Sub-processor List
This is an English translation provided for convenience. The legally binding version is the Czech original; in case of any discrepancy, the Czech version prevails.
Controller and publisher: Digital D&A s.r.o. | Company ID: 23691271 • Seat: Školská 660/3, Nové Město, 110 00 Prague • Contact: support@awentail.com • Last updated: 14 March 2026 | Version 1.0 • Customer notification of changes: at least 14 days in advance by e-mail
About this document
Digital D&A s.r.o. (operator of the Awentail platform) uses third-party services — so-called sub-processors — to run its operations. These sub-processors may have access to personal data that Awentail processes on behalf of its customers (controllers) under the Data Processing Agreement (DPA).
We publish this list in accordance with Art. 28(2) of Regulation (EU) 2016/679 (GDPR) and with our DPA, which grants customers a general authorisation to engage sub-processors together with the right to object.
ℹ We inform customers by e-mail of any change to this list (adding or replacing a sub-processor) at least 14 days before the change takes effect. A customer may object within 10 business days of the notification.
Awentail may change or replace sub-processors on an ongoing basis for operational, security or technological reasons, provided that the new sub-processor offers a comparable or higher level of personal data protection. Customers are always informed of such changes in accordance with the process set out below.
Awentail is not liable for a sub-processor’s breach of its obligations where such breach arose independently of Awentail’s instructions or control and where Awentail took reasonable contractual and organisational measures to ensure the sub-processor’s GDPR compliance.
Some sub-processors may use their own providers (sub-processors of sub-processors) within their infrastructure. These providers are contractually bound to maintain corresponding personal data protection standards. Examples: AWS uses its own data-centre providers, Cloudflare operates a global PoP network, Stripe uses banking partners for payment processing.
Legend
| Abbreviation / term | Explanation |
|---|---|
| EEA | European Economic Area (EU + Norway, Iceland, Liechtenstein) |
| SCC | Standard Contractual Clauses under Art. 46(2)(c) GDPR — mechanism for transfers outside the EEA |
| Adequacy Decision | European Commission adequacy decision — transfer without further safeguards (Art. 45 GDPR) |
| DPA | Data Processing Agreement — personal data processing agreement under Art. 28 GDPR |
List of sub-processors
| Sub-processor | Purpose of processing | Data processed | Location | Transfer mechanism | DPA / link |
|---|---|---|---|---|---|
| ▸ AI MODELS AND INFERENCE | |||||
| OpenAI (OpenAI, L.L.C.) | Generating AI assistant responses via LLM (GPT-4 and later) | Conversation content and queries — only data necessary to generate the response (data minimisation) | USA | SCC under Art. 46(2)(c) GDPR | openai.com/policies/data-processing-addendum |
| Anthropic (Anthropic, PBC) | Backup or alternative LLM inference (Claude models) | Conversation content and queries — only data necessary to generate the response (data minimisation) | USA | SCC under Art. 46(2)(c) GDPR | anthropic.com/legal/data-processing-addendum |
| ▸ CLOUD INFRASTRUCTURE AND DATABASE | |||||
| Supabase (Supabase, Inc.) | Primary database — PostgreSQL with pgvector; user authentication | User accounts, conversations, contacts, Knowledge Base | EEA (EU-West) | Within the EEA — not required | supabase.com/privacy |
| Amazon Web Services (Amazon.com, Inc.) | Cloud infrastructure, object storage (S3), serverless functions | Knowledge Base files, logs, backups | EEA (eu-west-1) | Within the EEA — not required | aws.amazon.com/compliance/gdpr-center |
| Vercel (Vercel Inc.) | Application frontend hosting (app.awentail.com) | Technical session data, IP addresses when accessing the application | EEA / USA | SCC under Art. 46(2)(c) GDPR | vercel.com/legal/privacy-policy |
| Cloudflare (Cloudflare, Inc.) | CDN, DDoS protection, DNS, SSL/TLS termination | IP addresses and HTTP metadata — processed temporarily for security and infrastructure protection | Global / EEA PoP | SCC under Art. 46(2)(c) GDPR | cloudflare.com/gdpr/introduction |
| ▸ PAYMENT INFRASTRUCTURE | |||||
| Stripe (Stripe Payments Europe, Ltd.) | Card payment processing, subscription management, invoicing | Billing details, payment metadata (Awentail does not store card numbers) | EEA (Ireland) | Within the EEA — not required | stripe.com/privacy |
