Skip to main content

Data Protection and GDPR at awork

Last updated: December 2025

Max Raschke avatar
Written by Max Raschke
Updated this week

Data Protection at awork

Protecting personal data is a top priority at awork.
We process personal data strictly in accordance with the EU General Data Protection Regulation (GDPR) and based on clearly defined legal and organizational requirements.


Roles & Responsibilities

awork processes personal data within clearly defined roles:

  • awork acts as a data processor in accordance with Art. 28 GDPR for customer data.

  • Our customers remain the data controllers for the content and personal data they process within awork.

  • Data protection–related decisions and processes are formally defined, documented, and embedded within our organization.


Hosting & Data Processing

  • Hosting of the awork platform exclusively in Germany

  • Use of a dedicated Microsoft Azure Germany tenant, fully controlled by awork

  • Primary data processing within the European Union

  • In selected cases, data transfers to third countries may occur, for example in the context of support or communication services

  • In such cases, data transfers are carried out exclusively based on appropriate safeguards, in particular:

    • EU Standard Contractual Clauses (SCCs)

    • Adequacy decisions of the European Commission, where applicable


Sub-processors

  • awork uses sub-processors solely for operating the platform and for support and service purposes.

  • Sub-processors are granted access to personal data only where strictly necessary for the specific purpose.

  • Access is limited to clearly defined and selected use cases.

  • All sub-processors are carefully selected, contractually bound, and regularly reviewed.

  • A current list of all sub-processors is made available transparently.


Data Protection Governance

  • External Data Protection Officer: PROLIANCE GmbH, Munich

  • Established data protection policies and procedures

  • Regular employee training and awareness measures

  • Defined processes for handling data protection requests and data subject rights


Agreements & Documents

  • Data Processing Agreement (DPA) in accordance with Art. 28 GDPR

  • Privacy Policy

  • Sub-processor List


Transparency & Contact

For further data protection–related questions, GDPR data subject requests, or individual assessments, please feel free to contact us.

Our external Data Protection Officer supports us in all privacy and compliance matters:

PROLIANCE GmbH

Leopoldstr. 21

80802 Munich, Germany

Did this answer your question?