Dazr Sign privacy notice
Last updated 5 October 2026 · For Dazr Sign at sign.dazr.eu, signing links, the Dazr Sign API and the check page.
If a translation of this page differs from the English version, the English version applies.
Who is responsible
Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065, is the controller for the personal data described in this notice. For anything about your data, write to privacy@dazr.eu.
Senders and signers
A sender uploads a PDF, adds recipients with their names and email addresses, and sends it. Each recipient receives an email with a personal link. To open it, they sign in with Dazr Identity using that email address. Someone without an account gets one when they first sign in with the emailed code; the Dazr Identity privacy notice covers that account.
The sender decides what a document contains and who receives it. We use the contents of a document only to provide the signing service: to show it, collect the signatures and produce the signed copy.
What we keep for each document
- The document. The PDF as uploaded and, when everyone has signed, the signed copy. Intermediate versions made while signing are deleted when the document is completed.
- Recipients. Their names and email addresses, their role (signer or receives a copy), the signing order, their status and the values they entered in the fields.
- Signatures. The signature and initials a signer draws or types and, when a signer signs for an organisation, its name and whether it is verified.
- The audit trail. Every step (sent, opened, viewed, signed, declined, reminded) with its time, the email address involved, how the person signed in, the country derived from the IP address, a short description of the device (browser and operating system) and a one-way hash of the IP address instead of the address itself. The audit trail is part of the signed copy, so everyone who receives that copy can read it.
- Messages. The sender’s optional message, and the reason if someone declines.
The check page
Anyone who has a copy of a completed document can check it at sign.dazr.eu/check. The file stays on their device; only its fingerprint (SHA-256) is sent to us. If it matches, the page shows the title, the dates, the names of the sender and signers with their email addresses partly hidden, and how each person signed.
Qualified electronic signatures
A sender can ask a signer for a qualified electronic signature. The signer then signs the PDF with their own qualified certificate from a qualified trust service provider and uploads the result. Dazr does not issue qualified signatures or certificates. We check the signature against the EU trusted lists and ask the certificate provider’s revocation service whether the certificate is still valid. We keep the details from the certificate: the name, the serial number in the name (for some providers a national identification or tax number), the country, any organisation named in it, the provider and the signing time. They are shown in the audit trail.
Where the option is offered, a signer can also confirm their identity with the EU Digital Identity Wallet, or sign with it. We then receive from the wallet only the signer’s given name, family name and the country that issued the identity, and add them to the audit trail.
Apps that use the Dazr Sign API
An app can prepare and send documents in your name through the Dazr Sign API once you allow it on the Dazr Identity consent screen. The app can see and manage only the documents it created. Its notifications (webhooks) carry the status of a document and its recipients, never the document itself. The organisation behind the app is responsible for what it does with that information. For each app we count API use per day, kept for 400 days.
Emails we send
We email recipients the signing request, the reminders the sender chose, and the signed copy or a link to it when everyone has signed. Senders hear when someone signs or declines. If an email cannot be delivered, our email provider tells us, so the sender can see that the address did not work.
Legal basis
For senders, and for signers using their own account, we process this data to provide the service (Article 6(1)(b) GDPR). We process recipients’ names and email addresses because the sender sent them a document, in our legitimate interest and the sender’s in completing the signing (Article 6(1)(f) GDPR). We keep the audit trail because a signature is only useful as evidence if its history can be shown (Article 6(1)(f) GDPR).
How long we keep it
- Documents, signed copies and audit trails stay until the sender deletes them or deletes their Dazr Identity account. Documents you received stay with their sender; deleting your own account does not delete them.
- Signing links stop working when the document is completed, cancelled or past its deadline.
- Uploads that were never used are deleted after 2 hours.
- Daily API counts: 400 days.
Visiting our websites
- Server logs. Our hosting provider records each request: IP address, browser (user agent), the address requested, status and time. We use these logs to run our services and keep them secure, and keep them for up to 30 days. Legal basis: our legitimate interest in operating secure websites (Article 6(1)(f) GDPR).
- Page statistics. We count page views with Vercel Web Analytics. It sets no cookies and does not store IP addresses; we only see totals, such as how often a page was viewed. Legal basis: our legitimate interest in knowing which pages people use (Article 6(1)(f) GDPR).
- No advertising or tracking. Our websites show no advertising and contain no third-party trackers, pixels or social media widgets. Fonts and scripts come from our own servers.
- Spam protection. Before a public form is sent, your browser solves a small calculation (proof of work). It runs on your device and sets no cookie.
When you contact us
If you use the contact form or write to one of our addresses, we receive your name, email address, company (optional), the topic, your message and the page you sent it from. The form emails your message to our inbox and a copy to you. We use it only to answer you and follow up on your request, and keep it for up to 24 months after our last contact. Legal basis: steps you ask for before a possible contract (Article 6(1)(b) GDPR) and our legitimate interest in answering questions (Article 6(1)(f) GDPR).
Cookies and storage on your device
We use no advertising or analytics cookies, so there is no cookie banner. What we store is needed for the service or remembers a choice you made, so it needs no consent:
__Secure-dazr_id(cookie): keeps you signed in to Dazr Identity on the dazr.eu sites. It cannot be read by scripts and ends after 30 days, or when you sign out.dazr_id_hint,dazr_id_ping(local storage): your name, email address and picture, so the page header can show who is signed in straight away, and a signal that keeps your open tabs in step when you sign in or out.dazr_lang(local storage): the language you picked.
Service providers
These companies process personal data for us, only on our instructions and under written contracts that oblige them to protect it:
- Vercel hosts our websites and server functions, stores files (Vercel Blob) and counts page views.
- Upstash runs the database (a key-value store) that holds accounts and records.
- Resend sends signing requests, reminders, signed copies and updates, and tells us when an email could not be delivered.
To check qualified signatures we contact public services that answer for themselves, not for us: the EU trusted lists and the certificate providers’ revocation services. Their requests name the certificate, not you as a user of Dazr Sign.
Where your data is stored
We store personal data in the European Union. Vercel, Upstash and Resend are companies based in the United States. Where one of our providers can access personal data from outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision of the European Commission.
How we protect your data
All traffic to our services is encrypted (HTTPS). Accounts, documents and files are also encrypted at rest with AES-256-GCM, on top of the encryption our providers apply, using keys held on our servers. This is not end-to-end encryption: our systems can decrypt the data in order to provide the service, and only the few people at Dazr who run it can access them.
Each document is encrypted with its own key. When everyone has signed, Dazr seals the PDF with its own digital signature, so any later change shows.
Your rights
You can ask us for access to your personal data, a copy in a portable format, correction, deletion or restriction, and you can object to processing based on our legitimate interests. Where we rely on your consent, you can withdraw it at any time.
Senders can delete their documents at any time. If you received a document, ask the sender to delete it. A completed audit trail cannot be changed without breaking the seal, because it is the evidence of what happened; where the law requires, we restrict or delete it.
Write to privacy@dazr.eu for anything you cannot do yourself. We reply within 30 days.
You can also complain to a data protection authority: in Italy the Garante per la protezione dei dati personali (garanteprivacy.it), or the authority where you live or work.
Changes to this notice
If we change this notice, we update the date at the top. Earlier versions are available on request.
Contact
- Privacy and data requests: privacy@dazr.eu
- Security: security@dazr.eu
- General: hello@dazr.eu
- Post: Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy