← Back to Security
Sub-processors
The third parties that process personal data on our behalf. To request copies of the relevant DPAs / transfer safeguards, email contact@personallyhired.com.
Currently active
These providers process personal data today.
| Sub-processor | Purpose | Personal data | Location / transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting & content delivery (CDN) | Request/usage data in transit, server logs, IP address | US company; served from the EU (Frankfurt). DPA with EU SCCs. View DPA → |
| Neon Inc. | Managed PostgreSQL database (primary data store) | All application data (accounts, applications, etc.) | US company; data hosted in AWS eu-central-1 (Frankfurt, EU). DPA with EU SCCs. View DPA → |
| Resend (Resend, Inc.) | Transactional & notification email delivery | Recipient name & email address, and message content (e.g. account confirmations, password resets, hiring notifications) | US company; email processed in the EU (Ireland, AWS eu-west-1). DPA with EU SCCs. View DPA → |
| Microsoft 365 (Microsoft Corporation) | Business email mailbox — receiving replies and direct correspondence sent to our contact address (contact@personallyhired.com); outbound system email is sent via Resend, above | Sender name & email address, and the content of email sent to or in reply to us | Microsoft is a US company; transfers rely on the EU-US Data Privacy Framework and EU SCCs. The mailbox is purchased and administered through GoDaddy (reseller), which therefore has administrative access to it. View DPA → |
| Vercel Blob (Vercel Inc.) | Private storage for candidate-uploaded résumé files | Résumé documents (candidate personal data) | Stored in the EU (Frankfurt). Private access — files are served only to the owning employer via authenticated, time-limited links, never publicly. DPA with EU SCCs. View DPA → |
| Whereby | Private, one-time video rooms for booked introductory calls | Participant display name; in-call audio & video; connection metadata. Calls are not recorded. Each room is unique to a single call and expires shortly after it ends. | EEA-based provider (Norway). No personal meeting links or accounts are exposed — each party receives a room link scoped to their one call. DPA with EU SCCs. View DPA → |
| Stripe (Stripe, Inc.) | Subscription billing & payment processing for employer plans | Billing contact name & email, subscription and payment metadata; card details are entered directly with Stripe and held by Stripe, not by us | US/EU. DPA with EU SCCs / the EU-US Data Privacy Framework. View DPA → |
Planned
Mocked today; these become active at launch as integrations go live.
| Sub-processor | Purpose | Personal data | Location / transfer safeguard |
|---|---|---|---|
| Google (reCAPTCHA) | Bot / abuse prevention | IP address, interaction signals | USA. Google DPA / SCCs / DPF. |
| Scheduling (e.g. Calendly / Google / Microsoft) | Interview scheduling | Name, email, calendar event | TBD. DPA / SCCs. |
Source code is stored on GitHub (USA); it does not contain production personal data. We aim to keep processing within the EU; where a provider is US-based, transfers rely on SCCs / the EU-US Data Privacy Framework via their DPA. See our Privacy Policy and Security overview.