Legal · BETIHUT-LEGAL-SUBP
Sub-processor Notice
- Entity
- XCITERR LTD. · AUTOMAIZE SOLUTIONS LTD
- Reg. No.
- 206478710 · HE 480609
- Effective
- 23 July 2026
- Status
- Version 1.3 · Effective
This Sub-processor Notice describes the processing chain used when XCITERR LTD. engages AUTOMAIZE SOLUTIONS LTD to provide Betihuti technology and when Automaize engages infrastructure providers to process personal data in connection with the Service. It forms part of the Data Processing Addendum.
1.Technology processing chain
- 1.1Where Xciterr controls an agency-recruitment purpose and instructs Automaize to host or operate the workflow, Automaize acts as Xciterr's technology processor. Where an employer Customer controls the purpose, the applicable order must record whether Xciterr and Automaize are processors or sub-processors in that chain.
- 1.2Automaize remains an independent controller for the limited platform-account, security, consent, AI-accountability and legal-compliance purposes identified in the Privacy Notice; those activities are not sub-processing under a Customer's instructions.
2.Categories of sub-processor
Before a provider processes production personal data as our sub-processor, it must be engaged under a written contract imposing obligations consistent with Article 28 GDPR. The relevant categories are:
- 2.1Cloud hosting and database services, which host the application and store personal data, with the EEA as the primary hosting region.
- 2.2AI, speech and transcription services, which parse CVs, support structured assessment, capture and transcribe interview audio, and generate assessment evidence for review.
- 2.3Communications and email-delivery services, which send status updates, interview invitations and account messages on our behalf.
- 2.4Billing, scheduling, observability, DNS/security and acquisition-measurement services, each limited to the data needed for the specific function.
3.Current sub-processors
The production sub-processor register for beta covers the following vendors and uses. A vendor remains blocked from production processing until the status item has been completed and recorded in the compliance pack:
- 3.1Google Cloud / Gemini / Firebase: AI assessment, transcription assistance, embeddings, location autocomplete, optional crash diagnostics, push delivery, Google authentication and optional Google Calendar synchronization. Data: Interview prompts, transcripts, score inputs, location search strings, push tokens, opt-in crash diagnostics, authentication identifiers, encrypted calendar authorization credentials, calendar availability windows, owned-event details and limited operational metadata. Region/transfers: EU regions by default where supported; international transfers covered by the provider DPA and transfer safeguards. Status: DPA and transfer impact review required before production enablement.
- 3.2Supabase: Postgres database, authentication, storage, edge functions and realtime infrastructure. Data: Candidate, employer, application, interview, consent, audit, storage-object and account data. Region/transfers: EU project region for production data. Status: DPA, security documentation and project-region evidence required before production enablement.
- 3.3WorkOS: Enterprise employer SSO connection brokering, directory synchronization and customer IT administration. Data: Employer identity identifiers, work email, display name, organization/directory/group identifiers and authentication or provisioning event metadata. Region/transfers: Provider-hosted identity infrastructure; EEA transfer and residency posture must be documented before production use. Status: Disabled; DPA, transfer impact, retention, security and subprocessor review required before production enablement.
- 3.4Vercel: Web application hosting, CDN delivery, preview deployments and application logs. Data: HTTP request metadata, application logs and limited account/session identifiers. Region/transfers: Edge network with EU deployment controls where available. Status: DPA, log-retention settings and transfer safeguards required before production enablement.
- 3.5Railway: Worker and media-relay hosting for background jobs and interview sessions. Data: Queue payloads, worker logs, media-relay metadata and transient interview transport data. Region/transfers: EU region for production services. Status: DPA, region evidence and log-retention settings required before production enablement.
- 3.6Stripe: Subscription billing, invoicing, payment processing and tax records. Data: Employer billing contacts, billing events, payment identifiers and invoice metadata. Region/transfers: International payment-processing network. Status: DPA and payment-data role mapping required before production enablement.
- 3.7Cal.com: Interview and support scheduling. Data: Candidate/employer contact details, appointment metadata and availability preferences. Region/transfers: Provider-hosted scheduling infrastructure. Status: DPA and calendar-data minimisation review required before production enablement.
- 3.8Resend: Transactional email delivery. Data: Recipient email addresses, message templates, delivery events and suppression metadata. Region/transfers: Provider-hosted email infrastructure. Status: DPA, DKIM/SPF/DMARC evidence and retention settings required before production enablement.
- 3.9Meta: Lead forms, conversion measurement and employer acquisition campaigns where enabled. Data: Campaign-event metadata and lead contact fields submitted through Meta surfaces. Region/transfers: International advertising and measurement infrastructure. Status: Controller/processor role assessment and consent gating required before production enablement.
- 3.10Cloudflare: DNS, edge security, bot protection and network-level availability controls. Data: HTTP request metadata, IP addresses, security events and DNS records. Region/transfers: Global edge network. Status: DPA, security-event retention settings and transfer safeguards required before production enablement.
- 3.11Sentry: Error monitoring, performance telemetry and incident diagnostics. Data: Error traces, stack frames, request metadata and scrubbed user/session identifiers. Region/transfers: EU data residency where configured. Status: DPA, PII scrubbing and sampling controls required before production enablement.
4.Safeguards
- 4.1Each sub-processor is subject to due diligence and to contractual data-protection obligations, including security, confidentiality and, where relevant, appropriate transfer safeguards.
- 4.2Where a sub-processor involves transfers outside the EEA, we document the transfer mechanism and supplementary measures before production use.
- 4.3Provider credentials are server-side only, access is least-privilege, and logs are configured to avoid storing interview content or special-category data unless explicitly required for support or incident response.
5.Changes
- 5.1We maintain this list and give prior notice of the addition or replacement of a sub-processor, allowing controllers to object on reasonable data-protection grounds before the change takes effect.
- 5.2Sub-processor questions, objections and privacy requests may be sent to privacy@betihuti.com or info@xciterr.com; security reports may be sent to security@betihuti.com; support requests may be sent to support@betihuti.com.
