AnswerWeave

Sub-processors

Last updated:

Draft — pending final vendor confirmation. Some vendor identifications below are placeholders pending confirmation of the specific production provider. This page is authoritative once finalised.

Hazen Technologies Inc (operator of AnswerWeave) engages the sub-processors listed below to help provide, secure, and support the Service. Each is bound by a written data-processing agreement imposing obligations no less protective than those we owe to our customers under our Data Processing Addendum.

Notification of changes. We will update this page and notify administrator email addresses on file at least fifteen (15) days before adding or replacing a sub-processor that processes Personal Data. Customers may reasonably object to a new sub-processor as described in §6 of the DPA.

Subscribing to notifications. To receive email notifications of sub-processor changes, contact support@answerweave.ai with the subject line “Subscribe: sub-processor updates.”

Current sub-processors

Sub-processorServiceData types processedProcessing locationDPA
OpenAI, L.L.C.Large-language-model inference, embeddings, and voice transcriptionChat prompts and content submitted for indexing (transient inputs); voice audio (transient, immediately discarded post-transcription)United StatesLink
Stripe, Inc.Subscription billing and payment processingCustomer name, email, billing address, tokenised payment details (card details are not visible to us)United States (Ireland for EEA customers)Link
Microsoft Corporation (Azure)Cloud infrastructure hosting: application servers, databases, object storage, secrets managementAll Customer Content and account dataUnited States; other regions per customer deployment configurationLink
Transactional email providerDelivery of transactional emails (account, security, and lead-notification emails)Recipient email address, message subject and body content, delivery metadataUnited StatesProvider-specific; available on request
Error monitoring and logging providerApplication error monitoring, diagnostic logging, and security event captureError stack traces, sanitised request metadata, performance metricsUnited States / European Union (region configurable)Provider-specific; available on request

Notes

  • No third-party model training. Our contracts with language-model and embedding providers restrict them from using Customer Content or End-User Data to train their foundation models on our behalf.
  • Payment card data. Full card details are collected, tokenised, and stored by Stripe under its own PCI-DSS Level 1 attestation. We do not store card numbers.
  • International transfers. Where transfers to a third country are required, we and our sub-processors rely on the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum, as described in §7 of the DPA.