Subprocessors & Service Levels
Transparency about who helps us deliver our services and what you can expect from us operationally. This page summarises our standard terms; the data processing agreement (DPA) and its annex signed with each client govern the specific engagement.
Subprocessors
Last rebuilt 2026-09-05 from a source-code inventory of the product repositories — the env contracts, outbound hostnames and deploy configuration — rather than from the previous version of this page. Where the two disagreed, the code won.
Subprocessors are listed per product, not as one combined list. A client using one product does not inherit another product's subprocessors, and being told otherwise is neither accurate nor reassuring. The data processing agreement and its annex signed for your engagement govern the specific relationship; this page reflects the same content.
How to read these tables
Each vendor falls into exactly one category, and the obligations differ:
- Subprocessor — processes client personal data on Available's instruction. Bound by a written data processing agreement with obligations equivalent to those Available has accepted toward its clients, covered by the 30-day change notice below.
- Your own system — a system you already own, which we connect to using your credentials (your Zendesk, your telephony provider). Not our subprocessor; the connection is described in the DPA's description of processing.
- Independent controller — decides its own purposes for the data (payment providers, review and social platforms). Named for transparency, not as part of a processing chain.
What is deliberately not listed: the systems holding Available's own business records about an engagement — accounting, invoicing, time tracking and our CRM. Available is the controller of that data, not a processor acting on your behalf, so naming those vendors as subprocessors would assert a chain that does not exist. Our handling of that data is covered by our own privacy notice.
Processing takes place within the EU/EEA unless the table says otherwise.
Shared platform
Available AI Assistant runs on a shared platform layer. These apply to it in addition to its own table below.
| Vendor | Category | Purpose | Data location |
|---|---|---|---|
| Vercel Inc. (USA) | Subprocessor | Hosting, serverless execution, scheduled jobs, static delivery | EU — Frankfurt (fra1), confirmed 2026-09-03 |
| Neon, LLC (USA — part of Databricks, Inc.) | Subprocessor | PostgreSQL with pgvector; all tenant data | EU — Frankfurt, confirmed 2026-09-03 |
| Vercel AI Gateway (USA) | Subprocessor | Routes prompts to the model providers below | USA |
| Anthropic PBC (USA) | Subprocessor | Chat and vision models | USA |
| OpenAI (USA) | Subprocessor | Fast model and text embeddings | USA |
| Resend (USA) | Subprocessor | Sign-in links, reports and notifications | TODO: confirm processing region |
| Zendesk | Your own system | Your helpdesk, reached with your credentials | Your instance |
Available AI Assistant — ai.available.dk
Copilot drafts, ticket classification, the help-centre widget, the fact scanner and the live-call panel. Adds one vendor to the shared platform above.
| Vendor | Category | Purpose | Data location |
|---|---|---|---|
| Brave Search (USA) | Subprocessor | Web-search queries issued by the copilot | USA |
Available Connect — connect.available.dk
An integration layer between your helpdesk and the phone system you already own. It is not a phone system itself, and it carries the smallest vendor surface in our estate.
| Vendor | Category | Purpose | Data location |
|---|---|---|---|
| Convex, Inc. (USA) | Subprocessor | Backend, database and real-time call state | EU — eu-west-1 (TODO: confirm from the provider console) |
| Resend (USA) | Subprocessor | Contact and lifecycle email | TODO: confirm processing region |
| Zendesk | Your own system | Your helpdesk, reached with your credentials | Your instance |
| Your telephony provider | Your own system | Relatel, FlexFone, MobiKOM, ipnordic, ACE/Norlys, Dstny — your own contract and account | Your provider |
My Available — mit.available.dk
The client portal: support, documentation, signing and account administration.
| Vendor | Category | Purpose | Data location |
|---|---|---|---|
| Cloud 66 Ltd | Subprocessor | Application hosting | TODO: confirm region; migration planned |
| Amazon Web Services EMEA SARL (Luxembourg) | Subprocessor | Object storage and outbound mail (S3, SES) | EU — eu-west-1 |
| Cloudflare Inc. (USA) | Subprocessor | DNS, CDN and WAF in front of the service | EU-localised / global edge (TODO: confirm Data Localisation Suite setup) |
| OpenAI (USA) | Subprocessor | Support assistant: chat, embeddings, vision | USA |
| Brave Search (USA) | Subprocessor | Web-search queries issued by the assistant | USA |
| GatewayAPI (Denmark) | Subprocessor | SMS for signing links and one-time codes | EU — Denmark |
| Prerender.io (USA) | Subprocessor | Rendering pages for search-engine crawlers | USA |
| Stripe | Independent controller | Payment processing — Stripe determines its own purposes for card data | EU/USA per Stripe's terms |
| Zendesk / Sunshine Conversations | Your own system | Helpdesk and messaging, reached with your credentials | Your instance |
| CVR (Danish Business Authority) | — | Company lookup by registration number; no personal data is submitted | Denmark |
Zendesk Konfigurator — zendesk.available.dk
An internal tool our consultants use to configure and document your Zendesk estate. It connects to your Zendesk with credentials you provide, and stores the project's chats, documentation, library and audit trail.
