Security & Trust
Hazonlive was built for European businesses. EU hosting, GDPR-compliant, AI transparency and an approval workflow that keeps you in control.
As of: 2026-07-31 · Reviewed quarterly
EU hosting, Frankfurt
Database, storage and web app run on AWS Frankfurt eu-central-1. All storage stays in the EU; AI processing is handled by the providers listed below.
GDPR-compliant
Data processing under Art. 28 GDPR. No data is shared with third parties without a processing agreement.
AI transparency
Every AI-generated item carries an AI label. EU AI Act ready.
Zero-training
Your data is never used to train AI models — contractually guaranteed with every LLM provider.
Where and how your data is processed
Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database connections run exclusively over encrypted channels.
Multi-tenant isolation: Every workspace is strictly separated from every other one through Supabase Row Level Security (RLS) — enforced in the database, not just in the application. A customer account cannot see another workspace's data. The one documented exception is our support access: we can open a time-limited customer view to help with problems. Every such access is cryptographically signed, logged and expires automatically. Email content from connected mailboxes stays hidden by default. It becomes visible only if you explicitly release your mailbox in the settings for a limited time (up to eight hours, revocable at any time). For Gmail mailboxes it stays blocked even then — Google's rules for access to mailbox data allow no exception based on your consent.
No training on your data: AI processing runs at Anthropic (Claude) and OpenAI (GPT, gpt-image-2) in the USA — safeguarded by data processing agreements and EU Standard Contractual Clauses. Your prompts and generated content are never used to train AI models; that is contractually safeguarded in our DPAs. Both providers retain inputs and outputs for up to 30 days for abuse detection — longer where content is flagged for safety reasons.
Authentication: Passwords are stored only as bcrypt hashes, never in plain text. Session cookies are Secure + SameSite=Lax; they are readable by the browser because the application evaluates the session there — this is mitigated by a strict Content Security Policy and HSTS. Rate limits against brute-force attacks are active, and two-factor authentication is mandatory for all operator accounts.
Backups & disaster recovery
Point-in-time recovery
Supabase PITR. Seven days of granularity, down to the second.
RPO ≤ 24 hours
Recovery Point Objective: the maximum data loss in a worst-case scenario.
RTO ≤ 4 hours
Recovery Time Objective: the maximum downtime during disaster recovery.
Our processors (sub-processors)
A complete list of all services that process data on our behalf. The “contract” column states what the processing rests on for each service — with most providers the DPA is incorporated into their terms of service.
| Provider | Purpose | Region | Safeguards |
|---|---|---|---|
Supabase Pte. Ltd. DPA incorporated into the terms of service | Database (PostgreSQL), auth, storage, edge functions | Stored in the EU (AWS Frankfurt, eu-central-1); contracting entity in Singapore, hence Standard Contractual Clauses apply in addition | Servers in the EU, encryption at rest (AES-256) and in transit (TLS 1.3) |
Anthropic PBC DPA and SCCs in place (anthropic.com/legal/dpa) | Claude LLM — text generation and document analysis | USA (US → EU: Standard Contractual Clauses under EU Decision 2021/914) | No use for training purposes; retained up to 30 days for abuse detection, longer where flagged |
OpenAI, L.L.C. DPA signed by both parties (3 July 2026) | GPT text models and gpt-image-2 image generation | USA (SCCs) | No use for training purposes; abuse logs kept up to 30 days |
Google LLC (Gemini API) Google Data Processing Addendum (Version 10, 7 May 2026) via the Paid Services clause | Backup image model — used only if the primary model fails | USA — no EU region option exists for this endpoint | No use for training purposes; prompts, reference images and outputs retained 55 days for abuse detection |
Plus Five Five, Inc. (Resend) DPA (31 Dec 2025) incorporated into the terms of service | Transactional email delivery (sign-up, notifications) | EU (AWS eu-west-1, Ireland) | Sending strictly task-related, TLS encryption |
Twilio Inc. Twilio Data Protection Addendum (9 Apr 2026) incorporated into the terms of service | Phone reception — only when the phone feature is enabled | USA (SCCs) | Call metadata and transcripts only, no workspace data |
AlphaAI Technologies Inc. (Tavily) / Brave Software Inc. No DPA covering the content of search queries; hence no personal data is sent there. Brave's DPA (21 Apr 2026) covers account data | Web research for the assistants (e.g. trend and lead research) | USA (SCCs) | Only the search term is transmitted (business type + location) — no documents, mailbox content, customer records or personal data |
Vercel Inc. DPA incorporated into the terms of service (§ 10.1) | Hosting of the web application and serverless functions | EU — deployment region Frankfurt (fra1), fixed | EU region enforced via Vercel config, TLS 1.3 |
Sentry / Functional Software, Inc. DPA v5.1.0, accepted on 31 July 2026 | Error tracking and performance monitoring | EU (ingest.de.sentry.io) | EU region endpoints, no plain-text prompts in error reports |
Stripe Payments Canada, Ltd. / Stripe, LLC DPA incorporated into the Stripe Services Agreement; for payment data Stripe acts as an independent controller | Payment provider for the technical processing of payments | Canada/USA or the regionally responsible Stripe entity | PCI-DSS-compliant, no card data stored at Hazonlive |
Incident response
GDPR Art. 33 — 72-hour notification duty: In the event of a personal-data breach, we inform you and the competent supervisory authority within 72 hours of becoming aware of it.
Escalation path: Security events are reported automatically to our Sentry monitoring (EU). Critical events trigger a direct notification to the Hazonlive team.
Audit trail: All sensitive operations (sign-in, plan change, data export) are stored with a timestamp, user ID and workspace ID in an immutable audit log.
Compliance contact
Questions about data processing, the DPA or data protection?
We respond to all compliance enquiries within two working days.
Service provider: AGAPE INNOVATIONS GROUP INC., Toronto, Canada · Legal notice (Imprint) · Privacy policy
Data processing agreement (DPA)
We provide every Pro and Business customer with a data processing agreement under Art. 28 GDPR. This bindingly governs:
- Processing purposes and categories
- Technical and organisational measures (TOMs)
- Sub-processor authorisation
- Data transfers to third countries (SCCs)
- Data-subject rights and cooperation
- Audit rights and controls
We send you the DPA as part of the onboarding process or on request.