Skip to main content

Hawi AgentsSubprocessor List

Effective 23 August 2026

Draft, pending legal review. Not yet in force.

Last Updated: 23 August 2026 Effective Date: 23 August 2026

This Subprocessor List identifies third parties that Hawi Inc, trading as Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, or “our”) may engage to process Customer Personal Data on Hawi's behalf in connection with the Hawi Services.

This list should be read together with:

  • the Hawi Privacy Policy;
  • Hawi Terms and Conditions;
  • Hawi Data Processing Agreement (“DPA”);
  • Hawi Security & Trust Policy;
  • and any applicable Order Form.

1. What is a subprocessor?

Where a Business Customer acts as a controller of personal data and appoints Hawi to process that data on its behalf, Hawi generally acts as a processor.

If Hawi then appoints another organisation to process that same Customer Personal Data on Hawi's behalf in order to provide the Services, that organisation may be a Subprocessor.

A Subprocessor is different from:

  • a customer-selected independent third party;
  • an independent controller;
  • a payment provider acting as its own controller for certain purposes;
  • or a service that never receives Customer Personal Data.

The legal role of a provider depends on the processing activity.

2. General authorisation

Where permitted by the applicable Hawi DPA, customers provide Hawi with general written authorisation to engage the Subprocessors identified in this List.

Hawi will use Subprocessors only where reasonably necessary to provide, secure, maintain or support the Services.

3. Subprocessor requirements

Where required by UK GDPR, GDPR or another applicable data-protection law, Hawi will require a Subprocessor to enter into written terms containing appropriate data-protection obligations.

Those obligations may address matters including:

  • confidentiality;
  • information security;
  • processing instructions;
  • breach notification;
  • deletion or return;
  • further subprocessing;
  • assistance with data-subject rights;
  • international transfers;
  • and appropriate technical and organisational measures.

4. Core Hawi subprocessors

The following providers form or are expected to form part of Hawi's core processing infrastructure where the relevant Services are enabled.

Supabase

Provider: Supabase Pte. Ltd. and applicable affiliates

Service category: Database, authentication, storage and application infrastructure

Purpose of processing:

Supabase may support Hawi functions including:

  • PostgreSQL database hosting;
  • authentication;
  • Account records;
  • Workspace information;
  • Agent records;
  • usage data;
  • audit information;
  • file metadata;
  • private object storage;
  • realtime functionality;
  • database functions;
  • and related backend infrastructure.

Categories of personal data potentially processed:

  • Account identifiers;
  • names;
  • email addresses;
  • phone-related verification information where applicable;
  • Workspace information;
  • user-generated content;
  • Agent configuration;
  • usage information;
  • audit information;
  • files or file metadata;
  • integration metadata;
  • and other Customer Personal Data stored by the customer through Hawi.

Data subjects may include:

  • Hawi users;
  • customer employees;
  • customer contractors;
  • customers' customers;
  • communication recipients;
  • and other persons whose information a customer lawfully processes through Hawi.

Primary Hawi project region: London, United Kingdom (eu-west-2).

Other processing locations: Supabase or its authorised subprocessors may process data in other locations according to the services, support arrangements and Supabase's contractual terms.

Transfer safeguards: Applicable contractual transfer safeguards, including SCC-based mechanisms where required.

Status: Core / Active

Vercel

Provider: Vercel Inc. and applicable affiliates

Service category: Frontend hosting, edge delivery and deployment infrastructure

Purpose of processing:

Vercel may support:

  • Hawi frontend hosting;
  • lightweight frontend route handlers and authenticated backend-for-frontend requests;
  • content delivery;
  • serverless or application functions;
  • deployment infrastructure;
  • routing;
  • request processing;
  • application logs;
  • operational monitoring;
  • and security functionality.

Categories of personal data potentially processed:

  • IP addresses;
  • HTTP request information;
  • Account-related request data;
  • application payloads passing through Hawi services;
  • technical logs;
  • device or browser information;
  • and Customer Personal Data handled by Hawi application functions.

