Dawiso s.r.o. publishes this page under Article 28 of Regulation (EU) 2023/2854, the Data Act. It states the jurisdiction to which the ICT infrastructure of the Dawiso cloud service is subject. It also describes the measures that protect customer data held in the European Union against unlawful international government access to it or transfer of it. Dawiso contracts for the Dawiso cloud service refer to this page.
Last updated: 16 September 2026
Jurisdiction of the ICT infrastructure
The Dawiso cloud service runs on infrastructure that Dawiso contracts from the companies below.
| Company | Role | Established in | Where it processes the data |
|---|---|---|---|
| Dawiso s.r.o. | Provider of the Dawiso cloud service | Czech Republic | — |
| Microsoft Ireland Operations Limited | Cloud platform that runs the service, including Azure AI Foundry | Ireland | Default: Microsoft Azure regions in the European Union. The standard AI functions use an Azure AI Foundry deployment in the EU Data Zone. Other location at the customer’s request, as agreed in the customer’s contract. |
| Amazon Web Services EMEA SARL | Cloud storage | Luxembourg, acting through its Czech branch | Default: data centers in the European Union. Other location at the customer’s request, as agreed in the customer’s contract. |
| Slack Technologies Limited | Messaging, for a customer that agrees to Slack as a communication channel | Ireland | United States |
Dawiso s.r.o. is a Czech company and is subject to Czech law and to EU law.
By default, the ICT infrastructure that runs the Dawiso cloud service is located in the European Union. Dawiso contracts for that infrastructure with companies established in the European Union. The infrastructure is therefore subject to EU law and to the law of the Member State concerned. Where a customer’s contract agrees another location, the infrastructure for that customer is also subject to the law of that location.
Slack processes data in the United States. The transfer to the United States happens only for a customer that agrees with Dawiso to use Slack as a communication channel.
Microsoft, Amazon Web Services, and Slack belong to groups whose parent companies are established in the United States. An authority outside the European Union can address a request to a parent or group company instead of the company established in the European Union. The measures under Measures against unlawful international government access and transfer address that risk.
Measures against unlawful international government access and transfer
Article 28 of the Data Act concerns non-personal data. Dawiso applies the measures below to all customer data held in the European Union. Personal data carries the additional protection described under Personal data.
Technical measures
- By default, the Dawiso cloud service, the support ticket system, and the standard AI functions run in Microsoft Azure regions in the European Union. The standard AI functions use an Azure AI Foundry deployment in the EU Data Zone.
- By default, backups of customer data are stored in data centers in the European Union.
- At the customer’s request, the Dawiso cloud service can run in another location, as agreed in the customer’s contract. Backups of that customer’s data are then stored in the same location.
- The application audit log of system and user activity is append-only. No user and no tenant administrator can change or delete an entry, through the interface or through the API.
Organizational measures
- Dawiso holds ISO/IEC 27001:2022 and ISO/IEC 27018:2019 certification for the information security management system that covers the development, operation, and delivery of the Dawiso platform.
- Dawiso also holds a SOC 2 Type 2 report and a CyberVadis rating for its security practices.
- Dawiso has appointed a data protection officer, reachable at dpo@dawiso.com.
- Dawiso staff and contractors work under the direct authority of Dawiso as persons acting under Article 29 of Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR). Each one signs a confidentiality undertaking.
Contractual measures
- Each sub-processor is bound by a written contract to the same data protection obligations that apply to Dawiso.
- Microsoft commits to challenge every government request for enterprise or public sector customer data where there is a lawful basis to do so. Microsoft also compensates the users of those customers if it discloses their data in response to a government request in breach of the GDPR.
- Amazon Web Services reviews every order it receives and objects to an order that is overbroad or otherwise inappropriate. It gives its customer, Dawiso, reasonable notice of a compelled disclosure, unless the law prohibits the notice.
- Slack participates in the EU-U.S. Data Privacy Framework through Salesforce. The Slack Data Processing Addendum also includes the EU standard contractual clauses.
- Where a sub-processor transfers personal data outside the European Economic Area, the Dawiso data processing terms require an adequacy decision first, and the EU standard contractual clauses as the fallback, with additional technical and organizational measures where they are needed.
Personal data
Article 28 of the Data Act concerns non-personal data. The GDPR and the Dawiso data processing terms govern personal data. The sub-processor list states the transfer safeguard that applies to each sub-processor.
For more information, see Sub-processors.
Changes to this page
Dawiso keeps this page updated, as Article 28 of the Data Act requires. The “Last updated” date changes with every change to the page. Advance notice of a new sub-processor follows the customer’s data processing terms.
Contact
Send questions about this page to the Dawiso data protection officer at dpo@dawiso.com.