Subprocessors
Subprocessors
Subprocessors
Updated 19/11/2025
1. Introduction
Hyaa AI Pty Ltd (“Hyaa AI”) uses third-party service providers (“Subprocessors”) to support the delivery of our platform, including hosting, storage, communications, AI processing, automation, and related infrastructure services.
Each Subprocessor listed below may process limited Personal Data on behalf of Hyaa AI customers as necessary to provide the Services. Hyaa AI performs due diligence and imposes contractual obligations on all Subprocessors to ensure they meet or exceed required data protection and security standards.
This page is updated whenever we add or replace a Subprocessor. Customers who have signed a DPA will receive advance notice of material changes.
2. Infrastructure & Hosting Subprocessors
Supabase (PostgreSQL, Auth, Storage)
Purpose: Primary database, authentication, and file storage
Data Processed: Candidate audio files, transcripts, summaries, resume data, metadata, customer account data
Location: USA / EU / Global (depending on region selection)
Transfer Mechanism: SCCs where applicable
Vercel
Purpose: Frontend hosting, edge delivery
Data Processed: Account identifiers, metadata, client requests
Location: Global
Transfer Mechanism: SCCs where applicable
3. Communication & Messaging Subprocessors
SendGrid (Twilio SendGrid)
Purpose: Transactional email delivery
Data Processed: Names, email addresses, notification content
Location: USA
Transfer Mechanism: SCCs
Twilio
Purpose: SMS (and optionally voice) communications
Data Processed: Phone numbers, message metadata
Location: Global
Transfer Mechanism: SCCs
3. AI Processing Subprocessors
OpenAI
Purpose: Transcription, summarization, analysis, AI scoring
Data Processed: Audio files, transcripts, resume content, candidate responses
Location: USA
Transfer Mechanism: SCCs
4. Data Collection, Scraping & Enrichment Subprocessors
ScrapingBee
Purpose: Webpage extraction, metadata capture, summarization pipelines
Data Processed: Public webpage content, job post data
Location: EU
Transfer Mechanism: Adequate jurisdiction
5. Payments & Billing Subprocessors
Stripe
Purpose: Payment processing, invoicing, subscription management
Data Processed: Billing information, payment data, customer contact details
Location: Global
Transfer Mechanism: SCCs
6. Analytics & Session Recording Tools
Microsoft Clarity
Purpose: Behaviour analytics, heatmaps, anonymised session recordings
Data Processed: Interaction metadata, page behaviour, anonymised inputs
Location: USA
Transfer Mechanism: SCCs
7. Additional Notes
Data Residency
Customer and candidate data is stored primarily within Supabase and Vercel regions selected by Hyaa AI. Some Subprocessors may process limited metadata outside the primary region under SCCs or equivalent safeguards.
Processor Agreements
Hyaa AI maintains written agreements with all Subprocessors requiring:
confidentiality
security controls consistent with Annex B of the DPA
cooperation with audits
lawful international transfer mechanisms
New Subprocessors
Customers with an active DPA will receive notification of new Subprocessors at least 30 days in advance where required.
Contact
For questions about Subprocessors or data protection:
Updated 19/11/2025
1. Introduction
Hyaa AI Pty Ltd (“Hyaa AI”) uses third-party service providers (“Subprocessors”) to support the delivery of our platform, including hosting, storage, communications, AI processing, automation, and related infrastructure services.
Each Subprocessor listed below may process limited Personal Data on behalf of Hyaa AI customers as necessary to provide the Services. Hyaa AI performs due diligence and imposes contractual obligations on all Subprocessors to ensure they meet or exceed required data protection and security standards.
This page is updated whenever we add or replace a Subprocessor. Customers who have signed a DPA will receive advance notice of material changes.
