Sub-processors
Version 1.0, last updated 30 August 2026
A sub-processor is a third party that CareerOS engages to process personal data on behalf of a University, in order to provide the CareerOS platform. This page lists every sub-processor we use, the personal data each one may process, where that processing takes place, and the safeguard used for any transfer of personal data outside the European Economic Area.
This list forms Annex III of the CareerOS Data Processing Agreement (DPA).
Some entries apply only where a University enables a specific module, or where an individual user chooses to connect a personal email or calendar account. Those conditions are set out in the "Applies when" column, and the sub-processor is not engaged for a University that has not enabled the relevant module.
Sub-processors
| Sub-processor | Service | Personal data | Hosting location | Transfer mechanism | Applies when |
|---|---|---|---|---|---|
| Google Cloud (including Firebase, Vertex AI and Gemini) | Hosting, storage, database, and AI features | All platform data | EU: Belgium (europe-west1), Italy (europe-west8), and Germany for Firestore (europe-west3). Three document storage buckets are hosted in the US today, with EU relocation planned. | Google Cloud Data Processing Addendum; EU Standard Contractual Clauses for the US-hosted buckets | Always |
| Auth0 (Okta) | Authentication and single sign-on | Email, name, identity IDs | EU tenant region | Okta Data Processing Addendum | Always |
| Customer.io | Transactional and campaign email | Email, name, user ID, events | EU region | Customer.io Data Processing Addendum (Standard Contractual Clauses) | Always. Campaign email applies only where the University enables newsletters. |
| Stream (GetStream) | In-app chat and group channels | User IDs, message content | EU: eu-west-4 (Dublin, Ireland) | Stream Data Processing Addendum | Where the University enables group channels or the student inbox |
| Algolia | Search and discovery | Searchable profile subset | United Kingdom (London) | Algolia Data Processing Agreement; UK adequacy decision under the GDPR | Always |
| Mixpanel | Product analytics | Pseudonymous user ID, events | EU, through Mixpanel's EU Data Residency option (Netherlands) | Mixpanel Data Processing Addendum | Always |
| Hotjar | UX analytics (session recordings, heatmaps) | Behavioural data, pseudonymous IDs | EU: AWS eu-west-1 (Ireland) | Hotjar Data Processing Agreement | Always |
| Google Analytics 4 | Web analytics | Page views, events, pseudonymous ID | Google global infrastructure | Google Ads Data Processing Terms | Always |
| Statsig | Feature experimentation | User ID, assignments | United States | Statsig Data Processing Addendum (Standard Contractual Clauses) | Always |
| Sentry | Error and performance monitoring | Error context, user ID, session replay | United States today. A migration to Sentry's EU region is in progress. | Sentry Data Processing Addendum (Standard Contractual Clauses; EU-U.S. Data Privacy Framework) | Always |
| Nylas | Calendar sync | Calendar events, OAuth tokens | Europe region, hosted in London (United Kingdom) | Nylas Data Processing Addendum; UK adequacy decision under the GDPR | Where the University enables CalendarOS |
| Microsoft (Graph API) | Outlook mail and calendar, via the user's own account connection | Mail and calendar content of the connected account | The user's own Microsoft tenant | Microsoft Products and Services Data Protection Addendum | Where the University enables Inbox or Outlook calendar and the user connects the account |
| Google (Gmail API and Workspace APIs) | Gmail, via the user's own account connection | Mail content of the connected account | The user's own Google Workspace tenant | Google Workspace Data Processing Amendment | Where the University enables Inbox and the user connects the account |
| Zoom | Live events (Meeting Web SDK) | Join and participant data | United States | Zoom Data Processing Addendum (Standard Contractual Clauses; EU-U.S. Data Privacy Framework) | Where the University enables Zoom events or video calls |
Incidental sub-processors
CareerOS also uses the following tools for internal operations and customer support. Customer personal data may incidentally pass through them in the course of that work, but they are not engaged to process personal data as part of the CareerOS platform itself.
- Google Workspace
- Slack
Changes to this list
When CareerOS adds a new sub-processor, we will notify each customer's named privacy contact at least 30 days before that sub-processor begins processing customer personal data. A customer may object to the new sub-processor under the terms of the DPA within that 30 day notice period.
Questions about this list can be sent to privacy@thecareeros.com.
Which sub-processors apply to me?
The table above is the complete, authoritative list. This section restates it from the perspective of the two roles that use the CareerOS platform on a University's licence, as a reading aid only; it does not add or remove any sub-processor.
As a student, which of these apply to me?
Google Cloud, Auth0, Customer.io, Algolia, Mixpanel, Hotjar, Google Analytics 4, Statsig and Sentry always apply, since they support core platform functions such as hosting, sign-in, email, search and error monitoring. Stream applies if your University has enabled group channels or the student inbox. Nylas applies if your University has enabled CalendarOS for booking appointments with an advisor. Microsoft and Google (Gmail) apply only if you personally choose to connect your own mailbox to the Inbox feature. Zoom applies if your University has enabled Zoom for events or video calls. This page does not cover employer-side processing, since CareerOS acts as an independent controller for employer accounts rather than as your University's processor.
As an advisor, which of these apply to me?
The same always-on group applies to advisor accounts: Google Cloud, Auth0, Customer.io, Algolia, Mixpanel, Hotjar, Google Analytics 4, Statsig and Sentry. Nylas applies where your University has enabled CalendarOS, since advisor availability and bookings are synced through it. Stream applies where group channels or student messaging are enabled. Microsoft or Google apply only if you connect your own mailbox to the Inbox feature. Zoom applies where your University has enabled Zoom for events. As with the student view, employer-side processing is out of scope of this list.