Subprocessors & Service Levels

Transparency about who helps us deliver our services and what you can expect from us operationally. This page summarises our standard terms; the data processing agreement (DPA) and its annex signed with each client govern the specific engagement.

Subprocessors

Last rebuilt 2026-09-05 from a source-code inventory of the product repositories — the env contracts, outbound hostnames and deploy configuration — rather than from the previous version of this page. Where the two disagreed, the code won.

Subprocessors are listed per product, not as one combined list. A client using one product does not inherit another product's subprocessors, and being told otherwise is neither accurate nor reassuring. The data processing agreement and its annex signed for your engagement govern the specific relationship; this page reflects the same content.

How to read these tables

Each vendor falls into exactly one category, and the obligations differ:

  • Subprocessor — processes client personal data on Available's instruction. Bound by a written data processing agreement with obligations equivalent to those Available has accepted toward its clients, covered by the 30-day change notice below.
  • Your own system — a system you already own, which we connect to using your credentials (your Zendesk, your telephony provider). Not our subprocessor; the connection is described in the DPA's description of processing.
  • Independent controller — decides its own purposes for the data (payment providers, review and social platforms). Named for transparency, not as part of a processing chain.

What is deliberately not listed: the systems holding Available's own business records about an engagement — accounting, invoicing, time tracking and our CRM. Available is the controller of that data, not a processor acting on your behalf, so naming those vendors as subprocessors would assert a chain that does not exist. Our handling of that data is covered by our own privacy notice.

Processing takes place within the EU/EEA unless the table says otherwise.

Shared platform

Available AI Assistant runs on a shared platform layer. These apply to it in addition to its own table below.

Vendor Category Purpose Data location
Vercel Inc. (USA) Subprocessor Hosting, serverless execution, scheduled jobs, static delivery EU — Frankfurt (fra1), confirmed 2026-09-03
Neon, LLC (USA — part of Databricks, Inc.) Subprocessor PostgreSQL with pgvector; all tenant data EU — Frankfurt, confirmed 2026-09-03
Vercel AI Gateway (USA) Subprocessor Routes prompts to the model providers below USA
Anthropic PBC (USA) Subprocessor Chat and vision models USA
OpenAI (USA) Subprocessor Fast model and text embeddings USA
Resend (USA) Subprocessor Sign-in links, reports and notifications TODO: confirm processing region
Zendesk Your own system Your helpdesk, reached with your credentials Your instance

Available AI Assistant — ai.available.dk

Copilot drafts, ticket classification, the help-centre widget, the fact scanner and the live-call panel. Adds one vendor to the shared platform above.

Vendor Category Purpose Data location
Brave Search (USA) Subprocessor Web-search queries issued by the copilot USA

Available Connect — connect.available.dk

An integration layer between your helpdesk and the phone system you already own. It is not a phone system itself, and it carries the smallest vendor surface in our estate.

Vendor Category Purpose Data location
Convex, Inc. (USA) Subprocessor Backend, database and real-time call state EU — eu-west-1 (TODO: confirm from the provider console)
Resend (USA) Subprocessor Contact and lifecycle email TODO: confirm processing region
Zendesk Your own system Your helpdesk, reached with your credentials Your instance
Your telephony provider Your own system Relatel, FlexFone, MobiKOM, ipnordic, ACE/Norlys, Dstny — your own contract and account Your provider

My Available — mit.available.dk

The client portal: support, documentation, signing and account administration.

Vendor Category Purpose Data location
Cloud 66 Ltd Subprocessor Application hosting TODO: confirm region; migration planned
Amazon Web Services EMEA SARL (Luxembourg) Subprocessor Object storage and outbound mail (S3, SES) EU — eu-west-1
Cloudflare Inc. (USA) Subprocessor DNS, CDN and WAF in front of the service EU-localised / global edge (TODO: confirm Data Localisation Suite setup)
OpenAI (USA) Subprocessor Support assistant: chat, embeddings, vision USA
Brave Search (USA) Subprocessor Web-search queries issued by the assistant USA
GatewayAPI (Denmark) Subprocessor SMS for signing links and one-time codes EU — Denmark
Prerender.io (USA) Subprocessor Rendering pages for search-engine crawlers USA
Stripe Independent controller Payment processing — Stripe determines its own purposes for card data EU/USA per Stripe's terms
Zendesk / Sunshine Conversations Your own system Helpdesk and messaging, reached with your credentials Your instance
CVR (Danish Business Authority) — Company lookup by registration number; no personal data is submitted Denmark

Zendesk Konfigurator — zendesk.available.dk

An internal tool our consultants use to configure and document your Zendesk estate. It connects to your Zendesk with credentials you provide, and stores the project's chats, documentation, library and audit trail.

