Skip to main content

Sub-processors

Third-party service providers that process data on our behalf

Version 1.5 · Last updated: August 17, 2026

Legally binding version

The German version of this document is the legally authoritative text. Translations into other languages are provided for convenience only; in case of any conflict or discrepancy, the German version prevails.

In accordance with GDPR Article 28 and the Swiss Federal Data Protection Act (FADP), we disclose the third-party providers that CHW-Services GmbH engages to deliver the preparAItor service. Each provider has been carefully selected and is bound by a data processing agreement that meets our security and compliance standards.

This list covers both processors (where we act as the controller for individual end users) and sub-processors (where we act as a processor for business customers under a Data Processing Addendum). The obligations under GDPR Article 28 and FADP Article 9 apply analogously in both arrangements.

Sub-processorPurposeData CategoriesLocation
Google LLC (Firebase)Authentication, database (Firestore), file storage, App CheckAccount data, CV content, generated documents, usage dataeurope-west6 (Zurich, Switzerland)
Google LLC (Vertex AI / Gemini)AI document generation, content analysis, web grounding for company enrichment, interview practice (including short-lived processing of audio input during voice interview sessions; voice recordings are not stored, only encrypted transcripts). Google does not use customer data to train its models.CV content, job postings, company data, interview audio (transient) and transcriptsEuropean Union — Google Cloud EU multi-region (regions in EU member states only)
Google LLC (Cloud KMS)Encryption key management for field-level encryption of sensitive dataEncryption keys only (no personal data)europe-west6 (Zurich, Switzerland)
Google LLC (Cloud Run)Document PDF/DOCX generation and heavy processingDocument content during generationeurope-west6 (Zurich, Switzerland)
Google LLC (reCAPTCHA Enterprise)Bot detection and fraud prevention via Firebase App Check on every API requestIP address, device fingerprint, interaction signalsGlobal infrastructure — transfer safeguards: Google Cloud DPA with SCCs
Stripe, Inc.Payment processing for one-time credit purchases, webhook handlingPayment details, billing address, customer ID, transaction metadataEuropean data centers (primary), with fallback to the United States
Resend (Resend, Inc.)Transactional email delivery (account confirmation, password reset, billing notifications, document ready notifications)Email address, display name, email contentUnited States — transfer safeguards: standard contractual clauses for EEA, UK and Swiss transfers
Microsoft CorporationOneDrive cloud file synchronization (optional, only when user explicitly connects their OneDrive account)Generated documents, OAuth tokens (encrypted)European data centers (primary)
Google LLC (Google Drive)Google Drive cloud file synchronization (optional, only when user explicitly connects their Google account)Generated documents, OAuth tokens (encrypted)User's Google Drive region — transfer safeguards: Google Cloud DPA with SCCs
Cloudflare, Inc.Cookieless, aggregate visitor measurement on our public marketing website (preparaitor.ch) only — page views, referring sites and approximate country. Uses no analytics cookies or persistent client-side identifiers; performs no fingerprinting and no cross-site tracking. Not loaded by the application at app.preparaitor.ch.Technical information necessary to process the request, including IP address; page address, referring site, approximate country, browser and device typeUnited States — transfer safeguards: Cloudflare’s Data Privacy Framework certifications, with standard contractual clauses as a fallback
PostHog, Inc.Cookieless, aggregate product measurement inside the application (app.preparaitor.ch) — how many people reach each step, on what device type, from which campaign. Sets no cookies, writes nothing to browser storage and keeps no persistent identifier; performs no session recording, no profiling and no cross-site tracking. Visitor counts derive from an irreversible hash calculated on PostHog’s servers with a secret that rotates daily and is then deleted. Never linked to an account: no name, e-mail address, user identifier, CV or job content is transmitted. Can be switched off in Settings.Technical information necessary to process the request, including IP address (discarded once the daily hash is computed, never stored); page address, referring site, browser, operating system, device type and screen size; interface language; campaign parameters; the name of the product step reachedEuropean Union (Frankfurt) — hosted on PostHog Cloud EU. PostHog, Inc. is a US company; transfer safeguards: standard contractual clauses under its data processing agreement
Google LLC (Google Ads)Advertising conversion measurement. Applies only to visitors who reach us by clicking one of our Google adverts. Google adds a click identifier to the landing address; if an account is then created we store that identifier and later report back to Google that a registration, and subsequently a first document generation, occurred. This is a server-to-server report: no advertising pixel, tag or cookie is used, and nothing is stored on or read from the visitor’s device.Google advertising click identifier (GCLID/GBRAID/WBRAID) and campaign parameters, together with the occurrence, time and assigned value of a conversion event. No name, e-mail address, CV, job data or account content is transmitted.United States — transfer safeguards: Google LLC is certified under the EU-US Data Privacy Framework and its Swiss and UK extensions, with standard contractual clauses as a fallback

