Hawi Agents — Subprocessor List
Effective 23 August 2026
Last Updated: 23 August 2026 Effective Date: 23 August 2026
This Subprocessor List identifies third parties that Hawi Inc, trading as Hawi Agents (“Hawi”, “Hawi Agents”, “we”, “us”, or “our”) may engage to process Customer Personal Data on Hawi's behalf in connection with the Hawi Services.
This list should be read together with:
- the Hawi Privacy Policy;
- Hawi Terms and Conditions;
- Hawi Data Processing Agreement (“DPA”);
- Hawi Security & Trust Policy;
- and any applicable Order Form.
1. WHAT IS A SUBPROCESSOR?
Where a Business Customer acts as a controller of personal data and appoints Hawi to process that data on its behalf, Hawi generally acts as a processor.
If Hawi then appoints another organisation to process that same Customer Personal Data on Hawi's behalf in order to provide the Services, that organisation may be a Subprocessor.
A Subprocessor is different from:
- a customer-selected independent third party;
- an independent controller;
- a payment provider acting as its own controller for certain purposes;
- or a service that never receives Customer Personal Data.
The legal role of a provider depends on the processing activity.
2. GENERAL AUTHORISATION
Where permitted by the applicable Hawi DPA, customers provide Hawi with general written authorisation to engage the Subprocessors identified in this List.
Hawi will use Subprocessors only where reasonably necessary to provide, secure, maintain or support the Services.
3. SUBPROCESSOR REQUIREMENTS
Where required by UK GDPR, GDPR or another applicable data-protection law, Hawi will require a Subprocessor to enter into written terms containing appropriate data-protection obligations.
Those obligations may address matters including:
- confidentiality;
- information security;
- processing instructions;
- breach notification;
- deletion or return;
- further subprocessing;
- assistance with data-subject rights;
- international transfers;
- and appropriate technical and organisational measures.
4. CORE HAWI SUBPROCESSORS
The following providers form or are expected to form part of Hawi's core processing infrastructure where the relevant Services are enabled.
SUPABASE
Provider: Supabase Pte. Ltd. and applicable affiliates
Service category: Database, authentication, storage and application infrastructure
Purpose of processing:
Supabase may support Hawi functions including:
- PostgreSQL database hosting;
- authentication;
- Account records;
- Workspace information;
- Agent records;
- usage data;
- audit information;
- file metadata;
- private object storage;
- realtime functionality;
- database functions;
- and related backend infrastructure.
Categories of personal data potentially processed:
- Account identifiers;
- names;
- email addresses;
- phone-related verification information where applicable;
- Workspace information;
- user-generated content;
- Agent configuration;
- usage information;
- audit information;
- files or file metadata;
- integration metadata;
- and other Customer Personal Data stored by the customer through Hawi.
Data subjects may include:
- Hawi users;
- customer employees;
- customer contractors;
- customers' customers;
- communication recipients;
- and other persons whose information a customer lawfully processes through Hawi.
Primary Hawi project region: London, United Kingdom (eu-west-2).
Other processing locations: Supabase or its authorised subprocessors may process data in other locations according to the services, support arrangements and Supabase's contractual terms.
Transfer safeguards: Applicable contractual transfer safeguards, including SCC-based mechanisms where required.
Status: Core / Active
VERCEL
Provider: Vercel Inc. and applicable affiliates
Service category: Application hosting and deployment infrastructure
Purpose of processing:
Vercel may support:
- Hawi frontend hosting;
- backend application execution;
- content delivery;
- serverless or application functions;
- deployment infrastructure;
- routing;
- request processing;
- application logs;
- operational monitoring;
- and security functionality.
Categories of personal data potentially processed:
- IP addresses;
- HTTP request information;
- Account-related request data;
- application payloads passing through Hawi services;
- technical logs;
- device or browser information;
- and Customer Personal Data handled by Hawi application functions.
Processing locations: May include the United States and other locations in which Vercel and its authorised subprocessors operate.
Transfer safeguards: Where an applicable Vercel processor DPA applies, Vercel provides contractual mechanisms for relevant international transfers, including SCC/UK transfer provisions where required.
Status: Core / Active
Important: Hawi must ensure that the Vercel plan and contractual arrangement used for production provides the data-processing protections required for Hawi's customers.
5. MODEL AND AGENT-EXECUTION SUBPROCESSORS
These providers may process information when Hawi routes an eligible Agent task to the relevant model service.
