Avantwerk CRM — Processor and Vendor Register

Version 3.1 · effective date to be set on publication

A vendor’s role depends on context and enabled feature. This Register does not present the hosted platform supplier’s downstream subprocessors as organisations contracted directly by Avantwerk. The supplier’s full name, applicable DPA and current downstream-register link are stated in the DPA, where the Customer authorises the engagement.

1. Customer CRM chain

Layer Organisation Context and role Location / transfer
Customer Business Customer Normally controller; roles shift where Customer is itself a processor Set by Customer
Avantwerk Bennovate sp. z o.o. Processor on Customer instructions Poland / EEA; access within service scope
Platform Hosted-platform supplier named in the DPA Avantwerk direct subprocessor for the hosted platform and enabled functions US, India and other locations disclosed in the DPA and supplier register; mechanism depends on recipient

The platform supplier maintains its current downstream register at the address stated in the DPA. On the verification date of 31 August 2026, the register included, among others:

  • infrastructure: Google Cloud Services and Amazon Web Services — storage, US;
  • optional/supporting services: Twilio, Mailgun, Chargebacks911, Pendo, ChartMogul, People Data Labs, Freshworks, Zapier, Stripe, Mozart Data and Persona — US;
  • AI: BotPress, RetellAI, Synthflow and OpenAI — US;
  • supplier affiliates in India and the United States.

This is a dated informational snapshot, not the binding maintained register. Recipient and scope depend on enabled features. Cloudflare, Anthropic, Hetzner and Fakturownia are not listed there as downstream subprocessors of the hosted-platform supplier.

2. Avantwerk direct subprocessors for a Customer project

This table contains only a vendor or contractor engaged by Avantwerk that actually receives access to the relevant Customer's CRM data. Each entry requires the full entity, service, data, purpose, transfer, DPA and an active Order. No completed entry means no authorisation to disclose data.

Entity and service Project / function Data and purpose Country / mechanism Status
[complete or: none] [complete] [complete] [complete] [approved / disabled]

An individual or implementation company with data access must either act under Bennovate's direct authority and confidentiality obligations or be a subprocessor bound by an appropriate agreement. The label “partner” does not determine that role.

3. Providers contracted directly by the Customer

A Customer account with an accounting, analytics, advertising, communications or other provider does not become an Avantwerk subprocessor merely because Avantwerk configures the integration. The Order must identify the account owner, specific provider and service, data, purpose, Avantwerk access and revocation method. A group name such as “Google” without the particular service and account is insufficient.

4. Avantwerk direct vendors in separate controller contexts

Vendor Confirmed product context Role / boundary Publication evidence gate
Stripe Payments Europe / Stripe group Avantwerk account billing connection; public paid journey not yet live Avantwerk billing vendor; not the CRM contact database merely because connected confirm contracting entity, flow and activated payments
Cloudflare, Inc. Avantwerk public-site DNS, delivery and security Avantwerk website-controller context; IP, requests and security telemetry confirm zones, logs, retention and contracting entity
Hetzner Online GmbH Defined services hosted directly by Bennovate CRM subprocessor only if an Order routes CRM data there identify service, data and environment or omit from CRM chain

4.1. Office and AI tools requiring account and data-flow classification

The tools below are not automatically subprocessors of Customer CRM data. They become Avantwerk direct subprocessors for a particular project only where Avantwerk, acting as processor, discloses Customer personal data to them or gives them access to it. Until then, they are vendors in a separate controller context or locally operated software.

Service / label Correct default classification Condition for use with Customer data Evidence status
Google Workspace (for example Gmail, Drive and Docs) Bennovate office vendor in its controller context Add to table 2 if project data enters a Bennovate Workspace account; confirm contracting entity, region, DPA and retention Workspace use confirmed; data scope and contract to confirm
Microsoft 365 (Outlook, OneDrive and Office applications) Bennovate office vendor in its controller context As above if project email or files containing Customer data enter Bennovate's tenant operator-reported use; tenant, licence, entity and flow to confirm
OpenAI (ChatGPT Business and Codex) Bennovate AI vendor under a business account; distinct from any use of the same technology in the hosted-platform supplier’s downstream chain Add to table 2 for a project if Avantwerk submits Customer data; specify purpose, data categories, retention settings and minimisation business account confirmed by operator; contracting entity, DPA and configuration to document
Gemini in Google Workspace AI feature within the business Google Workspace environment, not the consumer Gemini service Add to table 2 if Avantwerk submits Customer data; identify Workspace edition, settings, purpose and retention Workspace account confirmed by operator; edition, contracting entity and configuration to document
Amazon Web Services — Amazon Bedrock, EU workload region Bennovate cloud AI vendor; the selected model and feature affect the applicable terms and processing Add to table 2 if a project routes Customer data to Bedrock; identify account, exact region, model, logging/retention, encryption and purpose business use and EU workload region confirmed by operator; account, exact region, model and configuration to document
OpenClaw Software / execution layer, not itself a legal entity or automatic subprocessor Record the model, hosting, communications and memory providers actually configured for the deployment runtime providers and flows to inventory
Blackflake Bennovate-owned portfolio brand/platform, not an external vendor merely by name A separate legal relationship or infrastructure requires the entity, role and actual flow; the brand name does not replace them do not list as a subprocessor without a concrete flow

“CrowdFlow” has not been confirmed as a provider. If this means Cloudflare, it is already listed above. If it means another service, its full legal name, account and data flow must be established before entry.

Fakturownia and Anthropic are not stated as current direct CRM vendors without contractual and runtime evidence. If they process only Bennovate-controller records, they belong in that separate register.

5. Minimum record before activation

Field Required determination
Full legal entity and service [complete]
Role and context [complete]
Data and subject categories [complete]
Purpose and optional-feature trigger [complete]
Processing country and transfer mechanism [complete]
DPA / vendor notice [complete]
Added and last-verified dates [complete]

6. Changes and objections

Where reasonably possible, Avantwerk gives at least 30 days’ notice before a new direct CRM subprocessor. Customers may object on reasonable data-protection grounds. For the hosted-platform supplier’s downstream chain, Avantwerk relays material notice received without undue delay and does not promise a longer period than its supplier provides.

The change-notification and data-protection contact is [email protected]. This is a functional company mailbox and does not by itself represent appointment of a data protection officer.

Avantwerk CRM contractual content · Bennovate sp. z o.o. · [email protected]