Sub-processors
Last updated:
Hazen Technologies Inc (operator of AnswerWeave) engages the sub-processors listed below to help provide, secure, and support the Service. Each is bound by a written data-processing agreement imposing obligations no less protective than those we owe to our customers under our Data Processing Addendum.
Notification of changes. We will update this page and notify administrator email addresses on file at least fifteen (15) days before adding or replacing a sub-processor that processes Personal Data. Customers may reasonably object to a new sub-processor as described in §6 of the DPA.
Subscribing to notifications. To receive email notifications of sub-processor changes, contact support@answerweave.ai with the subject line “Subscribe: sub-processor updates.”
Current sub-processors
| Sub-processor | Service | Data types processed | Processing location | DPA |
|---|---|---|---|---|
| OpenAI, L.L.C. | Large-language-model inference, embeddings, and voice transcription | Chat prompts and content submitted for indexing (transient inputs); voice audio (transient, immediately discarded post-transcription) | United States | Link |
| Stripe, Inc. | Subscription billing and payment processing | Customer name, email, billing address, tokenised payment details (card details are not visible to us) | United States (Ireland for EEA customers) | Link |
| Microsoft Corporation (Azure) | Cloud infrastructure hosting: application servers, databases, object storage, secrets management | All Customer Content and account data | United States; other regions per customer deployment configuration | Link |
| Microsoft Corporation (Microsoft 365 — Exchange Online) | Delivery of transactional email (account verification, password reset and change, team invitations, promotional-code notices, and lead notifications) via authenticated SMTP relay | Recipient email address, message subject and body. Lead-notification emails additionally carry the End User’s submitted contact details and an AI-generated conversation summary | Per our Microsoft 365 tenant configuration | Link |
Notes
- No third-party model training. Our contracts with language-model and embedding providers restrict them from using Customer Content or End-User Data to train their foundation models on our behalf.
- Payment card data. Full card details are collected, tokenised, and stored by Stripe under its own PCI-DSS Level 1 attestation. We do not store card numbers.
- International transfers. Where transfers to a third country are required, we and our sub-processors rely on the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum, as described in §7 of the DPA.