Technical transparency

Exactly where your data sits, and what we do not do

No small print. This page explains how DuzMarc is set up technically, and which choices were deliberately made and deliberately avoided.

EU servers
European backups
GDPR by design
No trackers
No advertising networks
No Google Analytics
No marketing cookies
No data transfers outside the EU
No AI training on customer data
Hosting & backups

One server, one country, one jurisdiction

DuzMarc runs on infrastructure we manage ourselves within the EU. We deliberately did not choose an American hyperscaler such as AWS, Azure or Google Cloud, so that customer data cannot fall under foreign legislation such as the US Cloud Act.

Backups are also stored within the EU and kept encrypted. No customer data is structurally transferred to countries outside the European Union.

What this means in practice

  • Every customer organisation has its own separate database.
  • Email processing also runs on servers within the EU, like the rest of DuzMarc.
  • As few external connections as possible: functionality preferably runs locally rather than through external APIs.
Privacy by design

Only what is necessary, and nothing else

DuzMarc makes no money from advertising or from reselling data. So there is no reason to track anything either.

GDPR by design

Data stays within the EU, you can export and delete it yourself, and we keep no more than we need. The basis of the GDPR is built into how DuzMarc works technically, not bolted on afterwards.

No tracking or advertising

No Google Analytics, no advertising networks, no marketing pixels on the website or in the dashboard.

No AI on customer data

Your email data is never used to train AI models, ours or anyone else's.

Only necessary cookies

Nothing but functional session cookies to keep you logged in. No consent banner needed, because there is nothing to ask consent for.

CookiePurposeRetention
session Keeps you logged in while you use the dashboard. Expires on logout or when the session ends
csrf token Protects forms against misuse from other websites. Expires on logout or when the session ends
theme preference Remembers whether you use the light or dark theme. Stored locally, never recorded on the server
Independently tested

100% on the internet standards test

internet.nl is the independent test run by the Dutch internet community (including SIDN, the government and ISOC) for modern, secure internet standards such as IPv6, DNSSEC, DMARC, DKIM, SPF, STARTTLS and DANE. Our website, the dashboard (app.duzmarc.nl) and our entire mail infrastructure all achieve the maximum score.

Internet.nl: 100% score on the website test for duzmarc.nl Website test duzmarc.nl
Internet.nl: 100% score on the website test for app.duzmarc.nl Website test app.duzmarc.nl
Internet.nl: 100% score on the email test for duzmarc.nl Email test duzmarc.nl
Internet.nl: 100% score on the email test for reports.duzmarc.nl Email test reports.duzmarc.nl

Click a badge to see the full, current test result at internet.nl.

Security

Access for your team only

Every account can switch on two-step verification, with roles for administrators and members. What team members do is recorded in an audit log, so you can always trace who changed what.

Your data stays yours

Export and delete whenever you want

You can export your own report data at any time through the settings page. If you cancel, your data is permanently deleted within a set period rather than kept indefinitely.

Found a vulnerability, or still have questions?

Do get in touch, we answer personally.

info@duzmarc.nl Go to the knowledge base