Subprocessors
The subprocessor register, and why recruitment needs one
Recruitment software sends candidate text to other companies to do its job, and a buyer is entitled to know which categories of company those are before signing.
A subprocessor is a vendor that processes your candidate data so Surhires can run. The register lists them by category and named entity: hosting, model providers, messaging and telephony, email delivery, analytics and support tooling. A stated notice period runs before any addition, with an objection route. The published register is authoritative, not this page.
By Surhires Editorial · Published · Reviewed
What this page is, and where the live list actually lives
This is a plain-English explanation of how the subprocessor register works and what the categories mean. It is deliberately not a list of vendor names, because a list typed into a marketing page goes stale the week after it is written and then misleads the next reader. The authoritative register is the published one, versioned and dated, with a change-notification subscription attached to it.
The binding commitments about subprocessors sit in the data processing addendum: the flow-down terms, the notice period, the objection route and Soor LLC's continuing responsibility for its subprocessors' performance. This page explains that structure. The addendum is the document that enforces it, and nothing here is legal advice about whether the structure satisfies your obligations.
If you are running a security review right now, the two things to ask for are the current register with its version date and the notice period stated in the addendum. Those two facts tell you more about a vendor's data handling than any paragraph on a website.
Recruitment raises the stakes on this more than most software does
In most business software a subprocessor sees metadata: an email address, a company name, an invoice line. In recruitment software, the data flowing to other companies is the substance of a person's working life. A resume is employment history, education, salary expectation, location, immigration signals, health disclosures people put in without thinking, and often a photograph.
Two categories in particular receive that substance rather than metadata. Model providers receive resume text and job descriptions because parsing, matching and drafting cannot happen otherwise. Messaging and telephony providers receive message bodies, phone numbers and, where call recording is enabled, audio of a candidate speaking about their circumstances.
That is the honest reason this page exists as a separate page rather than a line in the privacy policy. A buyer evaluating recruitment software should know which categories of third party will hold candidate substance, because it is a question their own clients will eventually ask them.
The categories, and what each one actually receives
Six categories are used, and the register lists the named entities inside each one. Hosting and infrastructure holds the primary data store, object storage for uploaded documents, and encrypted backups. Model providers receive resume text, job descriptions and prompt context for parsing, matching, drafting and summarisation. Messaging and telephony providers carry SMS and WhatsApp message bodies, phone numbers and, where enabled, call audio.
Email delivery providers carry outbound message bodies, recipient addresses and delivery events. Analytics and product telemetry receives usage and error data about the application rather than candidate content. Support tooling receives whatever a person chooses to put into a support ticket, which is why the support process asks people not to paste candidate records into tickets.
Each category is described in the register with what it processes, why it is needed and where it processes. That last field is the one to read if you have a residency requirement, because a category can be fine in principle and unacceptable in the region a particular vendor runs in.
- Hosting and infrastructure: primary store, document storage, encrypted backups
- Model providers: resume text, job descriptions and prompt context
- Messaging and telephony: message bodies, numbers and optional call audio
- Email delivery: outbound bodies, recipient addresses, delivery events
- Analytics and telemetry: application usage and errors, not candidate content
- Support tooling: ticket content, which is why tickets should not carry records
Model providers are the category that deserves the most attention
The commitment here is specific. Candidate data sent to a model provider is sent to serve your request and is not used to train general models offered to anyone else. The contractual terms behind that sit with the provider and are reflected in the flow-down obligations of the addendum, and retention at the provider is configured to the shortest option the provider supports.
There are limits worth naming. Model processing is a synchronous call to another company's infrastructure, and while the content is transient and covered by the terms above, a firm with a hard rule against any candidate content leaving its own boundary cannot use AI matching, parsing or drafting. That is a real constraint, and the sensible answer is to disable those features rather than to pretend the calls do not happen.
Demographic data is a separate case with an absolute rule. It is never included in a prompt, a feature vector, an embedding, a training set or a fine-tune. The payload assembled for any model call is built from an allow-list of fields, and the demographic table is not on that list and cannot be added to it by configuration.
Notice, objection and what happens if you say no
A new subprocessor is not added quietly. The register is versioned, changes are published, and a subscription route exists so the person responsible for vendor management in your firm hears about a change without watching a web page. A stated notice period runs before the new subprocessor begins processing customer data.
Inside that period you can object on reasonable data protection grounds. An objection is a conversation first: sometimes the concern is met by configuration, by region selection or by excluding your tenant from the affected feature. Where it cannot be resolved, the escalation ends at termination for the affected service without penalty.
The reason to look for that escalation clause in any vendor's paper, not only this one, is simple. A notice you have no power to act on is an announcement. The objection route is what converts a notice into a control, and its absence tells you what the notice is actually worth.
