Sub-processor List
Last reviewed 23 September 2026 · Next scheduled review 29 July 2027
Overview
This page is Mentum's public sub-processor list under UK GDPR Article 28(2) (general authorisation) and Article 28(4) (the list customers use to evaluate sub-processor changes and exercise the objection right in our Data Processing Agreement at § 7.4(c)).
If you are a procurement team or Data Protection Officer evaluating Mentum, this page is the authoritative current state. If you have executed our DPA, the matching list at Annex III applies as a contractual term and is updated in lockstep with this page.
The controller of record is Mentum. Data-protection enquiries: privacy@mentumjobs.com. Mentum operates as a sole trader pre-launch and has not designated a formal Data Protection Officer under UK GDPR Art. 37 — the dpo@mentumjobs.com alias is the de-facto routing for DPO-style enquiries, including from procurement teams evaluating Mentum as a processor.
Subscribe to changes
We commit, under § 7.4(b) of the DPA, to thirty days' prior notice with a right to object for any new sub-processor before it begins processing Customer Personal Data.
- Email list: send a request to subprocessors@mentumjobs.com with the subject line
subscribe, including your organisation's legal name and the address you want notifications sent to. We will reply to confirm enrolment. - This page: material changes land here within one working day. The change-history section below captures the rolling twelve months.
We do not currently publish an RSS feed of sub-processor changes. If your procurement workflow requires one, write to privacy@mentumjobs.com and we will weigh it against engineering priorities.
Notification policy
- New sub-processor: thirty days' prior written notice via the channels above, with a right to object on documented data-protection grounds.
- Removal of a sub-processor: retrospective; this list is updated within one working day of the change.
- Material scope change (a sub-processor begins handling a new category of data, or moves data to a new region): treated as a new engagement and notified prospectively.
If you object to a proposed sub-processor and Mentum cannot offer a commercially reasonable alternative within thirty days, you may terminate the affected Service for cause with no early-termination fee, per § 7.4(c) of the DPA.
Current sub-processor list
| Sub-processor | Service | Hosting region | Transfer mechanism (UK / EEA) | External attestations | Mentum DPA status |
|---|---|---|---|---|---|
| Supabase Inc. | Postgres database, Authentication, Storage, Realtime, Edge Functions | US (default); EU regions available | UK adequacy / EU SCCs in Supabase ToS; UK GDPR addendum verification pending | SOC 2 Type 2; ISO 27001; HIPAA — trust.supabase.com | Included in Supabase ToS |
| Google LLC | Gemini API for embeddings, skill-experience estimation (pinned to Gemini by default), OCR of image-only CV PDFs when that fallback is enabled, and Mentum's standard AI processing whenever it, or one operation of it, is switched back from OpenAI; Firebase Cloud Messaging (web-push transport) | US | EU SCCs Module 2; Google Cloud Data Processing Addendum incorporated automatically into the Google agreement | SOC 2 Type 2; SOC 3; ISO 27001; ISO 27017; ISO 27018 — cloud.google.com/security/compliance | In effect: incorporated automatically, evidenced 29 July 2026; a residual service-scope question is with our external adviser |
| OpenAI | Responses API and Batch API for Mentum's standard AI processing (job-description extraction, CV structured extraction, AI match explanations, culture inference, entity and skill classification, persona generation, interview tips and kits, verification quiz pools, chat suggest-reply) and for Career Advisor, interview practice, Enhanced Insights, CV optimisation, Career Compass recommendations, career trajectory, employer hiring advisor and job-description generation. Only each feature's existing minimised prompt fields are sent. CV text including names is sent during CV parsing, with NI numbers, dates of birth and UK addresses removed first, and during CV optimisation, the documented exception where it is sent as written. | Provider/account dependent; must be evidenced for the production account before activation. EU data residency, where available to the account, does not cover the Batch API | DPA and transfer mechanism required before production | OpenAI security and privacy | Requests set store=false. API data is not used for training unless the organisation opts in; Mentum does not opt in. Batch API files are deleted when a batch settles, with a seven-day provider-side expiry as the backstop. No zero-retention claim is made until the production account controls are evidenced. |
| Twilio SendGrid Inc. | Transactional and lifecycle email delivery | US | EU SCCs Module 2 (implicit in ToS; signed DPA pending) | SOC 2 Type 2; ISO 27001; HIPAA-eligible — Twilio DPA | Pending execution |
