Sub-processors
Last updated:
Hazen Technologies Inc (operator of AnswerWeave) engages the sub-processors listed below to help provide, secure, and support the Service. Each is bound by a written data-processing agreement imposing obligations no less protective than those we owe to our customers under our Data Processing Addendum.
Notification of changes. We will update this page and notify administrator email addresses on file at least fifteen (15) days before adding or replacing a sub-processor that processes Personal Data. Customers may reasonably object to a new sub-processor as described in §6 of the DPA.
Subscribing to notifications. To receive email notifications of sub-processor changes, contact support@answerweave.ai with the subject line “Subscribe: sub-processor updates.”
Current sub-processors
| Sub-processor | Service | Data types processed | Processing location | DPA |
|---|---|---|---|---|
| OpenAI, L.L.C. | Large-language-model inference, embeddings, and voice transcription | Chat prompts and content submitted for indexing (transient inputs); voice audio (transient, immediately discarded post-transcription) | United States | Link |
| Stripe, Inc. | Subscription billing and payment processing | Customer name, email, billing address, tokenised payment details (card details are not visible to us) | United States (Ireland for EEA customers) | Link |
| Microsoft Corporation (Azure) | Cloud infrastructure hosting: application servers, databases, object storage, secrets management | All Customer Content and account data | United States; other regions per customer deployment configuration | Link |
| Transactional email provider | Delivery of transactional emails (account, security, and lead-notification emails) | Recipient email address, message subject and body content, delivery metadata | United States | Provider-specific; available on request |
| Error monitoring and logging provider | Application error monitoring, diagnostic logging, and security event capture | Error stack traces, sanitised request metadata, performance metrics | United States / European Union (region configurable) | Provider-specific; available on request |
Notes
- No third-party model training. Our contracts with language-model and embedding providers restrict them from using Customer Content or End-User Data to train their foundation models on our behalf.
- Payment card data. Full card details are collected, tokenised, and stored by Stripe under its own PCI-DSS Level 1 attestation. We do not store card numbers.
- International transfers. Where transfers to a third country are required, we and our sub-processors rely on the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum, as described in §7 of the DPA.