Notification policy

Before we engage a new sub-processor that processes customer personal data, we give existing customers at least 30 days' written notice so they can review and object. If a customer objects on reasonable data-protection grounds and we can't accommodate, they can terminate the affected service scope.

Current sub-processors

Vendor Purpose Region Transfer mechanism
Amazon Web Services (AWS)
Amazon Web Services EMEA SARL
Underlying cloud compute (Lambda), object storage (S3), NoSQL database (DynamoDB), secrets (Secrets Manager), messaging queues (SQS), event bus (EventBridge), CDN (CloudFront), identity (Cognito). EU — eu-central-1 (Frankfurt) DPA + Standard Contractual Clauses under the AWS master customer agreement.
Meta / WhatsApp Business Platform
WhatsApp Ireland Limited
Delivery of WhatsApp messages between candidates and the SmartHire service. Handles the underlying messaging protocol, encryption in transit, and delivery receipts. Global — EU-region delivery where available; may transit Meta infrastructure elsewhere in transit Meta Business Terms + WhatsApp Business Solution Terms + Meta Data Processing Terms (SCCs by reference).
AWS End User Messaging Social
AWS socialmessaging service
Outbound WhatsApp message delivery on AWS-managed WABA phone numbers. IAM-authenticated; no long-lived Meta access token stored. EU — eu-central-1 Same DPA + SCCs as AWS above.
Amazon Bedrock
AWS-hosted Anthropic Claude models
LLM inference for screening conversations, structured extraction, scoring, summaries. Bedrock is stateless per call — prompts and candidate data are not used to train the underlying models per AWS policy. EU — eu-central-1 Bedrock is an AWS service under the same DPA + SCCs.
Amazon Transcribe Speech-to-text for candidate voice notes. Audio buffers are ephemeral inside the service; SmartHire stores the resulting text transcript only. EU — eu-central-1 Same DPA + SCCs as AWS above.
Amazon Polly Text-to-speech for optional voice-out replies to candidates. EU — eu-central-1 Same DPA + SCCs as AWS above.
Amazon Cognito Identity provider for SmartHire dashboard users (recruiters, admins, hiring managers, interviewers). Handles authentication, MFA, password reset, Google federation. EU — eu-central-1 Same DPA + SCCs as AWS above.
Amazon SES
Simple Email Service
Transactional email — account verification, magic-link invitations to hiring managers, interview confirmations, weekly digests. EU — eu-central-1 Same DPA + SCCs as AWS above.
Google LLC
Calendar API + Sign-In
Optional: Google Calendar integration for interview scheduling; Google Sign-In for dashboard authentication. Only used when the customer connects a Google account. Global Google Cloud DPA + SCCs, invoked only for customers who connect Google services.
PostHog
PostHog Inc., EU-region deployment
Product analytics and session replay for signed-in dashboard users (app.smarthire.chat). Served same-origin via /ingest/*; uses browser localStorage and sets no cookies. Session recordings mask every input field by default and are disabled on login and credential pages. Not applied to candidate WhatsApp interactions. EU — eu.i.posthog.com PostHog DPA + SCCs under PostHog's EU-region terms.
RecordX
Interview recording & transcription
Optional: interview-recording capture, transcription, and audio playback for interviews booked through SmartHire. Audio and transcripts can be purged on candidate erasure. EU — eu-central-1 Operated under the same AWS DPA + SCCs.
Creem
Payment processor — not yet active
Billing and subscription payment processing. Not active in production as of this version — no live payment events flow to Creem. Will be enabled when the first paid plan ships. Global Creem's standard DPA / SCCs will govern when payments are enabled.

Related sub-processors (customer-controlled)

These are only in scope for customers who choose to connect them:

What we do not use

How to subscribe to updates

Customers with an active account are notified automatically. If you'd like to receive change notices as a prospective customer or reviewer, email legal@smarthire.chat and we'll add you to the notification list.