| ▸ CUSTOMER COMMUNICATION AND SUPPORT | |||||
| Resend (Resend Inc.) | Transactional e-mails (registration confirmations, invoices, notifications) | Customer e-mail addresses, metadata and content of transactional e-mails | USA | SCC under Art. 46(2)(c) GDPR | resend.com/legal/privacy-policy |
| Intercom (Intercom R&D Unlimited Company) | Customer support, live chat, help center | Name, e-mail, content of support conversations | EEA (Ireland) | Within the EEA — not required | intercom.com/legal/privacy |
| ▸ ANALYTICS AND MONITORING | |||||
| PostHog (PostHog, Inc.) | Product analytics — anonymised in-app user behaviour | Anonymised session data, clicks, pages (no PII) | EEA (EU cloud) | Within the EEA — not required | posthog.com/privacy |
| Sentry (Functional Software, Inc.) | Application error and exception monitoring | Stack traces, anonymised technical error details | USA | SCC under Art. 46(2)(c) GDPR | sentry.io/privacy |
| Datadog (Datadog, Inc.) | Infrastructure monitoring, logs, APM | Application logs, performance metrics (pseudonymised) | EEA (EU region) | Within the EEA — not required | datadoghq.com/legal/privacy |
| ▸ AUTHENTICATION AND SECURITY | |||||
| Supabase Auth (see Supabase above) | Login management, OAuth, session tokens | E-mail, hashed password, session tokens | EEA (EU-West) | Within the EEA — not required | supabase.com/privacy |
| ▸ WEBHOOKS AND INTEGRATIONS | |||||
| Svix (Svix, Inc.) | Webhook delivery to customers (notifications of new conversations, contacts) | Webhook payload containing conversation data per customer configuration | USA | SCC under Art. 46(2)(c) GDPR | svix.com/privacy |
| Cal.com (Cal.com, Inc.) | Calendar integration for the appointment booking feature | E-mail, name, booking times (if the customer enables the feature) | USA / EEA | SCC under Art. 46(2)(c) GDPR | cal.com/privacy |
Transfers of personal data outside the EEA
The following sub-processors are located outside the EEA. All transfers are secured by Standard Contractual Clauses (SCC) as adopted by Commission Implementing Decision (EU) 2021/914, or by another mechanism valid at the time of transfer under Art. 46 GDPR.
| Sub-processor | Location | Transfer mechanism | Note |
|---|---|---|---|
| OpenAI | USA | SCC (Controller-Processor) | Conversation content — minimisation of transferred data |
| Anthropic | USA | SCC (Controller-Processor) | Backup LLM — transfer only when actively used |
| Vercel | USA | SCC (Controller-Processor) | Technical session data only, no conversation PII |
| Cloudflare | USA | SCC (Controller-Processor) | IP addresses processed transiently, not persisted |
| Resend | USA | SCC (Controller-Processor) | E-mail addresses and content of transactional messages |
| Sentry | USA | SCC (Controller-Processor) | Technical error reports only, pseudonymised |
| Svix | USA | SCC (Controller-Processor) | Webhook payload per customer configuration |
ℹ Awentail continuously monitors developments in adequacy decisions and other transfer mechanisms. Awentail may in future also rely on other transfer mechanisms under Art. 45 or Art. 46 GDPR (for example the EU-US Data Privacy Framework or a new adequacy decision), where available and valid at the time of transfer. If a transfer mechanism changes, Awentail updates this list and informs customers.
Change notification process
Awentail follows the process below for every change to the sub-processor list:
| Step | Action | Deadline |
|---|---|---|
| 1 | Awentail updates this list at awentail.com/subprocessors | Before notifying customers |
| 2 | Customers are notified by e-mail at their registered address | At least 14 days before the change |
| 3 | A customer may raise a legitimate objection by e-mailing support@awentail.com | Within 10 business days of the notification |
| 4 | If no agreement is reached, the customer may terminate the contract with respect to the affected services | Under the terms of the DPA |
Change history
| Date | Version | Change | Notified to customers |
|---|---|---|---|
| 14 March 2026 | v1.0 | Initial release of the sub-processor list | As part of the platform launch |
Earlier versions of this list are archived for audit and compliance purposes and are available on request at support@awentail.com.
Questions about this list: support@awentail.com | awentail.com/subprocessors