Sub-processor List
Last reviewed 9 August 2026 · Next scheduled review 11 May 2027
Overview
This page is Mentum's public sub-processor list under UK GDPR Article 28(2) (general authorisation) and Article 28(4) (the list customers use to evaluate sub-processor changes and exercise the objection right in our Data Processing Agreement at § 7.4(c)).
If you are a procurement team or Data Protection Officer evaluating Mentum, this page is the authoritative current state. If you have executed our DPA, the matching list at Annex III applies as a contractual term and is updated in lockstep with this page.
The controller of record is Mentum. Data-protection enquiries: privacy@mentumjobs.com. Mentum operates as a sole trader pre-launch and has not designated a formal Data Protection Officer under UK GDPR Art. 37 — the dpo@mentumjobs.com alias is the de-facto routing for DPO-style enquiries, including from procurement teams evaluating Mentum as a processor.
Subscribe to changes
We commit, under § 7.4(b) of the DPA, to thirty days' prior notice with a right to object for any new sub-processor before it begins processing Customer Personal Data.
- Email list: send a request to subprocessors@mentumjobs.com with the subject line
subscribe, including your organisation's legal name and the address you want notifications sent to. We will reply to confirm enrolment. - This page: material changes land here within one working day. The change-history section below captures the rolling twelve months.
We do not currently publish an RSS feed of sub-processor changes. If your procurement workflow requires one, write to privacy@mentumjobs.com and we will weigh it against engineering priorities.
Notification policy
- New sub-processor: thirty days' prior written notice via the channels above, with a right to object on documented data-protection grounds.
- Removal of a sub-processor: retrospective; this list is updated within one working day of the change.
- Material scope change (a sub-processor begins handling a new category of data, or moves data to a new region): treated as a new engagement and notified prospectively.
If you object to a proposed sub-processor and Mentum cannot offer a commercially reasonable alternative within thirty days, you may terminate the affected Service for cause with no early-termination fee, per § 7.4(c) of the DPA.
Current sub-processor list
| Sub-processor | Service | Hosting region | Transfer mechanism (UK / EEA) | External attestations | Mentum DPA status |
|---|---|---|---|---|---|
| Supabase Inc. | Postgres database, Authentication, Storage, Realtime, Edge Functions | US (default); EU regions available | UK adequacy / EU SCCs in Supabase ToS; UK GDPR addendum verification pending | SOC 2 Type 2; ISO 27001; HIPAA — trust.supabase.com | Included in Supabase ToS |
| Google LLC | Gemini API for standard scoring narrative, extraction, classification, persona generation and embeddings; Firebase Cloud Messaging (web-push transport) | US | EU SCCs Module 2 (signed Google Cloud DPA required) | SOC 2 Type 2; SOC 3; ISO 27001; ISO 27017; ISO 27018 — cloud.google.com/security/compliance | Pending execution |
| OpenAI | Responses API for Career Advisor, interview practice, Enhanced Insights, CV optimisation, Career Compass recommendations, career trajectory, employer hiring advisor and job-description generation. Existing minimised prompt fields are retained; raw CV text is the documented CV-optimisation exception. | Provider/account dependent; verify before production | DPA and transfer mechanism required before production | OpenAI security and privacy | Requests set store=false. API data is not used for training unless the organisation opts in; Mentum does not opt in. No zero-retention claim is made until the production account controls are evidenced. |
| Twilio SendGrid Inc. | Transactional and lifecycle email delivery | US | EU SCCs Module 2 (implicit in ToS; signed DPA pending) | SOC 2 Type 2; ISO 27001; HIPAA-eligible — Twilio DPA | Pending execution |
| Railway Corp | Application hosting — API (uvicorn / FastAPI) and the Next.js frontend, including server-side rendering and its session-cookie handling; environment-variable secret store; build and deploy infrastructure; managed Redis (cache and rate-limit counters) | US (GCP compute primary; AWS secondary) | EU SCCs (implicit in ToS); signed DPA verification pending | SOC 2 Type 2 — railway.com/legal/security | Pending DPA verification |
