Service providers
Who processes personal data for GTJ, and what none of them can see.
This page will be reviewed by a qualified lawyer before registration opens. Last updated .
Current service providers
Global Talent Journey works with 5 companies that receive personal data: 3 process it on the operator’s instructions, and 2 decide their own purposes and take their own responsibility for what they do. The “Role” column says which is which. None of them can read the contents of your vault: vault files, workspaces and private profiles are encrypted on your device before any provider stores them.
| Provider | Role | What for | Personal data | Where | Transfer safeguard | Agreement status |
|---|---|---|---|---|---|---|
| Railway Corporation 548 Market St PMB 68956, San Francisco, California 94104, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Hosting the community engine: the application servers, the database and the cache that hold accounts, community posts, moderation records, encrypted workspace and profile records, file metadata and server logs | Account data (e-mail address, username, name), community content, moderation and appeal records, professional applications and contact requests, IP addresses and usage logs, encrypted records the operator cannot read | EU West region (Amsterdam, Netherlands). Railway's own volume backups are not used; database backups are kept in Cloudflare R2 storage in the EU jurisdiction | EU–US Data Privacy Framework and its UK Extension (Railway listed as active), with the EU Standard Contractual Clauses and UK Addendum in Railway's DPA as fallback. KVKK standard contract: not signed | Railway's data processing agreement has not been signed yet (it is completed through Railway's signature form) |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Registration of the domain name, DNS, delivery of this website, storage of encrypted vault files, storage of the community engine's database backups and deletion records, forwarding of e-mail sent to the contact address, processing with a language model of a question a website visitor types into the assistant on this site, so that it can be answered from this site's own published pages, and — for a member who uses the Pro document assistant — processing the text of that member's own documents with a language model, to turn it into the numbers that make the document searchable and to write the answer | IP addresses and request data of website visitors; encrypted vault files the operator cannot read; daily copies of the community engine's database (account data, community content, moderation and professional records, logs with IP addresses, and the encrypted records), and deletion records holding an account number and times; the sender, recipient, subject and content of e-mail sent to the contact address; the question a website visitor types into the assistant on this site, together with passages from this site's own published pages; and, for a member who uses the Pro document assistant, the readable text of that member's own documents — the whole document once while it is being indexed, and then the excerpts a question retrieves together with the question itself. Cloudflare states in writing that it does not use customer content to train the models it offers or to improve its own or third-party services, unless it has the customer's explicit consent | Encrypted vault files, database backups and deletion records: EU jurisdiction storage. Website delivery, DNS, e-mail forwarding, the language model that answers a website visitor's typed question, and the language model that processes document text for the Pro document assistant: Cloudflare's global network. Both the visitor's question and the member's document text are passed through rather than stored by GTJ's own worker, but Cloudflare publishes no retention period for the prompts and responses it receives, so how long they are kept there is not stated anywhere GTJ has read | EU–US Data Privacy Framework and its UK Extension (Cloudflare listed as active; all three certifications read 'Active – Re-certification under Review' with usage end 15 September 2027, read from the Commerce Department API on 22 September 2026), with the EU Standard Contractual Clauses and UK Addendum in Cloudflare's DPA as fallback. KVKK standard contract: not signed | Cloudflare's data processing addendum (version 6.4) is part of its self-serve agreement; the date GTJ accepted it has not been recorded yet |
| Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, United States Provider’s terms (checked ) | Processor — handles this data on GTJ’s instructions | Sending account e-mails from the community engine: address confirmation, sign-in links, password resets, notifications and contact requests delivered to a professional | Recipient e-mail address and name, and the content of those e-mails (for a contact request to a professional: the name, e-mail address and message the member chose to share) | Sending region EU (Ireland). Resend's regions page states that all account data, including e-mail metadata, logs and API records, is stored in the United States whatever the sending region, and its agreement states that its primary processing takes place in the United States | EU Standard Contractual Clauses, UK Addendum and the EU–US Data Privacy Framework with its UK Extension, as named in Resend's DPA; Resend's framework listing not yet checked by GTJ. KVKK standard contract: not signed | Resend's data processing addendum takes effect when its terms are accepted; the GTJ sending domain is set up and the engine has sent through it since 13 September 2026, but the date GTJ accepted the terms has not been recorded |
