Sub-Processors

Effective Date: April 11, 2026 Last Updated: April 11, 2026

This page lists the sub-processors that Sentient AI Inc. (dba "NexxaScreen") engages to process personal data on behalf of our customers in connection with the NexxaScreen platform.

For details on how sub-processor changes are communicated, see our Data Processing Agreement.

Current Sub-Processors

Sub-Processor Purpose Categories of Data Processed Hosting Location DPA Available
Amazon Web Services (AWS) Cloud infrastructure, object storage (S3), AI services (Bedrock), text-to-speech (Polly), email delivery (SES) All platform data including interview recordings, transcripts, and AI-generated assessments US (us-east-1) AWS DPA
Anthropic AI interview analysis, scoring, and communication assessment (Claude models via AWS Bedrock) Interview transcripts, de-identified interview data US Anthropic Terms
Deepgram Speech-to-text transcription Interview audio recordings US Deepgram Privacy
LiveKit Real-time video and audio infrastructure for live interviews Interview audio/video streams (transient — not stored by LiveKit) US LiveKit Privacy
Twilio SIP telephony for phone interviews, WhatsApp transactional messaging, SMS delivery Phone numbers, message content, call metadata US Twilio DPA
Meta Platforms (WhatsApp Business) WhatsApp promotional messaging (future) Phone numbers, message templates, delivery status US / EU Meta DPA
Stripe Payment processing and subscription billing Billing information, company details, transaction records (NexxaScreen does not store card numbers) US Stripe DPA
Laravel Forge Server provisioning and deployment management Server configuration data (no personal data directly) US
Hetzner Online Application hosting (primary servers) All platform data (encrypted at rest) EU (Germany) Hetzner DPA
Umami Privacy-focused website analytics (cookieless) Anonymized usage data (no personal data collected) Self-hosted
Google Analytics Website analytics (GA4) Anonymized usage data, IP addresses (anonymized), page views US Google DPA
Google (OAuth) Social authentication (Google Sign-In) Name, email address, profile photo (as authorized by user) US Google Privacy
LinkedIn (OAuth) Social authentication (LinkedIn Sign-In) Name, email address, professional profile data (as authorized by user) US LinkedIn DPA
Resend Transactional email delivery Email addresses, email content US Resend Privacy
Tavus AI-generated video avatars for interactive interviews Interview session data (transient — video generated in real-time, not stored by Tavus) US Tavus Privacy

Planned Sub-Processors

The following sub-processors are planned but not yet active. We will update this page and notify registered DPA contacts before they are engaged.

Sub-Processor Purpose Expected Data Hosting Location
PostHog Product analytics and session replay Usage data, session recordings US / EU
Veriff or Onfido Identity verification for candidates Government ID documents, selfie photos EU / US
Sentry Application error monitoring De-identified error context, stack traces (no personal data) US
Meta Cloud API WhatsApp Business promotional messaging (separate from Twilio integration) Phone numbers, message templates US / EU

Changes to Sub-Processors

NexxaScreen notifies customers who have executed a Data Processing Agreement at least 10 days before engaging a new sub-processor. To register for notifications, contact [email protected].

If you object to a new sub-processor, please refer to the objection process described in our Data Processing Agreement.

Contact

For questions about our sub-processors or data processing practices, contact us at [email protected].

We use essential cookies for site functionality and optional analytics cookies (Google Analytics) to understand how you use our site. Umami analytics is cookieless and always active. Cookie Policy