Skip to main content

Sub-processors

Last updated: January 2025

This page lists the sub-processors that Marxel uses to process personal data on behalf of our customers. This list forms Annex 1 of our Data Processing Agreement.

We will provide at least 14 days' notice before engaging any new sub-processor. If you have questions or wish to object to a sub-processor, contact us at hello@marxel.co.

Authorised Sub-processors

The following sub-processors are authorised to process personal data on behalf of our customers:

Sub-processorPurposeLocationData ProcessedEvidence
Vercel Inc.Application hosting and deliveryUnited States / global infrastructureApplication traffic, logs, and customer data in transitVercel DPA
Railway CorporationDatabase hosting where configuredUnited States / selected infrastructure regionApplication database records and customer data at restRailway DPA
UploadThingCV file upload and file storageUnited States / global infrastructureUploaded files, filenames, file URLs, and file metadataUploadThing Privacy
OpenAI, L.L.C.AI-powered parsing, OCR fallback, evaluation, and embeddingsUnited StatesCandidate data submitted to AI featuresOpenAI DPA
SentryError monitoring, performance monitoring, and session replayUnited States / European UnionError events, diagnostics, masked replay data, and operational metadataSentry DPA
Resend Inc.Transactional email deliveryUnited StatesEmail addresses, names, and email contentResend Privacy
Stripe Inc.Payment processing and subscription managementUnited States / global infrastructureBilling data and subscription metadata, not CV contentStripe DPA
PostHog Inc.Product analytics and masked session replay when enabled with consentUnited States / European UnionUsage events, product analytics metadata, and masked replay dataPostHog DPA
Google LLCGoogle OAuth authentication and website analytics when enabledUnited States / global infrastructureOAuth profile data, email addresses, IP addresses, and analytics eventsGoogle API Services User Data Policy
Upstash, Inc.Redis-backed caching and rate limiting when configuredUnited States / selected infrastructure regionCache keys, cached AI outputs, and rate-limit metadataUpstash Trust

Transfer Safeguards

We rely on provider data processing terms, transfer mechanisms such as Standard Contractual Clauses where applicable, and supplementary safeguards appropriate to each service.

For transfers from the UK, we also rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs where applicable.

Notification of Changes

We will update this page and provide at least 14 days' notice before engaging any new sub-processor.

If you wish to be notified of changes by email, please contact us at hello@marxel.co to subscribe to sub-processor updates.

Objection Process

If you have reasonable data protection grounds to object to a new sub-processor:

  1. Notify us within 14 days of receiving notice of the change
  2. Explain your objection with reference to specific data protection concerns
  3. We will work with you to find a mutually acceptable solution
  4. If no resolution is reached, you may terminate the affected service with no penalty

Contact

For questions about our sub-processors or to request a copy of the safeguards in place:

See also our Data Processing Agreement, Privacy Notice, and Terms of Service or contact us with any questions.