Skip to main content

FAQ

Last updated: December 2025

Max Raschke avatar
Written by Max Raschke
Updated over a month ago

Top 20 – The most frequently asked questions about data protection, security & AI at awork

Data Processing & GDPR

  1. In which role does awork process personal data?
    awork acts as a data processor under Art. 28 GDPR.

  2. Where is our customer data stored?
    Primarily in Germany (Microsoft Azure Germany).

  3. Are data processed or transferred outside the EU?
    In selected cases, yes – exclusively based on SCCs and/or adequacy decisions.

  4. Does awork conduct Transfer Impact Assessments (TIAs)?
    Yes, where required for third-country transfers.

  5. Which sub-processors does awork use – and for what purpose?
    awork uses selected sub-processors for platform operation and clearly defined support and service activities. The complete and current list of all sub-processors, including purpose and location, is available here.

  6. Can I object to a new sub-processor?
    Yes, for justified reasons, as defined in the DPA.

  7. Does awork have a Data Protection Officer?
    Yes, PROLIANCE GmbH (external DPO).

  8. Can I delete my data myself?
    Yes, workspace admins can delete the workspace independently.

  9. How long is data retained after deletion?
    Approximately 30 days, unless statutory obligations apply.

  10. Is awork GoBD-compliant?
    awork supports GoBD-compliant usage; correct application is the customer’s responsibility.


Security & Information Security

  1. Is awork ISO 27001 certified?
    Yes, ISO/IEC 27001, covering product, operations, and internal processes.

  2. Are Microsoft data centers secure?
    Yes, Azure Germany complies with ISO 27001, SOC 1/2, BSI C5, among others.

  3. Does Microsoft have access to our data?
    No. The Azure tenant is fully controlled by awork.

  4. Can awork employees freely access our workspace?
    No. Access is exception-based, e.g. in a support case when you give us your permission to investigate directly in your workspace. In general access is strictly limited (least privilege) and logged.

  5. Is tenant separation implemented?
    Yes, strict logical tenant separation at application and database level.

  6. Is customer data encrypted?
    Yes, in transit (TLS) and at rest.

  7. How does awork protect customer data against data loss and enable recovery?

    awork protects customer data through automated, regular backups with defined restore processes and recovery testing.


Artificial Intelligence (AI)

  1. Which AI does awork use?
    Microsoft Azure OpenAI, hosted in Europe (Sweden Central).

  2. Is customer data used for AI training?
    No. No AI model training with customer data.

  3. Is AI mandatory in awork?
    No. Enabled by default, but fully disableable by admins.

  4. How is awork classified under the EU AI Act?
    Low risk. No high-risk or prohibited AI practices.

Did this answer your question?