Scope

What we hold about your people.

Before anything else, the size of the risk. DBC1 holds a working directory of the employees you issue cards to — enough to render a card and keep it current, and no more. Your organisation decides what is held and why. We process it on your instructions, as your processor, under our data processing agreement.

What we hold
Identity
Name, job title, department and employer.
Work contact
Work email, work phone and the professional links you choose to publish on the card.
Media
Profile photo, company logo and any file uploaded to a card.
What we never hold
No personal life
No home address, no personal phone number, no date of birth, no national identifier.
No employment records
No salary, no performance data, no HR case files. DBC1 is not an HR system and does not try to be one.
No device access
We install nothing on employee devices and read nothing from them.
Nothing on the chip

The NFC chip carries a URL and nothing else. A card that is lost or picked up discloses only what is printed on its face.

The person tapping stays anonymous

A tap is a one-way exchange. The cardholder’s details go out; nothing comes back unless the recipient chooses to complete a form. We do not identify, track or profile the people who scan your employees’ cards.

Trusted by
Runs on
Google Cloud
Application hosting, database and file storage — three EU regions
Cloudflare
Edge network, DNS and DDoS protection
Compliance

What is in force today.

Four commitments bind us now, in contract and in code. Two certifications are still in preparation, and we keep those visually separate rather than implying a certificate we do not hold.

GDPR
EU General Data Protection Regulation
Compliant
DPA + SCCs
Signed before any production data is processed
Available
EU only
Three EU regions. No non-EU option, on request or otherwise
Data residency
AES-256
At rest, with TLS 1.3 in transit and keys in Cloud KMS
Encryption
SOC 2

Programme underway. The auditor and engagement are not yet confirmed. We will publish the report here when one exists.

ISO 27001

Programme underway. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.

Data residency

Where your data lives.

Primary hosting is Google Cloud, inside the European Union. The employee records behind your cards — the directory, the card content, the uploaded files — are stored and processed in the EU, and so are the backups. Two sub-processors operate outside it, and we name both rather than round the claim up. Cloudflare provides our edge network, DNS and DDoS protection, and that network is global by design. Postmark carries transactional email from a US entity. Both appear in our sub-processor register with their locations, and both are covered by the Standard Contractual Clauses.

europe-west1
Belgium
europe-central2
Poland
europe-west3
Germany
Inherited from Google Cloud

Our hosting provider holds SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications covering the physical and platform layer beneath DBC1. Those are Google’s certifications, not ours — they cover the infrastructure we run on, not the DBC1 application.

Why we don’t claim EU-only

It would be the stronger sentence, and we could probably get away with it. But a register that names a US processor and a page that claims otherwise is a contradiction you would find in two clicks, and it costs more than the sentence gains.

Controls

What protects the data today.

Encryption, access, logging, recovery and the people who hold the keys — as implemented, not as aspired to.

Encryption and data
Encryption in transit
TLS 1.3 with modern cipher suites on all public web and application endpoints, with HTTP redirected to HTTPS. Internal service-to-service traffic is encrypted.
Encryption at rest
AES-256, with keys managed by Google Cloud. Database backups, file storage and analytics stores are all encrypted under the same scheme.
Access and identity
Role-based access
Every administrative action is gated by role, with least-privilege defaults. Custom roles are available on the Enterprise tier. A full role-permission matrix is released to reviewers under NDA.
Single sign-on
SAML 2.0 against Okta or any SAML-compliant identity provider, so access follows the directory you already run.
Provisioning
SCIM 2.0 for automated user and group provisioning and deprovisioning.
Multi-factor authentication
Enforced for all administrators. Organisations can configure their own end-user MFA policy.
Session handling
Administrative sessions expire after eight hours of inactivity.
Offboarding
When someone leaves, their account and their cards are disabled immediately.
Visibility
Monitoring and logging
Application, infrastructure and security logs are centralised in Google Cloud Logging. Production systems are monitored around the clock, with an on-call rotation covering incidents at any hour.
Audit trail
Every administrative action is logged with actor, action, target and timestamp.
Export and retention
Audit logs are retained for 12 months and can be exported at any time, without raising a request with us.
SIEM forwarding
Log forwarding into your own SIEM is available on the Enterprise tier.
Resilience
Backups
Daily backups retained for 30 days. Restore procedures are tested quarterly, not assumed.
Replication
Customer data is replicated in real time across availability zones, with production deployed across multiple zones.
Recovery
Recovery time objective of four hours and a recovery point objective of fifteen minutes.
Availability
Target service availability is 99.9% monthly.
People and process
Vulnerability management
Dependencies and container images are continuously scanned. Critical patches are applied within seven days and high-severity patches within 30. An independent penetration test is conducted annually.
Breach notification
On a confirmed personal data breach affecting a customer, we notify the designated contact without undue delay and no later than 72 hours after becoming aware of it.
Personnel
Background checks and signed confidentiality agreements before anyone receives production access. Security awareness training annually.
Access reviews
Access permissions, production access and infrastructure are reviewed quarterly, with approvals retained.
Incident response
A documented plan with named roles, tested annually. You receive a full post-incident report, not a status update.
Pending

What is not in place yet.

