Subprocessors & Service Levels

Transparency about who helps us deliver our services and what you can expect from us operationally. This page summarises our standard terms; the data processing agreement (DPA) and its annex signed with each client govern the specific engagement.

Subprocessors

Subprocessors may process client personal data on Available's behalf. Every subprocessor is bound by a written data processing agreement with obligations equivalent to those Available has accepted toward its clients. Processing takes place within the EU/EEA unless stated otherwise.

Subprocessor Purpose Data location Safeguards & certifications
Vercel Inc. (USA) Hosting and running of Available's web services EU region (TODO: confirm Frankfurt/Stockholm) EU SCCs + UK addendum; EU-US DPF; ISO/IEC 27001:2022, SOC 2 Type 2, TISAX AL2
Amazon Web Services EMEA SARL (Luxembourg) Hosting and storage EU region (TODO: confirm eu-central-1) EU-established entity; AWS DPA with EU SCCs; ISO/IEC 27001, 27017, 27018, 27701; SOC 1/2/3; CSA STAR
Cloudflare Inc. (USA) DNS, CDN and WAF EU-localised / global edge (TODO: confirm Data Localisation Suite setup) EU SCCs in DPA; EU-US & Swiss-US DPF; ISO/IEC 27001, 27018, 27701; SOC 2 Type II; PCI DSS; BSI C5
Neon, LLC (USA — part of Databricks, Inc.) Database operations (PostgreSQL) EU region (TODO: confirm Frankfurt) EU SCCs via DPA; DPF via Databricks; ISO/IEC 27001:2022, 27701; SOC 2, SOC 3
Ordbogen A/S (Denmark) AI processing: sentiment/language analysis and text generation Denmark (own data centres, Odense) No third-country transfer; models developed, trained and operated in Denmark
Anthropic PBC (USA) AI processing — only where the client selects this provider USA EU SCCs (TODO: confirm certification listing)
OpenAI (USA) AI processing in the mit.available.dk assistant — only where the client enables it USA EU SCCs via OpenAI DPA (TODO: execute DPA; pending DPA-annex v1.1)

Available uses no other subprocessors in service delivery.

TODO before approving this page (see risk R-009): OpenAI is now listed above per the CEO decision (2026-08-26) — execute the OpenAI DPA and ship DPA-annex v1.1 with the 30-day client notice before this page goes live. Convex is in decommissioning (target 2026-12-31) and deliberately not listed. Confirm the bracketed regions, and keep this page and the DPA annex as one list, never two.

Danish-only AI option: clients can choose that all AI processing of their data happens exclusively with our Danish provider — in that case neither Anthropic nor OpenAI is used and no client data is transferred outside the EU/EEA. The choice is recorded in the agreement and can be changed on request.

Changes: additions or replacements of subprocessors are announced in writing with at least 30 days' notice, with a right to object as set out in the DPA.

Service levels

Our service levels cover Available's own services and integrations. Summary of the standard targets (the agreement's SLA annex governs):

Priority Definition First response
P1 — Critical Service unavailable or a key function down without workaround 4 hours — work starts immediately and continues within the service window; status every 4 hours
P2 — Significant Function limited, workaround exists 8 hours — work starts no later than the next business day
P3 — Other No operational impact; questions and change requests 2 business days — planned in dialogue
  • Uptime target: at least 99.5% within the agreed service window, measured per calendar month by external monitoring every minute, excluding announced maintenance. The standard service window is business days 08:00–16:00 CET; extended windows (e.g. weekday evenings) and weekend coverage are available by agreement.
  • Service credits: where an agreement includes service credits, missed targets carry defined credits, with a written action plan after a first missed month — the individual agreement governs amounts, caps, and claims.
  • Backup: data in Available's own services is backed up hourly with 7-day retention — maximum data loss on restore (RPO) is 1 hour.
  • Maintenance: announced at least 5 business days ahead, performed outside critical hours (typically weekends 22:00–06:00), capped at 4 hours/month. Security-critical patches may be applied faster, with notice at the latest upon execution.
  • Reporting: performance is measured and reported monthly, with a written action plan on repeated deviations.

Incident notification

If an incident affects your data or service, we notify affected clients per our contractual commitments and applicable law (including GDPR breach notification timelines), following our documented incident response process.

Questions or a copy of our DPA: security@available.dk (TODO: confirm address).

Version 0.2 · Last reviewed 2026-08-26