We keep this list short on purpose: every vendor below is load-bearing, and none of them receives your data for advertising or training. Rows marked "only when connected" process data only for workspaces that switch the integration on.
On this page
| Vendor | What it processes | Region | Applies to |
|---|---|---|---|
| Supabase | Database, authentication and file storage. Each workspace runs against its own isolated project. | EU | All workspaces |
| Vercel | Application hosting and cookieless, aggregated web analytics. | EU edge / global CDN | All workspaces |
| OpenAI | AI evaluation, search and assistant responses. Only the data needed for the specific request; never used for training. | EU endpoints where available | Default AI provider, replaceable with a self-hosted endpoint |
| Sign-in with Google Workspace, calendar scheduling and sending candidate email through your own Gmail grant. | Global | Only when you connect it | |
| Microsoft | Sign-in with Azure Entra ID (SSO). | Global | Only when you connect it |
| Flowcase (CVPartner) | Imports consultant CVs into your workspace. | EU | Only when you connect it |
| Tavily | Assistant web search. Off by default; queries are stripped of personal data before they leave the platform. | Global | Only when you enable web search |
| Email delivery (SMTP relay) | Delivers the platform’s notification email; messages can reference candidates. The operating vendor is named in the signed list that ships with the DPA. | Stated in the signed list | All workspaces |
Changes to this list
We add a vendor here before it processes any customer data, and beta workspaces are told about additions during onboarding. A signed, versioned copy of this list ships with the DPA.
Questions, or need the signed version: contact@talentautopilot.com