Skip to main content
Mentum
Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up
Loading...
Loading...
Mentum

Transparent, skills-based job matching.

Browse JobsCompaniesSalariesFor EmployersFor UniversitiesLog inSign up

© 2026 Mentum. All rights reserved.

Privacy PolicyTerms of ServiceCookie PolicyLegalTrust CentreAI TransparencyHelp CentreProduct updatesContact

Apprenticeship vacancies provided under the Open Government Licence v3.0. Contains public sector information.

← Back to Legal

Sub-processor List

Last reviewed 9 August 2026 · Next scheduled review 11 May 2027

Overview

This page is Mentum's public sub-processor list under UK GDPR Article 28(2) (general authorisation) and Article 28(4) (the list customers use to evaluate sub-processor changes and exercise the objection right in our Data Processing Agreement at § 7.4(c)).

If you are a procurement team or Data Protection Officer evaluating Mentum, this page is the authoritative current state. If you have executed our DPA, the matching list at Annex III applies as a contractual term and is updated in lockstep with this page.

The controller of record is Mentum. Data-protection enquiries: privacy@mentumjobs.com. Mentum operates as a sole trader pre-launch and has not designated a formal Data Protection Officer under UK GDPR Art. 37 — the dpo@mentumjobs.com alias is the de-facto routing for DPO-style enquiries, including from procurement teams evaluating Mentum as a processor.

Subscribe to changes

We commit, under § 7.4(b) of the DPA, to thirty days' prior notice with a right to object for any new sub-processor before it begins processing Customer Personal Data.

  • Email list: send a request to subprocessors@mentumjobs.com with the subject line subscribe, including your organisation's legal name and the address you want notifications sent to. We will reply to confirm enrolment.
  • This page: material changes land here within one working day. The change-history section below captures the rolling twelve months.

We do not currently publish an RSS feed of sub-processor changes. If your procurement workflow requires one, write to privacy@mentumjobs.com and we will weigh it against engineering priorities.

Notification policy

  • New sub-processor: thirty days' prior written notice via the channels above, with a right to object on documented data-protection grounds.
  • Removal of a sub-processor: retrospective; this list is updated within one working day of the change.
  • Material scope change (a sub-processor begins handling a new category of data, or moves data to a new region): treated as a new engagement and notified prospectively.

If you object to a proposed sub-processor and Mentum cannot offer a commercially reasonable alternative within thirty days, you may terminate the affected Service for cause with no early-termination fee, per § 7.4(c) of the DPA.

