Security & Trust
Hazonlive was built for European businesses. EU hosting, GDPR-compliant, AI transparency and an approval workflow that keeps you in control.
As of: 2026-07-03 · Reviewed quarterly
EU hosting, Frankfurt
Database, storage and web app run on AWS Frankfurt eu-central-1. All storage stays in the EU; AI processing is handled by the providers listed below.
GDPR-compliant
Data processing under Art. 28 GDPR. No data is shared with third parties without a processing agreement.
AI transparency
Every AI-generated item carries an AI label. EU AI Act ready.
Zero-training
Your data is never used to train AI models — contractually guaranteed with every LLM provider.
Where and how your data is processed
Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database connections run exclusively over encrypted channels.
Multi-tenant isolation: Every workspace is strictly separated from every other one through Supabase Row Level Security (RLS) — enforced in the database, not just in the application. A customer account cannot see another workspace's data. The one documented exception is our support access: we can open a time-limited customer view to help with problems. Every such access is cryptographically signed, logged and expires automatically — and email content from connected mailboxes stays hidden throughout.
No training on your data: We use zero-retention endpoints exclusively at Anthropic (Claude) and OpenAI (GPT, gpt-image-2). Processing takes place in the USA — safeguarded by EU Standard Contractual Clauses. Your prompts and generated content are never used to train AI models — contractually safeguarded in our DPAs.
Authentication: Passwords are stored only as bcrypt hashes, never in plain text. Session cookies are HttpOnly + Secure + SameSite=Lax. Rate limits against brute-force attacks are active.
Backups & disaster recovery
Point-in-time recovery
Supabase PITR. Seven days of granularity, down to the second.
RPO ≤ 24 hours
Recovery Point Objective: the maximum data loss in a worst-case scenario.
RTO ≤ 4 hours
Recovery Time Objective: the maximum downtime during disaster recovery.
Our processors (sub-processors)
A complete list of all services that process data on our behalf. A DPA is in place with each service.
| Provider | Purpose | Region | Safeguards |
|---|---|---|---|
Supabase, Inc. DPA available at supabase.com/privacy/dpa | Database (PostgreSQL), auth, storage, edge functions | EU (AWS Frankfurt, eu-central-1) | Servers in the EU, encryption at rest (AES-256) and in transit (TLS 1.3) |
Anthropic PBC DPA and SCCs in place (anthropic.com/legal/dpa) | Claude LLM — text generation and document analysis | USA (US → EU: Standard Contractual Clauses under EU Decision 2021/914) | Zero-retention API (prompts are NOT used for training purposes) |
OpenAI, L.L.C. DPA in place | GPT text models and gpt-image-2 image generation | USA (SCCs) | No training use, zero data retention for API usage |
Resend, Inc. DPA under Art. 28 GDPR | Transactional email delivery (sign-up, notifications) | EU (AWS eu-west-1, Ireland) | Sending strictly task-related, TLS encryption |
Twilio Inc. DPA and SCCs in place | Phone reception — only when the phone feature is enabled | USA (SCCs) | Call metadata and transcripts only, no workspace data |
Tavily Inc. / Brave Software Inc. DPA and SCCs in place | Web research for the assistants (e.g. trend and lead research) | USA (SCCs) | Derived search queries only, no documents or mailbox content |
Vercel Inc. DPA under Art. 28 GDPR | Hosting of the web application and serverless functions | EU — deployment region Frankfurt (fra1), fixed | EU region enforced via Vercel config, TLS 1.3 |
Sentry / Functional Software, Inc. DPA under Art. 28 GDPR | Error tracking and performance monitoring | EU (ingest.de.sentry.io) | EU region endpoints, no plain-text prompts in error reports |
Stripe, Inc. DPA and SCCs in place | Payment provider for the technical processing of payments | USA or the regionally responsible Stripe entity (e.g. Stripe Payments Europe, Ltd.) | PCI-DSS-compliant, no card data stored at Hazonlive |
Incident response
GDPR Art. 33 — 72-hour notification duty: In the event of a personal-data breach, we inform you and the competent supervisory authority within 72 hours of becoming aware of it.
Escalation path: Security events are reported automatically to our Sentry monitoring (EU). Critical events trigger a direct notification to the Hazonlive team.
Audit trail: All sensitive operations (sign-in, plan change, data export) are stored with a timestamp, user ID and workspace ID in an immutable audit log.
Compliance contact
Questions about data processing, the DPA or data protection?
We respond to all compliance enquiries within two working days.
Service provider: AGAPE INNOVATIONS GROUP INC., Toronto, Canada · Legal notice (Imprint) · Privacy policy
Data processing agreement (DPA)
We provide every Pro and Business customer with a data processing agreement under Art. 28 GDPR. This bindingly governs:
- Processing purposes and categories
- Technical and organisational measures (TOMs)
- Sub-processor authorisation
- Data transfers to third countries (SCCs)
- Data-subject rights and cooperation
- Audit rights and controls
We send you the DPA as part of the onboarding process or on request.