OPENAI
Provider: OpenAI OpCo, LLC, OpenAI Ireland Ltd. or another applicable OpenAI contracting affiliate
Service category: Model inference and related AI processing
Purpose of processing:
OpenAI may process information submitted by Hawi as necessary to:
- execute model requests;
- generate Agent responses;
- interpret instructions;
- perform structured generation;
- assist tool selection;
- process relevant task context;
- and provide related model functionality.
Categories of personal data potentially processed:
Depending on the customer's instructions, this may include:
- prompts;
- communication content;
- document excerpts;
- names;
- business information;
- contact information;
- Agent instructions;
- and other personal data contained within task context.
Processing locations: As specified by the applicable OpenAI Services, DPA and Subprocessor List.
Transfer safeguards: OpenAI's current business/API DPA provides applicable SCC and UK Addendum mechanisms for covered international transfers.
Status: Model provider / Active in Hawi's current metered provider configuration.
ANTHROPIC
Provider: Anthropic PBC and applicable affiliates
Service category: Model inference and related AI processing
Purpose of processing:
Anthropic may process information submitted by Hawi to:
- execute model requests;
- generate Agent responses;
- reason over permitted task context;
- assist with tool selection;
- and provide related model functionality.
Categories of personal data potentially processed:
Depending on customer instructions:
- prompts;
- emails or messages;
- document excerpts;
- business information;
- names;
- contact information;
- Agent instructions;
- and other Customer Personal Data supplied as model context.
Processing locations: According to Anthropic's applicable services, DPA and Subprocessor arrangements.
Transfer safeguards: Anthropic's current DPA incorporates appropriate SCC and UK Addendum provisions where applicable.
Status: Model provider / Active in Hawi's current metered provider configuration.
6. FEATURE-DEPENDENT SUBPROCESSORS
The following providers should be treated as feature-dependent.
A customer who does not enable or use the relevant feature may not have Customer Personal Data sent to that provider.
TWILIO
Provider: Twilio Inc. and applicable Twilio affiliates
Feature: Voice and/or communications functionality
Purpose of processing may include:
- telephone-number provisioning;
- making calls;
- receiving calls;
- transmitting communications;
- call routing;
- communications metadata;
- and supporting voice-Agent operation.
Categories of personal data potentially processed:
- telephone numbers;
- call participants;
- call metadata;
- communications content;
- call recordings where enabled;
- routing information;
- and associated technical data.
Legal-role note:
Twilio may act as a processor or Subprocessor for certain Customer Personal Data and may act as an independent controller for certain account, communications usage or legally required processing under its own terms.
Processing locations: According to the specific Twilio Service, telephone destination, infrastructure and Twilio subprocessor arrangements.
Transfer safeguards: Twilio's applicable Data Protection Addendum and international-transfer mechanisms.
Status: Feature-dependent — voice/communications.
ELEVENLABS
Provider: Eleven Labs Inc. and applicable affiliates
Feature: Speech, voice synthesis and related audio functionality where enabled
Purpose of processing may include:
- converting text to speech;
- voice synthesis;
- audio generation;
- voice-Agent audio processing;
- or other speech functionality.
Categories of personal data potentially processed:
Depending on configuration:
- text sent for speech generation;
- names;
- communication content;
- audio;
- voice information;
- and other personal data contained in the supplied material.
Processing locations: According to the selected ElevenLabs service, available data-residency configuration and its authorised subprocessors.
Transfer safeguards: ElevenLabs' applicable DPA provides international-transfer provisions including SCC and UK Addendum mechanisms where required.
Status: Feature-dependent — list as active only while Hawi production voice functionality actually uses ElevenLabs.
7. PAYMENT PROVIDERS AND OTHER THIRD PARTIES
Not every important provider is properly described as a Hawi Subprocessor in every context.
The following provider deserves separate disclosure.
STRIPE
Provider: Stripe, Inc. and/or the applicable Stripe affiliate
Service category: Payments and billing
Hawi uses Stripe for payment-related functionality.
Stripe may process:
- customer identity information;
- payment information;
- card information;
- billing address;
- transaction information;
- fraud signals;
- subscription information;
- and payment-related technical data.
Stripe's legal role varies according to the processing involved.
For some functions Stripe may process data on behalf of Hawi.
For other functions—particularly where Stripe must process information for:
- fraud prevention;
- regulatory compliance;
- payment-network obligations;
- financial reporting;
- or its own legal obligations—
Stripe may act as an independent controller.
