Security & Trust

Hazonlive was built for European businesses. EU hosting, GDPR-compliant, AI transparency and an approval workflow that keeps you in control.

As of: 2026-07-31 · Reviewed quarterly

EU hosting, Frankfurt

Database, storage and web app run on AWS Frankfurt eu-central-1. All storage stays in the EU; AI processing is handled by the providers listed below.

GDPR-compliant

Data processing under Art. 28 GDPR. No data is shared with third parties without a processing agreement.

AI transparency

Every AI-generated item carries an AI label. EU AI Act ready.

Zero-training

Your data is never used to train AI models — contractually guaranteed with every LLM provider.

Where and how your data is processed

Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database connections run exclusively over encrypted channels.

Multi-tenant isolation: Every workspace is strictly separated from every other one through Supabase Row Level Security (RLS) — enforced in the database, not just in the application. A customer account cannot see another workspace's data. The one documented exception is our support access: we can open a time-limited customer view to help with problems. Every such access is cryptographically signed, logged and expires automatically. Email content from connected mailboxes stays hidden by default. It becomes visible only if you explicitly release your mailbox in the settings for a limited time (up to eight hours, revocable at any time). For Gmail mailboxes it stays blocked even then — Google's rules for access to mailbox data allow no exception based on your consent.

No training on your data: AI processing runs at Anthropic (Claude) and OpenAI (GPT, gpt-image-2) in the USA — safeguarded by data processing agreements and EU Standard Contractual Clauses. Your prompts and generated content are never used to train AI models; that is contractually safeguarded in our DPAs. Both providers retain inputs and outputs for up to 30 days for abuse detection — longer where content is flagged for safety reasons.

Authentication: Passwords are stored only as bcrypt hashes, never in plain text. Session cookies are Secure + SameSite=Lax; they are readable by the browser because the application evaluates the session there — this is mitigated by a strict Content Security Policy and HSTS. Rate limits against brute-force attacks are active, and two-factor authentication is mandatory for all operator accounts.

Backups & disaster recovery

Point-in-time recovery

Supabase PITR. Seven days of granularity, down to the second.

RPO ≤ 24 hours

Recovery Point Objective: the maximum data loss in a worst-case scenario.

RTO ≤ 4 hours

Recovery Time Objective: the maximum downtime during disaster recovery.

Our processors (sub-processors)

A complete list of all services that process data on our behalf. The “contract” column states what the processing rests on for each service — with most providers the DPA is incorporated into their terms of service.

ProviderPurposeRegionSafeguards

Supabase Pte. Ltd.

DPA incorporated into the terms of service

Database (PostgreSQL), auth, storage, edge functionsStored in the EU (AWS Frankfurt, eu-central-1); contracting entity in Singapore, hence Standard Contractual Clauses apply in additionServers in the EU, encryption at rest (AES-256) and in transit (TLS 1.3)

Anthropic PBC

DPA and SCCs in place (anthropic.com/legal/dpa)

Claude LLM — text generation and document analysisUSA (US → EU: Standard Contractual Clauses under EU Decision 2021/914)No use for training purposes; retained up to 30 days for abuse detection, longer where flagged

OpenAI, L.L.C.

DPA signed by both parties (3 July 2026)

GPT text models and gpt-image-2 image generationUSA (SCCs)No use for training purposes; abuse logs kept up to 30 days

Google LLC (Gemini API)

Google Data Processing Addendum (Version 10, 7 May 2026) via the Paid Services clause

Backup image model — used only if the primary model failsUSA — no EU region option exists for this endpointNo use for training purposes; prompts, reference images and outputs retained 55 days for abuse detection

Plus Five Five, Inc. (Resend)

DPA (31 Dec 2025) incorporated into the terms of service

Transactional email delivery (sign-up, notifications)EU (AWS eu-west-1, Ireland)Sending strictly task-related, TLS encryption

Twilio Inc.

Twilio Data Protection Addendum (9 Apr 2026) incorporated into the terms of service

Phone reception — only when the phone feature is enabledUSA (SCCs)Call metadata and transcripts only, no workspace data

AlphaAI Technologies Inc. (Tavily) / Brave Software Inc.

No DPA covering the content of search queries; hence no personal data is sent there. Brave's DPA (21 Apr 2026) covers account data

Web research for the assistants (e.g. trend and lead research)USA (SCCs)Only the search term is transmitted (business type + location) — no documents, mailbox content, customer records or personal data

Vercel Inc.

DPA incorporated into the terms of service (§ 10.1)

Hosting of the web application and serverless functionsEU — deployment region Frankfurt (fra1), fixedEU region enforced via Vercel config, TLS 1.3

Sentry / Functional Software, Inc.

DPA v5.1.0, accepted on 31 July 2026

Error tracking and performance monitoringEU (ingest.de.sentry.io)EU region endpoints, no plain-text prompts in error reports

Stripe Payments Canada, Ltd. / Stripe, LLC

DPA incorporated into the Stripe Services Agreement; for payment data Stripe acts as an independent controller

Payment provider for the technical processing of paymentsCanada/USA or the regionally responsible Stripe entityPCI-DSS-compliant, no card data stored at Hazonlive

Incident response

GDPR Art. 33 — 72-hour notification duty: In the event of a personal-data breach, we inform you and the competent supervisory authority within 72 hours of becoming aware of it.

Escalation path: Security events are reported automatically to our Sentry monitoring (EU). Critical events trigger a direct notification to the Hazonlive team.

Audit trail: All sensitive operations (sign-in, plan change, data export) are stored with a timestamp, user ID and workspace ID in an immutable audit log.

Compliance contact

Questions about data processing, the DPA or data protection?

We respond to all compliance enquiries within two working days.

Service provider: AGAPE INNOVATIONS GROUP INC., Toronto, Canada · Legal notice (Imprint) · Privacy policy

Send enquiry

Data processing agreement (DPA)

We provide every Pro and Business customer with a data processing agreement under Art. 28 GDPR. This bindingly governs:

  • Processing purposes and categories
  • Technical and organisational measures (TOMs)
  • Sub-processor authorisation
  • Data transfers to third countries (SCCs)
  • Data-subject rights and cooperation
  • Audit rights and controls

We send you the DPA as part of the onboarding process or on request.