Third Party Index

Snapshot 21524

Document
Subprocessor list
URL
https://support.awork.com/en/articles/sub-processors-and-data-flows-3x9SMpdWaCX6
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
329468 bytes
SHA-256 (raw)
bdadb9ba89b1948a768b0f4ce964795042ebf38867e42b6b803723388a5eb2d9
SHA-256 (normalized text)
7455ba4ee41446059b28f53df7f076904f1a0fdf9aa9c2942244e01c4824c6ee

Normalized text

Scripts and page chrome removed; this is what change detection compares.

All groups
Trust Center
Sub-Processors & Data Flows
View your complete list of sub-processors handling your data, including their processing locations and security measures
Why Transparency Matters
You trust awork with your core business data – projects, tasks, teams, documents, and more. That's why we make sure it's always clear who processes your data, what they use it for, and where that processing happens.
Here's how we do it:
Service providers only get the data they need for their specific function.
We check data protection and information security before bringing anyone on board.
When a service provider processes your data as a subcontractor, we bind them contractually under Article 28 of the GDPR.
The legally binding and complete list of subcontractors is part of our current Data Processing Agreement.
Our Current Sub-Processors
General Platform Services
Provider	Purpose	Processing Location	Key Security Measures
Microsoft Azure Compute / Storage	Primary hosting and technical infrastructure for the awork platform	Germany: Frankfurt am Main (Germany West Central) and Berlin (Germany North)	DPA with Microsoft; ISO 27001, SOC 2, and BSI C5; encryption in transit and at rest; access based on least privilege principle
Microsoft Azure Front Door / CDN	Secure and fast application delivery and protection against cyberattacks	Primarily EU/Germany; if accessed from outside the EU, technical connection processing may briefly use geographically nearby infrastructure	DPA; EU data residency for stored customer data; encrypted transmission; no permanent storage of business content in CDN; technical connection data max. 30 days; adequacy decision or SCC where required
Birdie / Philo Labs	Error capture and analysis of reported product errors	Paris, France	EU processing; DPA; encrypted transmission; data minimization; automatic deletion after ticket resolution within 90 days
Twilio Segment	Technical data and context forwarding to Intercom for customer support	Primarily EU; processing in the USA within Twilio infrastructure possible	DPA; EU-US Data Privacy Framework; SCC as additional safeguard; data minimization
Intercom, Inc.	Customer support, support communication, and important system messages	USA	DPA; EU-US Data Privacy Framework; SCC as additional safeguard; ISO 27001 / SOC 2; encrypted transmission; data minimization
Optional AI Infrastructure and Model Inference
AI providers are not used simultaneously for every AI request. Which infrastructure is used depends on the model you actually selected or use for a specific function.
Provider / Service	Purpose	Processing Location	Storage, Training & Control
Microsoft Azure AI Foundry	AI features in the standard product and awork AI Add-on; specifically providing OpenAI models	EU: primarily Germany West Central, fallback resource Sweden Central	No storage of inference data on the model inference service; no training of general models; no direct access by OpenAI to prompts or model outputs; chat histories remain in awork-controlled Azure infrastructure
Google Cloud – Vertex AI	Providing selected Google/Gemini models	Belgium: europe-west1	No storage of inference data on the model inference service; no training of general models; processing in specified EU region; security filters for inputs and outputs
Amazon Web Services – Amazon Bedrock Runtime	Providing selected Anthropic models	EU: Germany, Ireland, France, Sweden, Italy, and Spain; exclusively geographically limited EU inference profiles	No storage of inference data on the model inference service; no training of general models; no access by model providers to prompts or model outputs; no global inference profile; Bedrock Guardrails
TensorX Limited	Providing selected open-source AI models	Exclusively EEA: Dublin, Ireland and Helsinki, Finland	Processing exclusively in volatile working memory on TensorX-owned hardware; no storage or logging of prompts/outputs; no training; no sharing with model providers
Important: AWS Bedrock is not used as a fallback or peak load backup for regular Azure-based AI processing.
How We Conduct Audits and Reviews
The type of review depends on a risk-based assessment of the service provider's size, role, and structure.
For large cloud and infrastructure providers, we rely especially on:
Independent audit reports and certifications like ISO 27001, SOC 2, or BSI C5,
Contractual transparency and review mechanisms in the respective Data Processing Agreements,
And additional security and data protection evidence.
For smaller or specialized service providers, we conduct our own reviews, such as document reviews, questionnaires, and assessments of technical and organizational measures.
AI infrastructure and AI model providers also go through a risk-based privacy and security review before they're approved.
Our Review and Approval Process
Before we use a new relevant service provider, we review:
Technical and organizational measures,
Processing locations and data flows,
Data processing agreements and any third-country safeguards,
Data minimization, retention, and training settings,
And integration into our information security and vendor management.
We regularly reassess the service providers we use.
Changes to Subcontractors and Objection
We notify you of planned additions or replacements of subcontractors at least six weeks before the planned change, as specified in our Data Processing Agreement.
You can object to such a change within the timeframe provided in your Data Processing Agreement for important reasons. The specific consequences of an objection depend on your current Data Processing Agreement.
Individual technical exclusion of already agreed upon and firmly integrated platform sub-processors is generally not possible, as this could impair core functions or secure service delivery.
Data Flow at a Glance
Which workspace data goes where?
For the general platform, simplified:
Central storage of workspace and business data happens in Microsoft Azure in Germany.
Support and communication data are processed via Intercom when you use support; technical data and context forwarding may happen via Segment.
Bug reports are only processed via Birdie in connection with a corresponding error report.
Optional AI processing only happens when you use the relevant AI function or model, or when it's configured to run.
Which AI data goes where?
When you make an AI request, here's what happens:
You start an AI function or agent, or a previously configured trigger/workflow starts an agent run.
The awork AI Runtime assembles the prompt and context needed for the operation.
The Model Router sends the request to exactly the AI system configured for the model you're using.
If a tool or connected system is needed, the access goes through the appropriate tool and permission checks first.
The result is returned to awork and shown to you or used for a previously authorized action.
Chat histories and AI content that awork stores for display in the product stay in awork-controlled Azure infrastructure. The model inference services we use don't store regular prompts and outputs for this purpose and don't use them to train general models.
If you connect external systems or MCP servers yourself, the data processing rules, permissions, and processing locations of those third-party providers also apply.
Permission-Based Data Access and Execution
AI functions can only access data and content that the triggering user already has permission to access. Agents can also execute actions within this permission scope. Your existing workspace, project, and object permissions apply unchanged; using AI doesn't create any additional access or execution rights. We transparently show which agent executed which action on behalf of which user.
Control by Administrators
You can use the awork platform without AI data processing. Standard product AI features can be disabled by administrators; the expanded awork AI Add-on requires a separate purchase.
Workspace administrators can also disable the AI models available for regular use. Some technical or foundational AI functions may be based on fixed preset models that aren't part of the regular model selection.
Binding Contractual Basis
The tables on this page provide transparent and understandable explanation of our setup. You'll find the complete and legally binding description of subcontractors, processing locations, and security measures in your current Data Processing Agreement.
Data Protection and GDPR at aworkPreviousawork and AINext
Last updated September 1, 2026Powered by happysupport.ai
RSSFor developers
© 2026 HappySupport. All rights reserved.
Privacy PolicyImprint
HappySearch can make mistakes.
Sources
No articles yet
Search to see source articles