| GitHub, Inc. (Microsoft) | Source-code repository, GitHub Actions CI/CD, Dependabot security advisories | US (Microsoft global) | EU SCCs via GitHub Customer Agreement (auto-applies on signup) | SOC 2 Type 2; ISO 27001; ISO 27017; ISO 27018; FedRAMP-High — github.com/security | Executed via GitHub Customer Agreement |
| Functional Software, Inc. (Sentry) | Error tracking, performance telemetry, replay-on-error capture | US (EU residency option available) | EU SCCs (implicit in ToS); signed DPA pending | SOC 2 Type 2; ISO 27001 — sentry.io/security | Pending execution |
| Redis provider (production pinning operator-pending) | Rate-limit sliding-window keys, daily Gemini cost-guard counter, Idempotency-Key body-hash store, async-task active-set | Provider-dependent | Provider-dependent | Provider-dependent | Pending provider pinning + DPA execution |
| Adzuna Ltd | Daily inbound job-feed ingestion (no candidate or customer PII flows outbound) | United Kingdom | UK adequacy (inbound flow only) | Not formally attested (private-company partnership) | Informal partner arrangement |
| postcodes.io | UK postcode geocoding (public reference data) | United Kingdom | UK adequacy (public data service) | Public data service | Not required (no personal data transmitted) |
| Nominatim (OpenStreetMap Foundation) | Free-text location geocoding for job search and profile postcode lookup. Browser-direct — the request does not transit Mentum's backend. | European Union (Germany) | UK adequacy (request originates from the user's browser; Mentum is not in the transfer chain) | Public data service | Not required (browser-direct request) |
| UK Education and Skills Funding Agency (DfE Apprenticeships Service) | Inbound apprenticeship-vacancy feed (no candidate or customer PII flows outbound) | United Kingdom (Crown infrastructure) | UK adequacy (Crown body; inbound flow only) | UK Government Service Standard | Not required (inbound feed) |
| Additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, and direct-employer ATS boards — Greenhouse, Lever, Ashby and similar) | Daily inbound job-listing ingestion (inbound only — no candidate or customer PII flows outbound) | United Kingdom / provider-dependent | UK adequacy / inbound flow only (no personal data sent) | Not formally attested (public or partner job feeds) | Not required (inbound feed) |
| Coursera, Inc. and Impact Tech, Inc. (Impact.com affiliate network) | Server-side affiliate redirect on learning-course links. When a candidate clicks a course link, Mentum's backend follows the Impact click-tracking chain (the request originates from Mentum's server, forwarding the browser's User-Agent) and 302-redirects the browser to Coursera with a click identifier (irclickid) in the URL. Impact receives Mentum's server IP, the forwarded User-Agent, and the minted click id; no candidate name, email, or profile data is sent. The candidate's browser then loads Coursera directly. | US | US — affiliate-network agreement; no candidate personal data transmitted (server-forwarded User-Agent + click id only) | Coursera: SOC 2 Type 2; Impact: SOC 2 Type 2 | Affiliate-network agreement; no candidate personal data shared from Mentum |
| ClamAV (open-source) | File-bytes virus scan on candidate document uploads — runs in Mentum's runtime container; no third-party data flow. | Local (Mentum runtime) | Not applicable | Not applicable (open-source library) | Not applicable (no vendor relationship) |
The detailed data-category breakdown for each row, including the data-minimisation controls applied at each integration boundary, is recorded in the markdown master (docs/legal/subprocessors.md), available on request via privacy@mentumjobs.com.
What is not a Mentum sub-processor
Two categories are commonly raised in procurement reviews. Both are out of scope for this list:
- OAuth identity providers (Google sign-in, LinkedIn OIDC sign-in) are upstream identity providers handing a one-time identity assertion to Supabase Auth at signup. They are not engaged by Mentum to process data on a customer's behalf — the user's prior relationship with Google or LinkedIn governs that flow.
