Dazr Suite data processing agreement
Last updated 6 October 2026 · For organisations that use Dazr Suite at suite.dazr.eu: Docs, Sheets, Slides and Files, including organisation spaces.
This agreement is published in English, which is the binding version.
1. Definitions
Terms used here have the meaning they have in Regulation (EU) 2016/679 (the GDPR). “Customer Personal Data” means personal data that the organisation, or its members acting for it, store in Dazr Suite: the content of files, documents, spreadsheets and presentations, their names, versions and comments, the activity of an organisation space, and the share links created for its files.
2. Subject matter, duration, nature and purpose
- Subject matter: storing and processing Customer Personal Data so that the organisation can create, edit, store and share its work with Dazr Docs, Sheets, Slides and Files.
- Duration: for as long as Customer Personal Data is stored in Dazr Suite, until it is deleted as described in section 12.
- Nature and purpose: hosting, storage, encryption, versioning, transmission, retrieval, sharing through links the organisation creates, and deletion, as described in the terms of use and the Dazr Suite privacy notice.
- Types of personal data: whatever the organisation puts in its files, together with the names, email addresses and roles of its members, the authors of comments, and the activity of its space. The organisation decides which personal data it stores, including any special categories.
- Categories of data subjects: the organisation’s members and employees, and any person who appears in the files the organisation stores.
3. Dazr’s obligations
- We process Customer Personal Data only on the documented instructions of the organisation. Using the functions of Dazr Suite is such an instruction. If we believe an instruction breaks the GDPR or other EU or Member State data protection law, we tell the organisation.
- Everyone at Dazr who can access Customer Personal Data is bound to confidentiality.
- We take the measures required by Article 32 GDPR; section 7 describes them.
- We engage sub-processors only as section 6 describes.
- Taking into account the nature of the processing, we help the organisation answer requests from data subjects and meet its obligations on security, breach notification, data protection impact assessments and prior consultation (Article 28(3)(e) and (f) GDPR).
- When the processing ends, we delete Customer Personal Data as section 12 describes, unless EU or Member State law requires us to keep it.
- We make available the information needed to show that we meet Article 28 GDPR, and allow and contribute to audits as section 9 describes.
4. The organisation’s obligations
- The organisation has a legal basis under Article 6, and where relevant Article 9, GDPR for the personal data it stores in Dazr Suite.
- The organisation decides who belongs to it and can reach its shared space, through its owner and admins in Dazr Identity, and which files are shared with a link.
- The organisation answers the requests of data subjects about its files. If we receive such a request, we pass it on to the organisation.
5. Where data is stored
We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.
6. Sub-processors
- The organisation authorises Dazr to engage these sub-processors: Vercel (hosting, server functions and file storage), Upstash (the database for accounts and records) and Resend (sending emails such as sign-in codes and notifications). Their locations and the data they handle are listed in the Dazr Files trust centre.
- We inform organisations at least 30 days before we add or replace a sub-processor, on this page and by email to the owner of each organisation.
- The organisation may object on reasonable data protection grounds. If we cannot meet the objection, the organisation may stop using Dazr Suite and take its files with it (section 12).
- Every sub-processor is bound by a written contract with data protection obligations no less protective than this agreement, and we remain responsible to the organisation for its work.
7. Security measures (Article 32 GDPR)
- Encryption. All traffic is encrypted with HTTPS, with HSTS preloaded. Files are encrypted with AES-256-GCM at the application layer, on top of our providers’ encryption, with a separate key for each person’s own files and for each organisation space, held on our servers. This is not end-to-end encryption: our systems can decrypt files in order to provide the service.
- Access control. Every request is checked against the current member list of the organisation; a member who leaves loses access at once. Only the owner and admins can delete files for good or empty the trash.
- Share links. Links give read-only access to one file and are checked on the server at every request: expiry, whether the link was turned off, whether the file is in the trash, and whether the person who created the link still belongs to the organisation.
- Sign-in. Dazr Identity, with passkeys or one-time codes sent by email (or Google or Microsoft); no passwords.
- Resilience. Each file keeps its last 10 versions and deleted files stay in the trash for 30 days. The database that holds accounts and file records is backed up daily, encrypted, in the European Union.
- Monitoring and limits. Requests are rate-limited per account and per IP address, scheduled jobs are monitored, and the live status is published at dazr.eu/status.
8. Personal data breaches
If we become aware of a personal data breach that affects Customer Personal Data, we notify the owner of the organisation without undue delay and no later than 72 hours after becoming aware of it. The notification describes, as far as known, the nature of the breach, its likely consequences, the measures taken or proposed, and a contact for more information. We help the organisation meet its own obligations under Articles 33 and 34 GDPR.
9. Audits
The organisation, or an auditor it appoints, may audit our compliance with this agreement once every twelve months, with at least 30 days’ written notice, during business hours, without unreasonable disruption and while respecting the confidentiality of other customers’ data. Where the information on our trust centre pages or a third-party report we hold answers the question, we provide that first.
10. Liability
Each party’s liability under this agreement follows the limits in the terms of use. Those limits do not restrict the rights of data subjects under Article 82 GDPR.
11. Term
This agreement applies for as long as we process Customer Personal Data, and sections 8, 9 and 12 continue after the organisation stops using Dazr Suite, for as long as we hold any of its data.
12. Return and deletion
The organisation can download all files of its space at any time as one .zip file (Storage, Download all files), and any single file with all its versions. Files deleted for good, an organisation that is deleted and its space, and an account that is deleted with its own files are removed from the live service at once. File contents are not part of our backups; the file records in the encrypted database backups expire after at most 12 months. Records that the law requires us to keep are kept only for that period.
13. Order of precedence
Where this agreement and the terms of use or the privacy notice differ on data protection, this agreement applies. Standard Contractual Clauses that apply to a transfer take precedence over both for the matters they cover.
14. Notices
- To Dazr: privacy@dazr.eu (data protection), security@dazr.eu (incidents) or legal@dazr.eu (contracts).
- To the organisation: the email address of its owner in Dazr Identity at the time of the notice.