1. What this list means
A subprocessor is a service provider engaged by Avapti that may process personal data on behalf of a ColleagueOne customer. This page identifies the known core providers for the private beta and the general provider categories that vary by customer configuration.
This is a draft inventory. Avapti must verify legal entity names, locations, transfer arrangements, and provider terms before publication or incorporation into a data processing addendum.
2. Core subprocessors
| Provider | Purpose | Processing location | Data involved |
|---|---|---|---|
| DigitalOcean | Cloud hosting and service infrastructure | Bangalore, India | Account data, workspace content, service and operational data |
| Optional Google account sign-in | Google-operated locations; confirm applicable region and terms | Name, email address, sign-in identifiers, and authentication metadata | |
| OpenRouter | Model gateway routing to the model provider selected for a run | Provider-operated locations; confirm applicable region and terms | Prompts, relevant workspace content, model configuration, and generated output |
3. AI model providers
ColleagueOne is model-agnostic. Relevant prompts and content pass through the model gateway to the provider used for a particular run. Depending on organisation and colleague configuration, providers may include:
| Provider | Purpose | Status |
|---|---|---|
| OpenAI | Model inference for authorised colleague runs | Available through the gateway; use depends on configuration |
| Anthropic | Model inference for authorised colleague runs | Available through the gateway; use depends on configuration |
| Other model providers | Model inference where enabled through the gateway | Provider must be disclosed and contractually approved as required before use |
Data location and retention can vary by provider and model. Customers should review the configured model providers and applicable data terms before submitting regulated or sensitive content.
4. Customer-enabled connections
A customer may authorise OAuth connections, plugins, or other third-party services so a colleague can perform requested work. These customer-enabled vendors receive data only when used for the authorised connection. Depending on the legal arrangement, a connected vendor may be the customer’s independent provider rather than Avapti’s subprocessor.
Connection credentials remain in the ColleagueOne gateway and are not handed to the AI colleague. The customer is responsible for deciding which connections to enable and for complying with the connected vendor’s terms.
5. Updates and objections
We may update this page when providers change. Contractual notice periods, objection rights, and any process for proposing a reasonable alternative will be set out in the customer’s agreement or data processing addendum. Customers should not rely on this draft as a substitute for those signed terms.
Contact
To request the current provider list or discuss a data processing addendum, emailhello@avapti.com.