Skima AI

SUBPROCESSORS

Last Updated: July, 2026

1. Why Skima Uses Third Party Services

Skima builds and operates its platform using a carefully selected group of third party service providers. These providers help us deliver secure, reliable, and scalable services to our customers. Depending on their role, some providers may process customer personal data strictly on our behalf, while others support our internal business operations without accessing customer recruitment data.

This includes providers used to operate and analyse our public website, in addition to those supporting the core recruitment platform.

Every subprocessor engaged by Skima is assessed before onboarding through our vendor security review process and is contractually required to process personal data only for the services they provide to us.

2. Our Vendor Classification

Not every vendor that Skima uses has access to customer data. For transparency, we classify vendors into the following categories.

Category Description
Platform Infrastructure Services required to host, secure and operate the Skima platform. These providers may process customer data as part of delivering the service.
AI Services Providers used for approved AI capabilities. These services are restricted to specific non customer PII workflows as described below.
Business Operations Services used internally by Skima for engineering, communication, compliance and customer relationship management. These services do not process customer recruitment data unless explicitly stated.

3. Current Subprocessors

We group our subprocessors below by the purpose they serve, consistent with how we classify vendor access to data.

3.1 Platform Infrastructure and AI Processing

These providers host, secure, and operate the Skima platform, including our AI-powered features.

Provider Why Skima Uses It Customer Data Access Data Location
Amazon Web Services (AWS) Hosts the Skima platform, databases, storage, backups, and compute infrastructure. All application data is processed within AWS. Customer personal data, application data, files, databases Ireland (eu-west-1)
Cloudflare Protects the platform from attacks, accelerates content delivery, provides DNS services, SSL termination, and Web Application Firewall protection. Transit metadata required to route traffic. Customer application data is not persistently stored. United States
OpenAI Generates AI assisted content such as job descriptions using enterprise Zero Data Retention endpoints. Candidate information is never sent. No candidate personal data. Only non personal prompts specifically intended for content generation. United States
OpenRouter Provides routing for approved language models used for non customer facing AI generation workflows under Zero Data Retention configurations. No candidate personal data. United States

3.2 Website Analytics

These providers help us understand how visitors use our public website. They do not process candidate or recruitment data.

Provider Why Skima Uses It Customer Data Access Data Location
Google Analytics Website traffic and usage analytics for skima.ai. Website visitor and usage data (e.g. pages viewed, referral source). No candidate or recruitment data. United States
RudderStack Analytics data pipeline used to route website visitor usage data to our analytics tools. Anonymous visitor identifiers and referral/campaign data. No candidate or recruitment data. United States

3.3 Business Operations and Compliance

These providers support our internal business operations, engineering, and compliance programme. They do not process candidate or recruitment data unless explicitly stated.

Provider Why Skima Uses It Customer Data Access Data Location
HubSpot Manages sales enquiries, customer relationships, product updates, and marketing communications. Business contact information of prospects and customers. Does not receive recruitment data. United States
Google Workspace Supports internal company email, calendar, document collaboration, and employee productivity. Internal employee communications. Customer recruitment data is not stored as part of service delivery. India
GitHub Hosts Skima source code repositories and software development workflows. Source code only. Customer production data is not stored in repositories. United States
IBM MaaS360 Secures company managed laptops and mobile devices through enterprise device management. Device inventory and employee device information only. United States
Linear Internal engineering project management, bug tracking, and product planning. Engineering work items only. Customer production data is not stored. United States
Scrut Automation Manages security compliance evidence, audit controls, risk registers, and certification workflows for SOC 2 and GDPR programmes. Compliance evidence and security documentation. Customer application data is not processed. United States

4. How We Protect Customer Data

Where a subprocessor processes customer personal data on our behalf, Skima ensures appropriate contractual and technical safeguards are in place. Depending on the provider and jurisdiction, these safeguards may include:

  • Data Processing Agreements (DPAs)
  • Standard Contractual Clauses (SCCs)
  • Encryption in transit and at rest
  • Role based access controls
  • Vendor security assessments
  • Periodic compliance reviews

Subprocessors are authorised to process personal data only for the specific services they provide to Skima and may not use that information for their own commercial purposes.

5. AI Service Providers

Skima's AI architecture is designed to minimize external data exposure. Candidate resumes, candidate profiles, interview data, and recruitment records are processed using Skima's proprietary AI infrastructure hosted within our primary cloud environment. External AI providers are used only for limited, non-customer-specific content generation capabilities, such as assisting recruiters with drafting job descriptions. These requests exclude candidate personal information and operate under enterprise agreements that prohibit data retention or model training.

6. Security Requirements for All Subprocessors

Before a service provider is approved, Skima evaluates its security and privacy posture. Depending on the nature of the service, we assess factors including:

  • Security certifications such as SOC 2
  • Encryption of data in transit and at rest
  • Access control and authentication practices
  • Compliance with applicable privacy regulations
  • Contractual commitments governing confidentiality and data protection
  • Support for international data transfer safeguards where required

Subprocessors that process personal data are required to maintain appropriate technical and organisational security measures throughout the duration of their engagement.

7. International Data Transfers

Some of our service providers operate across multiple jurisdictions. Where personal data is transferred internationally, Skima relies on the safeguards described in our Privacy Policy https://skima.ai/privacy-policy (Section 13) and Data Protection Addendum, including EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms under the Swiss FADP and DPDPA 2023, as applicable. Customers requiring further information may contact our Privacy Team.

8. Changes to Our Subprocessors

We may update our list of subprocessors as our products and services evolve. We provide at least 30 calendar days' advance notice before a new subprocessor is engaged to process customer personal data, or before any material change is made to an existing subprocessor's processing scope, consistent with our Data Protection Addendum. This page reflects Skima's current list of approved subprocessors as of the date above.

9. Contact

If you have questions regarding our subprocessors, vendor security practices or international data transfers, please contact:

Privacy Team

support@skima.ai

or

Data Protection Officer

yash@skima.ai

Version History

Version Date Description of Changes Created By Published By
1.0 July 2026 Initial publication of the Subprocessors page, listing current sub-processors grouped by purpose (Platform Infrastructure and AI Processing, Website Analytics, Business Operations and Compliance), international transfer safeguards, and vendor security requirements Yash Dave Sumit Rai