| Railway Corp | Application hosting — API (uvicorn / FastAPI) and the Next.js frontend, including server-side rendering and its session-cookie handling; environment-variable secret store; build and deploy infrastructure; managed Redis (cache and rate-limit counters) | US (GCP compute primary; AWS secondary) | EU SCCs (implicit in ToS); signed DPA verification pending | SOC 2 Type 2 — railway.com/legal/security | Pending DPA verification |
| GitHub, Inc. (Microsoft) | Source-code repository, GitHub Actions CI/CD, Dependabot security advisories | US (Microsoft global) | EU SCCs via GitHub Customer Agreement (auto-applies on signup) | SOC 2 Type 2; ISO 27001; ISO 27017; ISO 27018; FedRAMP-High — github.com/security | Executed via GitHub Customer Agreement |
| Functional Software, Inc. (Sentry) | Error tracking, performance telemetry, replay-on-error capture | US (EU residency option available) | EU SCCs (implicit in ToS); signed DPA pending | SOC 2 Type 2; ISO 27001 — sentry.io/security | Pending execution |
| Redis provider (production pinning operator-pending) | Rate-limit sliding-window keys, daily LLM cost-guard counter, Idempotency-Key body-hash store, async-task active-set | Provider-dependent | Provider-dependent | Provider-dependent | Pending provider pinning + DPA execution |
| Adzuna Ltd | Daily inbound job-feed ingestion (no candidate or customer PII flows outbound) | United Kingdom | UK adequacy (inbound flow only) | Not formally attested (private-company partnership) | Informal partner arrangement |
| postcodes.io | UK postcode geocoding (public reference data) | United Kingdom | UK adequacy (public data service) | Public data service | Not required (no personal data transmitted) |
| Nominatim (OpenStreetMap Foundation) | Free-text location geocoding for job search and profile postcode lookup. Browser-direct — the request does not transit Mentum's backend. | European Union (Germany) | UK adequacy (request originates from the user's browser; Mentum is not in the transfer chain) | Public data service | Not required (browser-direct request) |
| UK Education and Skills Funding Agency (DfE Apprenticeships Service) | Inbound apprenticeship-vacancy feed (no candidate or customer PII flows outbound) | United Kingdom (Crown infrastructure) | UK adequacy (Crown body; inbound flow only) | UK Government Service Standard | Not required (inbound feed) |
| Additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, direct-employer ATS boards — Greenhouse, Lever, Ashby and similar — myjobscotland (COSLA) and the Workable aggregated job-board feed) | Daily inbound job-listing ingestion (inbound only — no candidate or customer PII flows outbound) | United Kingdom / provider-dependent | UK adequacy / inbound flow only (no personal data sent) | Not formally attested (public or partner job feeds) | Not required (inbound feed) |
| Coursera, Inc. and Impact Tech, Inc. (Impact.com affiliate network) | Server-side affiliate redirect on learning-course links. When a candidate clicks a course link, Mentum's backend follows the Impact click-tracking chain (the request originates from Mentum's server, forwarding the browser's User-Agent) and 302-redirects the browser to Coursera with a click identifier (irclickid) in the URL. Impact receives Mentum's server IP, the forwarded User-Agent, and the minted click id; no candidate name, email, or profile data is sent. The candidate's browser then loads Coursera directly. | US | US — affiliate-network agreement; no candidate personal data transmitted (server-forwarded User-Agent + click id only) | Coursera: SOC 2 Type 2; Impact: SOC 2 Type 2 | Affiliate-network agreement; no candidate personal data shared from Mentum |
| ClamAV (open-source) | File-bytes virus scan on candidate document uploads — runs in Mentum's runtime container; no third-party data flow. | Local (Mentum runtime) | Not applicable | Not applicable (open-source library) | Not applicable (no vendor relationship) |
The detailed data-category breakdown for each row, including the data-minimisation controls applied at each integration boundary, is recorded in the markdown master (docs/legal/subprocessors.md), available on request via privacy@mentumjobs.com.
What is not a Mentum sub-processor
Two categories are commonly raised in procurement reviews. Both are out of scope for this list:
- OAuth identity providers (Google sign-in, LinkedIn OIDC sign-in) are upstream identity providers handing a one-time identity assertion to Supabase Auth at signup. They are not engaged by Mentum to process data on a customer's behalf — the user's prior relationship with Google or LinkedIn governs that flow.
- Browser web-push services (Mozilla Autopush, Apple Push Notification service, Microsoft Windows Notification Service) are chosen by the user's browser when push notifications are enabled. Push payloads are end-to-end encrypted per RFC 8030; the push provider sees only the encrypted bytes plus the destination endpoint URL. Google Firebase Cloud Messaging is the most common destination and is therefore listed under Google LLC; the other push services are not separately engaged by Mentum.
