Subprocessors & Service Levels
Transparency about who helps us deliver our services and what you can expect from us operationally. This page summarises our standard terms; the data processing agreement (DPA) and its annex signed with each client govern the specific engagement.
Subprocessors
Subprocessors may process client personal data on Available's behalf. Every subprocessor is bound by a written data processing agreement with obligations equivalent to those Available has accepted toward its clients. Processing takes place within the EU/EEA unless stated otherwise.
| Subprocessor | Purpose | Data location | Safeguards & certifications |
|---|---|---|---|
| Vercel Inc. (USA) | Hosting and running of Available's web services | EU region (TODO: confirm Frankfurt/Stockholm) | EU SCCs + UK addendum; EU-US DPF; ISO/IEC 27001:2022, SOC 2 Type 2, TISAX AL2 |
| Amazon Web Services EMEA SARL (Luxembourg) | Hosting and storage | EU region (TODO: confirm eu-central-1) | EU-established entity; AWS DPA with EU SCCs; ISO/IEC 27001, 27017, 27018, 27701; SOC 1/2/3; CSA STAR |
| Cloudflare Inc. (USA) | DNS, CDN and WAF | EU-localised / global edge (TODO: confirm Data Localisation Suite setup) | EU SCCs in DPA; EU-US & Swiss-US DPF; ISO/IEC 27001, 27018, 27701; SOC 2 Type II; PCI DSS; BSI C5 |
| Neon, LLC (USA — part of Databricks, Inc.) | Database operations (PostgreSQL) | EU region (TODO: confirm Frankfurt) | EU SCCs via DPA; DPF via Databricks; ISO/IEC 27001:2022, 27701; SOC 2, SOC 3 |
| Ordbogen A/S (Denmark) | AI processing: sentiment/language analysis and text generation | Denmark (own data centres, Odense) | No third-country transfer; models developed, trained and operated in Denmark |
| Anthropic PBC (USA) | AI processing — only where the client selects this provider | USA | EU SCCs (TODO: confirm certification listing) |
| OpenAI (USA) | AI processing in the mit.available.dk assistant — only where the client enables it | USA | EU SCCs via OpenAI DPA (TODO: execute DPA; pending DPA-annex v1.1) |
Available uses no other subprocessors in service delivery.
TODO before approving this page (see risk R-009): OpenAI is now listed above per the CEO decision (2026-08-26) — execute the OpenAI DPA and ship DPA-annex v1.1 with the 30-day client notice before this page goes live. Convex is in decommissioning (target 2026-12-31) and deliberately not listed. Confirm the bracketed regions, and keep this page and the DPA annex as one list, never two.
Danish-only AI option: clients can choose that all AI processing of their data happens exclusively with our Danish provider — in that case neither Anthropic nor OpenAI is used and no client data is transferred outside the EU/EEA. The choice is recorded in the agreement and can be changed on request.
Changes: additions or replacements of subprocessors are announced in writing with at least 30 days' notice, with a right to object as set out in the DPA.
Service levels
Our service levels cover Available's own services and integrations. Summary of the standard targets (the agreement's SLA annex governs):
| Priority | Definition | First response |
|---|---|---|
| P1 — Critical | Service unavailable or a key function down without workaround | 4 hours — work starts immediately and continues within the service window; status every 4 hours |
| P2 — Significant | Function limited, workaround exists | 8 hours — work starts no later than the next business day |
| P3 — Other | No operational impact; questions and change requests | 2 business days — planned in dialogue |
- Uptime target: at least 99.5% within the agreed service window, measured per calendar month by external monitoring every minute, excluding announced maintenance. The standard service window is business days 08:00–16:00 CET; extended windows (e.g. weekday evenings) and weekend coverage are available by agreement.
- Service credits: where an agreement includes service credits, missed targets carry defined credits, with a written action plan after a first missed month — the individual agreement governs amounts, caps, and claims.
- Backup: data in Available's own services is backed up hourly with 7-day retention — maximum data loss on restore (RPO) is 1 hour.
- Maintenance: announced at least 5 business days ahead, performed outside critical hours (typically weekends 22:00–06:00), capped at 4 hours/month. Security-critical patches may be applied faster, with notice at the latest upon execution.
- Reporting: performance is measured and reported monthly, with a written action plan on repeated deviations.
Incident notification
If an incident affects your data or service, we notify affected clients per our contractual commitments and applicable law (including GDPR breach notification timelines), following our documented incident response process.
Questions or a copy of our DPA: security@available.dk (TODO: confirm address).