Third Party Index

Snapshot 22281

Document
Subprocessor list
URL
https://trust.harmony.io/subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
151774 bytes
SHA-256 (raw)
9bf89a79e081a1ad3d008045e6aa8601d9717933f535a27a92508362050fda8a
SHA-256 (normalized text)
a5014b2487077c4e412bf54febe827d4557fb47c6ec05e646b88a62ae521ee4b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

The list
Every subprocessor is contracted under a data processing agreement that includes the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK, and is assessed before onboarding under the vendor risk control on this page. Our DPA lists them, and we will tell you before a new one starts processing customer data.
On models specifically: the models Harmony runs are hosted on AWS inside our own account, your prompts and context are not handed to a consumer AI product, and no model provider retains them. If you need the exact models and providers in scope for your workspace named in writing, ask us and we will put it in writing.
Harmony subprocessors, what they do, what customer data they can see, where they process it and the transfer mechanism
Subprocessor	Purpose	Customer data it can see	Location	Transfer mechanism
Amazon Web Services, Inc.	Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account.	All customer data: request and conversation content, attachments, directory and device records synced from your connected tools, and audit logs.	United States	Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum
Descope, Inc.	Authentication provider. Handles sign-in, session issuance and SSO federation.	Account identifiers and authentication metadata: name, work email address, identity provider and sign-in events. No request content.	United States	Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum
PostHog, Inc.	Product analytics. How the product is used, so we can see what is and is not working.	Product usage events and the account identifiers attached to them. No request content and no attachments.	United States	Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum
Our DPA lists these contractually. Ask for it at [email protected] or through the request form.
What we process for you
Harmony is the processor and you are the controller for everything in this table. It is processed to provide the service, and for nothing else.
Customer data Harmony processes as a processor
Category	Processed
Directory and identity data	Yes - Names, work email addresses, job details and group memberships, synced from the identity provider and HR system an admin connected.
Request and conversation content	Yes - What your employees ask Harmony, the agent’s replies, and anything they attach. Retained for the workspace and deleted with it.
Device and asset records	Yes - Device, asset and licence records read from the endpoint and asset tools an admin connected.
Special category data	No - Not required by the service and never requested by it. Harmony does not ask for health, biometric, or racial or ethnic origin data.
Payment card data	No - Never processed or stored in the Harmony platform.
What we process as a controller
Our own data, where Harmony is the controller. Nothing here is customer data you put into the platform.
Personal data Harmony processes as a controller
Category	Processed
Employee personal data	Yes - Our own employees and contractors, for employment and access management.
Business contact data	Yes - Names, work email addresses and company details of the people we talk to about Harmony.
Website analytics	Yes - Usage of harmony.io and this page. See the Cookies Notice at https://harmony.io/cookies-notice.