Processing locations: May include the United States and other locations in which Vercel and its authorised subprocessors operate.

Transfer safeguards: Where an applicable Vercel processor DPA applies, Vercel provides contractual mechanisms for relevant international transfers, including SCC/UK transfer provisions where required.

Status: Core / Active

Important: Hawi must ensure that the Vercel plan and contractual arrangement used for production provides the data-processing protections required for Hawi's customers. Long-running agent, worker, voice and execution workloads run on Railway rather than Vercel.

Railway

Provider: Railway Corp. and applicable affiliates

Service category: Long-running backend and worker hosting

Purpose of processing:

Railway runs Hawi's execution backend, runtime worker, voice gateway, developer worker and remote MCP service. These services process authorised requests from the Vercel frontend and use Supabase for durable state.

Categories of personal data potentially processed:

  • Agent prompts, context and model outputs;
  • Workspace and run identifiers;
  • connector action payloads;
  • live voice audio and transcripts where the voice feature is used;
  • and operational metadata required to execute and settle work.

Processing locations: The region selected for each Railway service. The production project and its contractual data locations require operator verification.

Transfer safeguards: Railway's applicable DPA and transfer mechanisms, including SCC/UK provisions where required.

Status: Core / Active for backend services.

Cloudflare

Provider: Cloudflare, Inc. and applicable affiliates

Service category: Turnstile bot and abuse prevention

Purpose of processing: Turnstile assesses public sign-up and authentication requests for automated abuse before Hawi accepts them.

Categories of personal data potentially processed: IP address, browser and device signals, challenge interaction and request metadata.

Processing locations: Cloudflare's global network. Exact contractual locations and transfer safeguards require verification under Cloudflare's applicable DPA.

Status: Feature-dependent. Turnstile runs only where both its public site key and server verification credential are configured.

5. Model and agent-execution subprocessors

These providers may process information when Hawi routes an eligible Agent task to the relevant model service.

Openai

Provider: OpenAI OpCo, LLC, OpenAI Ireland Ltd. or another applicable OpenAI contracting affiliate

Service category: Model inference and related AI processing

Purpose of processing:

OpenAI may process information submitted by Hawi as necessary to:

  • execute model requests;
  • generate Agent responses;
  • interpret instructions;
  • perform structured generation;
  • assist tool selection;
  • process relevant task context;
  • and provide related model functionality.

Categories of personal data potentially processed:

Depending on the customer's instructions, this may include:

  • prompts;
  • communication content;
  • document excerpts;
  • names;
  • business information;
  • contact information;
  • Agent instructions;
  • and other personal data contained within task context.

Processing locations: As specified by the applicable OpenAI Services, DPA and Subprocessor List.

Transfer safeguards: OpenAI's current business/API DPA provides applicable SCC and UK Addendum mechanisms for covered international transfers.

Status: Model provider / Active in Hawi's current metered provider configuration.

Anthropic

Provider: Anthropic PBC and applicable affiliates

Service category: Model inference and related AI processing

Purpose of processing:

Anthropic may process information submitted by Hawi to:

  • execute model requests;
  • generate Agent responses;
  • reason over permitted task context;
  • assist with tool selection;
  • and provide related model functionality.

Categories of personal data potentially processed:

Depending on customer instructions:

  • prompts;
  • emails or messages;
  • document excerpts;
  • business information;
  • names;
  • contact information;
  • Agent instructions;
  • and other Customer Personal Data supplied as model context.

Processing locations: According to Anthropic's applicable services, DPA and Subprocessor arrangements.

Transfer safeguards: Anthropic's current DPA incorporates appropriate SCC and UK Addendum provisions where applicable.

Status: Model provider / Active in Hawi's current metered provider configuration.

6. Feature-dependent subprocessors

The following providers should be treated as feature-dependent.

A customer who does not enable or use the relevant feature may not have Customer Personal Data sent to that provider.

