Sub-Processors & Data Flows

Why Transparency Matters

Our customers trust us with their most valuable data - projects, tasks, teams, and ideas.

That's why it's obvious to us: you should always know who processes your data and where it happens.

All sub-processors we use are carefully selected by us, contractually obligated, and regularly reviewed.

We have Data Processing Agreements (DPAs) in place with all service providers in accordance with Article 28 of the GDPR.

Our Current Sub-Processors

ProviderPurposeProcessing LocationSecurity Measures
Microsoft Azure (Germany)Hosting & infrastructure for aworkGermany (Frankfurt & Berlin)DPA with Microsoft, ISO 27001 / SOC 2 / BSI C5, encryption at rest & in transit
Microsoft Azure Front Door / CDNFast & secure delivery of the application (Content Delivery Network)EU; technically necessary short-term worldwide when accessed outside EUData residency guarantee, SCC/DPF protection, no content storage
Microsoft Azure OpenAI (EU)Optional AI feature (e.g. text & automation suggestions)EU (Sweden - Sweden Central)No data transfer outside EU, no training on customer data, DPA with Microsoft
Twilio SegmentTechnical data forwarding for support and event analysisEU / USADPA + SCC + DPF certification, data minimization, encrypted transfer
Intercom Inc.In-app support, help center, and system notificationsUSADPA + SCC + DPF (certification), ISO 27001 / SOC 2, TLS encryption
Birdie (Philo Labs, France)Bug reporting tool for error tracking in the productFrance (EU)DPA with exclusive EU processing, no third-country transfer, automatic deletion after 90 days

How We Conduct Audits and Reviews

The type of review depends on the size and structure of each sub-processor:

  • For global cloud providers (e.g. Microsoft, Twilio, Intercom), traditional on-site audits are not planned. Instead, we rely on:
    • regularly published audit reports (e.g. SOC 2, ISO 27001, BSI C5),
    • contractually guaranteed transparency and review mechanisms in the DPAs,
    • and certifications by independent third parties, which are renewed annually.
  • For smaller or European sub-processors (e.g. Birdie), we conduct our own reviews - such as document reviews, questionnaires, and security evidence in accordance with Article 28(3)(h) of the GDPR.

This combination enables realistic, risk-based audits without compromising security or operations.

Our Review and Approval Process

Before we use a new sub-processor, we conduct a Privacy & Security Check:

  • Assessment of technical and organizational measures,
  • review of legal bases (DPA, SCC, or DPF),
  • approval by COO and CTO,
  • annual review and audit.

Our list of sub-processors is updated regularly.

Customers are informed of changes at least 6 weeks in advance and can object in accordance with Article 28(2) of the GDPR.

Why Individual Objection to Existing Sub-Processors Isn't Possible

We know this topic is sensitive, so we want to explain transparently why individual exclusion of certain sub-processors isn't possible.

Some service providers (e.g. Microsoft Azure or Intercom) are technically deeply integrated into our infrastructure.

Excluding them would impair central functions or the security of the entire system.

The GDPR deliberately provides that customers are informed about new sub-processors and can object within a specified period.

For already existing sub-processors, this right does not apply, because they are part of the agreed scope of services.

When we do use new sub-processors, we do so exclusively to provide or improve specific functionalities.

These partners only process strictly limited data that is absolutely necessary for that function, such as technical metadata or communication information.

Instead of an individual right to object, we provide our customers with a special termination right if they fundamentally disagree with the addition of a new sub-processor.

This way, the decision stays in your hands at all times, without compromising the technical integrity of awork.

We ensure that all sub-processors we use, whether new or established, meet the same high security and data protection standards.

We check this regularly as part of our Information Security Management System (ISMS).

Data Flow at a Glance

  • All customer data is stored in Germany (Azure Germany).
  • Support and communication data flows, when you use chat or support, through Intercom (USA, but with EU adequacy decision)
  • Technical event data is sometimes forwarded via Twilio Segment to Intercom.
  • Bug reports are only transmitted via Birdie (France) on request.
  • The AI feature (Azure OpenAI) is optional, operates exclusively within the EU, and uses no data for training.
Last updated HappySupportPowered by happysupport.ai
© 2026 HappySupport. All rights reserved.