Top 20 – The most frequently asked questions about data protection, security & AI at awork
Data Processing & GDPR
In which role does awork process personal data?
awork acts as a data processor under Art. 28 GDPR.Where is our customer data stored?
Primarily in Germany (Microsoft Azure Germany).Are data processed or transferred outside the EU?
In selected cases, yes – exclusively based on SCCs and/or adequacy decisions.Does awork conduct Transfer Impact Assessments (TIAs)?
Yes, where required for third-country transfers.Which sub-processors does awork use – and for what purpose?
Solely for platform operation and support/service purposes.Can I object to a new sub-processor?
Yes, for justified reasons, as defined in the DPA.Does awork have a Data Protection Officer?
Yes, PROLIANCE GmbH (external DPO).Can I delete my data myself?
Yes, workspace admins can delete the workspace independently.How long is data retained after deletion?
Approximately 30 days, unless statutory obligations apply.Is awork GoBD-compliant?
awork supports GoBD-compliant usage; correct application is the customer’s responsibility.
Security & Information Security
Is awork ISO 27001 certified?
Yes, ISO/IEC 27001, covering product, operations, and internal processes.Are Microsoft data centers secure?
Yes, Azure Germany complies with ISO 27001, SOC 1/2, BSI C5, among others.Does Microsoft have access to our data?
No. The Azure tenant is fully controlled by awork.Can awork employees freely access our workspace?
No. Access is exception-based, e.g. in a support case when you give us your permission to investigate directly in your workspace. In general access is strictly limited (least privilege) and logged.Is tenant separation implemented?
Yes, strict logical tenant separation at application and database level.Is customer data encrypted?
Yes, in transit (TLS) and at rest.
Artificial Intelligence (AI)
Which AI does awork use?
Microsoft Azure OpenAI, hosted in Europe (Sweden Central).Is customer data used for AI training?
No. No AI model training with customer data.Is AI mandatory in awork?
No. Enabled by default, but fully disableable by admins.How is awork classified under the EU AI Act?
Low risk. No high-risk or prohibited AI practices.
