All trust topics

Trust Center

Subprocessors

Provider information to support your data processing review.

Content updated: October 1, 2026

Understanding the Scope

Edworking uses external services to host and operate the product. Which services process your data depends on the features and integrations used. An integration you connect may also be subject to your own agreement with that provider.

The providers below are an operational overview, not an exhaustive contractual subprocessor register. A provider's role depends on the processing: for example, Edworking's own marketing is separate from processing workspace data on a customer's behalf. Request the applicable agreement and provider schedule for your organisation.

Providers and Purposes

ProviderPurpose and possible dataLocation and retention information
RailwayBackend and realtime collaboration hosting; account and workspace informationProduction service configuration checked October 1, 2026: backend in Amsterdam, Netherlands; collaboration service in California, USA. These locations do not establish the locations of every connected service or backup.
PlanetScaleManaged application database; account details and workspace recordsProduction database dashboard checked October 1, 2026: AWS London (eu-west-2). Scheduled database backups run every 12 hours with two-day retention; protected backups can remain longer. Recovery testing is separate from backup creation.
Google Cloud StorageFile storage; attachments, images and recordingsStorage settings checked October 1, 2026: private files in London (europe-west2), public-file storage in the EU multi-region. Both buckets retain deleted objects for seven days for recovery; versioning is off. Product trash cleanup is handled by a daily application job. These locations do not cover every export, backup or other Google Cloud service.
Amazon Web ServicesS3 storage and meeting or transcription services; files, recordings and audioS3 use confirmed by Edworking; meeting and transcription integrations are present in the application. Confirm the regions and retention for the feature used.
Google Gemini APIPrimary AI provider; prompts, relevant workspace context, attachments and audio for enabled featuresAPI processing terms depend on the account and features. See AI Data and Privacy; account-specific retention and data sharing settings require verification.
CrispSupport chat, service status and help centre; support messages and contact detailsUse confirmed by Edworking. Processing locations and retention require verification against the account and agreement.
MailjetMarketing and transactional email; recipient details and message contentMarketing use confirmed by Edworking; transactional delivery is also implemented in the application. Processing locations and retention require verification.

The application also integrates OpenAI for AI processing and Weaviate for search indexes. Their feature scope, processing terms and deletion handling need to be included in the applicable provider schedule. Ask which providers apply to the AI or search features your team uses.

Payment, monitoring, analytics and other communication services must also be considered when confirming the complete provider schedule for a customer's use. This overview does not imply that an unlisted service cannot process data.

Locations and Transfers

A provider name alone does not establish where all processing occurs. Hosting, support, backups and model processing may have different locations. Request the locations and transfer arrangements that apply to your intended use.