Snapshot 21524
Normalized text
Scripts and page chrome removed; this is what change detection compares.
All groups Trust Center Sub-Processors & Data Flows View your complete list of sub-processors handling your data, including their processing locations and security measures Why Transparency Matters You trust awork with your core business data – projects, tasks, teams, documents, and more. That's why we make sure it's always clear who processes your data, what they use it for, and where that processing happens. Here's how we do it: Service providers only get the data they need for their specific function. We check data protection and information security before bringing anyone on board. When a service provider processes your data as a subcontractor, we bind them contractually under Article 28 of the GDPR. The legally binding and complete list of subcontractors is part of our current Data Processing Agreement. Our Current Sub-Processors General Platform Services Provider Purpose Processing Location Key Security Measures Microsoft Azure Compute / Storage Primary hosting and technical infrastructure for the awork platform Germany: Frankfurt am Main (Germany West Central) and Berlin (Germany North) DPA with Microsoft; ISO 27001, SOC 2, and BSI C5; encryption in transit and at rest; access based on least privilege principle Microsoft Azure Front Door / CDN Secure and fast application delivery and protection against cyberattacks Primarily EU/Germany; if accessed from outside the EU, technical connection processing may briefly use geographically nearby infrastructure DPA; EU data residency for stored customer data; encrypted transmission; no permanent storage of business content in CDN; technical connection data max. 30 days; adequacy decision or SCC where required Birdie / Philo Labs Error capture and analysis of reported product errors Paris, France EU processing; DPA; encrypted transmission; data minimization; automatic deletion after ticket resolution within 90 days Twilio Segment Technical data and context forwarding to Intercom for customer support Primarily EU; processing in the USA within Twilio infrastructure possible DPA; EU-US Data Privacy Framework; SCC as additional safeguard; data minimization Intercom, Inc. Customer support, support communication, and important system messages USA DPA; EU-US Data Privacy Framework; SCC as additional safeguard; ISO 27001 / SOC 2; encrypted transmission; data minimization Optional AI Infrastructure and Model Inference AI providers are not used simultaneously for every AI request. Which infrastructure is used depends on the model you actually selected or use for a specific function. Provider / Service Purpose Processing Location Storage, Training & Control Microsoft Azure AI Foundry AI features in the standard product and awork AI Add-on; specifically providing OpenAI models EU: primarily Germany West Central, fallback resource Sweden Central No storage of inference data on the model inference service; no training of general models; no direct access by OpenAI to prompts or model outputs; chat histories remain in awork-controlled Azure infrastructure Google Cloud – Vertex AI Providing selected Google/Gemini models Belgium: europe-west1 No storage of inference data on the model inference service; no training of general models; processing in specified EU region; security filters for inputs and outputs Amazon Web Services – Amazon Bedrock Runtime Providing selected Anthropic models EU: Germany, Ireland, France, Sweden, Italy, and Spain; exclusively geographically limited EU inference profiles No storage of inference data on the model inference service; no training of general models; no access by model providers to prompts or model outputs; no global inference profile; Bedrock Guardrails TensorX Limited Providing selected open-source AI models Exclusively EEA: Dublin, Ireland and Helsinki, Finland Processing exclusively in volatile working memory on TensorX-owned hardware; no storage or logging of prompts/outputs; no training; no sharing with model providers Important: AWS Bedrock is not used as a fallback or peak load backup for regular Azure-based AI processing. How We Conduct Audits and Reviews The type of review depends on a risk-based assessment of the service provider's size, role, and structure. For large cloud and infrastructure providers, we rely especially on: Independent audit reports and certifications like ISO 27001, SOC 2, or BSI C5, Contractual transparency and review mechanisms in the respective Data Processing Agreements, And additional security and data protection evidence. For smaller or specialized service providers, we conduct our own reviews, such as document reviews, questionnaires, and assessments of technical and organizational measures. AI infrastructure and AI model providers also go through a risk-based privacy and security review before they're approved. Our Review and Approval Process Before we use a new relevant service provider, we review: Technical and organizational measures, Processing locations and data flows, Data processing agreements and any third-country safeguards, Data minimization, retention, and training settings, And integration into our information security and vendor management. We regularly reassess the service providers we use. Changes to Subcontractors and Objection We notify you of planned additions or replacements of subcontractors at least six weeks before the planned change, as specified in our Data Processing Agreement. You can object to such a change within the timeframe provided in your Data Processing Agreement for important reasons. The specific consequences of an objection depend on your current Data Processing Agreement. Individual technical exclusion of already agreed upon and firmly integrated platform sub-processors is generally not possible, as this could impair core functions or secure service delivery. Data Flow at a Glance Which workspace data goes where? For the general platform, simplified: Central storage of workspace and business data happens in Microsoft Azure in Germany. Support and communication data are processed via Intercom when you use support; technical data and context forwarding may happen via Segment. Bug reports are only processed via Birdie in connection with a corresponding error report. Optional AI processing only happens when you use the relevant AI function or model, or when it's configured to run. Which AI data goes where? When you make an AI request, here's what happens: You start an AI function or agent, or a previously configured trigger/workflow starts an agent run. The awork AI Runtime assembles the prompt and context needed for the operation. The Model Router sends the request to exactly the AI system configured for the model you're using. If a tool or connected system is needed, the access goes through the appropriate tool and permission checks first. The result is returned to awork and shown to you or used for a previously authorized action. Chat histories and AI content that awork stores for display in the product stay in awork-controlled Azure infrastructure. The model inference services we use don't store regular prompts and outputs for this purpose and don't use them to train general models. If you connect external systems or MCP servers yourself, the data processing rules, permissions, and processing locations of those third-party providers also apply. Permission-Based Data Access and Execution AI functions can only access data and content that the triggering user already has permission to access. Agents can also execute actions within this permission scope. Your existing workspace, project, and object permissions apply unchanged; using AI doesn't create any additional access or execution rights. We transparently show which agent executed which action on behalf of which user. Control by Administrators You can use the awork platform without AI data processing. Standard product AI features can be disabled by administrators; the expanded awork AI Add-on requires a separate purchase. Workspace administrators can also disable the AI models available for regular use. Some technical or foundational AI functions may be based on fixed preset models that aren't part of the regular model selection. Binding Contractual Basis The tables on this page provide transparent and understandable explanation of our setup. You'll find the complete and legally binding description of subcontractors, processing locations, and security measures in your current Data Processing Agreement. Data Protection and GDPR at aworkPreviousawork and AINext Last updated September 1, 2026Powered by happysupport.ai RSSFor developers © 2026 HappySupport. All rights reserved. Privacy PolicyImprint HappySearch can make mistakes. Sources No articles yet Search to see source articles