Security & Trust

Hazonlive was built for European businesses. Database and storage in Frankfurt, GDPR-compliant, AI transparency and an approval workflow that keeps you in control.

As of: 2026-09-28 · Reviewed quarterly

Database and storage in Frankfurt

Database and storage are located on AWS Frankfurt eu-central-1; the web app's serverless functions are configured in Frankfurt (fra1). AI processing, the hosting platform and email delivery are handled by the providers listed below, partly in the USA.

GDPR-compliant

Data processing under Art. 28 GDPR. No data is shared with third parties without a processing agreement.

AI transparency

Inside Hazonlive, every AI-generated item carries an “AI-generated” label. Hazonlive adds no AI notice to published social media posts; you can add one to the post text yourself before scheduling.

Zero-training

Your data is never used to train AI models — contractually guaranteed with every LLM provider.

Independent security assessment

TAC Security badge: ESOF, Verified and Secured by ADA CASA Assessor

Independently security-assessed

CASA · App Defense Alliance

Assessment lab: TAC Security

TAC Security is an authorised assessment lab of the App Defense Alliance. The Alliance is an industry initiative for open security standards; Meta, Google and Microsoft are represented on its steering committee.

Where and how your data is processed

Encryption: All data is encrypted at rest (AES-256) and in transit. The application enforces TLS and permits 1.2 and above; where the browser supports it, TLS 1.3 is used. Database connections run exclusively over encrypted channels.

Multi-tenant isolation: Every workspace is strictly separated from every other one through Supabase Row Level Security (RLS) — enforced in the database, not just in the application. A customer account cannot see another workspace's data. The one documented exception is our support access: we can open a time-limited customer view to help with problems. Every such access is cryptographically signed, logged and expires automatically. Email content from connected mailboxes stays hidden by default. It becomes visible only if you explicitly release your mailbox in the settings for a limited time (up to eight hours, revocable at any time). For Gmail mailboxes it stays blocked even then — Google's rules for access to mailbox data allow no exception based on your consent.

No training on your data: AI processing runs at Anthropic and OpenAI in the USA, and the backup image model at Google — safeguarded by data processing agreements and EU Standard Contractual Clauses. Your prompts and generated content are never used to train AI models; that is contractually safeguarded in our DPAs. Anthropic and OpenAI retain inputs and outputs for up to 30 days for abuse detection, Google for 55 days — longer where content is flagged for safety reasons.

Authentication: Passwords are stored only as bcrypt hashes, never in plain text. Session cookies are Secure + SameSite=Lax; a strict Content Security Policy and HSTS provide additional protection. Rate limits against brute-force attacks are active, and two-factor authentication is mandatory for all operator accounts.

Backups & disaster recovery

Daily backups

Supabase backs the database up automatically every day. The backups are encrypted and held in the same EU region as the live data.

Restoring

If the worst happens, we restore the database from a backup. We will not state binding recovery objectives (RPO/RTO) here until we have evidenced them in a restore exercise — a number we have not rehearsed would be an estimate, not a commitment.

Retention periods

Audit entries are deleted automatically after 12 months. Content is subject to fixed periods, for example 90 days for unanswered inbox messages and for chat histories without activity. The deletion runs are a monitored cron job.

Our processors (sub-processors)

A complete list of all services that process data on our behalf. The “contract” column states what the processing rests on for each service — with most providers the DPA is incorporated into their terms of service.

ProviderPurposeRegionSafeguards

Supabase Pte. Ltd.

