DBC1 stores the employee identity data behind every card your company issues. This page states what is in place today — where data lives, how it is encrypted, who can reach it, and what we commit to when something goes wrong. The full document library sits in our Trust Center.



Four commitments bind us now, in contract and in code. Two certifications are still in preparation, and we keep those visually separate rather than implying a certificate we do not hold.
Programme underway. The auditor and engagement are not yet confirmed. We will publish the report here when one exists.
Programme underway. The certification body is not yet confirmed. Until a certificate is issued we describe our controls as aligned with Annex A and represent nothing further.
Primary hosting is Google Cloud, across three EU regions. Customer data is stored and processed inside the European Union. We do not offer non-EU regions — on request or otherwise.
Our hosting provider holds SOC 1, SOC 2, ISO 27001, ISO 27017, ISO 27018 and PCI DSS certifications covering the physical and platform layer beneath DBC1. Those are Google’s certifications, not ours — they cover the infrastructure we run on, not the DBC1 application.
Encryption, key management, access control and recovery — as implemented, not as aspired to.
Until these ship, joiner, mover and leaver events are actioned by our team from the employee record you nominate as source of truth, and high-severity incidents are reported directly to your named contact.
Every sub-processor is bound by a data processing agreement mirroring the protections in our DPA with you. Named identities, entity locations and transfer mechanisms are listed in Annex III and published in the Trust Center.
| Category | Purpose | Location |
|---|---|---|
| Cloud hosting and infrastructure | Application hosting, database and file storage | EU |
| Edge network and DNS | Content delivery, DNS and DDoS protection | EU / US |
| Transactional email | Card delivery and system notifications | Annex III |
| Customer support tooling | Support requests and in-product messaging | EU |
| Product analytics and monitoring | Usage analytics, error and performance monitoring | Annex III |
| CRM platforms you connect | Sales and lead management | Your choice |
New sub-processors are notified in writing to your designated data protection contact at least 30 days before we add or replace one, together with a revised annex, and you have a right to object. That notice goes to you directly rather than being published — a change that gives you a right to object should not depend on you noticing a website update.
This page is the overview. Every policy, plan and agreement behind it lives in the Trust Center — most of it open, the rest released on request within one business day. Requests are reviewed, never routed to sales.
Open the Trust CenterQuestionnaires, vendor reviews and data protection requests go to a named inbox, not a contact form.
Security questionnaires, vendor reviews, requests for additional documentation.
security@dbc1.comGDPR questions, data subject access requests, and anything for the Data Protection Officer.
dpo@dbc1.comFound a vulnerability? Report it to security@dbc1.com. We confirm receipt within 2 business days, investigate and tell you what we find, keep you informed through remediation, and will not pursue legal action against good-faith research. Please give us reasonable opportunity to remediate before publishing. We do not run a paid bounty, but we credit researchers publicly on request.
Send the questionnaire. We complete it ourselves, we do not route it through sales, and we answer “not yet” where that is the honest answer.
Email the security team