Skip to main content
ColleagueOne
Product
OverviewColleagues & teamsWorkspaceAutomationsConnectionsGovernance & security
Use casesSecurityDocsCompany
Sign inRequest access
ProductUse casesSecurityDocsCompanyRequest accessSign in
Draft — pending legal review

Legal · Service providers

Subprocessors

Providers that may process customer personal data to help Avapti operate ColleagueOne. The exact list depends on the models and connections an organisation enables.

Effective date: [DATE]

On this page

  1. What this list means
  2. Core subprocessors
  3. Model providers
  4. Customer connections
  5. Changes

1. What this list means

A subprocessor is a service provider engaged by Avapti that may process personal data on behalf of a ColleagueOne customer. This page identifies the known core providers for the private beta and the general provider categories that vary by customer configuration.

This is a draft inventory. Avapti must verify legal entity names, locations, transfer arrangements, and provider terms before publication or incorporation into a data processing addendum.

2. Core subprocessors

ProviderPurposeProcessing locationData involved
DigitalOceanCloud hosting and service infrastructureBangalore, IndiaAccount data, workspace content, service and operational data
GoogleOptional Google account sign-inGoogle-operated locations; confirm applicable region and termsName, email address, sign-in identifiers, and authentication metadata
OpenRouterModel gateway routing to the model provider selected for a runProvider-operated locations; confirm applicable region and termsPrompts, relevant workspace content, model configuration, and generated output

3. AI model providers

ColleagueOne is model-agnostic. Relevant prompts and content pass through the model gateway to the provider used for a particular run. Depending on organisation and colleague configuration, providers may include:

ProviderPurposeStatus
OpenAIModel inference for authorised colleague runsAvailable through the gateway; use depends on configuration
AnthropicModel inference for authorised colleague runsAvailable through the gateway; use depends on configuration
Other model providersModel inference where enabled through the gatewayProvider must be disclosed and contractually approved as required before use

Data location and retention can vary by provider and model. Customers should review the configured model providers and applicable data terms before submitting regulated or sensitive content.

4. Customer-enabled connections

A customer may authorise OAuth connections, plugins, or other third-party services so a colleague can perform requested work. These customer-enabled vendors receive data only when used for the authorised connection. Depending on the legal arrangement, a connected vendor may be the customer’s independent provider rather than Avapti’s subprocessor.

Connection credentials remain in the ColleagueOne gateway and are not handed to the AI colleague. The customer is responsible for deciding which connections to enable and for complying with the connected vendor’s terms.

5. Updates and objections

We may update this page when providers change. Contractual notice periods, objection rights, and any process for proposing a reasonable alternative will be set out in the customer’s agreement or data processing addendum. Customers should not rely on this draft as a substitute for those signed terms.

Contact

To request the current provider list or discuss a data processing addendum, emailhello@avapti.com.

ColleagueOne

AI colleagues that do real work,
under your governance.

Invite-only beta

Product

Colleagues & teamsWorkspaceAutomationsConnectionsGovernance & securityRequest access

Resources

DocumentationAPI referenceChangelogStatus

Company

AboutContactSecurityResponsible disclosure

Legal

PrivacyTermsCookie noticeAcceptable useDPA summarySubprocessors

© 2026 Avapti. All rights reserved.

Built for accountable work.