GDPR & Processing
Last updated: September 14, 2026
This page describes a different relationship than our privacy policy. Where the privacy policy covers your data as a website visitor, this page covers data that Rec-Motion customers (recruitment agencies) process in their own workspace โ for example, candidate data in an ATS.
Who is who
For data a customer enters into their workspace, the customer is the controller (they determine purpose and means โ which candidates, for which vacancies). Rec-Motion is a processor: we process that data only on the customer's instructions, as set out in a data processing agreement.
Data processing agreement
Every customer using the platform enters into a data processing agreement with Rec-Motion under GDPR Art. 28. Contact privacy@rec-motion.eufor a copy of the template or to get one signed.
Sub-processors
To run the platform, we use the following sub-processors. Any change to this list is communicated to customers in advance.
- Supabase โ database, authentication and realtime functionality
- Cloudflare โ file storage (CVs, documents, recordings) and network security
- Vercel โ application hosting
- Resend โ transactional email (invites, notifications)
- Anthropic (Claude API) โ AI features like summaries and message generation; see below
AI processing
Certain features (like summarizing a candidate profile or generating an outreach message) send relevant text to Anthropic's Claude API. This data is not used to train Anthropic's models. AI features can be reviewed per workspace by the customer themselves.
Data location
Where possible, we choose infrastructure with EU data centers. For specific questions about where your workspace's data is stored, contact your account manager or privacy@rec-motion.eu.
Data subject rights
As a candidate whose data sits in a customer workspace, direct your access, correction, or deletion request to the recruitment agency itself โ they are the controller. Rec-Motion supports customers in handling such requests but doesn't act on them directly without the customer's instruction.
Security incidents
In the event of a data breach affecting a customer's data, we notify the affected customer without undue delay so they can meet their own reporting obligations.