1. About This Document
This document lists all third-party subprocessors engaged by the Provider under AITACS Talent
(Recruiting Calendar & CRM Suite), available at aitacscrm.app/talent. AITACS Talent is a
separate product from the Provider's companion CRM for healthcare professionals — it maintains its own,
isolated database and its own subprocessor relationships; this list covers AITACS Talent only. It is
maintained in accordance with GDPR Article 28(2) and the Data Processing
Agreement (DPA).
1.1. The Controller has granted general written authorization
for the Processor to engage the subprocessors listed below (see DPA
§6.1).
1.2. The Processor shall notify the Controller at least
14 days in advance of any addition, removal, or replacement of a subprocessor. Notification
will be sent via email to the address associated with the Controller's account.
1.3. The Controller may object to a new subprocessor on
reasonable data protection grounds within the 14-day notice period. If the objection cannot be resolved, the
Controller may terminate the affected service component without penalty (see DPA §6.3).
2. Summary
| Subprocessor | Country | Function | Receives Identifying Candidate Data? | Transfer Safeguard |
| OpenAI, LLC |
USA |
Chat assistant, candidate analysis, document-import extraction |
Partially — de-identified for screening/analysis; full
document content for import (see §3) |
SCCs + de-identification for two of three features |
| Hetzner Online GmbH |
Germany / Finland |
Database and application hosting |
Yes — encrypted |
SCCs + TLS 1.2+ |
| Google LLC (Firebase) |
USA |
Recruiter authentication |
No — email & UID only |
Google DPA + SCCs |
| Google LLC (Calendar API) |
USA |
Interview scheduling sync |
No — scheduling metadata only |
Google Cloud DPA + SCCs |
| Zapier, Inc. |
USA |
Webhook relay for Recruiter's own Zoom interview scheduling events |
Yes — host/participant email, meeting metadata,
recording URL |
Shared webhook secret over TLS; Zapier's own DPA |
3. Detailed Subprocessor Information
Function:
Three distinct features: (1) "Elia for HR" dashboard chat assistant; (2) AI candidate
analysis (gap analysis, screening, interview questions, scorecard summaries); (3) résumé/company-document
import extraction.
Data received:
For features (1) and (2): a pseudonym plus job-relevant professional data (skills,
desired salary, notice period) — full name, phone, email, and résumé link are stripped before
transmission, and free-text notes are scrubbed of contact-like patterns. For feature (3): the uploaded
document's content as-is, including any name and contact details it contains — that extraction is the
feature's purpose. See Privacy Policy §3 for the full
data flow.
Data NOT sent:
For features (1) and (2) only: real names, phone numbers, email addresses, physical
addresses. Age, gender, race, ethnicity, disability, religion, and marital status are never sent by any
feature, because the Candidate schema does not collect them in the first place.
Discrimination risk:
Anti-discrimination by design — for
the chat assistant and candidate-analysis features, protected characteristics are physically absent from
what reaches the AI model, because the Platform's Candidate schema does not collect them at all.
Data retention:
Data processed via OpenAI API with zero-retention policy. API
inputs and outputs are not used to train models. Retention: 0 days (per OpenAI API Data Usage
Policy).
Transfer safeguard:
OpenAI Data Processing Addendum, incorporating EU Standard Contractual Clauses
(SCCs, Commission Implementing Decision (EU) 2021/914).
DPA status:
In place — OpenAI's standard API DPA
applies to all three features.
Function:
MySQL database hosting, PHP application server, SSL/TLS termination, automated
backups.
Data received:
All Platform data, including Candidate records (names, contacts,
professional data), Recruiter account data, interview history, calendar events. Own, isolated database —
not shared with the Provider's companion coach/therapist product. Data is encrypted in transit (TLS
1.2+).
Data retention:
Data retained for the duration of the hosting agreement. Full deletion upon account
termination, per the retention schedule in the DPA §11.
Transfer safeguard:
Standard Contractual Clauses (SCCs). TLS 1.2+ encryption for all data in transit.
Server-level access controls.
