Subprocessor List
Kempian's sub-processors, what they do, and where enterprise customers can get full data-flow detail.
This document identifies the third-party sub-processors Kempian uses to operate the Platform, and explains how Kempian handles changes to that list. It is for customers, prospective customers, and other parties evaluating Kempian's data-handling practices.
*This document is part of Kempian's Trust Center documentation. It is reviewed periodically and does not constitute legal advice. Draft v0.2 — pending final legal review before publication.*
Kempian ("we," "us," "our") refers to Adept AI Inc., a Delaware corporation, principal place of business at registered address placeholder.
Public Summary
Kempian engages a limited set of sub-processors to provide the Platform. These include the AI providers that power the AI Features (Candidate Matching, Resume Parsing, the Job Creation Assistant, and the Chat Assistant), plus the infrastructure and operational vendors that support hosting, payments, communications, and analytics.
| Sub-processor | Purpose | Data categories | Location |
| OpenAI | AI processing — Candidate Matching, Resume Parsing, Job Creation Assistant | CV/resume content, employment history, location (Candidate Matching, Resume Parsing); employer-supplied job description inputs, no candidate personal data (Job Creation Assistant) | region |
| Anthropic | AI processing — Candidate Matching | CV/resume content, employment history, location | region |
| HuggingFace | AI processing — Candidate Matching (embedding generation and similarity scoring) | CV/resume content, employment history, location | region |
| Cloud hosting provider | Infrastructure hosting for the Platform | All Platform data, as needed to host the service | region |
| Payment processor | Billing and payment processing for employer/organisation subscriptions | Employer/organisation billing and contact details | region |
| Email delivery provider | Transactional and notification email delivery | Name, email address, and message content necessary to deliver notifications | region |
| Analytics provider | Platform usage analytics | Usage and activity data | region |
Kempian's Chat Assistant runs on Kempian's internal backend and does not currently rely on a named third-party AI sub-processor for its core function.
Change notification. Kempian will notify customers of material changes to this Subprocessor List — including the addition or replacement of a sub-processor — before the change takes effect, through the Platform or by other reasonable means. This is a policy commitment Kempian applies to all customers, not only those with a signed Data Processing Addendum.
How to object. A customer that reasonably objects to a new sub-processor on data-protection grounds may raise the objection with trust@kempian.com. Kempian will work with the customer in good faith to address the objection. This may include making a commercially reasonable change to the processing or, where no resolution is available, allowing the customer to terminate the affected service under its agreement with Kempian.
Enterprise Due-Diligence Detail — Available Under NDA
This section provides additional detail for enterprise customers, procurement teams, and security/legal reviewers conducting vendor due diligence. It is shared candidly, consistent with Kempian's approach in the AI Governance Statement: what is contractually confirmed today, and what remains in progress.
DPA signature status
Kempian intends to have signed Data Processing Agreements in place with each sub-processor listed above, covering matters such as no use of submitted data to train general-purpose models, contractually defined retention limits, and appropriate security commitments.
As of this draft, DPAs with OpenAI, Anthropic, and HuggingFace are not yet confirmed as signed. Until confirmed, enterprise customers should treat OpenAI's and Anthropic's publicly stated enterprise/API-tier positions on data-training exclusion and configurable retention as the target contractual position Kempian is working toward with each provider. This is not yet an already-verified control. DPA status for the infrastructure and operational vendors listed above (cloud hosting provider, payment processor, email delivery provider, analytics provider) is likewise pending confirmation, and will be updated in this document as agreements are finalized.
Data flow detail
| Sub-processor | Specific data categories received | Triggering AI Feature / function |
| OpenAI | Full CV/resume text and structured extraction output (Resume Parsing); CV content, employment history, and location signals used for scoring (Candidate Matching); employer-supplied job requirements and role details, no candidate personal data (Job Creation Assistant) | Candidate Matching, Resume Parsing, Job Creation Assistant |
| Anthropic | CV content, employment history, and location signals used for scoring and for generating "Why this match?" explanation text | Candidate Matching |
| HuggingFace | CV content and employment history, processed to generate embeddings for similarity scoring | Candidate Matching |
| Cloud hosting provider | All Platform data at rest and in transit, as needed to operate the service | Platform-wide infrastructure |
| Payment processor | Employer/organisation billing contact details and payment metadata; no candidate personal data | Billing |
| Email delivery provider | Recipient name, email address, and notification content | Transactional and account notifications |
| Analytics provider | Usage and activity data; not intended to include candidate CV content | Product analytics |
Kempian's data-pseudonymisation control for data sent to third-party AI providers (the "Prompt Sanitiser") is designed but not yet fully built. See the AI Governance Statement for current status. Until it is operational, the data categories above reach the named AI providers substantially as collected, subject to Kempian's standard data-minimization practices in how each AI Feature is integrated.
Audit rights and full agreements
Full, signed data processing agreements (once executed), Standard Contractual Clauses documentation, and audit rights are available to enterprise customers on request, subject to a mutual non-disclosure agreement. Requests should be directed to trust@kempian.com.
Related Documents
This Subprocessor List should be read together with: the Privacy Policy, the AI Transparency Notice, the AI Governance Statement, the Security Overview, and the Data Processing Addendum.
Contact
- Subprocessor notifications, objections, and enterprise due-diligence requests: trust@kempian.com
- General privacy questions: privacy@kempian.com
- Security vulnerability reports: security@kempian.com
Kempian — Subprocessor List — v0.3 (Draft) — July 2026