Current sub-processor list

Sub-processorServiceHosting regionTransfer mechanism (UK / EEA)External attestationsMentum DPA status
Supabase Inc.Postgres database, Authentication, Storage, Realtime, Edge FunctionsUS (default); EU regions availableUK adequacy / EU SCCs in Supabase ToS; UK GDPR addendum verification pendingSOC 2 Type 2; ISO 27001; HIPAA — trust.supabase.comIncluded in Supabase ToS
Google LLCGemini API for standard scoring narrative, extraction, classification, persona generation and embeddings; Firebase Cloud Messaging (web-push transport)USEU SCCs Module 2 (signed Google Cloud DPA required)SOC 2 Type 2; SOC 3; ISO 27001; ISO 27017; ISO 27018 — cloud.google.com/security/compliancePending execution
OpenAIResponses API for Career Advisor, interview practice, Enhanced Insights, CV optimisation, Career Compass recommendations, career trajectory, employer hiring advisor and job-description generation. Existing minimised prompt fields are retained; raw CV text is the documented CV-optimisation exception.Provider/account dependent; verify before productionDPA and transfer mechanism required before productionOpenAI security and privacyRequests set store=false. API data is not used for training unless the organisation opts in; Mentum does not opt in. No zero-retention claim is made until the production account controls are evidenced.
Twilio SendGrid Inc.Transactional and lifecycle email deliveryUSEU SCCs Module 2 (implicit in ToS; signed DPA pending)SOC 2 Type 2; ISO 27001; HIPAA-eligible — Twilio DPAPending execution
Railway CorpApplication hosting — API (uvicorn / FastAPI) and the Next.js frontend, including server-side rendering and its session-cookie handling; environment-variable secret store; build and deploy infrastructure; managed Redis (cache and rate-limit counters)US (GCP compute primary; AWS secondary)EU SCCs (implicit in ToS); signed DPA verification pendingSOC 2 Type 2 — railway.com/legal/securityPending DPA verification
GitHub, Inc. (Microsoft)Source-code repository, GitHub Actions CI/CD, Dependabot security advisoriesUS (Microsoft global)EU SCCs via GitHub Customer Agreement (auto-applies on signup)SOC 2 Type 2; ISO 27001; ISO 27017; ISO 27018; FedRAMP-High — github.com/securityExecuted via GitHub Customer Agreement
Functional Software, Inc. (Sentry)Error tracking, performance telemetry, replay-on-error captureUS (EU residency option available)EU SCCs (implicit in ToS); signed DPA pendingSOC 2 Type 2; ISO 27001 — sentry.io/securityPending execution
Redis provider (production pinning operator-pending)Rate-limit sliding-window keys, daily Gemini cost-guard counter, Idempotency-Key body-hash store, async-task active-setProvider-dependentProvider-dependentProvider-dependentPending provider pinning + DPA execution
Adzuna LtdDaily inbound job-feed ingestion (no candidate or customer PII flows outbound)United KingdomUK adequacy (inbound flow only)Not formally attested (private-company partnership)Informal partner arrangement
postcodes.ioUK postcode geocoding (public reference data)United KingdomUK adequacy (public data service)Public data serviceNot required (no personal data transmitted)
Nominatim (OpenStreetMap Foundation)Free-text location geocoding for job search and profile postcode lookup. Browser-direct — the request does not transit Mentum's backend.European Union (Germany)UK adequacy (request originates from the user's browser; Mentum is not in the transfer chain)Public data serviceNot required (browser-direct request)
UK Education and Skills Funding Agency (DfE Apprenticeships Service)Inbound apprenticeship-vacancy feed (no candidate or customer PII flows outbound)United Kingdom (Crown infrastructure)UK adequacy (Crown body; inbound flow only)UK Government Service StandardNot required (inbound feed)
Additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, and direct-employer ATS boards — Greenhouse, Lever, Ashby and similar)Daily inbound job-listing ingestion (inbound only — no candidate or customer PII flows outbound)United Kingdom / provider-dependentUK adequacy / inbound flow only (no personal data sent)Not formally attested (public or partner job feeds)Not required (inbound feed)
Coursera, Inc. and Impact Tech, Inc. (Impact.com affiliate network)Server-side affiliate redirect on learning-course links. When a candidate clicks a course link, Mentum's backend follows the Impact click-tracking chain (the request originates from Mentum's server, forwarding the browser's User-Agent) and 302-redirects the browser to Coursera with a click identifier (irclickid) in the URL. Impact receives Mentum's server IP, the forwarded User-Agent, and the minted click id; no candidate name, email, or profile data is sent. The candidate's browser then loads Coursera directly.USUS — affiliate-network agreement; no candidate personal data transmitted (server-forwarded User-Agent + click id only)Coursera: SOC 2 Type 2; Impact: SOC 2 Type 2Affiliate-network agreement; no candidate personal data shared from Mentum
ClamAV (open-source)File-bytes virus scan on candidate document uploads — runs in Mentum's runtime container; no third-party data flow.Local (Mentum runtime)Not applicableNot applicable (open-source library)Not applicable (no vendor relationship)

The detailed data-category breakdown for each row, including the data-minimisation controls applied at each integration boundary, is recorded in the markdown master (docs/legal/subprocessors.md), available on request via privacy@mentumjobs.com.

