Skip to main content

Trust & Security

Security & Compliance

How we protect your organisation's data, from encryption and access controls to GDPR compliance and responsible disclosure.

Last updated: April 2026  ·  Awaio AB  ·  Corp. ID: 559257-9832

Security is a core part of how Awaio is built and operated. We handle workplace data on behalf of organisations across Europe, and we take that responsibility seriously. This page summarises our approach to data protection, infrastructure security, and compliance obligations.

If you have questions not covered here, or you are conducting a vendor security assessment, contact us at support@awaio.com.

GDPR

Awaio AB is incorporated in Sweden and subject to the General Data Protection Regulation (GDPR) as implemented in Swedish law. We act as a data controller for data collected through our website and as a data processor when processing personal data on behalf of our customers.

Our GDPR commitments include:

  • Processing personal data only on a lawful basis
  • Providing data subjects with rights of access, rectification, erasure, and portability
  • Maintaining records of processing activities (Article 30)
  • Entering into Data Processing Agreements (DPAs) with customers upon request
  • Conducting Data Protection Impact Assessments (DPIAs) where required
  • Notifying affected customers and the Swedish Authority for Privacy Protection (IMY) within 72 hours of a confirmed personal data breach

Our full privacy practices are described in the Privacy Policy. To request a DPA or exercise your data subject rights, contact support@awaio.com.

Where your data lives

Customer data processed by Awaio is stored within the European Union. We do not transfer personal data to countries outside the EU/EEA without appropriate safeguards in place.

Our infrastructure runs on Google Cloud Platform (GCP), using EU-based regions. Subprocessors who handle personal data are subject to contractual obligations that meet GDPR transfer requirements.

Subprocessors used to run awaio.com:

  • Firebase / Google Cloud Platform, website hosting (EU regions)
  • HubSpot, website forms, live chat, and email communications
  • Google Analytics, website analytics
  • LinkedIn Insight Tag, ad conversion tracking, loaded only with your consent
  • Meta Pixel, ad conversion tracking, loaded only with your consent
  • Hotjar, session behaviour analytics, loaded only with your consent

This list covers awaio.com only. Subprocessors used by the Awaio app and admin portal are documented separately.

Data in transit & at rest

In transit: All data transmitted between clients and Awaio services is encrypted using TLS 1.2 or higher. We enforce HTTPS across all our web properties and APIs.

At rest: Data stored in our databases and file storage is encrypted at rest using AES-256. Encryption keys are managed through Google Cloud Key Management Service (KMS).

Backups: Database backups are encrypted with the same standards and stored in geographically separated EU locations.

Who can access your data

Access to customer data by Awaio personnel is restricted on a need-to-know basis. We apply the principle of least privilege across our internal systems.

  • Production access requires multi-factor authentication (MFA)
  • Access to customer data is logged and auditable
  • Employee access is reviewed and revoked promptly upon offboarding
  • Third-party access is granted only under contractual obligation and reviewed regularly

Within the Awaio platform, customer administrators control user roles, permissions, and access to their organisation's data.

Platform & availability

Awaio runs on Google Cloud Platform, leveraging managed services for compute, storage, and databases. GCP maintains its own extensive compliance certifications including ISO 27001, SOC 2, and others, details are available at cloud.google.com/security/compliance.

Our platform is designed for high availability with automatic failover and regular recovery testing. We monitor systems continuously and maintain incident response procedures to minimise disruption.

Live uptime and incident history for awaio.com, the web app, and the admin portal are published on our status page.

Report a vulnerability

If you believe you have found a security vulnerability in any Awaio product or service, please report it to us responsibly. We ask that you:

  • Contact us at support@awaio.com before disclosing publicly
  • Give us reasonable time to investigate and remediate before disclosure
  • Avoid accessing, modifying, or deleting data that does not belong to you

We will acknowledge receipt within 2 business days, keep you informed of our progress, and credit researchers who report valid vulnerabilities (if desired).

Security enquiries

For security-related questions, vendor assessments, DPA requests, or vulnerability reports:

  • Email: support@awaio.com
  • Subject line: Include "Security" or "Compliance" for faster routing
  • Post: Awaio AB, Östra Storgatan 9, 553 20 Jönköping, Sweden

For general support, visit the support page or our Help Center.