When your organization uses HireDay, you are the controller of your employees’ personal data and HireDay is the processor. To run the service we engage a small number of other companies that process that data on our behalf. Those companies are sub-processors, and Article 28(2) of the UK GDPR and EU GDPR requires us to tell you who they are and to let you object before we add a new one.
This page is that list. It is complete — there are no sub-processors we use and do not name here.
1. Current sub-processors
Amazon Web Services
- Legal entity: Amazon Web Services EMEA SARL (Luxembourg), contracting on behalf of Amazon Web Services, Inc.
- Processing location: US East (N. Virginia),
us-east-1 - Function: Application hosting, database storage, file storage, and outbound email delivery (Amazon SES)
- Data accessed: All customer data stored in HireDay — employee names, work email addresses, job titles, start dates, manager relationships, onboarding task content and completion records
- Transfer mechanism: AWS Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. See our International Data Transfers page.
- Certifications: ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 1/2/3
- Engaged since: September 2026
Anthropic
- Legal entity: Anthropic PBC (United States)
- Processing location: United States
- Function: Generating suggested onboarding checklist tasks when an administrator asks for them. This is an optional feature; if nobody in your organization uses it, no data reaches Anthropic.
- Data accessed: The template’s name, department and role tag; the titles, owners and day-offsets of tasks already on that template; and any free text the administrator types into the suggestion prompt. We do not send employee records, email addresses or completion history. We cannot, however, prevent an administrator from typing a person’s name into the prompt box, so we describe that field as capable of carrying personal data rather than claiming it never does.
- Transfer mechanism: Standard Contractual Clauses with the UK Addendum, under Anthropic’s commercial terms. Anthropic does not train models on data submitted through its API.
- Certifications: SOC 2 Type II, ISO/IEC 42001
- Engaged since: September 2026
Stripe
- Legal entity: Stripe Payments Europe, Limited (Ireland)
- Processing location: European Union and United States
- Function: Subscription billing and payment processing. Engaged only for organizations on a paid plan — a free-plan organization’s data never reaches Stripe.
- Data accessed: Billing contact name and email address, and the billing account identifier. Card details are collected by Stripe directly and never reach HireDay’s systems.
- Transfer mechanism: Stripe Data Processing Agreement incorporating the Standard Contractual Clauses and the UK Addendum.
- Certifications: PCI DSS Level 1, SOC 1/2 Type II
- Engaged since: September 2026
2. How we handle changes
You grant HireDay general written authorisation to engage sub-processors, under Article 28(2). That authorisation comes with an obligation on us and a right for you:
- We give 30 days’ notice. Before we add or replace a sub-processor, we email your organization’s administrator contact at least 30 days before that sub-processor begins processing any of your data. The notice names the entity, its jurisdiction and processing location, what it will do, what data it will access, and the transfer mechanism if it is outside the UK or EEA.
- You have 14 days to object. Reply to that notice, or write to hello@hireday.io, within 14 days of receiving it. An objection needs to rest on a reasonable data-protection concern rather than simple preference — for example, that the new sub-processor lacks an adequate transfer mechanism or appropriate security controls.
- If we cannot resolve it, you can leave. We will work with you in good faith for 30 days to find an alternative. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rated refund of any prepaid fees.
We notify you; we do not expect you to watch this page. Regulators have been clear that publishing a list a customer must monitor is not, on its own, a notification mechanism. This page is a register you can check at any time, not a substitute for the email.
If your administrator contact has changed, tell us at hello@hireday.io so notices reach the right person.
3. What we require of them
Article 28(4) requires us to bind each sub-processor to data-protection obligations equivalent to the ones we owe you, and leaves us fully liable to you for their performance. Each of the companies above is engaged under a written agreement that requires them to process data only on documented instructions, keep it confidential, maintain appropriate security measures, help us respond to data-subject requests and breaches, and delete or return data when the engagement ends.
4. Infrastructure that is not sub-processing
For completeness: our source code is hosted on GitLab and our own company email runs on Google Workspace. Neither processes your employees’ personal data on our behalf, so neither is a sub-processor of yours — if you write to us, that correspondence reaches our mailbox like any other email.
Cloudflare (Cloudflare, Inc., United States) hosts our public website at www.hireday.io. If you leave your email address there to hear when we launch, Cloudflare stores that address for us. That address is ours to handle as controller, under our Privacy Policy; it is not your employees’ data, and Cloudflare never receives any data from inside HireDay. So Cloudflare is our processor for the website, not a sub-processor of yours. It processes under Cloudflare’s Data Processing Addendum, which incorporates the Standard Contractual Clauses.
5. Questions
Write to hello@hireday.io. If you need a signed Data Processing Agreement, see our Data Processing Agreement.