DPA incorporated into the terms of service

Database (PostgreSQL), auth, storage, edge functionsStored in the EU (AWS Frankfurt, eu-central-1); contracting entity in Singapore, hence Standard Contractual Clauses apply in additionServers in the EU, encryption at rest (AES-256) and in transit (TLS 1.3)

Anthropic PBC

DPA and SCCs in place (anthropic.com/legal/dpa)

Claude LLM — text generation, document analysis and web search for the assistants (Anthropic runs the search with Brave Search as its sub-processor)USA (US → EU: Standard Contractual Clauses under EU Decision 2021/914)No use for training purposes; retained up to 30 days for abuse detection, longer where flagged

OpenAI OpCo, LLC

DPA signed by both parties (3 July 2026)

Text AI (fallback during outages, selectable per assistant), semantic search (embeddings) and image generationUSA (SCCs)No use for training purposes; abuse logs kept up to 30 days

Google LLC (Gemini API)

Google Data Processing Addendum (Version 10, 7 May 2026) via the Paid Services clause

Backup image model — used only if the primary model failsUSA — no EU region option exists for this endpointNo use for training purposes; prompts, reference images and outputs retained 55 days for abuse detection

Plus Five Five, Inc. (Resend)

DPA (27 Aug 2026) incorporated into the terms of service

Transactional email delivery (sign-up, notifications — including call notifications with caller data)USA (storage); sending via AWS eu-west-1 (Ireland)Sending strictly task-related, TLS encryption; Standard Contractual Clauses in the DPA plus EU-U.S. Data Privacy Framework (without Swiss-U.S.; re-certification under review)

Twilio Inc.

Twilio Data Protection Addendum (9 Apr 2026) incorporated into the terms of service; processor for the telephone service, independent controller for its own purposes (including security and abuse detection, legal obligations, product improvement) — for connection and usage data and, to that extent, also for call content

Phone reception — only when the phone feature is enabledUSA (primarily EU-U.S. Data Privacy Framework, alternatively BCRs or Standard Contractual Clauses under the DPA)Call metadata and call content (Twilio speech recognition and text-to-speech), no call recording

Vercel Inc.

DPA incorporated into the terms of service (§ 10.1)

Hosting of the web application and serverless functionsUSA (provider's primary processing); serverless functions configured in Frankfurt (fra1); EU-U.S. Data Privacy FrameworkSOC 2 Type 2, TLS 1.3; our central server logger redacts fields containing credentials

Sentry / Functional Software, Inc.

DPA v5.1.0, accepted on 31 July 2026

Error tracking and performance monitoringEU ingest (ingest.de.sentry.io); provider in the USA, Standard Contractual ClausesEU region endpoints; no prompts, AI responses or request content

Stripe Payments Canada, Ltd. / Stripe, LLC

DPA with Stripe, LLC incorporated into the Stripe Services Agreement; processor for payment processing, independent controller for its own purposes (including fraud and risk checks, AML/KYC, legal obligations)

Payment provider for the technical processing of paymentsCanada/USA (primarily EU-U.S. Data Privacy Framework, alternatively Standard Contractual Clauses)PCI-DSS-compliant, no card data stored at Hazonlive

Incident response

GDPR Art. 33 — 72-hour notification duty: In the event of a personal-data breach, we inform you and the competent supervisory authority within 72 hours of becoming aware of it.

Escalation path: Security events are reported automatically to our Sentry monitoring (EU). Critical events trigger a direct notification to the Hazonlive team.

Audit trail: Changes to workspace and team, and assistant actions — invitations and roles, connected channels, approvals, sending and publishing, deleted conversations — are recorded with a timestamp, user ID and workspace ID. Members can read their own workspace's log and export it as CSV; it is written server-side only, and entries are deleted after 12 months. Sign-ins are not in this log: they go to our operational log, and there without the address in clear — only a non-reversible fingerprint and the domain.

Compliance contact

Questions about data processing, the DPA or data protection?

We respond to all compliance enquiries within two working days.

Service provider: AGAPE INNOVATIONS GROUP INC., Toronto, Canada · Legal notice (Imprint) · Privacy policy

Send enquiry

Data processing agreement (DPA)

We provide every Pro and Business customer with a data processing agreement under Art. 28 GDPR. This bindingly governs:

  • Processing purposes and categories
  • Technical and organisational measures (TOMs)
  • Sub-processor authorisation
  • Data transfers to third countries (SCCs)
  • Data-subject rights and cooperation
  • Audit rights and controls

We send you the DPA as part of the onboarding process or on request.