| Vendor | Category | Purpose | Data location |
|---|---|---|---|
| Vercel Inc. (USA) | Subprocessor | Hosting, and the Blob store holding uploaded and emailed-in project documents and generated reports | EU — Frankfurt (fra1) for the application; TODO: confirm the Blob store's region |
| Neon, LLC (USA — part of Databricks, Inc.) | Subprocessor | PostgreSQL — projects, chats, documentation, audit trail | TODO: confirm region |
| Vercel AI Gateway (USA) | Subprocessor | Routes the agent's prompts to the model provider | USA |
| Anthropic PBC (USA) | Subprocessor | The configurator agent's language model | USA |
| Resend (USA) | Subprocessor | Inbound document drop-box — documents emailed to a project address land in its library | TODO: confirm processing region |
| Brave Search (USA) | Subprocessor | The agent's web-search queries (Zendesk documentation, release notes, public help centres) | USA |
| Zendesk | Your own system | Your instance, reached with credentials you provide | Your instance |
available.dk
Our marketing site is not a client-data processing relationship: visitors to it are not processed on any client's behalf, so no subprocessor chain arises. Trackers on the site are consent-gated through our consent management platform, and Available is the controller for that data. It is covered by our privacy notice rather than by this page.
Our own systems — trust.available.dk and status.available.dk
Neither processes client personal data on a client's behalf, so neither has a subprocessor list. trust.available.dk is this trust portal, holding Available's own employee policy acknowledgements and training records. status.available.dk holds service-level measurement. They are named here so that their absence from the tables above is visibly a decision rather than an omission.
Products not yet released
Available Insights, Mentions, Transcriptions, Phone, Learning, OnAir and Core are not yet processing client data. Each product's subprocessor list is published here, and included in the DPA annex, before that product processes any client personal data — not afterwards.
Danish-only AI option: clients can choose that all AI processing of their data happens exclusively with our Danish provider, Ordbogen A/S (Odense, Denmark — models developed, trained and operated in Denmark). In that case neither Anthropic nor OpenAI is used and no client data is transferred outside the EU/EEA. The choice is recorded in the agreement and can be changed on request.
Changes: additions or replacements of subprocessors are announced in writing with at least 30 days' notice, with a right to object as set out in the DPA.
Service levels
Our service levels cover Available's own services and integrations. Summary of the standard targets (the agreement's SLA annex governs):
| Priority | Definition | First response |
|---|---|---|
| P1 — Critical | Service unavailable or a key function down without workaround | 4 hours — work starts immediately and continues within the service window; status every 4 hours |
| P2 — Significant | Function limited, workaround exists | 8 hours — work starts no later than the next business day |
| P3 — Other | No operational impact; questions and change requests | 2 business days — planned in dialogue |
- Uptime target: at least 99.5% within the agreed service window, measured per calendar month by external monitoring every minute, excluding announced maintenance. The standard service window is business days 08:00–16:00 CET; extended windows (e.g. weekday evenings) and weekend coverage are available by agreement.
- Service credits: where an agreement includes service credits, missed targets carry defined credits, with a written action plan after a first missed month — the individual agreement governs amounts, caps, and claims.
- Backup: data in Available's own services is backed up hourly with 7-day retention — maximum data loss on restore (RPO) is 1 hour.
- Maintenance: announced at least 5 business days ahead, performed outside critical hours (typically weekends 22:00–06:00), capped at 4 hours/month. Security-critical patches may be applied faster, with notice at the latest upon execution.
- Reporting: performance is measured and reported monthly, with a written action plan on repeated deviations.
Incident notification
If an incident affects your data or service, we notify affected clients per our contractual commitments and applicable law (including GDPR breach notification timelines), following our documented incident response process.
Questions or a copy of our DPA: security@available.dk.