Trust Center
Subprocessors
3 subprocessors, all of them in the United States. The column that matters is what each one can see, so it is the one stated in full.
The list
Every subprocessor is contracted under a data processing agreement that includes the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK, and is assessed before onboarding under the vendor risk control on this page. Our DPA lists them, and we will tell you before a new one starts processing customer data.
On models specifically: the models Harmony runs are hosted on AWS inside our own account, your prompts and context are not handed to a consumer AI product, and no model provider retains them. If you need the exact models and providers in scope for your workspace named in writing, ask us and we will put it in writing.
| Subprocessor | Purpose | Customer data it can see | Location | Transfer mechanism |
|---|---|---|---|---|
Amazon Web Services, Inc. | Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account. | All customer data: request and conversation content, attachments, directory and device records synced from your connected tools, and audit logs. | United States | Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum |
| Authentication provider. Handles sign-in, session issuance and SSO federation. | Account identifiers and authentication metadata: name, work email address, identity provider and sign-in events. No request content. | United States | Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum | |
PostHog, Inc. | Product analytics. How the product is used, so we can see what is and is not working. | Product usage events and the account identifiers attached to them. No request content and no attachments. | United States | Data processing agreement including the EU Standard Contractual Clauses and the UK Addendum |
Our DPA lists these contractually. Ask for it at privacy@harmony.io or through the request form.
What we process for you
Harmony is the processor and you are the controller for everything in this table. It is processed to provide the service, and for nothing else.
| Category | Processed |
|---|---|
| Directory and identity data | Yes - Names, work email addresses, job details and group memberships, synced from the identity provider and HR system an admin connected. |
| Request and conversation content | Yes - What your employees ask Harmony, the agent’s replies, and anything they attach. Retained for the workspace and deleted with it. |
| Device and asset records | Yes - Device, asset and licence records read from the endpoint and asset tools an admin connected. |
| Special category data | No - Not required by the service and never requested by it. Harmony does not ask for health, biometric, or racial or ethnic origin data. |
| Payment card data | No - Never processed or stored in the Harmony platform. |
What we process as a controller
Our own data, where Harmony is the controller. Nothing here is customer data you put into the platform.
| Category | Processed |
|---|---|
| Employee personal data | Yes - Our own employees and contractors, for employment and access management. |
| Business contact data | Yes - Names, work email addresses and company details of the people we talk to about Harmony. |
| Website analytics | Yes - Usage of harmony.io and this page. See the Cookies Notice at https://harmony.io/cookies-notice. |

