Subprocessor transparency

This page lists the providers Skilltage uses to operate its B2B recruitment service.

Processor role

Customer organisations are normally controllers for candidate and recruitment data. Skilltage acts as processor for customer recruitment workflows and uses subprocessors to provide hosting, storage, authentication, AI assistance, diagnostics, analytics, transactional email, and support.

Skilltage uses the providers below to operate the service. Organisation-level legal acceptance is handled during onboarding, while customer-specific candidate notices remain the customer's responsibility.

Cloudflare

  • Purpose: public landing, authenticated frontend, candidate, and ops frontend hosting; edge delivery; request routing; Turnstile protection for public forms; and support email routing through Cloudflare Email Routing.
  • Data involved: visitor and app route request metadata, security metadata, limited form metadata where applicable, and support routing metadata for messages sent to support@skilltage.com.
  • Transfers: Cloudflare processing is governed by Cloudflare's DPA, subprocessor disclosures, and applicable transfer safeguards including SCCs where required.

AWS

  • Purpose: AWS backend hosting, queueing, scheduled jobs, logging, tracing, production operations dashboard, and platform transactional email.
  • Data involved: API request metadata, organisation and recruitment workflow records processed by backend services, async job metadata, operational logs and traces, and platform email metadata/content for legal-acceptance confirmations.
  • Region: production infrastructure uses EU regional processing where available, with eu-central-1 as the primary AWS application region.
  • Transfers: AWS processing is governed by the AWS DPA, service terms, subprocessor disclosures, and applicable transfer safeguards including SCCs where required.

Supabase

  • Purpose: Postgres database, authentication, user invite/account bootstrap, JWT verification material, and candidate document storage.
  • Data involved: organisation, membership, account, recruitment-case, candidate, document, AI trace, human trace, consent evidence, and auth records needed to operate Skilltage.
  • Region: Skilltage uses Supabase Central EU (Frankfurt / eu-central-1); each Supabase project is bound to its selected primary region.
  • Transfers: Supabase processing is governed by Supabase's DPA, subprocessor disclosures, and applicable transfer safeguards where required.

OpenAI

  • Purpose: configured AI-assisted recruitment workflows, including PDF CV parsing, candidate evaluation, job draft assistance, and draft communication assistance.
  • Data involved: uploaded CV content, job requirements, prompts, generated outputs, and related workflow context needed for parsing, evaluation, and draft assistance.
  • Retention and training: OpenAI API customer data may be retained for abuse monitoring for up to 30 days or according to the configured API retention mode. OpenAI states that API data is not used to train models unless explicit data sharing is enabled; Skilltage does not enable data sharing for model training.
  • Transfers: OpenAI processing and subprocessor use are governed by OpenAI's DPA, subprocessor list, and applicable transfer safeguards including SCCs where required.

Sentry

  • Purpose: optional error, performance, and trace diagnostics for browser, Cloudflare runtime, backend, and worker paths.
  • Data involved: error events, stack traces, request IDs, route/runtime metadata, sanitized tags, and performance spans. Browser diagnostics start only after diagnostics consent, and default PII collection remains off unless explicitly approved.
  • Region: Sentry supports regional data residency; the applicable processing location follows Skilltage's configured Sentry project.
  • Transfers: Sentry processing is governed by Sentry's DPA, subprocessor disclosures, and applicable transfer safeguards including SCCs where required.

PostHog

  • Purpose: consent-gated product analytics for page journeys, onboarding funnels, recruitment workflow usage, and approved public landing measurements.
  • Data involved: route and event metadata, consent state, pseudonymous identifiers, and approved workflow properties. Skilltage does not send CV text, candidate free text, prompt bodies, recruiter notes, or sent email bodies to PostHog.
  • Region: Skilltage uses the PostHog EU host for consented analytics; PostHog Cloud EU is hosted in AWS eu-central-1 in Frankfurt.
  • Transfers: PostHog processing is governed by PostHog's DPA, subprocessor disclosures, and applicable transfer safeguards where required.

Apollo

  • Purpose: consent-gated public website visitor analytics that helps Skilltage identify visiting companies and understand page-level engagement.
  • Data involved: visited domains and pages, visit timing and frequency, and network or browser identifiers used by Apollo to associate website activity with companies.
  • Transfers: Apollo processing is governed by Apollo's DPA and applicable transfer safeguards, including the EU Standard Contractual Clauses where required.

Mautic

  • Purpose: consent-gated public website visitor analytics and page-visit history for later lead identification through explicit forms, tracked emails, or other approved identity workflows.
  • Data involved: visited pages, visit timing and frequency, and browser/device identifiers used to maintain an anonymous visitor history. Skilltage does not send account email, organisation identity, CV text, or recruiter data from the landing site.
  • Transfers: Mautic processing occurs on Skilltage's Mautic instance at m.skilltage.com; applicable hosting and transfer safeguards govern the processing.

Zoho Desk

  • Purpose: organisation-customer support ticketing, Help Center, in-app ASAP support widget, and feedback widget for customer support.
  • Data involved: support request content, contact details provided by the requester, ticket metadata, widget metadata, and feedback submitted by organisation users. Candidates normally contact the hiring organisation for recruitment-specific requests.
  • Region: Skilltage uses the Zoho Desk EU tenant and support.skilltage.com Help Center for customer support.
  • Transfers: Zoho processing is governed by Zoho's privacy terms, DPA/subprocessor disclosures, and applicable transfer safeguards including SCC-based safeguards where required.

Vendor governance

Provider legal names, data processing terms, transfer mechanisms, and processing locations are tracked as part of Skilltage's vendor governance.

This page describes Skilltage's implemented vendor controls and does not represent external certification or legal approval.