Last updated: 2026-05-16
A “sub-processor” is any third party we use to deliver the service. Per GDPR Article 28, you have the right to know the full list and what each one does. Per the LinkedIn API Terms of Use, the same disclosure rule applies for any party that touches LinkedIn-sourced data.
Active sub-processors
| Company | Role | Data accessed | Location | International-transfer basis |
|---|---|---|---|---|
| Mistral AI | LLM provider — the intended managed-tier provider at launch. The managed tiers are closed pre-launch, so no LLM provider receives user traffic on our keys today; BYOM users reach the provider they configure themselves (see the user-elected section below). | Drafting prompts at request time, once managed tiers open. | European Union | None required (intra-EU) |
| Anthropic | LLM provider — available as a BYOM choice; not the platform default. | Drafting prompts (your CV materials + the JD) at request time, when you configure an Anthropic key. Not stored beyond the request. | EU region where available; US fallback otherwise. Trained-on-data prohibition contractually in place. | EU SCCs (Standard Contractual Clauses, Module 2 Controller-to-Processor) for any US-region traffic |
| Stripe | Payment processor for the managed tiers when they open — no live payment processing today | Will access email, name, payment method, billing address, subscription status — billing data only. Never your CV/letter/application data. Never LinkedIn-imported data. | Ireland (EU) for EU customers | None required (intra-EU) |
| Cloudflare | Authoritative DNS for all omoikane domains, including omoikane.coach (DNS-only — the proxy is disabled on the customer surface, so traffic goes straight to our edge) and the redirect domains (omoikane.nl, .tech, .careers, .gr). Also serves the Turnstile bot-check widget on our forms. | DNS queries and Turnstile challenge traffic (browser signals during a bot check). No application data — customer traffic does not pass through Cloudflare’s proxy. | Global | Public DNS records carry no personal data. Turnstile challenge traffic reaches Cloudflare’s global network; SCCs (Cloudflare’s standard data processing addendum) cover any non-EEA processing, and would equally apply if proxy mode were ever enabled |
| gigahost.no AS | (1) Hosting provider for the application servers (notrf01dmz0{1,2}) and the database hosts (notrf01dmz0{3,4}) — all application data at rest, encrypted. (2) Edge anycast VPS at the Norway (Trondheim) POP — sees in-flight customer traffic for the duration of a single TLS connection only; persists no data. | All application data at rest (encrypted at rest); in-transit customer traffic at the NO edge POP. No application-level access on the storage hosts. | Norway (EEA) | None required (Norway is in the EEA) |
| Proton AG | Mailbox provider behind the reply-tracker inbound path: replies sent to your per-application tracker alias are received and stored in a Proton mailbox, then read into omoikane over an operator-run bridge. Applies only if you use the reply tracker. | Recruiter reply emails to tracker aliases (sender, subject, body) while they sit in the mailbox. | Switzerland | Switzerland adequacy decision (Commission Decision 2000/518/EC) — no SCCs required |
| iFog GmbH | Edge anycast VPS at the Switzerland (Zürich) POP — runs HAProxy and terminates TLS before re-encrypting over IPsec to the EEA storage layer. Sees in-flight customer traffic for the duration of a single TLS connection only; persists no data. | In-transit customer traffic at the CH edge POP. No data at rest. | Switzerland | Switzerland adequacy decision (Commission Decision 2000/518/EC) — no SCCs required |
First-party infrastructure (not a sub-processor)
The third host in our YugabyteDB cluster (the Leiden quorum witness, nllei01dmz01) runs on operator-managed infrastructure in Leiden, the Netherlands. Because it is not a third party, it is not a sub-processor under GDPR Art. 28; we mention it here for transparency about where your data physically lives. It carries the same encryption-at-rest and IPsec-in-transit posture as the gigahost.no hosts.
A self-hosted Umami analytics instance at analytics.cubeos.app also runs on operator-managed infrastructure (same Leiden location). It records anonymous aggregate page-view counts and is cookieless on the tracked domain (omoikane.coach) — see the Cookie policy for the full disclosure including the localStorage opt-out flag it honours. The analytics server receives no cookies (the script’s fetch uses credentials: omit) and no IP-level joins are made. Because it is operator-managed first-party infrastructure, it is not a sub-processor under GDPR Art. 28.
Edge network and TLS termination
User traffic to omoikane.coach reaches a three-VPS anycast pool that runs HAProxy and terminates TLS at the edge before re-encrypting over IPsec to our EEA-only storage layer. No user data is persisted on the edge nodes — they hold session state for the duration of a single connection only. Locations: Switzerland (Zürich, iFog GmbH), Norway (Trondheim, gigahost.no AS) and the United States (Houston, Texas, iFog GmbH). The US POP is retired from this domain before the managed tiers open to the public, returning the pool to EEA + Switzerland.
The Swiss and Norwegian legs need no Standard Contractual Clauses — Switzerland holds an adequacy decision and Norway is in the EEA. The US (Houston) leg is a third-country, in-transit-only leg: TLS terminates there, nothing is stored, and traffic is re-encrypted to EEA storage. That leg is retired from this domain before the managed tiers open.
LinkedIn integration
When you opt into the LinkedIn data import, LinkedIn Ireland Unlimited Company is the source of the data, not a sub-processor of ours. Once data lands on our infrastructure, it is seen only by the sub-processors above — or by the bring-your-own-model provider you yourself configure, which receives LinkedIn-derived material in drafting prompts (user-elected; see the Security page for the provider list and where each one runs).
LinkedIn’s role and obligations to you for the data they hold are governed by LinkedIn’s own privacy policy. Our obligations begin the moment the data enters our systems and are governed by our privacy policy together with:
- The LinkedIn API Terms of Use (linkedin.com/legal/l/api-terms-of-use)
- The LinkedIn DMA Portability API Additional Terms (linkedin.com/legal/l/portability-api-terms)
- The LinkedIn BD Data Processing Agreement (legal.linkedin.com/bd-dpa) incorporated by reference into the Portability Terms at §3.3
Removed / former sub-processors
None as of the Last updated date above.
Things we explicitly do NOT use
- No third-party (commercial) analytics platform — no Google Analytics, no Plausible, no Matomo cloud, no Fathom, no Mixpanel, no Segment, no Rudderstack. We run a self-hosted Umami instance on operator-owned infrastructure (
analytics.cubeos.app) for cookieless aggregate page-view counts; full disclosure including the localStorage opt-out flag lives on the Cookie policy page. The Umami operator and the Omoikane operator are the same legal entity, so Umami is first-party infrastructure, not a sub-processor. - No advertising platform
- No customer-data platform
- No email marketing platform (no Mailchimp, no Klaviyo, no Customer.io)
- No third-party error trackers (we run our own — Loki + Grafana on our own infrastructure)
- No “AI training partner” — your data is not licensed to anyone for any model-training purpose, ours or theirs
- No third-party identity provider for your account (Authentik, our own self-hosted IdP, is the only consumer of your authentication credentials)
Notification
If we add a sub-processor, you get an email at least 30 days before they go live, identifying who they are, what data they will see, where they are located, and what international-transfer basis covers them. You can export and delete during the notice window if you object.
Contact
For sub-processor questions or DPA requests: privacy@omoikane.coach.