- A versioned, dated register rather than a paragraph in a policy
- Change notification by subscription, not by watching a page
- A stated notice period before processing begins
- Objection on reasonable data protection grounds inside the period
- Unresolved objections escalate to termination for the affected service
Your own integrations are not our subprocessors
This distinction gets lost regularly and it matters. When you connect your own LinkedIn Recruiter seat, your own WhatsApp Business number, your own Twilio account, your own job board contract or your own accounting system, you are the one instructing that vendor. They are your processors or your independent controllers, not ours, and they do not appear on our register.
The practical consequence is that your data protection assessment has to cover them, your contracts have to reach them, and their notices belong in your candidate-facing documentation. A buyer who assumes the CRM vendor's register covers the whole stack ends up with a gap exactly where the candidate messaging happens.
Where an integration is provided as part of the service rather than connected under your own account, it sits on the register like anything else. The integration pages state which model applies for each connector, and the register is the place to check when the answer matters.
How to use the register during a security review
Reviewers tend to ask for a list and stop. The register is more useful read as four questions per entry: what does this vendor receive, why is it necessary, where does it process, and what happens to your tenant if you object to it. An entry that cannot answer the second question is a vendor somebody should be removing rather than documenting.
For firms whose clients audit them, the register is also a supply-chain document. Staffing suppliers to regulated buyers are routinely asked to name the subprocessors behind their own tooling, and being able to hand over a versioned register with a date on it is considerably easier than reconstructing one under a deadline.
The register is not a certification and does not imply one. It is a disclosure. What it lets you do is make your own decision about a chain of vendors instead of taking a single reassuring sentence on trust.
What you get
Versioned register
Published with a version and a date, so a reviewer can cite the exact list they assessed.
Six named categories
Hosting, model providers, messaging and telephony, email delivery, analytics, support tooling.
Per-entry purpose
Each entry states what it processes, why it is required and where the processing happens.
Change subscription
Notification of additions and removals by subscription rather than by watching a page.
Stated notice period
A defined period runs before a new subprocessor begins processing customer data.
Objection route
Reasonable data protection objections raised inside the notice period get a real response.
Escalation to exit
An unresolved objection ends at termination for the affected service, without penalty.
Flow-down terms
Every subprocessor is bound by terms no less protective than the data processing addendum.
Continuing responsibility
Soor LLC remains answerable to you for its subprocessors, rather than pointing downstream.
No training on your data
Model providers process your requests; your candidate data does not train general models.
Minimum retention at providers
Provider-side retention configured to the shortest option each provider supports.
Demographic exclusion
Demographic fields are never sent to a model, and cannot be added to the payload by configuration.
Feature-level opt-out
Firms that cannot send candidate text to a model can disable parsing, matching and drafting.
Your integrations excluded
Connectors you authorise under your own accounts are your processors, not ours, and are named as such.
Questions recruiters ask
Why does this page not list the vendor names?
Because a list on a marketing page goes stale and then misleads whoever reads it next. The authoritative register is published separately, versioned and dated, with change notification attached. Ask for the current version during procurement and keep it with your assessment. A name typed here in good faith six months ago is worse than no name at all.
Does our candidate data get used to train AI models?
No. Data sent to a model provider serves your request, and is not used to train general models offered to other customers. Provider-side retention is configured to the shortest option available, and demographic fields are never included in any model payload. Those commitments are reflected in the flow-down terms of the data processing addendum.
Can we use Surhires if candidate text may not leave our boundary?
Partly. Pipeline, records, scheduling and reporting work without external model calls. Parsing, matching, drafting and summarisation do not, because they are calls to another company's infrastructure. The honest answer is to disable those features rather than to pretend the calls do not happen, and to size the value of the product accordingly before you buy.
What can we actually do if we object to a new subprocessor?
Raise it inside the notice period on data protection grounds. Some concerns are resolved by configuration, region selection or excluding your tenant from the affected feature. Where it cannot be resolved, the escalation ends at termination for the affected service without penalty. A notice clause with no objection route is an announcement rather than a control.
Do the integrations we connect ourselves appear on your register?
No. When you connect your own LinkedIn Recruiter seat, WhatsApp number, telephony account or job board contract, you are instructing that vendor and they sit in your chain rather than ours. Your assessment and your candidate-facing notices need to cover them. Connectors provided as part of the service do appear on the register.
Does publishing a register mean you are certified?
No, and it should not be read that way. A register is a disclosure that lets you assess a vendor chain yourself. It is not an audit, a certification or an assurance report. SOC 2 readiness is a separate programme in progress with a Type I report as the first deliverable, and no Type II report is claimed until one is issued.
Keep reading
- What the processor agreement commits us to, clause by clause
- Two sets of people, two different roles, one privacy position
- The compliance matrix, walked posture by posture
- Holding candidate data lawfully under UK and EU GDPR
- The engineering answer to how your candidate data is protected
- Where responsibility sits for every regime that touches recruitment
- Twelve named agents, and where each one really stands
See it against your own reqs
Bring one live role and three resumes. In twenty minutes you will see the match scores, the shortlist and the placement invoice that comes out the other end.