← Back to Security

Sub-processors

The third parties that process personal data on our behalf. To request copies of the relevant DPAs / transfer safeguards, email contact@personallyhired.com.

Currently active

These providers process personal data today.

Sub-processorPurposePersonal dataLocation / transfer safeguard
Vercel Inc.Application hosting & content delivery (CDN)Request/usage data in transit, server logs, IP addressUS company; served from the EU (Frankfurt). DPA with EU SCCs. View DPA →
Neon Inc.Managed PostgreSQL database (primary data store)All application data (accounts, applications, etc.)US company; data hosted in AWS eu-central-1 (Frankfurt, EU). DPA with EU SCCs. View DPA →
Resend (Resend, Inc.)Transactional & notification email deliveryRecipient name & email address, and message content (e.g. account confirmations, password resets, hiring notifications)US company; email processed in the EU (Ireland, AWS eu-west-1). DPA with EU SCCs. View DPA →
Microsoft 365 (Microsoft Corporation)Business email mailbox — receiving replies and direct correspondence sent to our contact address (contact@personallyhired.com); outbound system email is sent via Resend, aboveSender name & email address, and the content of email sent to or in reply to usMicrosoft is a US company; transfers rely on the EU-US Data Privacy Framework and EU SCCs. The mailbox is purchased and administered through GoDaddy (reseller), which therefore has administrative access to it. View DPA →
Vercel Blob (Vercel Inc.)Private storage for candidate-uploaded résumé filesRésumé documents (candidate personal data)Stored in the EU (Frankfurt). Private access — files are served only to the owning employer via authenticated, time-limited links, never publicly. DPA with EU SCCs. View DPA →
WherebyPrivate, one-time video rooms for booked introductory callsParticipant display name; in-call audio & video; connection metadata. Calls are not recorded. Each room is unique to a single call and expires shortly after it ends.EEA-based provider (Norway). No personal meeting links or accounts are exposed — each party receives a room link scoped to their one call. DPA with EU SCCs. View DPA →
Stripe (Stripe, Inc.)Subscription billing & payment processing for employer plansBilling contact name & email, subscription and payment metadata; card details are entered directly with Stripe and held by Stripe, not by usUS/EU. DPA with EU SCCs / the EU-US Data Privacy Framework. View DPA →

Planned

Mocked today; these become active at launch as integrations go live.

Sub-processorPurposePersonal dataLocation / transfer safeguard
Google (reCAPTCHA)Bot / abuse preventionIP address, interaction signalsUSA. Google DPA / SCCs / DPF.
Scheduling (e.g. Calendly / Google / Microsoft)Interview schedulingName, email, calendar eventTBD. DPA / SCCs.

Source code is stored on GitHub (USA); it does not contain production personal data. We aim to keep processing within the EU; where a provider is US-based, transfers rely on SCCs / the EU-US Data Privacy Framework via their DPA. See our Privacy Policy and Security overview.