Security and data protection are foundational to Ozer. We're committed to keeping your client data, business information, and team communications safe — and being transparent about how we do it.
Last updated: 30 July 2026
Ozer is designed to comply with the UK GDPR, EU GDPR, and the Data Protection Act 2018. We act as a processor for personal data you store in your workspace (for example clients, notes, and transcripts) and as a controller for account and authentication data, product analytics and security logs, and SaaS billing records. We do not sell your data to third parties.
Ozer is operated by Oodle Designs Ltd, a UK registered company. We are registered with the UK Information Commissioner's Office (ICO) as a data controller.
Our Data Processing Agreement (UK GDPR Article 28) is in effect for business customers and is available at /dpa and as a downloadable file at /legal/ozer-dpa.md. Counsel review of the full agreement remains in progress. Questions: privacy@ozer.so.
Ozer's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See the Privacy Policy.
We are working toward SOC 2 Type II certification. Our infrastructure provider (Supabase/AWS) already holds SOC 2 Type II certification — details available at supabase.com/security.
Ozer engages the following sub-processors to deliver the service. This register matches our Privacy Policy and DPA. Integrations that are not yet shipped are excluded.
| Name | Purpose | Data (high level) | Location & transfer mechanism |
|---|---|---|---|
| Supabase / AWS | Database, auth, storage | Workspace and account data | EU West (Ireland) — no restricted transfer |
| Stripe | SaaS billing and Connect payments | Customer IDs, subscription status; card numbers stay with Stripe | US — Stripe Data Transfers Addendum (UK IDTA incorporated; EU-US Data Privacy Framework incl. UK Extension) |
| Anthropic | AI language model features | Workspace / email / transcript text prompts | US — DPA with EU SCCs and UK Addendum; EU-US Data Privacy Framework |
| Gmail, Calendar, Workspace directory | Mailbox, calendar, and directory data | US/global — Google Data Processing Terms (SCCs and UK Addendum incorporated) | |
| Microsoft | Signatures directory sync | Staff profile and photo data | US/global — Microsoft Products and Services Data Protection Addendum (SCCs and UK Addendum incorporated) |
| ZeptoMail (Zoho) | Transactional email | Recipient, subject, message body | EU data centre — Zoho DPA with standard contractual clauses |
| Bunny.net (BunnyWay d.o.o.) | Video hosting and streaming | Media files and video metadata | Slovenia (EU) — EU-headquartered; DPA in place; EU storage region |
| Voyage AI | Semantic search embeddings | Text excerpts and search queries | US — Voyage AI DPA with EU SCCs and UK ICO Addendum |
| PostHog, Inc. | Product analytics, feature flags, error/session diagnostics, and session replay | Usage events, device/browser data, user/account identifiers; UI session recordings (inputs masked; 30-day recording retention) | EU (PostHog EU Cloud) — PostHog DPA with EU SCCs and UK Addendum |
We give at least 30 days' notice of intended additions or replacements of sub-processors, via update to this Trust Centre register and, for material changes, by email to the Controller's account contact, with an opportunity to object on reasonable grounds (see the DPA).
Ozer is hosted on Supabase, which runs on Amazon Web Services (AWS). AWS maintains ISO 27001, SOC 1, SOC 2, and SOC 3 certifications. Supabase itself holds SOC 2 Type II certification.
Ozer has no physical servers. All infrastructure is managed by Supabase/AWS, which operate enterprise-grade data centres with strict physical access controls.
Access to Ozer's production database and infrastructure is restricted to authorised team members only. All access requires strong authentication. Database administration access is audited.
Data tables in Ozer enforce Row-Level Security (RLS) policies at the database level so workspace data is scoped to the correct account and cannot be accessed across workspaces via the standard application path.
We plan to conduct annual third-party penetration testing as we approach general availability. Customers with specific security assessment requirements should contact us at security@ozer.so.
All data sent to and from Ozer is encrypted in transit using HTTPS with TLS 1.2 or higher.
Data stored in Ozer is encrypted at rest using AES-256 encryption via our Supabase/AWS infrastructure.
OAuth access and refresh tokens for Google integrations (including Gmail Email Assistant and Google Calendar) are encrypted at the application layer using AES-256-GCM before storage. Microsoft 365 Signatures connection tokens are stored in our database without a separate application-layer wrap and rely on AES-256 encryption at rest. Tokens are deleted when you disconnect the integration.
Primary customer data storage is in AWS EU West (Ireland). Where a sub-processor processes personal data outside the UK/EEA, we rely on the transfer mechanisms listed in the sub-processor table above — UK International Data Transfer Addendum and/or EU Standard Contractual Clauses incorporated into each provider's data processing terms, and, where applicable, the EU-US Data Privacy Framework and its UK Extension.
Supabase maintains automated daily database backups with point-in-time recovery. Backups are stored in encrypted form across multiple availability zones.
Feature-specific retention periods are set out in the Privacy Policy. On account termination we delete customer data across our systems within 30 days, except records we must keep for legal reasons (for example, billing records retained for 6 years for tax purposes).
Ozer uses Supabase Auth for user authentication. Passwords are never stored in plain text. We support:
All Ozer API routes are authenticated. API keys are scoped and revocable. Rate limiting is applied to all public-facing endpoints.
All code changes to Ozer go through version control on GitHub, peer review, and automated testing before deployment. We follow OWASP secure development guidelines.
We regularly audit our dependencies for known vulnerabilities using automated tooling. Critical vulnerabilities are patched on a priority basis.
Ozer is deployed on infrastructure designed for high availability. Supabase/AWS provides automatic failover across multiple availability zones.
We maintain documented procedures for disaster recovery. In the event of a significant incident, we can restore service from automated backups.
Ozer has a documented Security Incident Response process. Where a personal data breach affects Controller personal data, we notify the Controller without undue delay and in any event within 72 hours of becoming aware, in line with our DPA.
Our live status page is available at status.ozer.so.
We take security disclosures seriously. If you discover a vulnerability in Ozer, please report it to us at security@ozer.so.
We ask that you:
We will acknowledge your report within 2 business days, and will keep you updated as we investigate and resolve the issue.
For any security or privacy questions, contact us at security@ozer.so.
For DPA requests or GDPR queries, contact privacy@ozer.so.