2. Infrastructure & Hosting Subprocessors
Supabase (PostgreSQL, Auth, Storage)
Purpose: Primary database, authentication, and file storage
Data Processed: Candidate audio files, transcripts, summaries, resume data, metadata, customer account data
Location: USA / EU / Global (depending on region selection)
Transfer Mechanism: SCCs where applicable
Vercel
Purpose: Frontend hosting, edge delivery
Data Processed: Account identifiers, metadata, client requests
Location: Global
Transfer Mechanism: SCCs where applicable
3. Communication & Messaging Subprocessors
SendGrid (Twilio SendGrid)
Purpose: Transactional email delivery
Data Processed: Names, email addresses, notification content
Location: USA
Transfer Mechanism: SCCs
Twilio
Purpose: SMS (and optionally voice) communications
Data Processed: Phone numbers, message metadata
Location: Global
Transfer Mechanism: SCCs
3. AI Processing Subprocessors
OpenAI
Purpose: Transcription, summarization, analysis, AI scoring
Data Processed: Audio files, transcripts, resume content, candidate responses
Location: USA
Transfer Mechanism: SCCs
4. Data Collection, Scraping & Enrichment Subprocessors
ScrapingBee
Purpose: Webpage extraction, metadata capture, summarization pipelines
Data Processed: Public webpage content, job post data
Location: EU
Transfer Mechanism: Adequate jurisdiction
5. Payments & Billing Subprocessors
Stripe
Purpose: Payment processing, invoicing, subscription management
Data Processed: Billing information, payment data, customer contact details
Location: Global
Transfer Mechanism: SCCs
6. Analytics & Session Recording Tools
Microsoft Clarity
Purpose: Behaviour analytics, heatmaps, anonymised session recordings
Data Processed: Interaction metadata, page behaviour, anonymised inputs
Location: USA
Transfer Mechanism: SCCs
7. Additional Notes
Data Residency
Customer and candidate data is stored primarily within Supabase and Vercel regions selected by Hyaa AI. Some Subprocessors may process limited metadata outside the primary region under SCCs or equivalent safeguards.
Processor Agreements
Hyaa AI maintains written agreements with all Subprocessors requiring:
confidentiality
security controls consistent with Annex B of the DPA
cooperation with audits
lawful international transfer mechanisms
New Subprocessors
Customers with an active DPA will receive notification of new Subprocessors at least 30 days in advance where required.
Contact
For questions about Subprocessors or data protection:
Updated 19/11/2025
1. Introduction
Hyaa AI Pty Ltd (“Hyaa AI”) uses third-party service providers (“Subprocessors”) to support the delivery of our platform, including hosting, storage, communications, AI processing, automation, and related infrastructure services.
Each Subprocessor listed below may process limited Personal Data on behalf of Hyaa AI customers as necessary to provide the Services. Hyaa AI performs due diligence and imposes contractual obligations on all Subprocessors to ensure they meet or exceed required data protection and security standards.
This page is updated whenever we add or replace a Subprocessor. Customers who have signed a DPA will receive advance notice of material changes.
2. Infrastructure & Hosting Subprocessors
Supabase (PostgreSQL, Auth, Storage)
Purpose: Primary database, authentication, and file storage
Data Processed: Candidate audio files, transcripts, summaries, resume data, metadata, customer account data
Location: USA / EU / Global (depending on region selection)
Transfer Mechanism: SCCs where applicable
Vercel
Purpose: Frontend hosting, edge delivery
Data Processed: Account identifiers, metadata, client requests
Location: Global
Transfer Mechanism: SCCs where applicable
3. Communication & Messaging Subprocessors
SendGrid (Twilio SendGrid)
Purpose: Transactional email delivery
Data Processed: Names, email addresses, notification content
Location: USA
Transfer Mechanism: SCCs
Twilio
Purpose: SMS (and optionally voice) communications
Data Processed: Phone numbers, message metadata
Location: Global
Transfer Mechanism: SCCs
3. AI Processing Subprocessors
OpenAI
Purpose: Transcription, summarization, analysis, AI scoring
Data Processed: Audio files, transcripts, resume content, candidate responses
Location: USA
Transfer Mechanism: SCCs
4. Data Collection, Scraping & Enrichment Subprocessors
ScrapingBee
Purpose: Webpage extraction, metadata capture, summarization pipelines
Data Processed: Public webpage content, job post data
Location: EU
Transfer Mechanism: Adequate jurisdiction
5. Payments & Billing Subprocessors
Stripe
Purpose: Payment processing, invoicing, subscription management
Data Processed: Billing information, payment data, customer contact details
Location: Global
Transfer Mechanism: SCCs
6. Analytics & Session Recording Tools
Microsoft Clarity
Purpose: Behaviour analytics, heatmaps, anonymised session recordings
Data Processed: Interaction metadata, page behaviour, anonymised inputs
Location: USA
Transfer Mechanism: SCCs
7. Additional Notes
Data Residency
Customer and candidate data is stored primarily within Supabase and Vercel regions selected by Hyaa AI. Some Subprocessors may process limited metadata outside the primary region under SCCs or equivalent safeguards.
Processor Agreements
Hyaa AI maintains written agreements with all Subprocessors requiring:
confidentiality
security controls consistent with Annex B of the DPA
cooperation with audits
lawful international transfer mechanisms
New Subprocessors
Customers with an active DPA will receive notification of new Subprocessors at least 30 days in advance where required.
Contact
For questions about Subprocessors or data protection:

