Sub-processor List

Zelvar uses the following third-party sub-processors to deliver our services. We conduct due diligence on all sub-processors and require them to maintain appropriate security standards.

VendorPurposeData ProcessedRegionCertifications
SupabaseDatabase, authentication, and storageAll candidate and recruiter data, authentication tokens, uploaded filesUS-East-1 (AWS)SOC 2 Type II, ISO 27001
Anthropic (Claude)AI screening analysis and transcript processingCall transcript text only — no PII beyond what candidates share verballyUnited StatesSOC 2 Type II
Retell AIVoice calling infrastructure and AI agent hostingAudio recordings (90-day retention), call metadataUnited StatesSOC 2 Type II
TwilioSMS message deliveryPhone numbers, message contentUnited StatesSOC 2 Type II, ISO 27001, HIPAA eligible
SendGrid (Twilio)Transactional email deliveryEmail addresses, email contentUnited StatesSOC 2 Type II, ISO 27001
n8nWorkflow automation and trigger orchestrationTrigger events only — no PII stored in n8nEU / United StatesISO 27001 (in progress)
NetlifyApplication hosting and CDN deliveryNo personal data — static assets onlyUnited StatesSOC 2 Type II
CloudflareDNS, domain registration, and DDoS protectionNo personal data — DNS resolution onlyGlobalSOC 2 Type II, ISO 27001, PCI DSS

Last updated: April 4, 2026.

We notify clients of material sub-processor changes 30 days in advance via email. If you have questions about our sub-processors, contact [email protected].