← Back to Security

Sub-processors

The third parties that process personal data on our behalf. To request copies of the relevant DPAs / transfer safeguards, email contact@personallyhired.com.

Currently active

These providers process personal data today.

Sub-processorPurposePersonal dataLocation / transfer safeguard
Vercel Inc.Application hosting & content delivery (CDN)Request/usage data in transit, server logs, IP addressUS company; served from the EU (Frankfurt). DPA with EU SCCs. View DPA →
Neon Inc.Managed PostgreSQL database (primary data store)All application data (accounts, applications, etc.)US company; data hosted in AWS eu-central-1 (Frankfurt, EU). DPA with EU SCCs. View DPA →
Resend (Resend, Inc.)Transactional & notification email deliveryRecipient name & email address, and message content (e.g. account confirmations, password resets, hiring notifications)US company; email processed in the EU (Ireland, AWS eu-west-1). DPA with EU SCCs. View DPA →
Vercel Blob (Vercel Inc.)Private storage for candidate-uploaded résumé filesRésumé documents (candidate personal data)Stored in the EU (Frankfurt). Private access — files are served only to the owning employer via authenticated, time-limited links, never publicly. DPA with EU SCCs. View DPA →

Planned

Mocked today; these become active at launch as integrations go live.

Sub-processorPurposePersonal dataLocation / transfer safeguard
Google (reCAPTCHA)Bot / abuse preventionIP address, interaction signalsUSA. Google DPA / SCCs / DPF.
Scheduling (e.g. Calendly / Google / Microsoft)Interview schedulingName, email, calendar eventTBD. DPA / SCCs.
WherebyPrivate 1:1 video rooms for booked introductory callsParticipant display name; in-call audio/video; connection metadataEEA-based provider (Norway); call-media routing region to be confirmed with Whereby.
Payments (e.g. Stripe)Subscription billingBilling contact, payment metadataUSA/EU. DPA / SCCs.

Source code is stored on GitHub (USA); it does not contain production personal data. We aim to keep processing within the EU; where a provider is US-based, transfers rely on SCCs / the EU-US Data Privacy Framework via their DPA. See our Privacy Policy and Security overview.