DBC1 stores the employee identity data behind every card your company issues. This page states what is in place today — where data lives, how it is encrypted, who can reach it, and what we commit to when something goes wrong. The full document library sits in our Trust Center.
Before anything else, the size of the risk. DBC1 holds a working directory of the employees you issue cards to — enough to render a card and keep it current, and no more. Your organisation decides what is held and why. We process it on your instructions, as your processor, under our data processing agreement.
The NFC chip carries a URL and nothing else. A card that is lost or picked up discloses only what is printed on its face.
A tap is a one-way exchange. The cardholder’s details go out; nothing comes back unless the recipient chooses to complete a form. We do not identify, track or profile the people who scan your employees’ cards.


Four commitments bind us now, in contract and in code. Two certifications are still in preparation, and we keep those visually separate rather than implying a certificate we do not hold.
Programme underway. The auditor and engagement are not yet confirmed. We will publish the report here when one exists.
Programme underway. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.
Primary hosting is Google Cloud, inside the European Union. The employee records behind your cards — the directory, the card content, the uploaded files — are stored and processed in the EU, and so are the backups. Two sub-processors operate outside it, and we name both rather than round the claim up. Cloudflare provides our edge network, DNS and DDoS protection, and that network is global by design. Postmark carries transactional email from a US entity. Both appear in our sub-processor register with their locations, and both are covered by the Standard Contractual Clauses.
Our hosting provider holds SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications covering the physical and platform layer beneath DBC1. Those are Google’s certifications, not ours — they cover the infrastructure we run on, not the DBC1 application.
It would be the stronger sentence, and we could probably get away with it. But a register that names a US processor and a page that claims otherwise is a contradiction you would find in two clicks, and it costs more than the sentence gains.
Encryption, access, logging, recovery and the people who hold the keys — as implemented, not as aspired to.
Four capabilities and two certifications are still in progress. We list them here rather than leaving you to discover them in a questionnaire, and we state where each one stands rather than giving a date we cannot hold.
A vendor that publishes only what it has forces you to find the rest yourself. You would find it, and it would cost us more at that point than it costs here.
Every sub-processor below is bound by a data processing agreement mirroring the protections in our DPA with you, and each appears in Annex III. We publish the names rather than the categories, because a category tells you nothing you can assess.
| Category | Purpose | Location |
|---|---|---|
| Cloud hosting and infrastructure | Application hosting, database and file storage | EU |
| Edge network and DNS | Content delivery, DNS and DDoS protection | EU / US |
| Transactional email | Card delivery and system notifications | Annex III |
| Customer support tooling | Support requests and in-product messaging | EU |
| Product analytics and monitoring | Usage analytics, error and performance monitoring | Annex III |
| CRM platforms you connect | Sales and lead management | Your choice |
| Sub-processor | What it does | Where |
|---|---|---|
| Google Cloud EMEA | Application hosting, database and file storage | EU — Frankfurt |
| Cloudflare, Inc. | Edge network, DNS and DDoS protection | EU and US — global edge network |
| Gleap GmbH | In-product support and feedback | EU — Frankfurt |
| Lettermint B.V. | Transactional email | Netherlands |
| Postmark (ActiveCampaign, LLC) | Transactional email | US |
We notify your designated data protection contact in writing at least 30 days before we add or replace any sub-processor, together with a revised annex, and you have a right to object. That notice goes to you directly rather than being published — a change that gives you a right to object should not depend on you noticing a website update. The current register is maintained in our Trust Center. Where this page and the Trust Center differ, the Trust Center is correct.
This page is the overview. Every policy, plan and agreement behind it lives in the Trust Center — most of it open, the rest released on request within one business day. Requests are reviewed, never routed to sales.
Open the Trust CenterQuestionnaires, vendor reviews and data protection requests go to a named inbox, not a contact form.
Security questionnaires, vendor reviews, requests for additional documentation.
security@dbc1.comGDPR questions, data subject access requests, and anything for the Data Protection Officer.
dpo@dbc1.comFound a vulnerability? Report it to security@dbc1.com. We confirm receipt within 2 business days, investigate and tell you what we find, keep you informed through remediation, and will not pursue legal action against good-faith research. Please give us reasonable opportunity to remediate before publishing. We do not run a paid bounty, but we credit researchers publicly on request.
Send the questionnaire. We complete it ourselves, we do not route it through sales, and we answer “not yet” where that is the honest answer.
Email the security team