Skip to main content

Sub-Processors & Data Flows

View your complete list of sub-processors handling your data, including their processing locations and security measures

Why Transparency Matters

You trust awork with your core business data – projects, tasks, teams, documents, and more. That's why we make sure it's always clear who processes your data, what they use it for, and where that processing happens.

Here's how we do it:

  • Service providers only get the data they need for their specific function.

  • We check data protection and information security before bringing anyone on board.

  • When a service provider processes your data as a subcontractor, we bind them contractually under Article 28 of the GDPR.

  • The legally binding and complete list of subcontractors is part of our current Data Processing Agreement.

Our Current Sub-Processors

General Platform Services

ProviderPurposeProcessing LocationKey Security Measures
Microsoft Azure Compute / StoragePrimary hosting and technical infrastructure for the awork platformGermany: Frankfurt am Main (Germany West Central) and Berlin (Germany North)DPA with Microsoft; ISO 27001, SOC 2, and BSI C5; encryption in transit and at rest; access based on least privilege principle
Microsoft Azure Front Door / CDNSecure and fast application delivery and protection against cyberattacksPrimarily EU/Germany; if accessed from outside the EU, technical connection processing may briefly use geographically nearby infrastructureDPA; EU data residency for stored customer data; encrypted transmission; no permanent storage of business content in CDN; technical connection data max. 30 days; adequacy decision or SCC where required
Birdie / Philo LabsError capture and analysis of reported product errorsParis, FranceEU processing; DPA; encrypted transmission; data minimization; automatic deletion after ticket resolution within 90 days
Twilio SegmentTechnical data and context forwarding to Intercom for customer supportPrimarily EU; processing in the USA within Twilio infrastructure possibleDPA; EU-US Data Privacy Framework; SCC as additional safeguard; data minimization
Intercom, Inc.Customer support, support communication, and important system messagesUSADPA; EU-US Data Privacy Framework; SCC as additional safeguard; ISO 27001 / SOC 2; encrypted transmission; data minimization

Optional AI Infrastructure and Model Inference

AI providers are not used simultaneously for every AI request. Which infrastructure is used depends on the model you actually selected or use for a specific function.

Provider / ServicePurposeProcessing LocationStorage, Training & Control
Microsoft Azure AI FoundryAI features in the standard product and awork AI Add-on; specifically providing OpenAI modelsEU: primarily Germany West Central, fallback resource Sweden CentralNo storage of inference data on the model inference service; no training of general models; no direct access by OpenAI to prompts or model outputs; chat histories remain in awork-controlled Azure infrastructure
Google Cloud – Vertex AIProviding selected Google/Gemini modelsBelgium: europe-west1No storage of inference data on the model inference service; no training of general models; processing in specified EU region; security filters for inputs and outputs
Amazon Web Services – Amazon Bedrock RuntimeProviding selected Anthropic modelsEU: Germany, Ireland, France, Sweden, Italy, and Spain; exclusively geographically limited EU inference profilesNo storage of inference data on the model inference service; no training of general models; no access by model providers to prompts or model outputs; no global inference profile; Bedrock Guardrails
TensorX LimitedProviding selected open-source AI modelsExclusively EEA: Dublin, Ireland and Helsinki, FinlandProcessing exclusively in volatile working memory on TensorX-owned hardware; no storage or logging of prompts/outputs; no training; no sharing with model providers

Important: AWS Bedrock is not used as a fallback or peak load backup for regular Azure-based AI processing.

How We Conduct Audits and Reviews

The type of review depends on a risk-based assessment of the service provider's size, role, and structure.

For large cloud and infrastructure providers, we rely especially on:

  • Independent audit reports and certifications like ISO 27001, SOC 2, or BSI C5,

  • Contractual transparency and review mechanisms in the respective Data Processing Agreements,

  • And additional security and data protection evidence.

For smaller or specialized service providers, we conduct our own reviews, such as document reviews, questionnaires, and assessments of technical and organizational measures.

AI infrastructure and AI model providers also go through a risk-based privacy and security review before they're approved.

Our Review and Approval Process

Before we use a new relevant service provider, we review:

  • Technical and organizational measures,

  • Processing locations and data flows,

  • Data processing agreements and any third-country safeguards,

  • Data minimization, retention, and training settings,

  • And integration into our information security and vendor management.

We regularly reassess the service providers we use.

Changes to Subcontractors and Objection

We notify you of planned additions or replacements of subcontractors at least six weeks before the planned change, as specified in our Data Processing Agreement.

You can object to such a change within the timeframe provided in your Data Processing Agreement for important reasons. The specific consequences of an objection depend on your current Data Processing Agreement.

Individual technical exclusion of already agreed upon and firmly integrated platform sub-processors is generally not possible, as this could impair core functions or secure service delivery.

Data Flow at a Glance

Which workspace data goes where?

For the general platform, simplified:

  • Central storage of workspace and business data happens in Microsoft Azure in Germany.

  • Support and communication data are processed via Intercom when you use support; technical data and context forwarding may happen via Segment.

  • Bug reports are only processed via Birdie in connection with a corresponding error report.

  • Optional AI processing only happens when you use the relevant AI function or model, or when it's configured to run.

Which AI data goes where?

When you make an AI request, here's what happens:

  1. You start an AI function or agent, or a previously configured trigger/workflow starts an agent run.

  2. The awork AI Runtime assembles the prompt and context needed for the operation.

  3. The Model Router sends the request to exactly the AI system configured for the model you're using.

  4. If a tool or connected system is needed, the access goes through the appropriate tool and permission checks first.

  5. The result is returned to awork and shown to you or used for a previously authorized action.

Chat histories and AI content that awork stores for display in the product stay in awork-controlled Azure infrastructure. The model inference services we use don't store regular prompts and outputs for this purpose and don't use them to train general models.

If you connect external systems or MCP servers yourself, the data processing rules, permissions, and processing locations of those third-party providers also apply.

Permission-Based Data Access and Execution

AI functions can only access data and content that the triggering user already has permission to access. Agents can also execute actions within this permission scope. Your existing workspace, project, and object permissions apply unchanged; using AI doesn't create any additional access or execution rights. We transparently show which agent executed which action on behalf of which user.

Control by Administrators

You can use the awork platform without AI data processing. Standard product AI features can be disabled by administrators; the expanded awork AI Add-on requires a separate purchase.

Workspace administrators can also disable the AI models available for regular use. Some technical or foundational AI functions may be based on fixed preset models that aren't part of the regular model selection.

Binding Contractual Basis

The tables on this page provide transparent and understandable explanation of our setup. You'll find the complete and legally binding description of subcontractors, processing locations, and security measures in your current Data Processing Agreement.

Last updated HappySupportPowered by happysupport.ai
© 2026 HappySupport. All rights reserved.
HappySearch can make mistakes.

Sources

No articles yet

Search to see source articles