SIKER ("we") uses trusted vendors ("subprocessors" or data processors) that process personal data on our behalf to operate the ecosystem (infrastructure, authentication, payments, communications, analytics, support, and AI). This page fulfills transparency under the SIKER Legal Framework 2025 and institutional Data Processing Agreements (DPA).
1. Scope
This page identifies external processors that handle personal data on SIKER's behalf. It applies to the ecosystem described in the 2025 Legal Framework (siker.info, Auth, Seek, TalentOS, PathMaker, and related services), in coordination with the Privacy Policy and DPAs signed with institutions.
2. General authorization
An institutional client that signs a DPA authorizes SIKER to engage subprocessors listed on this page and those added per the change procedure (section 3). SIKER imposes contractual obligations equivalent to the DPA regarding confidentiality, security, assistance, and data deletion.
3. Changes to subprocessors
When we add or replace a relevant subprocessor:
- We will update the public list at siker.info/subprocessors with the effective date
- We will notify clients with an active DPA at least fourteen (14) days in advance, except for security urgency or legal requirement
- The client may object on substantiated data protection grounds; if no reasonable alternative exists, additional measures or termination may be negotiated per the DPA
4. Subprocessor list
Typical subprocessors in the SIKER ecosystem (the list may vary by product and environment). For each entry: provider, purpose, general data category, and location/transfer status when confirmed:
- Amazon Web Services (AWS) — Purpose: cloud infrastructure and hosting. Data category: account, service and operational data as needed to run the platform. Location/transfer: as set out in the agreement in force with the provider.
- Google Cloud Platform — Purpose: hosting, databases and managed services where used. Data category: service data per deployment. Location/transfer: as set out in the agreement in force with the provider.
- Authentication / identity providers used by SIKER Auth — Purpose: sign-in and session management. Data category: identity and authentication data. Location/transfer: as set out in the agreement in force with the provider.
- Stripe — Purpose: payment processing and subscription billing. Data category: billing and payment metadata (card numbers handled by the processor). Location/transfer: per Stripe terms.
- SendGrid (Twilio) — Purpose: transactional email and notifications. Data category: contact and message metadata. Location/transfer: as set out in the agreement in force with the provider.
- Mixpanel — Purpose: product analytics and usage events (when enabled). Data category: usage and device/event metadata. Location/transfer: as set out in the agreement in force with the provider.
- Google Analytics — Purpose: web visit metrics (when enabled). Data category: online identifiers and usage. Location/transfer: as set out in the agreement in force with the provider.
- Intercom — Purpose: messaging and support communications (when enabled). Data category: contact and support content. Location/transfer: as set out in the agreement in force with the provider.
- Anthropic (Claude commercial API) — Purpose: AI-assisted generation for selected TalentOS/product features. Data category: minimized/pseudonymized task inputs and model outputs (not direct database access). Location/transfer: per Anthropic commercial terms. See https://www.anthropic.com/legal/privacy and https://www.anthropic.com/legal/data-processing-addendum.
- Other AI providers (if enabled for a product outside TalentOS’s default Claude path) — Purpose: AI assistance for that product. Data category: task-scoped inputs/outputs. Location/transfer: as set out in the agreement in force with the provider.
5. Subprocessor obligations
We require subprocessors to: (a) process data only per documented instructions; (b) ensure confidentiality of authorized personnel; (c) implement appropriate security measures; (d) assist with data subject requests and impact assessments when applicable; (e) notify security incidents without undue delay; (f) delete or return data when the service ends, except for legal retention.
6. Enterprise clients
Institutional DPAs may restrict subprocessor categories, require data location in specific regions, or approve additional sub-processors. Audit requests or security questionnaires: dpa@siker.info.
7. Contact
Questions about subprocessors, objection notices, or data processing agreements:
Related documents
Processing of personal data, legal bases, and data subject rights are described in the Privacy Policy.
The authorized, up-to-date list is published at siker.info/subprocessors. B2B clients with a DPA may receive additional notice of material changes.