Privacy Policy
Last Updated: July 2026 · Version 2.0
This Privacy Policy explains how Deznot ("we", "us", "our") collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the ePrivacy Directive 2002/58/EC.
1. Data Controller
Deznot is the Data Controller responsible for your personal data. For any data protection inquiries, contact our Data Protection Officer at:
Email: dpo@deznot.com
2. Personal Data We Process
- Account data: First name, last name, work email, password (bcrypt-hashed)
- Organization data: Company name, legal name, country, tax ID, timezone
- Usage data: Login timestamps, session tokens, IP addresses for security
- Billing data: Payment method tokens (processed by Stripe — we do not store card numbers)
- Compliance data: Sanctions screening results, compliance status
- Technical data: Browser type, operating system, device identifiers
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b)): Account creation, service delivery
- Legal obligation (Art. 6(1)(c)): Sanctions screening, tax records, audit logs
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention
- Consent (Art. 6(1)(a)): Analytics cookies, marketing communications
4. Data Retention
- Account data: Retained while account is active; deleted 90 days after account closure
- Audit logs: Retained for 2 years per legal requirements
- Sanctions screening logs: Retained for 5 years per OFAC/EU compliance requirements
- Billing records: Retained for 7 years per tax regulations
- Session data: Deleted on logout or after 30 days of inactivity
5. Your Rights Under GDPR
- Right of access (Art. 15): Request a copy of your personal data
- Right to rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to restrict processing (Art. 18): Limit how we use your data
- Right to data portability (Art. 20): Receive your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)): Withdraw consent at any time
To exercise any of these rights, email privacy@deznot.com. We respond within 30 days.
6. International Data Transfers
Your data may be processed in countries outside the EU/EEA. We ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission and additional safeguards where required.
7. Sub-Processors
We use the following sub-processors to provide our services:
- Stripe — Payment processing (PCI-DSS compliant)
- Redis Labs — Session caching
- Let's Encrypt — SSL certificate issuance
A full and updated list is available at /subprocessors.
8. Data Security
We implement industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, bcrypt password hashing, JWT-based authentication with refresh token rotation, and regular security audits. Access to personal data is restricted to authorized personnel on a need-to-know basis.
9. Breach Notification
In the event of a personal data breach, we will notify the supervisory authority within 72 hours (Art. 33) and affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Art. 34).
10. Cookies
We use cookies in accordance with our Cookie Policy. You can manage your cookie preferences at any time through the cookie consent banner or in your account settings.
11. Complaints
You have the right to lodge a complaint with your local supervisory authority. However, we encourage you to contact us first at dpo@deznot.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email and update the "Last Updated" date above. Continued use of the service constitutes acceptance of the updated policy.
