Trust & data protection

Trust Centre

Vaizy is built in the Netherlands and runs on European infrastructure for core product data. AI processing is routed server-side with contractual safeguards and data-minimisation controls. Here is where your data lives and how we keep it safe.

Where your data lives

Every service we rely on, plotted by where it physically processes your data. Almost all run inside the EU. The one exception, OpenAI, is bound by EU Standard Contractual Clauses, processes prompts with zero data retention, and receives only the limited context needed for AI responses.

European Union· 7/8United States
Supabase

Database, auth & realtime

Hetzner / Coolify

Hosting & infrastructure (Germany)

Bunny.net

Content delivery network

Mollie

Payment processing & billing

PostHog

Product analytics

Featurebase

Knowledge base, changelog & feedback

Lettermint

Transactional & product email

OpenAI

AI assistant processing

Core customer data stays in the EU

All sub-processors are bound by Data Processing Agreements. The current list is published at vaizy.com/subprocessors and mirrored in our DPA.

How your data is protected

Concrete measures, not slogans. Each one is enforced today and documented in our Privacy Policy.

The AI never sees sensitive data

AI requests pass through a server-side gateway that minimises and masks sensitive context before model processing. Client code never calls the AI provider directly.

Encrypted, always

TLS 1.2+ on everything in transit. Stored data is encrypted at rest by Supabase.

You see only your own data

Row Level Security is enforced on every database table, and role-based access controls govern what each member can do.

Sign in with a second factor

Authentication runs on Supabase Auth with multi-factor (TOTP) support, so a password alone is not enough.

Secrets stay on the server

API keys and provider credentials live in server-managed secrets. They are never shipped to the browser.

Hardened in production

Production builds and database access paths are reviewed and hardened to reduce accidental exposure and common misconfiguration risks.

Browser-level defences

HSTS, X-Frame-Options DENY, a strict Content Security Policy, and a locked-down permissions policy ship with every page.

EU AI Act transparency

AI features are labelled wherever they appear, a person stays in charge of every decision, and the assistant is never used for decisions with legal or similarly significant effects on a person, consistent with the EU AI Act (Regulation (EU) 2024/1689).

If something goes wrong

No system is risk-free, and we will not pretend otherwise. If a breach affects your data, we notify you and the Dutch supervisory authority (Autoriteit Persoonsgegevens) without undue delay, and within 72 hours of becoming aware, as GDPR requires.

What we don't claim yet

We don't hold SOC 2 or ISO 27001 certification today. We'd rather tell you that than imply a badge we haven't earned. Our security posture is built on GDPR compliance, EU data residency, and the measures above. Formal certification is on our roadmap as we grow.

Read the fine print

Every claim on this page is backed by our legal documents. Read them in full, or ask us anything.