Trust Center

Subprocessors

3 subprocessors, all of them in the United States. The column that matters is what each one can see, so it is the one stated in full.

The list

Every subprocessor is contracted under a data processing agreement that includes the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK, and is assessed before onboarding under the vendor risk control on this page. Our DPA lists them, and we will tell you before a new one starts processing customer data.

On models specifically: the models Harmony runs are hosted on AWS inside our own account, your prompts and context are not handed to a consumer AI product, and no model provider retains them. If you need the exact models and providers in scope for your workspace named in writing, ask us and we will put it in writing.

Harmony subprocessors, what they do, what customer data they can see, where they process it and the transfer mechanism
SubprocessorPurposeCustomer data it can seeLocationTransfer mechanism
Amazon Web Services, Inc. logoAmazon Web Services, Inc.Primary cloud provider. All Harmony compute, storage and networking runs here, and the language models Harmony uses are hosted inside our own AWS account.All customer data: request and conversation content, attachments, directory and device records synced from your connected tools, and audit logs.United StatesData processing agreement including the EU Standard Contractual Clauses and the UK Addendum
Descope, Inc. logoDescope, Inc.Authentication provider. Handles sign-in, session issuance and SSO federation.Account identifiers and authentication metadata: name, work email address, identity provider and sign-in events. No request content.United StatesData processing agreement including the EU Standard Contractual Clauses and the UK Addendum
PostHog, Inc. logoPostHog, Inc.Product analytics. How the product is used, so we can see what is and is not working.Product usage events and the account identifiers attached to them. No request content and no attachments.United StatesData processing agreement including the EU Standard Contractual Clauses and the UK Addendum

Our DPA lists these contractually. Ask for it at privacy@harmony.io or through the request form.

What we process for you

Harmony is the processor and you are the controller for everything in this table. It is processed to provide the service, and for nothing else.

Customer data Harmony processes as a processor
CategoryProcessed
Directory and identity dataYes - Names, work email addresses, job details and group memberships, synced from the identity provider and HR system an admin connected.
Request and conversation contentYes - What your employees ask Harmony, the agent’s replies, and anything they attach. Retained for the workspace and deleted with it.
Device and asset recordsYes - Device, asset and licence records read from the endpoint and asset tools an admin connected.
Special category dataNo - Not required by the service and never requested by it. Harmony does not ask for health, biometric, or racial or ethnic origin data.
Payment card dataNo - Never processed or stored in the Harmony platform.

What we process as a controller

Our own data, where Harmony is the controller. Nothing here is customer data you put into the platform.

Personal data Harmony processes as a controller
CategoryProcessed
Employee personal dataYes - Our own employees and contractors, for employment and access management.
Business contact dataYes - Names, work email addresses and company details of the people we talk to about Harmony.
Website analyticsYes - Usage of harmony.io and this page. See the Cookies Notice at https://harmony.io/cookies-notice.