What is not a Mentum sub-processor

Two categories are commonly raised in procurement reviews. Both are out of scope for this list:

  • OAuth identity providers (Google sign-in, LinkedIn OIDC sign-in) are upstream identity providers handing a one-time identity assertion to Supabase Auth at signup. They are not engaged by Mentum to process data on a customer's behalf — the user's prior relationship with Google or LinkedIn governs that flow.
  • Browser web-push services (Mozilla Autopush, Apple Push Notification service, Microsoft Windows Notification Service) are chosen by the user's browser when push notifications are enabled. Push payloads are end-to-end encrypted per RFC 8030; the push provider sees only the encrypted bytes plus the destination endpoint URL. Google Firebase Cloud Messaging is the most common destination and is therefore listed under Google LLC; the other push services are not separately engaged by Mentum.

Change history — last twelve months

DateChange
28 Jul 2026Removed Vercel Inc. The Next.js frontend has never been deployed to Vercel — it runs as a Railway service alongside the API — so no personal data has ever been processed by Vercel. The Railway Corp row is widened accordingly to cover frontend hosting, server-side rendering and its session cookies, and managed Redis. This corrects the record; it is not a change of processor.
16 Jul 2026Platform name finalised as Mentum ahead of launch. No change to sub-processors, data flows, hosting regions or transfer mechanisms — a pre-launch branding update only.
15 Jul 2026Reinstated the Coursera, Inc. / Impact Tech, Inc. sub-processor row. Learning-course links now route through a server-side affiliate redirect (GET /api/coursera/go): Mentum's backend resolves the Impact click-tracking chain and forwards the browser's User-Agent, so a processor relationship exists again. The 11 Jul 2026 entry below (recording the removal while links were direct) is retained for an accurate history.
14 Jul 2026Added the additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, and direct-employer ATS boards) as a consolidated inbound-only transparency row — inbound ingestion only, no candidate or customer data transmitted.
11 Jul 2026Removed the Coursera, Inc. / Impact Tech, Inc. row — Coursera learning-course links are now direct (no affiliate wrapper), so no data-flow or processor relationship exists.
11 May 2026Public sub-processor list created at /legal/subprocessors; added Nominatim, UK DfE Apprenticeships Service, and Coursera/Impact as transparency entries (browser-direct or inbound-only); merged Firebase Cloud Messaging into the Google LLC row.
6 May 2026Added Railway, Vercel, GitHub, Sentry, and Redis provider as sub-processors (previously implicit; explicit Record of Processing Activities entries created). Pinned Twilio SendGrid as the production email provider.
4 April 2026Added Adzuna Ltd as inbound data source (job-feed ingestion); noted informal DPA status.

Entries older than twelve months age out of this section. The full audit trail of changes is held in version control alongside the markdown master.

Onward sub-processors

UK GDPR Article 28(2) and ISO 27001 Annex A.5.21 require Mentum to maintain awareness of which sub-processors our sub-processors use. The position for each:

Sub-processorOnward sub-processors
SupabaseAmazon Web Services (compute / storage / network); Cloudflare (CDN, optional)
Google LLCGoogle Cloud (compute / storage / DNS / network) — covered by the Google Cloud DPA
SentryAmazon Web Services (compute / storage); Google Cloud (some services)
Twilio SendGridAmazon Web Services (compute); Twilio internal infrastructure
RailwayGoogle Cloud (primary compute); Amazon Web Services (some services)
GitHubMicrosoft Azure (compute); Microsoft 365 (auth)

How to object to a sub-processor

  1. Email privacy@mentumjobs.com with the subject line "Sub-processor objection — [vendor name]".
  2. State the data-protection ground (typically: inadequate transfer mechanism, missing attestation, or risk to a category of data subject your organisation is responsible for).
  3. We respond within five working days with either an alternative sub-processor, a mitigation plan, or — if no commercially reasonable alternative exists — confirmation of your right to terminate the affected Service under § 7.4(c) of the DPA.

Related: Privacy Policy | Data Processing Agreement | Terms of Service | Cookie Policy