Trust Center

Sub-processors

Last updated: May 28, 2026

To deliver the Hirex platform, we engage a limited set of third-party sub-processors. Each one is bound by appropriate data protection terms, including, where applicable, the European Commission's Standard Contractual Clauses for international transfers, and is contractually obligated to handle customer data with the same standards we apply ourselves.

Change notifications. We notify customers at least 30 days before adding or replacing a sub-processor that processes customer personal data. Customers may object during the notification period; if the parties cannot resolve the objection, the customer may terminate the affected portion of the Services without penalty.


Core sub-processors

These are engaged for all customer tenants.

Hosting and infrastructure

VendorPurposeData processedRegion
Amazon Web Services (AWS)Cloud infrastructureAll customer dataIreland (eu-west-1)
Heroku, a Salesforce companyPlatform-as-a-Service (application and worker hosting)All customer dataAWS Ireland
Heroku PostgresPrimary relational databaseCandidates, users, applications, all structured PIIAWS Ireland
Heroku RedisCache and queueSession state and ephemeral background workAWS Ireland
Cloudflare R2Object storageRésumés, attachments, interview recordings, audit archivesEuropean Union
CloudflareCDN, Web Application Firewall, DDoS protection, bot management, edge TLS terminationIPs, network metadata, bot detection signalsGlobal edge network

AI and machine learning

VendorPurposeData processedRegion
OpenAICV evaluation, criteria generation, content generationCandidate and job data sent at the time of feature useUnited States
AnthropicCandidate evaluation, content generationCandidate and job data sent at the time of feature useUnited States
Google (Gemini API)Résumé parsingUploaded CV contentUnited States
DeepgramSpeech-to-text transcription of one-way video interviews (where enabled)Interview audioUnited States
Exa.aiAI-assisted candidate sourcingSearch queriesUnited States

Customer data is not used to train any AI provider's models. All four LLM providers operate on zero-data-retention terms where supported on their enterprise tier. Transfers are covered by Standard Contractual Clauses (Module 2) and documented Transfer Impact Assessments. See our Responsible AI page for detail.

Email and customer communications

VendorPurposeData processedRegion
Mailgun (Sinch)Transactional and candidate email deliveryRecipient addresses, email contentUnited States
IntercomIn-app and pre-sale support chatUser identity, support conversation contentUnited States

Calendar and interview scheduling

VendorPurposeData processedRegion
NylasCalendar and email sync for interview schedulingCalendar events, attendees, scheduling metadataUnited States

Analytics and observability

VendorPurposeData processedRegion
SentryApplication error monitoringStack traces, user/context identifiersUnited States
Scout APMApplication performance monitoringRequest and query telemetryUnited States
BetterStack (Logtail)Centralized log aggregationApplication logsUnited States
PostHogProduct analyticsFeature usage events, properties, session infoUnited States
Google BigQueryReporting and analytics warehouseAggregated, pseudonymized analyticsUnited States

Payments

VendorPurposeData processedRegion
StripeSubscription billingBilling contact, payment method (Stripe stores card data, Hirex does not)United States

Network

VendorPurposeData processedRegion
QuotaGuardStatic-IP egress proxy for outbound API callsNetwork metadata onlyUnited States

Customer-enabled integrations

The following are engaged only when a customer explicitly enables the corresponding integration in their tenant. Where engaged, the customer is the data controller and is responsible for the contractual relationship with the integration provider. Hirex passes data to these providers strictly on the customer's documented instruction.


Change notifications

We notify customers at least 30 days in advance of:

  • adding a new sub-processor that processes customer personal data
  • replacing an existing sub-processor with a different one
  • material changes to the purpose or scope of an existing sub-processor's processing

Notifications are published on this page. Customers also receive advance notice through the contact details in their agreement.


How to read this list

Each vendor named in the Core sub-processors tables is engaged for all customer tenants by default. Engagement of an integration in the "Customer-enabled" section requires the customer's explicit configuration.

Where data is transferred outside the European Economic Area (the United States, in particular), the transfer is governed by the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module 2: Controller-to-Processor) and supplementary safeguards documented in our Transfer Impact Assessments. Summaries are available to customers on request under NDA.

For details on our hosting, encryption, and security practices, see our Security page. For details on our AI use, see our Responsible AI page. For our Data Processing Addendum, see the DPA.


Contact

  • Sub-processor questions: [email protected]
  • Data Protection Officer: Burak Yılmaz ([email protected])
  • Sub-processor change notifications: published on this page; customers receive advance notice per their agreement.

Unlock your
recruitment potential!

Hirex is the only recruitment platform you need.

© Hirex HR, Inc.