Accordingly, Hawi does not categorise every Stripe processing activity as Subprocessor processing.
Status: Payment service provider / Active.
8. CUSTOMER-SELECTED INTEGRATIONS
Hawi supports integrations with third-party services.
Examples may include customer-selected:
- email accounts;
- calendars;
- CRM systems;
- commerce platforms;
- productivity software;
- project-management systems;
- banking connections;
- and other business applications.
These providers are not automatically Hawi Subprocessors.
Where a customer chooses to connect an independent third-party account, the customer may already have a direct contractual relationship with that provider.
Hawi may communicate with that provider according to the customer's instructions.
The third party's own:
- privacy policy;
- terms;
- DPA;
- security practices;
- and legal obligations
may apply independently.
9. CONNECTOR CATALOGUE DOES NOT EQUAL SUBPROCESSOR LIST
A provider appearing in Hawi's Integration catalogue does not mean:
- Hawi sends that provider every customer's data;
- the provider is a Hawi Subprocessor;
- the provider is enabled;
- the customer has connected it;
- or the provider receives personal data.
A Connector generally receives data only when the relevant functionality is:
- available;
- configured;
- authorised;
- and used.
10. DOWNSTREAM SUBPROCESSORS
Many of Hawi's direct Subprocessors use their own subprocessors.
For example, a cloud or model provider may rely on:
- data-centre providers;
- cloud infrastructure;
- support services;
- content-delivery networks;
- security vendors;
- or related infrastructure.
Hawi does not reproduce every downstream provider's full changing list on this page.
Customers may review the direct provider's current subprocessor information using the resources maintained by that provider.
11. SUBPROCESSOR CHANGE NOTICES
Where required by Hawi's DPA, Hawi will provide advance notice of a new Subprocessor that will materially process Customer Personal Data.
Notice may be provided through:
- email;
- the Hawi dashboard;
- this Subprocessor List;
- or another reasonable mechanism specified by the DPA.
12. SUBPROCESSOR NOTIFICATION SUBSCRIPTION
Customers who wish to receive Subprocessor change notices may register at:
[INSERT SUBPROCESSOR NOTIFICATION EMAIL OR FORM]
Example:
subprocessors@[YOUR-DOMAIN]
Customers should keep their notification contact information current.
13. CUSTOMER OBJECTIONS
Where a customer has a contractual or statutory right to object to a new Subprocessor, the objection must:
- be made within the period specified by the applicable DPA;
- be in writing;
- identify the relevant Subprocessor;
- and explain the reasonable data-protection grounds for the objection.
Hawi and the customer will attempt in good faith to resolve a valid objection.
14. POSSIBLE RESOLUTIONS TO AN OBJECTION
Depending on technical and commercial feasibility, Hawi may consider measures such as:
- limiting use of the Subprocessor;
- changing configuration;
- offering an alternative provider;
- disabling the affected feature;
- or another appropriate solution.
Hawi cannot guarantee that an alternative architecture will always be commercially or technically available.
15. IF AN OBJECTION CANNOT BE RESOLVED
Where required by the applicable DPA, if Hawi and the customer cannot resolve a valid objection, the customer may have the right to terminate the affected Service in accordance with the DPA.
The applicable DPA governs any refund or financial consequence of such termination.
16. INTERNATIONAL DATA TRANSFERS
Some Subprocessors may process Customer Personal Data outside:
- the United Kingdom;
- European Economic Area;
- or customer's country of origin.
Where required, Hawi will use an appropriate legal mechanism for restricted transfers.
These may include:
- adequacy regulations;
- adequacy decisions;
- Standard Contractual Clauses;
- the UK Addendum;
- the UK International Data Transfer Agreement;
- binding corporate rules where legally appropriate;
- or another recognised mechanism.
17. DATA RESIDENCY
A service's primary hosting region should not be confused with exclusive data residency.
For example, a database may be hosted primarily in London while:
- support;
- security;
- metadata;
- backups;
- control-plane activity;
- or downstream Subprocessors
operate elsewhere.
Where Hawi contractually promises specific residency requirements, those requirements will be described separately.
18. MINIMUM DATA SHARING
Hawi seeks to limit Subprocessor access to information reasonably necessary to provide the relevant function.
For example:
- a model provider should receive task-relevant model context rather than unrelated Account data;
- a voice provider should receive information relevant to the call;
- and a payment provider should receive information required for payment and fraud processing.
