Sub-processors
Last updated: August 2, 2026
When Kendor processes candidate data on behalf of a hiring organization (see our Data Processing Agreement), we use a small set of infrastructure providers as sub-processors. Each one is bound by a data-processing agreement with obligations equivalent to those we owe our customers. Our own infrastructure runs in the European Union.
Current sub-processors
| Sub-processor | Purpose | Data categories | Location / transfer mechanism |
|---|---|---|---|
| netcup GmbH | Hosting — application servers, database and the isolated code-execution environment | All platform data | Frankfurt, Germany (EU). German provider — no international transfer. |
| Amazon Web Services (S3) | Artifact storage — assessment workspaces, submissions, recordings, exports, uploaded images | Candidate artifacts and uploaded files | EU (Frankfurt, eu-central-1). Data resides in the EU; AWS is additionally certified under the EU–US Data Privacy Framework. |
| Mailgun (Sinch) | Transactional email — invitations, notifications, password resets | Names, email addresses, email content | EU region endpoint (processing and storage in the EU). Provider is US-headquartered; DPF certification and SCCs apply as a safeguard. |
| Cloudflare | DNS, CDN and security in front of the application | Traffic metadata (IP addresses, request logs) | Global edge network. Certified under the EU–US Data Privacy Framework. |
Changes to this list
We give hiring organizations at least 30 days’ advance notice before adding or replacing a sub-processor that processes candidate data, by email to organization owners. If you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected service. The date above reflects the most recent change.
Questions
Questions about our sub-processors or to request notification for your organization: email hello@kendor.io.