Trust & Security
Security & Compliance
How we protect your organisation's data, from encryption and access controls to GDPR compliance and responsible disclosure.
Last updated: April 2026 · Awaio AB · Corp. ID: 559257-9832
Overview
Security is a core part of how Awaio is built and operated. We handle workplace data on behalf of organisations across Europe, and we take that responsibility seriously. This page summarises our approach to data protection, infrastructure security, and compliance obligations.
If you have questions not covered here, or you are conducting a vendor security assessment, contact us at support@awaio.com.
Compliance
GDPR
Awaio AB is incorporated in Sweden and subject to the General Data Protection Regulation (GDPR) as implemented in Swedish law. We act as a data controller for data collected through our website and as a data processor when processing personal data on behalf of our customers.
Our GDPR commitments include:
- Processing personal data only on a lawful basis
- Providing data subjects with rights of access, rectification, erasure, and portability
- Maintaining records of processing activities (Article 30)
- Entering into Data Processing Agreements (DPAs) with customers upon request
- Conducting Data Protection Impact Assessments (DPIAs) where required
- Notifying affected customers and the Swedish Authority for Privacy Protection (IMY) within 72 hours of a confirmed personal data breach
Our full privacy practices are described in the Privacy Policy. To request a DPA or exercise your data subject rights, contact support@awaio.com.
Data residency
Where your data lives
Customer data processed by Awaio is stored within the European Union. We do not transfer personal data to countries outside the EU/EEA without appropriate safeguards in place.
Our infrastructure runs on Google Cloud Platform (GCP), using EU-based regions. Subprocessors who handle personal data are subject to contractual obligations that meet GDPR transfer requirements.
Subprocessors used to run awaio.com:
- Firebase / Google Cloud Platform, website hosting (EU regions)
- HubSpot, website forms, live chat, and email communications
- Google Analytics, website analytics
- LinkedIn Insight Tag, ad conversion tracking, loaded only with your consent
- Meta Pixel, ad conversion tracking, loaded only with your consent
- Hotjar, session behaviour analytics, loaded only with your consent
This list covers awaio.com only. Subprocessors used by the Awaio app and admin portal are documented separately.
Encryption
Data in transit & at rest
In transit: All data transmitted between clients and Awaio services is encrypted using TLS 1.2 or higher. We enforce HTTPS across all our web properties and APIs.
At rest: Data stored in our databases and file storage is encrypted at rest using AES-256. Encryption keys are managed through Google Cloud Key Management Service (KMS).
Backups: Database backups are encrypted with the same standards and stored in geographically separated EU locations.
Access controls
Who can access your data
Access to customer data by Awaio personnel is restricted on a need-to-know basis. We apply the principle of least privilege across our internal systems.
- Production access requires multi-factor authentication (MFA)
- Access to customer data is logged and auditable
- Employee access is reviewed and revoked promptly upon offboarding
- Third-party access is granted only under contractual obligation and reviewed regularly
Within the Awaio platform, customer administrators control user roles, permissions, and access to their organisation's data.
Infrastructure
Platform & availability
Awaio runs on Google Cloud Platform, leveraging managed services for compute, storage, and databases. GCP maintains its own extensive compliance certifications including ISO 27001, SOC 2, and others, details are available at cloud.google.com/security/compliance.
Our platform is designed for high availability with automatic failover and regular recovery testing. We monitor systems continuously and maintain incident response procedures to minimise disruption.
Live uptime and incident history for awaio.com, the web app, and the admin portal are published on our status page.
Responsible disclosure
Report a vulnerability
If you believe you have found a security vulnerability in any Awaio product or service, please report it to us responsibly. We ask that you:
- Contact us at support@awaio.com before disclosing publicly
- Give us reasonable time to investigate and remediate before disclosure
- Avoid accessing, modifying, or deleting data that does not belong to you
We will acknowledge receipt within 2 business days, keep you informed of our progress, and credit researchers who report valid vulnerabilities (if desired).
Contact
Security enquiries
For security-related questions, vendor assessments, DPA requests, or vulnerability reports:
- Email: support@awaio.com
- Subject line: Include "Security" or "Compliance" for faster routing
- Post: Awaio AB, Östra Storgatan 9, 553 20 Jönköping, Sweden
For general support, visit the support page or our Help Center.