AITACS Talent — Recruiting Calendar & CRM Suite  ·  Terms · Privacy · Informed Consent
AITACS Talent — Legal Documentation

Subprocessor List

Last Updated: 2026-07-13  ·  Version: 0.1-draft  ·  Provider: Artem Chukov, Israel

GDPR Art. 28

1. About This Document

This document lists all third-party subprocessors engaged by the Provider under AITACS Talent (Recruiting Calendar & CRM Suite), available at aitacscrm.app/talent. AITACS Talent is a separate product from the Provider's companion CRM for healthcare professionals — it maintains its own, isolated database and its own subprocessor relationships; this list covers AITACS Talent only. It is maintained in accordance with GDPR Article 28(2) and the Data Processing Agreement (DPA).

1.1. The Controller has granted general written authorization for the Processor to engage the subprocessors listed below (see DPA §6.1).

1.2. The Processor shall notify the Controller at least 14 days in advance of any addition, removal, or replacement of a subprocessor. Notification will be sent via email to the address associated with the Controller's account.

1.3. The Controller may object to a new subprocessor on reasonable data protection grounds within the 14-day notice period. If the objection cannot be resolved, the Controller may terminate the affected service component without penalty (see DPA §6.3).

2. Summary

SubprocessorCountryFunctionReceives Identifying Candidate Data?Transfer Safeguard
OpenAI, LLC USA Chat assistant, candidate analysis, document-import extraction Partially — de-identified for screening/analysis; full document content for import (see §3) SCCs + de-identification for two of three features
Hetzner Online GmbH Germany / Finland Database and application hosting Yes — encrypted SCCs + TLS 1.2+
Google LLC (Firebase) USA Recruiter authentication No — email & UID only Google DPA + SCCs
Google LLC (Calendar API) USA Interview scheduling sync No — scheduling metadata only Google Cloud DPA + SCCs
Zapier, Inc. USA Webhook relay for Recruiter's own Zoom interview scheduling events Yes — host/participant email, meeting metadata, recording URL Shared webhook secret over TLS; Zapier's own DPA

3. Detailed Subprocessor Information

OpenAI, LLC

🇺🇸 United States
Function: Three distinct features: (1) "Elia for HR" dashboard chat assistant; (2) AI candidate analysis (gap analysis, screening, interview questions, scorecard summaries); (3) résumé/company-document import extraction. Data received: For features (1) and (2): a pseudonym plus job-relevant professional data (skills, desired salary, notice period) — full name, phone, email, and résumé link are stripped before transmission, and free-text notes are scrubbed of contact-like patterns. For feature (3): the uploaded document's content as-is, including any name and contact details it contains — that extraction is the feature's purpose. See Privacy Policy §3 for the full data flow. Data NOT sent: For features (1) and (2) only: real names, phone numbers, email addresses, physical addresses. Age, gender, race, ethnicity, disability, religion, and marital status are never sent by any feature, because the Candidate schema does not collect them in the first place. Discrimination risk: Anti-discrimination by design — for the chat assistant and candidate-analysis features, protected characteristics are physically absent from what reaches the AI model, because the Platform's Candidate schema does not collect them at all. Data retention: Data processed via OpenAI API with zero-retention policy. API inputs and outputs are not used to train models. Retention: 0 days (per OpenAI API Data Usage Policy). Transfer safeguard: OpenAI Data Processing Addendum, incorporating EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914). DPA status: In place — OpenAI's standard API DPA applies to all three features.

Hetzner Online GmbH

🇩🇪 Germany / 🇫🇮 Finland
Function: MySQL database hosting, PHP application server, SSL/TLS termination, automated backups. Data received: All Platform data, including Candidate records (names, contacts, professional data), Recruiter account data, interview history, calendar events. Own, isolated database — not shared with the Provider's companion coach/therapist product. Data is encrypted in transit (TLS 1.2+). Data retention: Data retained for the duration of the hosting agreement. Full deletion upon account termination, per the retention schedule in the DPA §11. Transfer safeguard: Standard Contractual Clauses (SCCs). TLS 1.2+ encryption for all data in transit. Server-level access controls. DPA status: DPA required — the Processor maintains a data processing agreement with the hosting provider.