Vendor Category Purpose Data location
Vercel Inc. (USA) Subprocessor Hosting, and the Blob store holding uploaded and emailed-in project documents and generated reports EU — Frankfurt (fra1) for the application; TODO: confirm the Blob store's region
Neon, LLC (USA — part of Databricks, Inc.) Subprocessor PostgreSQL — projects, chats, documentation, audit trail TODO: confirm region
Vercel AI Gateway (USA) Subprocessor Routes the agent's prompts to the model provider USA
Anthropic PBC (USA) Subprocessor The configurator agent's language model USA
Resend (USA) Subprocessor Inbound document drop-box — documents emailed to a project address land in its library TODO: confirm processing region
Brave Search (USA) Subprocessor The agent's web-search queries (Zendesk documentation, release notes, public help centres) USA
Zendesk Your own system Your instance, reached with credentials you provide Your instance

available.dk

Our marketing site is not a client-data processing relationship: visitors to it are not processed on any client's behalf, so no subprocessor chain arises. Trackers on the site are consent-gated through our consent management platform, and Available is the controller for that data. It is covered by our privacy notice rather than by this page.

Our own systems — trust.available.dk and status.available.dk

Neither processes client personal data on a client's behalf, so neither has a subprocessor list. trust.available.dk is this trust portal, holding Available's own employee policy acknowledgements and training records. status.available.dk holds service-level measurement. They are named here so that their absence from the tables above is visibly a decision rather than an omission.

Products not yet released

Available Insights, Mentions, Transcriptions, Phone, Learning, OnAir and Core are not yet processing client data. Each product's subprocessor list is published here, and included in the DPA annex, before that product processes any client personal data — not afterwards.

Danish-only AI option: clients can choose that all AI processing of their data happens exclusively with our Danish provider, Ordbogen A/S (Odense, Denmark — models developed, trained and operated in Denmark). In that case neither Anthropic nor OpenAI is used and no client data is transferred outside the EU/EEA. The choice is recorded in the agreement and can be changed on request.

Changes: additions or replacements of subprocessors are announced in writing with at least 30 days' notice, with a right to object as set out in the DPA.

Service levels

Our service levels cover Available's own services and integrations. Summary of the standard targets (the agreement's SLA annex governs):

Priority Definition First response
P1 — Critical Service unavailable or a key function down without workaround 4 hours — work starts immediately and continues within the service window; status every 4 hours
P2 — Significant Function limited, workaround exists 8 hours — work starts no later than the next business day
P3 — Other No operational impact; questions and change requests 2 business days — planned in dialogue
  • Uptime target: at least 99.5% within the agreed service window, measured per calendar month by external monitoring every minute, excluding announced maintenance. The standard service window is business days 08:00–16:00 CET; extended windows (e.g. weekday evenings) and weekend coverage are available by agreement.
  • Service credits: where an agreement includes service credits, missed targets carry defined credits, with a written action plan after a first missed month — the individual agreement governs amounts, caps, and claims.
  • Backup: data in Available's own services is backed up hourly with 7-day retention — maximum data loss on restore (RPO) is 1 hour.
  • Maintenance: announced at least 5 business days ahead, performed outside critical hours (typically weekends 22:00–06:00), capped at 4 hours/month. Security-critical patches may be applied faster, with notice at the latest upon execution.
  • Reporting: performance is measured and reported monthly, with a written action plan on repeated deviations.

Incident notification

If an incident affects your data or service, we notify affected clients per our contractual commitments and applicable law (including GDPR breach notification timelines), following our documented incident response process.

Questions or a copy of our DPA: security@available.dk.

Version 0.3 · Last reviewed 2026-09-05