assistants (e.g. trend and lead research)USA (SCCs)Derived search queries only, no documents or mailbox content

Vercel Inc.

DPA under Art. 28 GDPR

Hosting of the web application and serverless functionsEU — deployment region Frankfurt (fra1), fixedEU region enforced via Vercel config, TLS 1.3

Sentry / Functional Software, Inc.

DPA under Art. 28 GDPR

Error tracking and performance monitoringEU (ingest.de.sentry.io)EU region endpoints, no plain-text prompts in error reports

Stripe, Inc.

DPA and SCCs in place

Payment provider for the technical processing of paymentsUSA or the regionally responsible Stripe entity (e.g. Stripe Payments Europe, Ltd.)PCI-DSS-compliant, no card data stored at Hazonlive

Incident response

GDPR Art. 33 — 72-hour notification duty: In the event of a personal-data breach, we inform you and the competent supervisory authority within 72 hours of becoming aware of it.

Escalation path: Security events are reported automatically to our Sentry monitoring (EU). Critical events trigger a direct notification to the Hazonlive team.

Audit trail: All sensitive operations (sign-in, plan change, data export) are stored with a timestamp, user ID and workspace ID in an immutable audit log.

Compliance contact

Questions about data processing, the DPA or data protection?

We respond to all compliance enquiries within two working days.

Service provider: AGAPE INNOVATIONS GROUP INC., Toronto, Canada · Legal notice (Imprint) · Privacy policy

Send enquiry

Data processing agreement (DPA)

We provide every Pro and Business customer with a data processing agreement under Art. 28 GDPR. This bindingly governs:

  • Processing purposes and categories
  • Technical and organisational measures (TOMs)
  • Sub-processor authorisation
  • Data transfers to third countries (SCCs)
  • Data-subject rights and cooperation
  • Audit rights and controls

We send you the DPA as part of the onboarding process or on request.