DPA status:
DPA required — the Processor
maintains a data processing agreement with the hosting provider.
Function:
Recruiter authentication and identity management. Provides secure sign-in and unique
User IDs (UIDs) for data isolation.
Data received:
Recruiter email address and UID only. No Candidate data.
Data retention:
Per Google Firebase terms. Account data retained until account deletion.
Transfer safeguard:
Google Cloud DPA (includes SCCs). See Firebase Privacy and
Security.
DPA status:
Included — Google Cloud Data Processing
Terms apply automatically to Firebase services.
Function:
OAuth-based calendar synchronisation. When the Recruiter connects their Google
Account, AITACS Talent can read and write interview events to the Recruiter's Google Calendar.
Data received:
Interview event metadata created or modified by the Platform: event title, date,
time, duration. The Recruiter is responsible for what they include in event titles/descriptions; the
Platform does not automatically export Candidate professional notes to Google Calendar. Subject to the
Google API Services User Data Policy Limited Use requirements.
OAuth scope:
Minimum necessary scope (calendar.events — read/write events). The
Recruiter may revoke access at any time via Google Account
Permissions.
Data retention:
Calendar events are stored in the Recruiter's own Google Calendar account. The
Provider does not cache or store Google Calendar data on Provider servers beyond the active session.
Transfer safeguard:
Google Cloud Data Processing Terms (incorporating SCCs). OAuth 2.0 with short-lived
access tokens.
DPA status:
Included — Google Cloud DPA covers
Calendar API.
Function:
Webhook relay: when a Recruiter's own Zoom account (connected via the Recruiter's own
Zapier automation) reports a "meeting ended" event, Zapier forwards the relevant metadata to the
Platform's webhook endpoint. The Platform has no direct integration with Zoom — Zoom
itself is a third-party tool the Recruiter uses on their own account, independent of the Platform.
Data received:
Meeting ID, meeting topic, host email, participant emails, scheduled start/end time,
and (if produced) a recording URL — as configured by the Recruiter's own Zapier automation, forwarded to
the Platform via a shared webhook secret over TLS.
Data retention:
Zapier's own retention policy governs data in transit through its automation
platform; the Platform stores only the resulting interview record (scheduling metadata and, if present,
the recording URL) once received.
Transfer safeguard:
Shared webhook secret validated via constant-time comparison; TLS in transit.
Zapier's own Privacy Policy and DPA govern its processing as the Recruiter's chosen automation provider.
DPA status:
Recruiter-configured — the Recruiter,
not the Provider, selects and configures the Zapier automation and Zoom account; the Provider only
receives the resulting webhook.
Not Yet Subprocessors
No payment processor (e.g. PayPal, Paddle.com Market Limited) is technically connected to AITACS Talent at
the time of writing (see Terms of Service §3). The
Platform's live video/audio interview widget ("Transcription Module") exists in the Provider's companion
coach product but has not yet been adapted or activated for AITACS Talent. Neither is listed above; each
will be added to this list, and notified per Section 4 below, before it goes live — not assumed in advance.
4. Change Notification Policy
4.1. The Processor commits to maintaining this list in an
accurate and up-to-date state.
4.2. Before engaging any new subprocessor or replacing an
existing one, the Processor shall:
a) Update this Subprocessor
List at least 14 days before the new subprocessor begins processing data;
b) Send an email notification
to all active Recruiters (Controllers) describing the change, the identity and location of the new
subprocessor, and the data it will process;
c) Allow the Controller to
object within the 14-day notice period on reasonable data protection grounds.
4.3. If the Controller objects and the Processor cannot
reasonably accommodate the objection, the Controller may terminate the affected service component without
penalty, as specified in DPA §6.3.
5. Change Log
2026-07-13
Initial publication. Five subprocessors listed: OpenAI LLC,
Hetzner Online GmbH, Google Firebase, Google Calendar API, Zapier Inc.
Subscribe to Updates
To receive notifications about subprocessor changes, ensure your account email is current in the Platform
settings. All change notifications are sent to the email address associated with your AITACS Talent
account.