A vendor’s role depends on context and enabled feature. This Register does not present the hosted platform supplier’s downstream subprocessors as organisations contracted directly by Avantwerk. The supplier’s full name, applicable DPA and current downstream-register link are stated in the DPA, where the Customer authorises the engagement.
1. Customer CRM chain
| Layer | Organisation | Context and role | Location / transfer |
|---|---|---|---|
| Customer | Business Customer | Normally controller; roles shift where Customer is itself a processor | Set by Customer |
| Avantwerk | Bennovate sp. z o.o. | Processor on Customer instructions | Poland / EEA; access within service scope |
| Platform | Hosted-platform supplier named in the DPA | Avantwerk direct subprocessor for the hosted platform and enabled functions | US, India and other locations disclosed in the DPA and supplier register; mechanism depends on recipient |
The platform supplier maintains its current downstream register at the address stated in the DPA. On the verification date of 31 August 2026, the register included, among others:
- infrastructure: Google Cloud Services and Amazon Web Services — storage, US;
- optional/supporting services: Twilio, Mailgun, Chargebacks911, Pendo, ChartMogul, People Data Labs, Freshworks, Zapier, Stripe, Mozart Data and Persona — US;
- AI: BotPress, RetellAI, Synthflow and OpenAI — US;
- supplier affiliates in India and the United States.
This is a dated informational snapshot, not the binding maintained register. Recipient and scope depend on enabled features. Cloudflare, Anthropic, Hetzner and Fakturownia are not listed there as downstream subprocessors of the hosted-platform supplier.
2. Avantwerk direct subprocessors for a Customer project
This table contains only a vendor or contractor engaged by Avantwerk that actually receives access to the relevant Customer's CRM data. Each entry requires the full entity, service, data, purpose, transfer, DPA and an active Order. No completed entry means no authorisation to disclose data.
| Entity and service | Project / function | Data and purpose | Country / mechanism | Status |
|---|---|---|---|---|
[complete or: none] |
[complete] |
[complete] |
[complete] |
[approved / disabled] |
An individual or implementation company with data access must either act under Bennovate's direct authority and confidentiality obligations or be a subprocessor bound by an appropriate agreement. The label “partner” does not determine that role.
3. Providers contracted directly by the Customer
A Customer account with an accounting, analytics, advertising, communications or other provider does not become an Avantwerk subprocessor merely because Avantwerk configures the integration. The Order must identify the account owner, specific provider and service, data, purpose, Avantwerk access and revocation method. A group name such as “Google” without the particular service and account is insufficient.
4. Avantwerk direct vendors in separate controller contexts
| Vendor | Confirmed product context | Role / boundary | Publication evidence gate |
|---|---|---|---|
| Stripe Payments Europe / Stripe group | Avantwerk account billing connection; public paid journey not yet live | Avantwerk billing vendor; not the CRM contact database merely because connected | confirm contracting entity, flow and activated payments |
| Cloudflare, Inc. | Avantwerk public-site DNS, delivery and security | Avantwerk website-controller context; IP, requests and security telemetry | confirm zones, logs, retention and contracting entity |
| Hetzner Online GmbH | Defined services hosted directly by Bennovate | CRM subprocessor only if an Order routes CRM data there | identify service, data and environment or omit from CRM chain |
4.1. Office and AI tools requiring account and data-flow classification
The tools below are not automatically subprocessors of Customer CRM data. They become Avantwerk direct subprocessors for a particular project only where Avantwerk, acting as processor, discloses Customer personal data to them or gives them access to it. Until then, they are vendors in a separate controller context or locally operated software.
| Service / label | Correct default classification | Condition for use with Customer data | Evidence status |
|---|---|---|---|
| Google Workspace (for example Gmail, Drive and Docs) | Bennovate office vendor in its controller context | Add to table 2 if project data enters a Bennovate Workspace account; confirm contracting entity, region, DPA and retention | Workspace use confirmed; data scope and contract to confirm |
| Microsoft 365 (Outlook, OneDrive and Office applications) | Bennovate office vendor in its controller context | As above if project email or files containing Customer data enter Bennovate's tenant | operator-reported use; tenant, licence, entity and flow to confirm |
| OpenAI (ChatGPT Business and Codex) | Bennovate AI vendor under a business account; distinct from any use of the same technology in the hosted-platform supplier’s downstream chain | Add to table 2 for a project if Avantwerk submits Customer data; specify purpose, data categories, retention settings and minimisation | business account confirmed by operator; contracting entity, DPA and configuration to document |
| Gemini in Google Workspace | AI feature within the business Google Workspace environment, not the consumer Gemini service | Add to table 2 if Avantwerk submits Customer data; identify Workspace edition, settings, purpose and retention | Workspace account confirmed by operator; edition, contracting entity and configuration to document |
| Amazon Web Services — Amazon Bedrock, EU workload region | Bennovate cloud AI vendor; the selected model and feature affect the applicable terms and processing | Add to table 2 if a project routes Customer data to Bedrock; identify account, exact region, model, logging/retention, encryption and purpose | business use and EU workload region confirmed by operator; account, exact region, model and configuration to document |
| OpenClaw | Software / execution layer, not itself a legal entity or automatic subprocessor | Record the model, hosting, communications and memory providers actually configured for the deployment | runtime providers and flows to inventory |
| Blackflake | Bennovate-owned portfolio brand/platform, not an external vendor merely by name | A separate legal relationship or infrastructure requires the entity, role and actual flow; the brand name does not replace them | do not list as a subprocessor without a concrete flow |
“CrowdFlow” has not been confirmed as a provider. If this means Cloudflare, it is already listed above. If it means another service, its full legal name, account and data flow must be established before entry.
Fakturownia and Anthropic are not stated as current direct CRM vendors without contractual and runtime evidence. If they process only Bennovate-controller records, they belong in that separate register.
5. Minimum record before activation
| Field | Required determination |
|---|---|
| Full legal entity and service | [complete] |
| Role and context | [complete] |
| Data and subject categories | [complete] |
| Purpose and optional-feature trigger | [complete] |
| Processing country and transfer mechanism | [complete] |
| DPA / vendor notice | [complete] |
| Added and last-verified dates | [complete] |
6. Changes and objections
Where reasonably possible, Avantwerk gives at least 30 days’ notice before a new direct CRM subprocessor. Customers may object on reasonable data-protection grounds. For the hosted-platform supplier’s downstream chain, Avantwerk relays material notice received without undue delay and does not promise a longer period than its supplier provides.
The change-notification and data-protection contact is [email protected]. This is a functional company mailbox and does not by itself represent appointment of a data protection officer.
