Legal

Subprocessors.

The third-party services Crimson Talent relies on to deliver the Services — what each one does, the data it may touch, and where it operates. All customer data stays in the United States.

Last updated April 2026

To provide our recruiting services and Talent Analytics platform, Crimson engages a small set of carefully vetted subprocessors. Each one is bound by a written agreement with data-protection obligations no less protective than those in our Data Processing Agreement, and Crimson remains fully accountable for their performance. Every vendor below either operates entirely within the United States or is contractually restricted to processing customer data in US regions.

Data residency: all customer personal data is stored and processed in the United States (primarily AWS us-east-1 and us-west-2). We do not transfer customer data outside the US in the ordinary course of providing the Services.

Current subprocessors

The following table lists every subprocessor that may process customer personal data as of the date above.

SubprocessorPurposeData processedLocationCategory
Amazon Web ServicesPrimary cloud hosting & compute (us-east-1, us-west-2)All customer data at rest & in processingUnited StatesInfrastructure
Amazon RDS (PostgreSQL)Managed relational database for the platformCandidate & account recordsUnited StatesDatabase
CloudflareCDN, DDoS protection & WAFRequest metadata, IP addressesUnited StatesNetwork
DatadogInfrastructure monitoring, logging & SIEMOperational logs, limited metadataUnited StatesMonitoring
SnowflakeAnalytics data warehouse for reportingAggregated & pseudonymized platform dataUnited StatesAnalytics
SendGrid (Twilio)Transactional & notification email deliveryNames, email addresses, message contentUnited StatesCommunications
TwilioSMS & verification messagingPhone numbers, message contentUnited StatesCommunications
StripePayment processing & billingBilling contact & payment metadataUnited StatesBilling
OktaSingle sign-on & identity managementAuthentication identifiers, emailUnited StatesIdentity
Google WorkspaceInternal email, documents & collaborationBusiness communications, attachmentsUnited StatesProductivity
DocuSignElectronic signature for agreements & offersSigner names, emails, document contentUnited Statese-Signature
Tawk.toLive chat & visitor support widgetChat messages, name & email if providedUnited StatesSupport

How we vet vendors

Before a vendor is approved to process customer data, it goes through our security-review process. We evaluate the vendor's own certifications (SOC 2, ISO 27001 or equivalent), review its security and privacy documentation, assess the categories of data it will access under a data-minimization lens, and confirm US data-residency commitments. Every approved vendor signs a data-processing agreement incorporating the relevant Standard Contractual Clauses and breach-notification terms. We re-review each subprocessor at least annually and whenever the nature of its processing materially changes.

Data stays in the United States

Crimson deliberately selects vendors that can process customer data within the United States. Where a global vendor offers multiple regions, we contractually restrict processing to US regions and disable cross-region replication of customer personal data. This keeps our data-residency posture simple and predictable for customers with US-only requirements.

Notification of changes

We keep this page current and update it whenever we add, remove or materially change a subprocessor. Customers can subscribe to advance notifications of subprocessor changes by emailing trust@crimsontalent.com; we provide reasonable prior notice and, consistent with our DPA, a fair opportunity to raise a legitimate data-protection objection before a new subprocessor begins processing customer data.

Questions about a specific vendor? Our trust team is happy to share additional detail — including a vendor's certifications — under NDA. Reach us at trust@crimsontalent.com, or read more in our Security overview.