Exactly where your data sits, and what we do not do
No small print. This page explains how DuzMarc is set up technically, and which choices were deliberately made and deliberately avoided.
One server, one country, one jurisdiction
DuzMarc runs on infrastructure we manage ourselves within the EU. We deliberately did not choose an American hyperscaler such as AWS, Azure or Google Cloud, so that customer data cannot fall under foreign legislation such as the US Cloud Act.
Backups are also stored within the EU and kept encrypted. No customer data is structurally transferred to countries outside the European Union.
What this means in practice
- Every customer organisation has its own separate database.
- Email processing also runs on servers within the EU, like the rest of DuzMarc.
- As few external connections as possible: functionality preferably runs locally rather than through external APIs.
Only what is necessary, and nothing else
DuzMarc makes no money from advertising or from reselling data. So there is no reason to track anything either.
GDPR by design
Data stays within the EU, you can export and delete it yourself, and we keep no more than we need. The basis of the GDPR is built into how DuzMarc works technically, not bolted on afterwards.
No tracking or advertising
No Google Analytics, no advertising networks, no marketing pixels on the website or in the dashboard.
No AI on customer data
Your email data is never used to train AI models, ours or anyone else's.
Only necessary cookies
Nothing but functional session cookies to keep you logged in. No consent banner needed, because there is nothing to ask consent for.
| Cookie | Purpose | Retention |
|---|---|---|
| session | Keeps you logged in while you use the dashboard. | Expires on logout or when the session ends |
| csrf token | Protects forms against misuse from other websites. | Expires on logout or when the session ends |
| theme preference | Remembers whether you use the light or dark theme. | Stored locally, never recorded on the server |
100% on the internet standards test
internet.nl is the independent test run by the Dutch internet community (including SIDN, the government and ISOC) for modern, secure internet standards such as IPv6, DNSSEC, DMARC, DKIM, SPF, STARTTLS and DANE. Our website, the dashboard (app.duzmarc.nl) and our entire mail infrastructure all achieve the maximum score.
Click a badge to see the full, current test result at internet.nl.
Access for your team only
Every account can switch on two-step verification, with roles for administrators and members. What team members do is recorded in an audit log, so you can always trace who changed what.
Export and delete whenever you want
You can export your own report data at any time through the settings page. If you cancel, your data is permanently deleted within a set period rather than kept indefinitely.
Found a vulnerability, or still have questions?
Do get in touch, we answer personally.