Four capabilities and two certifications are still in progress. We list them here rather than leaving you to discover them in a questionnaire, and we state where each one stands rather than giving a date we cannot hold.

Capabilities
TOTP and WebAuthn
Multi-factor authentication is enforced for every administrator today, through your identity provider. Enrolment of TOTP or hardware second factors inside DBC1 is not yet available.
Re-authentication
Sensitive administrative actions do not yet prompt for a fresh authentication challenge.
Session revocation
Administrators cannot yet terminate another user’s active sessions from the console. Sessions expire after eight hours of inactivity.
Public status page
No public status page today. High-severity incidents are reported directly to your named contact within four hours.
Certifications
SOC 2
Programme underway. No report has been issued, and the auditor and engagement are not yet confirmed. We will publish the report here when one exists.
ISO 27001
Programme underway. No certificate has been issued, and the certification body is not yet confirmed. Until then we describe our controls as aligned with Annex A and represent nothing further.
Why this section exists

A vendor that publishes only what it has forces you to find the rest yourself. You would find it, and it would cost us more at that point than it costs here.

Sub-processors

Named, not categorised.

Every sub-processor below is bound by a data processing agreement mirroring the protections in our DPA with you, and each appears in Annex III. We publish the names rather than the categories, because a category tells you nothing you can assess.

CategoryPurposeLocation
Cloud hosting and infrastructureApplication hosting, database and file storageEU
Edge network and DNSContent delivery, DNS and DDoS protectionEU / US
Transactional emailCard delivery and system notificationsAnnex III
Customer support toolingSupport requests and in-product messagingEU
Product analytics and monitoringUsage analytics, error and performance monitoringAnnex III
CRM platforms you connectSales and lead managementYour choice
Sub-processorWhat it doesWhere
Google Cloud EMEAApplication hosting, database and file storageEU — Frankfurt
Cloudflare, Inc.Edge network, DNS and DDoS protectionEU and US — global edge network
Gleap GmbHIn-product support and feedbackEU — Frankfurt
Lettermint B.V.Transactional emailNetherlands
Postmark (ActiveCampaign, LLC)Transactional emailUS
Notification of changes

We notify your designated data protection contact in writing at least 30 days before we add or replace any sub-processor, together with a revised annex, and you have a right to object. That notice goes to you directly rather than being published — a change that gives you a right to object should not depend on you noticing a website update. The current register is maintained in our Trust Center. Where this page and the Trust Center differ, the Trust Center is correct.

Trust Center

The evidence, not just the summary.

This page is the overview. Every policy, plan and agreement behind it lives in the Trust Center — most of it open, the rest released on request within one business day. Requests are reviewed, never routed to sales.

Open the Trust Center
Security Whitepaper
Information Security Policy
Access Control Policy
Cryptography Policy
Secure Development Policy
Incident Response Plan
Business Continuity and DR Plan
Physical Security Policy
Third-Party Management Policy
Data Management Policy
Data Processing Agreement
Service Level Agreement
Cardholder Privacy Notice
Master Services Agreement
Exhibit C — Feature Terms
Contact

Reaching the security team.

Questionnaires, vendor reviews and data protection requests go to a named inbox, not a contact form.

Security inquiries

Security questionnaires, vendor reviews, requests for additional documentation.

security@dbc1.com
Data protection inquiries

GDPR questions, data subject access requests, and anything for the Data Protection Officer.

dpo@dbc1.com
Responsible disclosure

Found a vulnerability? Report it to security@dbc1.com. We confirm receipt within 2 business days, investigate and tell you what we find, keep you informed through remediation, and will not pursue legal action against good-faith research. Please give us reasonable opportunity to remediate before publishing. We do not run a paid bounty, but we credit researchers publicly on request.

Still have questions your review board needs answered?

Send the questionnaire. We complete it ourselves, we do not route it through sales, and we answer “not yet” where that is the honest answer.

Email the security team