Transfer Safeguards

  • Standard Contractual Clauses (SCCs) executed with all providers where applicable
  • Data Processing Agreements (DPAs) in place with every provider
  • Encryption in transit (HTTPS/TLS) and at rest
  • Field-level encryption via Google Cloud KMS for sensitive personal data
  • Data localization to European data centers where technically feasible
  • Regular security and compliance audits
  • Transfer Impact Assessment (TIA) conducted for all cross-border data flows per Schrems II requirements
  • No cookie-based or cross-site tracking analytics in use (no Google Analytics, no error-tracking SDKs, no marketing pixels or advertising tags). Three forms of measurement exist, none of which stores or reads anything on a visitor’s device: cookieless, aggregate visitor counting on our public marketing website, which does not identify or fingerprint visitors; cookieless, aggregate product measurement inside the application, which keeps no persistent identifier, is never linked to an account and can be switched off in Settings; and server-side advertising conversion measurement, which reports a registration back to Google Ads against the click identifier Google itself added to the landing address, and only for visitors who arrived via one of our adverts
  • Compliance with Swiss FADP and EU GDPR

Changelog

  • August 17, 2026Version 1.5 — Added PostHog, Inc. as a processor for cookieless, aggregate product measurement inside the application, hosted in the European Union. The statement that no analytics runs inside the application was amended accordingly; we continue to confirm that no cookie-based, profile-based or cross-site tracking analytics is in use, that nothing is stored on or read from your device for measurement, and that the measurement can be switched off in Settings.
  • July 31, 2026Version 1.4 — Added Google LLC (Google Ads) as a recipient for advertising conversion measurement. When a visitor reaches us by clicking one of our Google adverts, the click identifier Google places in the landing address is stored with the resulting account and reported back to Google to record that a registration occurred. No advertising pixel, tag or cookie is introduced and nothing is stored on or read from a visitor’s device; the report is made server-to-server and carries no name, e-mail address, CV, job data or account content. The transfer-safeguards statement was amended accordingly.
  • July 27, 2026Version 1.3 — Replaced Postmark (AC PM LLC) with Resend, Inc. as our transactional email provider. Email delivery continues to take place in the United States; the categories of data processed are unchanged. Resend, Inc. is certified under the EU-US Data Privacy Framework and its UK extension, and transfers from Switzerland and the EEA are additionally safeguarded by standard contractual clauses.
  • July 21, 2026Version 1.2 — Replaced Brevo SAS with Postmark (AC PM LLC) as our transactional email provider; email delivery now takes place in the United States rather than the European Union. Added Cloudflare, Inc. as a processor for cookieless, aggregate visitor measurement on our public marketing website. The transfer-safeguards statement was amended accordingly: we no longer state that no analytics service is used, and instead confirm that no cookie-based or cross-site tracking analytics is in use.
  • April 26, 2026Version 1.1 — Clarified controller vs. processor role. Specified that voice interview audio is processed transiently by Vertex AI and not stored. Added explicit statement that no analytics or telemetry services are used.
  • April 10, 2026Version 1.0 — Initial publication.

For questions about our sub-processors, to request a DPA, or to object to sub-processor changes, contact us at admin@preparaitor.ch.

See also: Privacy Policy · Terms of Service