Twilio

Provider: Twilio Inc. and applicable Twilio affiliates

Feature: Voice and/or communications functionality

Purpose of processing may include:

  • telephone-number provisioning;
  • making calls;
  • receiving calls;
  • transmitting communications;
  • call routing;
  • communications metadata;
  • and supporting voice-Agent operation.

Categories of personal data potentially processed:

  • telephone numbers;
  • call participants;
  • call metadata;
  • communications content;
  • call recordings where enabled;
  • routing information;
  • and associated technical data.

Legal-role note:

Twilio may act as a processor or Subprocessor for certain Customer Personal Data and may act as an independent controller for certain account, communications usage or legally required processing under its own terms.

Processing locations: According to the specific Twilio Service, telephone destination, infrastructure and Twilio subprocessor arrangements.

Transfer safeguards: Twilio's applicable Data Protection Addendum and international-transfer mechanisms.

Status: Feature-dependent — voice/communications.

Elevenlabs

Provider: Eleven Labs Inc. and applicable affiliates

Feature: Speech, voice synthesis and related audio functionality where enabled

Purpose of processing may include:

  • converting text to speech;
  • voice synthesis;
  • audio generation;
  • voice-Agent audio processing;
  • or other speech functionality.

Categories of personal data potentially processed:

Depending on configuration:

  • text sent for speech generation;
  • names;
  • communication content;
  • audio;
  • voice information;
  • and other personal data contained in the supplied material.

Processing locations: According to the selected ElevenLabs service, available data-residency configuration and its authorised subprocessors.

Transfer safeguards: ElevenLabs' applicable DPA provides international-transfer provisions including SCC and UK Addendum mechanisms where required.

Status: Feature-dependent — list as active only while Hawi production voice functionality actually uses ElevenLabs.

7. Payment providers and other third parties

Not every important provider is properly described as a Hawi Subprocessor in every context.

The following provider deserves separate disclosure.

Stripe

Provider: Stripe, Inc. and/or the applicable Stripe affiliate

Service category: Payments and billing

Hawi uses Stripe for payment-related functionality.

Stripe may process:

  • customer identity information;
  • payment information;
  • card information;
  • billing address;
  • transaction information;
  • fraud signals;
  • subscription information;
  • and payment-related technical data.

Stripe's legal role varies according to the processing involved.

For some functions Stripe may process data on behalf of Hawi.

For other functions—particularly where Stripe must process information for:

  • fraud prevention;
  • regulatory compliance;
  • payment-network obligations;
  • financial reporting;
  • or its own legal obligations—

Stripe may act as an independent controller.

Accordingly, Hawi does not categorise every Stripe processing activity as Subprocessor processing.

Status: Payment service provider / Active.

8. Customer-selected integrations

Hawi supports integrations with third-party services.

Examples may include customer-selected:

  • email accounts;
  • calendars;
  • CRM systems;
  • commerce platforms;
  • productivity software;
  • project-management systems;
  • banking connections;
  • and other business applications.

These providers are not automatically Hawi Subprocessors.

Where a customer chooses to connect an independent third-party account, the customer may already have a direct contractual relationship with that provider.

Hawi may communicate with that provider according to the customer's instructions.

The third party's own:

  • privacy policy;
  • terms;
  • DPA;
  • security practices;
  • and legal obligations

may apply independently.

9. Connector catalogue does not equal subprocessor list

A provider appearing in Hawi's Integration catalogue does not mean:

  • Hawi sends that provider every customer's data;
  • the provider is a Hawi Subprocessor;
  • the provider is enabled;
  • the customer has connected it;
  • or the provider receives personal data.

A Connector generally receives data only when the relevant functionality is:

  • available;
  • configured;
  • authorised;
  • and used.

10. Downstream subprocessors

Many of Hawi's direct Subprocessors use their own subprocessors.

For example, a cloud or model provider may rely on:

  • data-centre providers;
  • cloud infrastructure;
  • support services;
  • content-delivery networks;
  • security vendors;
  • or related infrastructure.

Hawi does not reproduce every downstream provider's full changing list on this page.

