Skip to content
AnswerWeave

Sub-processors

Last updated:

Hazen Technologies Inc (operator of AnswerWeave) engages the sub-processors listed below to help provide, secure, and support the Service. Each is bound by a written data-processing agreement imposing obligations no less protective than those we owe to our customers under our Data Processing Addendum.

Notification of changes. We will update this page and notify administrator email addresses on file at least fifteen (15) days before adding or replacing a sub-processor that processes Personal Data. Customers may reasonably object to a new sub-processor as described in §6 of the DPA.

Subscribing to notifications. To receive email notifications of sub-processor changes, contact support@answerweave.ai with the subject line “Subscribe: sub-processor updates.”

Current sub-processors

Sub-processorServiceData types processedProcessing locationDPA
OpenAI, L.L.C.Large-language-model inference, embeddings, and voice transcriptionChat prompts and content submitted for indexing (transient inputs); voice audio (transient, immediately discarded post-transcription)United StatesLink
Stripe, Inc.Subscription billing and payment processingCustomer name, email, billing address, tokenised payment details (card details are not visible to us)United States (Ireland for EEA customers)Link
Microsoft Corporation (Azure)Cloud infrastructure hosting: application servers, databases, object storage, secrets managementAll Customer Content and account dataUnited States; other regions per customer deployment configurationLink
Microsoft Corporation (Microsoft 365 — Exchange Online)Delivery of transactional email (account verification, password reset and change, team invitations, promotional-code notices, and lead notifications) via authenticated SMTP relayRecipient email address, message subject and body. Lead-notification emails additionally carry the End User’s submitted contact details and an AI-generated conversation summaryPer our Microsoft 365 tenant configurationLink

Notes

  • No third-party model training. Our contracts with language-model and embedding providers restrict them from using Customer Content or End-User Data to train their foundation models on our behalf.
  • Payment card data. Full card details are collected, tokenised, and stored by Stripe under its own PCI-DSS Level 1 attestation. We do not store card numbers.
  • International transfers. Where transfers to a third country are required, we and our sub-processors rely on the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum, as described in §7 of the DPA.