The third-party services Crimson Talent relies on to deliver the Services — what each one does, the data it may touch, and where it operates. All customer data stays in the United States.
To provide our recruiting services and Talent Analytics platform, Crimson engages a small set of carefully vetted subprocessors. Each one is bound by a written agreement with data-protection obligations no less protective than those in our Data Processing Agreement, and Crimson remains fully accountable for their performance. Every vendor below either operates entirely within the United States or is contractually restricted to processing customer data in US regions.
us-east-1 and us-west-2). We do not transfer customer data outside the US in the ordinary course of providing the Services.The following table lists every subprocessor that may process customer personal data as of the date above.
| Subprocessor | Purpose | Data processed | Location | Category |
|---|---|---|---|---|
| Amazon Web Services | Primary cloud hosting & compute (us-east-1, us-west-2) | All customer data at rest & in processing | United States | Infrastructure |
| Amazon RDS (PostgreSQL) | Managed relational database for the platform | Candidate & account records | United States | Database |
| Cloudflare | CDN, DDoS protection & WAF | Request metadata, IP addresses | United States | Network |
| Datadog | Infrastructure monitoring, logging & SIEM | Operational logs, limited metadata | United States | Monitoring |
| Snowflake | Analytics data warehouse for reporting | Aggregated & pseudonymized platform data | United States | Analytics |
| SendGrid (Twilio) | Transactional & notification email delivery | Names, email addresses, message content | United States | Communications |
| Twilio | SMS & verification messaging | Phone numbers, message content | United States | Communications |
| Stripe | Payment processing & billing | Billing contact & payment metadata | United States | Billing |
| Okta | Single sign-on & identity management | Authentication identifiers, email | United States | Identity |
| Google Workspace | Internal email, documents & collaboration | Business communications, attachments | United States | Productivity |
| DocuSign | Electronic signature for agreements & offers | Signer names, emails, document content | United States | e-Signature |
| Tawk.to | Live chat & visitor support widget | Chat messages, name & email if provided | United States | Support |
Before a vendor is approved to process customer data, it goes through our security-review process. We evaluate the vendor's own certifications (SOC 2, ISO 27001 or equivalent), review its security and privacy documentation, assess the categories of data it will access under a data-minimization lens, and confirm US data-residency commitments. Every approved vendor signs a data-processing agreement incorporating the relevant Standard Contractual Clauses and breach-notification terms. We re-review each subprocessor at least annually and whenever the nature of its processing materially changes.
Crimson deliberately selects vendors that can process customer data within the United States. Where a global vendor offers multiple regions, we contractually restrict processing to US regions and disable cross-region replication of customer personal data. This keeps our data-residency posture simple and predictable for customers with US-only requirements.
We keep this page current and update it whenever we add, remove or materially change a subprocessor. Customers can subscribe to advance notifications of subprocessor changes by emailing trust@crimsontalent.com; we provide reasonable prior notice and, consistent with our DPA, a fair opportunity to raise a legitimate data-protection objection before a new subprocessor begins processing customer data.