Customers may review the direct provider's current subprocessor information using the resources maintained by that provider.

11. Subprocessor change notices

Where required by Hawi's DPA, Hawi will provide advance notice of a new Subprocessor that will materially process Customer Personal Data.

Notice may be provided through:

  • email;
  • the Hawi dashboard;
  • this Subprocessor List;
  • or another reasonable mechanism specified by the DPA.

12. Subprocessor notification subscription

Customers who wish to receive Subprocessor change notices may register at:

help@hawiagents.com

Customers should keep their notification contact information current.

13. Customer objections

Where a customer has a contractual or statutory right to object to a new Subprocessor, the objection must:

  • be made within the period specified by the applicable DPA;
  • be in writing;
  • identify the relevant Subprocessor;
  • and explain the reasonable data-protection grounds for the objection.

Hawi and the customer will attempt in good faith to resolve a valid objection.

14. Possible resolutions to an objection

Depending on technical and commercial feasibility, Hawi may consider measures such as:

  • limiting use of the Subprocessor;
  • changing configuration;
  • offering an alternative provider;
  • disabling the affected feature;
  • or another appropriate solution.

Hawi cannot guarantee that an alternative architecture will always be commercially or technically available.

15. If an objection cannot be resolved

Where required by the applicable DPA, if Hawi and the customer cannot resolve a valid objection, the customer may have the right to terminate the affected Service in accordance with the DPA.

The applicable DPA governs any refund or financial consequence of such termination.

16. International data transfers

Some Subprocessors may process Customer Personal Data outside:

  • the United Kingdom;
  • European Economic Area;
  • or customer's country of origin.

Where required, Hawi will use an appropriate legal mechanism for restricted transfers.

These may include:

  • adequacy regulations;
  • adequacy decisions;
  • Standard Contractual Clauses;
  • the UK Addendum;
  • the UK International Data Transfer Agreement;
  • binding corporate rules where legally appropriate;
  • or another recognised mechanism.

17. Data residency

A service's primary hosting region should not be confused with exclusive data residency.

For example, a database may be hosted primarily in London while:

  • support;
  • security;
  • metadata;
  • backups;
  • control-plane activity;
  • or downstream Subprocessors

operate elsewhere.

Where Hawi contractually promises specific residency requirements, those requirements will be described separately.

18. Minimum data sharing

Hawi seeks to limit Subprocessor access to information reasonably necessary to provide the relevant function.

For example:

  • a model provider should receive task-relevant model context rather than unrelated Account data;
  • a voice provider should receive information relevant to the call;
  • and a payment provider should receive information required for payment and fraud processing.

19. Subprocessor security review

Before introducing a material Subprocessor, Hawi should assess factors proportionate to risk, including:

  • service purpose;
  • categories of personal data;
  • security programme;
  • contractual protections;
  • breach obligations;
  • access controls;
  • encryption;
  • retention;
  • data location;
  • transfer mechanisms;
  • further subprocessors;
  • regulatory history where relevant;
  • and available independent assurance.

20. Contractual protections

Where a provider acts as a Subprocessor, Hawi seeks to use contractual arrangements that address appropriate requirements under applicable law.

These may include obligations concerning:

  • documented instructions;
  • confidentiality;
  • security;
  • subprocessing;
  • data-subject requests;
  • breach assistance;
  • deletion or return;
  • regulatory assistance;
  • and international transfers.

21. Subprocessor incidents

If a Subprocessor informs Hawi of a security incident affecting Hawi Customer Personal Data, Hawi will assess:

  • what data was affected;
  • which customers were affected;
  • the nature of the incident;
  • containment measures;
  • legal notification requirements;
  • and additional remediation.

Hawi will provide customer notifications where required by applicable law or contract.

22. Removal of a subprocessor

A provider may be removed from this List where Hawi:

  • stops using the provider;
  • replaces the provider;
  • removes the relevant feature;
  • or determines that the provider no longer processes Customer Personal Data on Hawi's behalf.

Removal from this page does not necessarily mean all historical provider records are immediately deleted if lawful retention periods still apply.

