Dazr Sign privacy notice

Who is responsible

Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, is the controller for the personal data described in this notice. For anything about your data, write to privacy@dazr.eu.

Senders and signers

A sender uploads a PDF, adds recipients with their names and email addresses, and sends it. Each recipient receives an email with a personal link. To open it, they sign in with Dazr Identity using that email address. Someone without an account gets one when they first sign in with the emailed code; the Dazr Identity privacy notice covers that account.

The sender decides what a document contains and who receives it. We use the contents of a document only to provide the signing service: to show it, collect the signatures and produce the signed copy.

What we keep for each document

The check page

Anyone who has a copy of a completed document can check it at sign.dazr.eu/check. The file stays on their device; only its fingerprint (SHA-256) is sent to us. If it matches, the page shows the title, the dates, the names of the sender and signers with their email addresses partly hidden, and how each person signed.

Qualified electronic signatures

A sender can ask a signer for a qualified electronic signature. The signer then signs the PDF with their own qualified certificate from a qualified trust service provider and uploads the result. Dazr does not issue qualified signatures or certificates. We check the signature against the EU trusted lists and ask the certificate provider’s revocation service whether the certificate is still valid. We keep the details from the certificate: the name, the serial number in the name (for some providers a national identification or tax number), the country, any organisation named in it, the provider and the signing time. They are shown in the audit trail.

Where the option is offered, a signer can also confirm their identity with the EU Digital Identity Wallet, or sign with it. We then receive from the wallet only the signer’s given name, family name and the country that issued the identity, and add them to the audit trail.

Apps that use the Dazr Sign API

An app can prepare and send documents in your name through the Dazr Sign API once you allow it on the Dazr Identity consent screen. The app can see and manage only the documents it created. Its notifications (webhooks) carry the status of a document and its recipients, never the document itself. The organisation behind the app is responsible for what it does with that information. For each app we count API use per day, kept for 400 days.

Emails we send

We email recipients the signing request, the reminders the sender chose, and the signed copy or a link to it when everyone has signed. Senders hear when someone signs or declines. If an email cannot be delivered, our email provider tells us, so the sender can see that the address did not work.

For senders, and for signers using their own account, we process this data to provide the service (Article 6(1)(b) GDPR). We process recipients’ names and email addresses because the sender sent them a document, in our legitimate interest and the sender’s in completing the signing (Article 6(1)(f) GDPR). We keep the audit trail because a signature is only useful as evidence if its history can be shown (Article 6(1)(f) GDPR).

How long we keep it

Visiting our websites

When you contact us

If you use the contact form or write to one of our addresses, we receive your name, email address, company (optional), the topic, your message and the page you sent it from. The form emails your message to our inbox and a copy to you. We use it only to answer you and follow up on your request, and keep it for up to 24 months after our last contact. Legal basis: steps you ask for before a possible contract (Article 6(1)(b) GDPR) and our legitimate interest in answering questions (Article 6(1)(f) GDPR).

Cookies and storage on your device

We use no advertising or analytics cookies, so there is no cookie banner. What we store is needed for the service or remembers a choice you made, so it needs no consent:

Service providers

These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:

To check qualified signatures we contact public services that answer for themselves, not for us: the EU trusted lists and the certificate providers’ revocation services. Their requests name the certificate, not you as a user of Dazr Sign.

Where your data is stored

We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.

How we protect your data

All traffic to our services is encrypted (HTTPS). Accounts, documents and files are also encrypted at rest with AES-256-GCM, on top of the encryption our providers apply, using keys held on our servers. This is not end-to-end encryption: our systems can decrypt the data in order to provide the service, and only the few people at Dazr who run it can access them.

Each document is encrypted with its own key. When everyone has signed, Dazr seals the PDF with its own digital signature, so any later change shows.

Your rights

You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.

Senders can delete their documents at any time. If you received a document, ask the sender to delete it. A completed audit trail cannot be changed without breaking the seal, because it is the evidence of what happened; where the law requires, we restrict or delete it.

Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.

You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.

Changes to this notice

If we change this notice, we update the date at the top. Earlier versions are available on request.

Contact