- Browser web-push services (Mozilla Autopush, Apple Push Notification service, Microsoft Windows Notification Service) are chosen by the user's browser when push notifications are enabled. Push payloads are end-to-end encrypted per RFC 8030; the push provider sees only the encrypted bytes plus the destination endpoint URL. Google Firebase Cloud Messaging is the most common destination and is therefore listed under Google LLC; the other push services are not separately engaged by Mentum.
Change history — last twelve months
| Date | Change |
|---|---|
| 28 Jul 2026 | Removed Vercel Inc. The Next.js frontend has never been deployed to Vercel — it runs as a Railway service alongside the API — so no personal data has ever been processed by Vercel. The Railway Corp row is widened accordingly to cover frontend hosting, server-side rendering and its session cookies, and managed Redis. This corrects the record; it is not a change of processor. |
| 16 Jul 2026 | Platform name finalised as Mentum ahead of launch. No change to sub-processors, data flows, hosting regions or transfer mechanisms — a pre-launch branding update only. |
| 15 Jul 2026 | Reinstated the Coursera, Inc. / Impact Tech, Inc. sub-processor row. Learning-course links now route through a server-side affiliate redirect (GET /api/coursera/go): Mentum's backend resolves the Impact click-tracking chain and forwards the browser's User-Agent, so a processor relationship exists again. The 11 Jul 2026 entry below (recording the removal while links were direct) is retained for an accurate history. |
| 14 Jul 2026 | Added the additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards via Stonefish, and direct-employer ATS boards) as a consolidated inbound-only transparency row — inbound ingestion only, no candidate or customer data transmitted. |
| 11 Jul 2026 | Removed the Coursera, Inc. / Impact Tech, Inc. row — Coursera learning-course links are now direct (no affiliate wrapper), so no data-flow or processor relationship exists. |
| 11 May 2026 | Public sub-processor list created at /legal/subprocessors; added Nominatim, UK DfE Apprenticeships Service, and Coursera/Impact as transparency entries (browser-direct or inbound-only); merged Firebase Cloud Messaging into the Google LLC row. |
| 6 May 2026 | Added Railway, Vercel, GitHub, Sentry, and Redis provider as sub-processors (previously implicit; explicit Record of Processing Activities entries created). Pinned Twilio SendGrid as the production email provider. |
| 4 April 2026 | Added Adzuna Ltd as inbound data source (job-feed ingestion); noted informal DPA status. |
Entries older than twelve months age out of this section. The full audit trail of changes is held in version control alongside the markdown master.
Onward sub-processors
UK GDPR Article 28(2) and ISO 27001 Annex A.5.21 require Mentum to maintain awareness of which sub-processors our sub-processors use. The position for each:
| Sub-processor | Onward sub-processors |
|---|---|
| Supabase | Amazon Web Services (compute / storage / network); Cloudflare (CDN, optional) |
| Google LLC | Google Cloud (compute / storage / DNS / network) — covered by the Google Cloud DPA |
| Sentry | Amazon Web Services (compute / storage); Google Cloud (some services) |
| Twilio SendGrid | Amazon Web Services (compute); Twilio internal infrastructure |
| Railway | Google Cloud (primary compute); Amazon Web Services (some services) |
| GitHub | Microsoft Azure (compute); Microsoft 365 (auth) |
How to object to a sub-processor
- Email privacy@mentumjobs.com with the subject line "Sub-processor objection — [vendor name]".
- State the data-protection ground (typically: inadequate transfer mechanism, missing attestation, or risk to a category of data subject your organisation is responsible for).
- We respond within five working days with either an alternative sub-processor, a mitigation plan, or — if no commercially reasonable alternative exists — confirmation of your right to terminate the affected Service under § 7.4(c) of the DPA.
Related: Privacy Policy | Data Processing Agreement | Terms of Service | Cookie Policy