23. New features

New Hawi features may require additional specialist providers.

Before customer personal data is materially processed by a new Subprocessor, Hawi will update this List and provide any notice required under the applicable DPA.

24. Current subprocessor summary

ProviderServiceStatusData potentially processed
SupabaseDatabase, authentication, storage and backend infrastructureCore / ActiveAccount, Workspace, Agent, file and application data
VercelHosting, application execution, delivery and operational infrastructureCore / ActiveRequests, application data and technical logs
RailwayContainer hosting for execution, runtime, voice, developer-worker and remote MCP servicesCore / ActiveAgent prompts and responses in transit, voice audio in transit
CloudflareTurnstile bot and abuse preventionFeature-dependentIP address, browser/device signals and challenge metadata
OpenAIModel inferenceActive model providerTask context, prompts and relevant Customer Personal Data
AnthropicModel inferenceActive model providerTask context, prompts and relevant Customer Personal Data
Vercel AI GatewayModel routing for the support assistant and public previewsFeature-dependentSupport questions, page context and demo input
TwilioVoice/communications, and SMS verification codesFeature-dependentPhone numbers, call metadata and communications data
DeepgramSpeech-to-text for live callsFeature-dependentCall audio and transcript text, including what other call participants say
ElevenLabsSpeech/voice functionalityFeature-dependentText, audio and voice-related information
Fish AudioSpeech synthesis, where configured instead of ElevenLabsFeature-dependentText sent for synthesis
ResendTransactional email deliveryActiveEmail addresses and message content. No marketing email is sent.
UpstashRedis for rate limiting and the shared public catalogue cacheOptionalAccount identifiers or IP addresses used as counter keys
PlaidBank account connectionsFeature-dependentBank account metadata; Hawi stores only a provider reference
GoogleGoogle Analytics 4 on public pagesOptional, consent onlyOnline identifiers, IP address and page interaction

This table is generated from, and tested against, src/lib/privacy/subprocessors.ts, which records for each provider the environment variables that switch it on and the code path that contacts it. A provider that the code can reach and this page does not name fails subprocessors.test.ts, so the two cannot drift apart silently. The contractual status of each provider (DPA in place, transfer mechanism executed) is recorded as REQUIRES_VERIFICATION in that file and is outstanding legal work — nothing in this repository evidences a signed contract.

25. Provider resources

Customers conducting supplier due diligence may request or consult information maintained by the applicable providers, including their:

  • privacy notices;
  • data-processing agreements;
  • subprocessor lists;
  • trust centres;
  • security documentation;
  • and international-transfer documentation.

26. Hawi data processing agreement

Where Hawi processes personal data on behalf of a Business Customer and applicable law requires a processor contract, the Hawi DPA should govern that processing relationship.

The DPA should address:

  • subject matter;
  • duration;
  • nature and purpose;
  • personal-data categories;
  • data-subject categories;
  • processing instructions;
  • confidentiality;
  • security;
  • Subprocessors;
  • data-subject rights;
  • assistance;
  • breaches;
  • deletion and return;
  • audits;
  • and international transfers.

27. Questions

Questions concerning this Subprocessor List may be sent to:

Privacy: help@hawiagents.com

Legal: help@hawiagents.com

Security: help@hawiagents.com

Subprocessor notifications: help@hawiagents.com

28. Changes to this list

This page may be updated when:

  • a new Subprocessor is appointed;
  • a provider is removed;
  • a provider's function changes materially;
  • processing locations change materially;
  • or Hawi's architecture changes.

The “Last Updated” date identifies the current published version.

29. Important distinction

For clarity:

Subprocessor does not mean “every company Hawi communicates with.”

A provider is generally listed as a Subprocessor where it processes Customer Personal Data on Hawi's behalf in connection with Hawi's provision of the Services.

Customer-selected third-party services and providers acting as independent controllers may be separately disclosed in Hawi's Privacy Policy rather than categorised as Subprocessors.

END OF SUBPROCESSOR LIST