Dazr Identity Developer Terms
Version 2026-10-03 · Last updated 3 October 2026 · Apply to every organisation that lets people sign in with Dazr Identity.
1. About these terms
These terms are an agreement between Dazr, Viale Cesare Poggi 1, 15061 Arquata Scrivia (AL), Italy, VAT IT 02801250065 ("Dazr", "we"), and the organisation that registers an app for Sign in with Dazr Identity ("you"). Sign in with Dazr Identity is the OpenID Connect service at identity.dazr.eu that lets people sign in to your website or app with their Dazr Identity account ("the Service").
The person who accepts these terms in the developer console confirms that they may bind the organisation. We record the version, the date and who accepted. Our general Terms of service apply where these terms say nothing.
2. Who can register an app
- An app always belongs to an organisation in Dazr Identity. Only the owners and admins of that organisation can register and manage it.
- The details you give (app name, homepage, privacy policy, support email, purpose, redirect addresses) must be accurate and kept up to date. People see them on the consent screen.
- A new app is in testing: only members of your organisation can sign in, and the consent screen says so. To let anyone sign in, your organisation must be verified and the app must pass our review. We may refuse an app that is misleading, asks for more data than its purpose needs, or has no adequate privacy policy.
3. Who is responsible for the data
Dazr is the controller for the Dazr Identity account itself. When a person approves your app on the consent screen, Dazr discloses the approved data to you at that person's request. From the moment you receive it, you are an independent controller for that data within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR).
You are not our processor and we are not yours, so no data processing agreement under Article 28 GDPR is needed between us. We are not joint controllers either: each of us decides its own purposes and means and is responsible for its own compliance.
4. Your obligations as a controller
- Have a lawful basis under Article 6 GDPR for everything you do with the data.
- Publish your own privacy notice that meets Article 13 GDPR, link it in the app settings and keep that link working. People see it on the consent screen.
- Ask only for the scopes your app needs. The purpose line you enter must truthfully describe why you need the data.
- Answer requests from people about their data, including access and deletion requests, through the support email in your app settings, within the time limits the GDPR sets.
- When you transfer the data outside the European Economic Area, do so only under Chapter V GDPR.
5. What you may and may not do with the data
Use the data only to sign people in, to set up and run their account with you, and for the purpose shown on the consent screen. You must not:
- Sell, rent or give the data to anyone else, or use or share it for advertising.
- Use it for profiling or for decisions that have nothing to do with the purpose shown on the consent screen.
- Combine it with other data to track people across websites or services.
- Try to re-identify people from their pairwise ID, or to link pairwise IDs from different organisations.
- Keep using the data or tokens after a person removed your access, beyond what the law requires you to keep.
6. Pairwise IDs
Every organisation receives a different random ID (the sub claim) for the same person, so two unrelated organisations cannot correlate their users. Your apps share one ID per person. Use it only as the key of the account in your systems.
7. Organisation details
With the organisations scope you receive only the organisations a person ticks on the consent screen, with their role. The verified status means that Dazr checked an official document for that organisation at one point in time. It is not a guarantee about the organisation or about the person's authority to act for it.
8. Security
- Keep client secrets confidential and on your servers only, never in a browser, a mobile app or a code repository. Rotate a secret in the console as soon as you suspect it leaked.
- Use PKCE, check
stateandnonce, and verify every ID token: signature, issuer, audience and expiry. - Register only exact redirect addresses that you control.
- Protect the data and tokens you receive with appropriate technical and organisational measures (Article 32 GDPR), and keep tokens no longer than needed.
9. Personal data breaches
If a breach affects data you received through the Service, or your client secrets or tokens, tell us at security@dazr.eu without undue delay and in any case within 72 hours of becoming aware of it. That does not replace your own duty to notify the supervisory authority and the people concerned under Articles 33 and 34 GDPR.
10. People stay in control
People can see every app they connected and remove access at any time in Dazr Identity. When they do, your tokens stop working at once. Data you already received stays your responsibility: if the person asks you to delete it, you must do so unless the law requires you to keep it.
11. The Sign in with Dazr Identity button
- Use the button and wording from the developer docs: "Sign in with Dazr Identity". You may adapt the size, not the logo, colours or wording.
- Do not suggest that Dazr endorses, certifies or partners with your app, and do not use "Dazr" in your app's name, logo or domain.
- Do not imitate the Dazr Identity sign-in or consent screens in your own app.
12. Review, suspension and ending
We may review an app at any time. We may suspend or remove an app, or revoke its tokens, if it breaks these terms, misleads people, puts their data or our service at risk, or if the law requires it. Where we can, we tell the organisation's admins first and give them a chance to fix the problem; in urgent cases we act first and explain afterwards.
You can delete an app in the console at any time. Deleting it revokes all its tokens and consents. Your obligations for data you already received continue after the app or these terms end.
13. Fees
The Service is free. If we ever introduce fees, we will tell you at least 60 days in advance and charge nothing without your agreement.
14. Availability and changes to the Service
We do our best to keep the Service available, but we do not promise uninterrupted availability. We announce changes that need work on your side, such as new endpoints or the end of a feature, in advance, except where an urgent security fix cannot wait.
15. Warranty and liability
The Service is provided "as is". To the maximum extent permitted by law, Dazr is not liable for indirect, incidental, special or consequential damages, or for lost profits, arising from the Service. You are responsible towards people and authorities for your own processing of the data you receive. Nothing in these terms limits liability for fraud, gross negligence, wilful misconduct, or anything that cannot be limited under applicable law.
16. Changes to these terms
We may update these terms. We email the admins of every organisation with an app at least 30 days before a material change takes effect. If you keep using the Service after that date, the new version applies; if you do not agree, you can delete your apps.
17. Governing law and venue
These terms are governed by Italian law. Disputes are heard in the courts of Italy.
18. Contact
- Questions about these terms and app reviews: hello@dazr.eu
- Security and breach reports: security@dazr.eu
- Privacy / GDPR: privacy@dazr.eu