SUBPROCESSORS
Last Updated: July, 2026
1. Why Skima Uses Third Party Services
Skima builds and operates its platform using a carefully selected group of third party service providers. These providers help us deliver secure, reliable, and scalable services to our customers. Depending on their role, some providers may process customer personal data strictly on our behalf, while others support our internal business operations without accessing customer recruitment data.
This includes providers used to operate and analyse our public website, in addition to those supporting the core recruitment platform.
Every subprocessor engaged by Skima is assessed before onboarding through our vendor security review process and is contractually required to process personal data only for the services they provide to us.
2. Our Vendor Classification
Not every vendor that Skima uses has access to customer data. For transparency, we classify vendors into the following categories.
| Category | Description |
|---|---|
| Platform Infrastructure | Services required to host, secure and operate the Skima platform. These providers may process customer data as part of delivering the service. |
| AI Services | Providers used for approved AI capabilities. These services are restricted to specific non customer PII workflows as described below. |
| Business Operations | Services used internally by Skima for engineering, communication, compliance and customer relationship management. These services do not process customer recruitment data unless explicitly stated. |
3. Current Subprocessors
We group our subprocessors below by the purpose they serve, consistent with how we classify vendor access to data.
3.1 Platform Infrastructure and AI Processing
These providers host, secure, and operate the Skima platform, including our AI-powered features.
| Provider | Why Skima Uses It | Customer Data Access | Data Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosts the Skima platform, databases, storage, backups, and compute infrastructure. All application data is processed within AWS. | Customer personal data, application data, files, databases | Ireland (eu-west-1) |
| Cloudflare | Protects the platform from attacks, accelerates content delivery, provides DNS services, SSL termination, and Web Application Firewall protection. | Transit metadata required to route traffic. Customer application data is not persistently stored. | United States |
| OpenAI | Generates AI assisted content such as job descriptions using enterprise Zero Data Retention endpoints. Candidate information is never sent. | No candidate personal data. Only non personal prompts specifically intended for content generation. | United States |
| OpenRouter | Provides routing for approved language models used for non customer facing AI generation workflows under Zero Data Retention configurations. | No candidate personal data. | United States |
3.2 Website Analytics
These providers help us understand how visitors use our public website. They do not process candidate or recruitment data.
| Provider | Why Skima Uses It | Customer Data Access | Data Location |
|---|---|---|---|
| Google Analytics | Website traffic and usage analytics for skima.ai. | Website visitor and usage data (e.g. pages viewed, referral source). No candidate or recruitment data. | United States |
| RudderStack | Analytics data pipeline used to route website visitor usage data to our analytics tools. | Anonymous visitor identifiers and referral/campaign data. No candidate or recruitment data. | United States |
3.3 Business Operations and Compliance
These providers support our internal business operations, engineering, and compliance programme. They do not process candidate or recruitment data unless explicitly stated.
| Provider | Why Skima Uses It | Customer Data Access | Data Location |
|---|---|---|---|
| HubSpot | Manages sales enquiries, customer relationships, product updates, and marketing communications. | Business contact information of prospects and customers. Does not receive recruitment data. | United States |
| Google Workspace | Supports internal company email, calendar, document collaboration, and employee productivity. | Internal employee communications. Customer recruitment data is not stored as part of service delivery. | India |
| GitHub | Hosts Skima source code repositories and software development workflows. | Source code only. Customer production data is not stored in repositories. | United States |
| IBM MaaS360 | Secures company managed laptops and mobile devices through enterprise device management. | Device inventory and employee device information only. | United States |
| Linear | Internal engineering project management, bug tracking, and product planning. | Engineering work items only. Customer production data is not stored. | United States |
| Scrut Automation | Manages security compliance evidence, audit controls, risk registers, and certification workflows for SOC 2 and GDPR programmes. | Compliance evidence and security documentation. Customer application data is not processed. | United States |
4. How We Protect Customer Data
Where a subprocessor processes customer personal data on our behalf, Skima ensures appropriate contractual and technical safeguards are in place. Depending on the provider and jurisdiction, these safeguards may include:
- Data Processing Agreements (DPAs)
- Standard Contractual Clauses (SCCs)
- Encryption in transit and at rest
- Role based access controls
- Vendor security assessments
- Periodic compliance reviews
Subprocessors are authorised to process personal data only for the specific services they provide to Skima and may not use that information for their own commercial purposes.
5. AI Service Providers
Skima's AI architecture is designed to minimize external data exposure. Candidate resumes, candidate profiles, interview data, and recruitment records are processed using Skima's proprietary AI infrastructure hosted within our primary cloud environment. External AI providers are used only for limited, non-customer-specific content generation capabilities, such as assisting recruiters with drafting job descriptions. These requests exclude candidate personal information and operate under enterprise agreements that prohibit data retention or model training.
6. Security Requirements for All Subprocessors
Before a service provider is approved, Skima evaluates its security and privacy posture. Depending on the nature of the service, we assess factors including:
- Security certifications such as SOC 2
- Encryption of data in transit and at rest
- Access control and authentication practices
- Compliance with applicable privacy regulations
- Contractual commitments governing confidentiality and data protection
- Support for international data transfer safeguards where required
Subprocessors that process personal data are required to maintain appropriate technical and organisational security measures throughout the duration of their engagement.
7. International Data Transfers
Some of our service providers operate across multiple jurisdictions. Where personal data is transferred internationally, Skima relies on the safeguards described in our Privacy Policy https://skima.ai/privacy-policy (Section 13) and Data Protection Addendum, including EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms under the Swiss FADP and DPDPA 2023, as applicable. Customers requiring further information may contact our Privacy Team.
8. Changes to Our Subprocessors
We may update our list of subprocessors as our products and services evolve. We provide at least 30 calendar days' advance notice before a new subprocessor is engaged to process customer personal data, or before any material change is made to an existing subprocessor's processing scope, consistent with our Data Protection Addendum. This page reflects Skima's current list of approved subprocessors as of the date above.
9. Contact
If you have questions regarding our subprocessors, vendor security practices or international data transfers, please contact:
Privacy Team
or
Data Protection Officer
Version History
| Version | Date | Description of Changes | Created By | Published By |
|---|---|---|---|---|
| 1.0 | July 2026 | Initial publication of the Subprocessors page, listing current sub-processors grouped by purpose (Platform Infrastructure and AI Processing, Website Analytics, Business Operations and Compliance), international transfer safeguards, and vendor security requirements | Yash Dave | Sumit Rai |