Google LLC (Firebase Authentication)

🇺🇸 United States
Function: Recruiter authentication and identity management. Provides secure sign-in and unique User IDs (UIDs) for data isolation. Data received: Recruiter email address and UID only. No Candidate data. Data retention: Per Google Firebase terms. Account data retained until account deletion. Transfer safeguard: Google Cloud DPA (includes SCCs). See Firebase Privacy and Security. DPA status: Included — Google Cloud Data Processing Terms apply automatically to Firebase services.

Google LLC — Google Calendar API

🇺🇸 United States
Function: OAuth-based calendar synchronisation. When the Recruiter connects their Google Account, AITACS Talent can read and write interview events to the Recruiter's Google Calendar. Data received: Interview event metadata created or modified by the Platform: event title, date, time, duration. The Recruiter is responsible for what they include in event titles/descriptions; the Platform does not automatically export Candidate professional notes to Google Calendar. Subject to the Google API Services User Data Policy Limited Use requirements. OAuth scope: Minimum necessary scope (calendar.events — read/write events). The Recruiter may revoke access at any time via Google Account Permissions. Data retention: Calendar events are stored in the Recruiter's own Google Calendar account. The Provider does not cache or store Google Calendar data on Provider servers beyond the active session. Transfer safeguard: Google Cloud Data Processing Terms (incorporating SCCs). OAuth 2.0 with short-lived access tokens. DPA status: Included — Google Cloud DPA covers Calendar API.

Zapier, Inc.

🇺🇸 United States
Function: Webhook relay: when a Recruiter's own Zoom account (connected via the Recruiter's own Zapier automation) reports a "meeting ended" event, Zapier forwards the relevant metadata to the Platform's webhook endpoint. The Platform has no direct integration with Zoom — Zoom itself is a third-party tool the Recruiter uses on their own account, independent of the Platform. Data received: Meeting ID, meeting topic, host email, participant emails, scheduled start/end time, and (if produced) a recording URL — as configured by the Recruiter's own Zapier automation, forwarded to the Platform via a shared webhook secret over TLS. Data retention: Zapier's own retention policy governs data in transit through its automation platform; the Platform stores only the resulting interview record (scheduling metadata and, if present, the recording URL) once received. Transfer safeguard: Shared webhook secret validated via constant-time comparison; TLS in transit. Zapier's own Privacy Policy and DPA govern its processing as the Recruiter's chosen automation provider. DPA status: Recruiter-configured — the Recruiter, not the Provider, selects and configures the Zapier automation and Zoom account; the Provider only receives the resulting webhook.
Not Yet Subprocessors

No payment processor (e.g. PayPal, Paddle.com Market Limited) is technically connected to AITACS Talent at the time of writing (see Terms of Service §3). The Platform's live video/audio interview widget ("Transcription Module") exists in the Provider's companion coach product but has not yet been adapted or activated for AITACS Talent. Neither is listed above; each will be added to this list, and notified per Section 4 below, before it goes live — not assumed in advance.

4. Change Notification Policy

4.1. The Processor commits to maintaining this list in an accurate and up-to-date state.

4.2. Before engaging any new subprocessor or replacing an existing one, the Processor shall:

a) Update this Subprocessor List at least 14 days before the new subprocessor begins processing data;

b) Send an email notification to all active Recruiters (Controllers) describing the change, the identity and location of the new subprocessor, and the data it will process;

c) Allow the Controller to object within the 14-day notice period on reasonable data protection grounds.

4.3. If the Controller objects and the Processor cannot reasonably accommodate the objection, the Controller may terminate the affected service component without penalty, as specified in DPA §6.3.

5. Change Log

2026-07-13 Initial publication. Five subprocessors listed: OpenAI LLC, Hetzner Online GmbH, Google Firebase, Google Calendar API, Zapier Inc.
Subscribe to Updates

To receive notifications about subprocessor changes, ensure your account email is current in the Platform settings. All change notifications are sent to the email address associated with your AITACS Talent account.

Related Compliance Documents

Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us