Change history — last twelve months
| Date | Change |
|---|---|
| 23 Sep 2026 | Change in scope, no new sub-processor. OpenAI widened from the eight premium surfaces to Mentum's standard AI processing on gpt-6-luna, including CV structured extraction, AI match explanations, culture inference and job-description extraction through the OpenAI Batch API. Google keeps embeddings, OCR of image-only CV PDFs and skill-experience estimation (pinned to Gemini by default), and remains the configured fallback for standard processing. A change in scope is notified prospectively: OpenAI does not process production customer personal data on the widened scope until its activation prerequisites (contracting entity, DPA, transfer mechanism and account controls) are closed, and until then a production deployment runs the standard route on Google. |
| 14 Sep 2026 | Added myjobscotland (COSLA), live since 13 August 2026 under an explicit written feed grant, and theWorkable aggregated job-board feed, live since 23 August 2026, to the inbound job-feed sources row. Both are inbound only: no candidate or customer personal data flows outbound to either. They were recorded in the internal registers on those dates and this page was brought into line on 14 September 2026; the lag is recorded here rather than backdated. |
| 28 Jul 2026 | Removed Vercel Inc. The Next.js frontend has never been deployed to Vercel — it runs as a Railway service alongside the API — so no personal data has ever been processed by Vercel. The Railway Corp row is widened accordingly to cover frontend hosting, server-side rendering and its session cookies, and managed Redis. This corrects the record; it is not a change of processor. |
| 16 Jul 2026 | Platform name finalised as Mentum ahead of launch. No change to sub-processors, data flows, hosting regions or transfer mechanisms — a pre-launch branding update only. |
| 15 Jul 2026 | Reinstated the Coursera, Inc. / Impact Tech, Inc. sub-processor row. Learning-course links now route through a server-side affiliate redirect (GET /api/coursera/go): Mentum's backend resolves the Impact click-tracking chain and forwards the browser's User-Agent, so a processor relationship exists again. The 11 Jul 2026 entry below (recording the removal while links were direct) is retained for an accurate history. |
| 14 Jul 2026 | Added the additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, and direct-employer ATS boards) as a consolidated inbound-only transparency row — inbound ingestion only, no candidate or customer data transmitted. |
| 11 Jul 2026 | Removed the Coursera, Inc. / Impact Tech, Inc. row — Coursera learning-course links are now direct (no affiliate wrapper), so no data-flow or processor relationship exists. |
| 11 May 2026 | Public sub-processor list created at /legal/subprocessors; added Nominatim, UK DfE Apprenticeships Service, and Coursera/Impact as transparency entries (browser-direct or inbound-only); merged Firebase Cloud Messaging into the Google LLC row. |
| 6 May 2026 | Added Railway, Vercel, GitHub, Sentry, and Redis provider as sub-processors (previously implicit; explicit Record of Processing Activities entries created). Pinned Twilio SendGrid as the production email provider. |
| 4 April 2026 | Added Adzuna Ltd as inbound data source (job-feed ingestion); noted informal DPA status. |
Entries older than twelve months age out of this section. The full audit trail of changes is held in version control alongside the markdown master.
Onward sub-processors
UK GDPR Article 28(2) and ISO 27001 Annex A.5.21 require Mentum to maintain awareness of which sub-processors our sub-processors use. The position for each:
| Sub-processor | Onward sub-processors |
|---|---|
| Supabase | Amazon Web Services (compute / storage / network); Cloudflare (CDN, optional) |
| Google LLC | Google Cloud (compute / storage / DNS / network) — covered by the Google Cloud DPA |
| Sentry | Amazon Web Services (compute / storage); Google Cloud (some services) |
| Twilio SendGrid | Amazon Web Services (compute); Twilio internal infrastructure |
| Railway | Google Cloud (primary compute); Amazon Web Services (some services) |
| GitHub | Microsoft Azure (compute); Microsoft 365 (auth) |
How to object to a sub-processor
- Email privacy@mentumjobs.com with the subject line "Sub-processor objection — [vendor name]".
- State the data-protection ground (typically: inadequate transfer mechanism, missing attestation, or risk to a category of data subject your organisation is responsible for).
- We respond within five working days with either an alternative sub-processor, a mitigation plan, or — if no commercially reasonable alternative exists — confirmation of your right to terminate the affected Service under § 7.4(c) of the DPA.
Related: Privacy Policy | Data Processing Agreement | Terms of Service | Cookie Policy