19. SUBPROCESSOR SECURITY REVIEW
Before introducing a material Subprocessor, Hawi should assess factors proportionate to risk, including:
- service purpose;
- categories of personal data;
- security programme;
- contractual protections;
- breach obligations;
- access controls;
- encryption;
- retention;
- data location;
- transfer mechanisms;
- further subprocessors;
- regulatory history where relevant;
- and available independent assurance.
20. CONTRACTUAL PROTECTIONS
Where a provider acts as a Subprocessor, Hawi seeks to use contractual arrangements that address appropriate requirements under applicable law.
These may include obligations concerning:
- documented instructions;
- confidentiality;
- security;
- subprocessing;
- data-subject requests;
- breach assistance;
- deletion or return;
- regulatory assistance;
- and international transfers.
21. SUBPROCESSOR INCIDENTS
If a Subprocessor informs Hawi of a security incident affecting Hawi Customer Personal Data, Hawi will assess:
- what data was affected;
- which customers were affected;
- the nature of the incident;
- containment measures;
- legal notification requirements;
- and additional remediation.
Hawi will provide customer notifications where required by applicable law or contract.
22. REMOVAL OF A SUBPROCESSOR
A provider may be removed from this List where Hawi:
- stops using the provider;
- replaces the provider;
- removes the relevant feature;
- or determines that the provider no longer processes Customer Personal Data on Hawi's behalf.
Removal from this page does not necessarily mean all historical provider records are immediately deleted if lawful retention periods still apply.
23. NEW FEATURES
New Hawi features may require additional specialist providers.
Before customer personal data is materially processed by a new Subprocessor, Hawi will update this List and provide any notice required under the applicable DPA.
24. CURRENT SUBPROCESSOR SUMMARY
| Provider | Service | Status | Data potentially processed |
|---|---|---|---|
| Supabase | Database, authentication, storage and backend infrastructure | Core / Active | Account, Workspace, Agent, file and application data |
| Vercel | Hosting, application execution, delivery and operational infrastructure | Core / Active | Requests, application data and technical logs |
| OpenAI | Model inference | Active model provider | Task context, prompts and relevant Customer Personal Data |
| Anthropic | Model inference | Active model provider | Task context, prompts and relevant Customer Personal Data |
| Twilio | Voice/communications | Feature-dependent | Phone numbers, call metadata and communications data |
| ElevenLabs | Speech/voice functionality | Feature-dependent | Text, audio and voice-related information |
| Stripe | Payments | Active; role varies | Billing, payment and fraud-related information |
25. PROVIDER RESOURCES
Customers conducting supplier due diligence may request or consult information maintained by the applicable providers, including their:
- privacy notices;
- data-processing agreements;
- subprocessor lists;
- trust centres;
- security documentation;
- and international-transfer documentation.
26. HAWI DATA PROCESSING AGREEMENT
Where Hawi processes personal data on behalf of a Business Customer and applicable law requires a processor contract, the Hawi DPA should govern that processing relationship.
The DPA should address:
- subject matter;
- duration;
- nature and purpose;
- personal-data categories;
- data-subject categories;
- processing instructions;
- confidentiality;
- security;
- Subprocessors;
- data-subject rights;
- assistance;
- breaches;
- deletion and return;
- audits;
- and international transfers.
27. QUESTIONS
Questions concerning this Subprocessor List may be sent to:
Privacy: [INSERT PRIVACY EMAIL]
Legal: [INSERT LEGAL EMAIL]
Security: [INSERT SECURITY EMAIL]
Subprocessor notifications: [INSERT SUBPROCESSOR NOTIFICATION EMAIL]
28. CHANGES TO THIS LIST
This page may be updated when:
- a new Subprocessor is appointed;
- a provider is removed;
- a provider's function changes materially;
- processing locations change materially;
- or Hawi's architecture changes.
The “Last Updated” date identifies the current published version.
29. IMPORTANT DISTINCTION
For clarity:
Subprocessor does not mean “every company Hawi communicates with.”
A provider is generally listed as a Subprocessor where it processes Customer Personal Data on Hawi's behalf in connection with Hawi's provision of the Services.
Customer-selected third-party services and providers acting as independent controllers may be separately disclosed in Hawi's Privacy Policy rather than categorised as Subprocessors.
END OF SUBPROCESSOR LIST