Ozer Trust Centre

Security and data protection are foundational to Ozer. We're committed to keeping your client data, business information, and team communications safe — and being transparent about how we do it.

Last updated: 30 July 2026

Compliance

SOC 2 — planned
ISO 27001 — via AWS

GDPR

Ozer is designed to comply with the UK GDPR, EU GDPR, and the Data Protection Act 2018. We act as a processor for personal data you store in your workspace (for example clients, notes, and transcripts) and as a controller for account and authentication data, product analytics and security logs, and SaaS billing records. We do not sell your data to third parties.

UK ICO Registration

Ozer is operated by Oodle Designs Ltd, a UK registered company. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.

Data Processing Agreement

Our Data Processing Agreement (UK GDPR Article 28) is in effect for business customers and is available at /dpa and as a downloadable file at /legal/ozer-dpa.md. Counsel review of the full agreement remains in progress. Questions: privacy@ozer.so.

Google API Limited Use

Ozer's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See the Privacy Policy.

SOC 2 Type II (Roadmap)

We are working toward SOC 2 Type II certification. Our infrastructure provider (Supabase/AWS) already holds SOC 2 Type II certification — details available at supabase.com/security.

Sub-processors

Ozer engages the following sub-processors to deliver the service. This register matches our Privacy Policy and DPA. Integrations that are not yet shipped are excluded.

NamePurposeData (high level)Location & transfer mechanism
Supabase / AWSDatabase, auth, storageWorkspace and account dataEU West (Ireland) — no restricted transfer
StripeSaaS billing and Connect paymentsCustomer IDs, subscription status; card numbers stay with StripeUS — Stripe Data Transfers Addendum (UK IDTA incorporated; EU-US Data Privacy Framework incl. UK Extension)
AnthropicAI language model featuresWorkspace / email / transcript text promptsUS — DPA with EU SCCs and UK Addendum; EU-US Data Privacy Framework
GoogleGmail, Calendar, Workspace directoryMailbox, calendar, and directory dataUS/global — Google Data Processing Terms (SCCs and UK Addendum incorporated)
MicrosoftSignatures directory syncStaff profile and photo dataUS/global — Microsoft Products and Services Data Protection Addendum (SCCs and UK Addendum incorporated)
ZeptoMail (Zoho)Transactional emailRecipient, subject, message bodyEU data centre — Zoho DPA with standard contractual clauses
Bunny.net (BunnyWay d.o.o.)Video hosting and streamingMedia files and video metadataSlovenia (EU) — EU-headquartered; DPA in place; EU storage region
Voyage AISemantic search embeddingsText excerpts and search queriesUS — Voyage AI DPA with EU SCCs and UK ICO Addendum
PostHog, Inc.Product analytics, feature flags, error/session diagnostics, and session replayUsage events, device/browser data, user/account identifiers; UI session recordings (inputs masked; 30-day recording retention)EU (PostHog EU Cloud) — PostHog DPA with EU SCCs and UK Addendum

We give at least 30 days' notice of intended additions or replacements of sub-processors, via update to this Trust Centre register and, for material changes, by email to the Controller's account contact, with an opportunity to object on reasonable grounds (see the DPA).

Infrastructure & Hosting

Cloud Infrastructure

Ozer is hosted on Supabase, which runs on Amazon Web Services (AWS). AWS maintains ISO 27001, SOC 1, SOC 2, and SOC 3 certifications. Supabase itself holds SOC 2 Type II certification.

Physical Access Control

Ozer has no physical servers. All infrastructure is managed by Supabase/AWS, which operate enterprise-grade data centres with strict physical access controls.

Access Control

Access to Ozer's production database and infrastructure is restricted to authorised team members only. All access requires strong authentication. Database administration access is audited.

Row-Level Security

Data tables in Ozer enforce Row-Level Security (RLS) policies at the database level so workspace data is scoped to the correct account and cannot be accessed across workspaces via the standard application path.

Penetration Testing

We plan to conduct annual third-party penetration testing as we approach general availability. Customers with specific security assessment requirements should contact us at security@ozer.so.

Data Flow

Data in Transit

All data sent to and from Ozer is encrypted in transit using HTTPS with TLS 1.2 or higher.

Data at Rest

Data stored in Ozer is encrypted at rest using AES-256 encryption via our Supabase/AWS infrastructure.

OAuth token security

OAuth access and refresh tokens for Google integrations (including Gmail Email Assistant and Google Calendar) are encrypted at the application layer using AES-256-GCM before storage. Microsoft 365 Signatures connection tokens are stored in our database without a separate application-layer wrap and rely on AES-256 encryption at rest. Tokens are deleted when you disconnect the integration.

Data Residency & transfers

Primary customer data storage is in AWS EU West (Ireland). Where a sub-processor processes personal data outside the UK/EEA, we rely on the transfer mechanisms listed in the sub-processor table above — UK International Data Transfer Addendum and/or EU Standard Contractual Clauses incorporated into each provider's data processing terms, and, where applicable, the EU-US Data Privacy Framework and its UK Extension.

Backups

Supabase maintains automated daily database backups with point-in-time recovery. Backups are stored in encrypted form across multiple availability zones.

Retention

Feature-specific retention periods are set out in the Privacy Policy. On account termination we delete customer data across our systems within 30 days, except records we must keep for legal reasons (for example, billing records retained for 6 years for tax purposes).

Application Security

Authentication

Ozer uses Supabase Auth for user authentication. Passwords are never stored in plain text. We support:

  • Email + password (with secure hashing via bcrypt)
  • Magic link / OTP login
  • Google OAuth (planned)
  • SAML/SSO (on roadmap for agency plans)

API Security

All Ozer API routes are authenticated. API keys are scoped and revocable. Rate limiting is applied to all public-facing endpoints.

Secure Development

All code changes to Ozer go through version control on GitHub, peer review, and automated testing before deployment. We follow OWASP secure development guidelines.

Dependency Management

We regularly audit our dependencies for known vulnerabilities using automated tooling. Critical vulnerabilities are patched on a priority basis.

Business Continuity

High Availability

Ozer is deployed on infrastructure designed for high availability. Supabase/AWS provides automatic failover across multiple availability zones.

Disaster Recovery

We maintain documented procedures for disaster recovery. In the event of a significant incident, we can restore service from automated backups.

Incident Response

Ozer has a documented Security Incident Response process. Where a personal data breach affects Controller personal data, we notify the Controller without undue delay and in any event within 72 hours of becoming aware, in line with our DPA.

Status Page

Our live status page is available at status.ozer.so.

Vulnerability Disclosure

Reporting a Vulnerability

We take security disclosures seriously. If you discover a vulnerability in Ozer, please report it to us at security@ozer.so.

We ask that you:

  • Do not publicly disclose the vulnerability before we've had a chance to investigate and fix it
  • Provide enough detail for us to reproduce the issue
  • Act in good faith and avoid accessing or modifying other users' data

We will acknowledge your report within 2 business days, and will keep you updated as we investigate and resolve the issue.

Contact

For any security or privacy questions, contact us at security@ozer.so.

For DPA requests or GDPR queries, contact privacy@ozer.so.