| Google LLC (Sign in with Google) 1600 Amphitheatre Parkway, Mountain View, California 94043, United States Provider’s terms (checked ) | Independent controller — decides its own purposes; GTJ instructs it about nothing | Authenticating a member who chooses to sign in with a Google account, instead of an e-mail address and password | What Google returns to GTJ: the member's Google account identifier, e-mail address and name. What Google itself learns: that this Google account signed in to Global Talent Journey, and when, because the sign-in happens on Google's own page. GTJ sends Google no vault file, no workspace, no community content and no document | Not stated for this product. Google's privacy policy says only that it maintains servers around the world and that information may be processed on servers outside the country where the person lives | EU–US Data Privacy Framework, the Swiss–US Framework and the UK Extension: Google LLC is listed as Active on all three (the Data Privacy Framework list, read 19 September 2026), covering HR and non-HR data. No agreement between GTJ and Google covers this product; the agreement column says what was read. KVKK standard contract: not signed | None recorded. Google's API Terms of Service incorporate the Google Controller-Controller Data Protection Terms, under which each party 'is an independent controller', but those terms apply only to the services Google lists as covered — and Google's own list does not name Sign in with Google. The in-scope list of the Google Cloud Data Processing Addendum does not name it either. Both lists read 19 September 2026: Google states no role for this product on any page GTJ has read |
| Apple Inc. (Sign in with Apple) One Apple Park Way, Cupertino, California 95014, United States Provider’s terms (checked ) | Independent controller — decides its own purposes; GTJ instructs it about nothing | Authenticating a member who chooses to sign in with an Apple Account, instead of an e-mail address and password | What Apple returns to GTJ: an Apple account identifier, the name the member may edit before sharing it, an e-mail address which is a forwarding address generated by Apple if the member chooses to hide the real one, and a simple binary score Apple describes as giving the developer confidence that the member is a real person. What Apple itself learns: Apple's privacy page states that Apple does not track which apps or websites a person signs in to, or when. GTJ sends Apple no vault file, no workspace, no community content and no document | Not stated for this product. Apple's privacy policy says personal data collected worldwide is generally stored by Apple Inc. in the United States, and that personal data relating to individuals in the European Economic Area, the United Kingdom and Switzerland is controlled by Apple Distribution International Limited in Ireland | None recorded, and this row is the only one on this page in that position. Apple Inc. is not on the Data Privacy Framework list at all — not as an active participant and not as an inactive one (searched as 'Apple Inc.' and as 'Apple', 19 September 2026) — so the safeguard the other rows rely on does not exist here. Whether the Irish Apple entity named in Apple's own privacy policy answers the question for members in the European Economic Area and the United Kingdom is an open legal point, and it answers nothing for members in Türkiye. Owner item O-41. KVKK standard contract: not signed | None recorded. No data processing agreement for Sign in with Apple was found in the Apple Developer Program License Agreement (read 19 September 2026). Its Sign in with Apple clause sets out what the developer may not do with the data — not sell or share it with advertising platforms, data brokers or information resellers, and not try to re-identify a member who chose to stay anonymous — and states no role for Apple itself |
Each provider’s status was read from its own published terms on the date shown in its row. “Not signed” and “not recorded” describe GTJ’s paperwork, which is still being completed before registration opens.
Hosting providers
For Turkish Law No. 5651, the hosting providers of this service are Railway Corporation (the community engine) and Cloudflare, Inc. (this website and file storage). Their names and addresses are in the first column above.
Signing in with Google or Apple
Signing in with Google or Apple is not available yet, and neither company receives any personal data from Global Talent Journey today. Both are already rows in the table above, with the date, the transfer safeguard and the agreement status, because a company is listed before a single sign-in reaches it rather than after.
Each provider is switched on separately. Whichever is on, choosing it opens that provider’s own sign-in page in your browser; you are never asked for that provider’s password here. What the provider and GTJ then exchange is this and nothing else:
- The provider gives GTJ your e-mail address, your name and the account identifier that provider uses for you. Nothing else: not your vault, not your workspace, not what you post in the community, and not your contacts, calendar, files or anything else in your account with that provider.
- Apple sends two further things, and they are worth knowing before you choose it. If you pick “Hide My Email”, the address GTJ receives is a forwarding address Apple generates for GTJ, not your own — mail still reaches you, and GTJ never learns the real address. Apple also sends a simple yes-or-no indication of whether you appear to be a real person, which Apple calculates and GTJ cannot see the workings of. Google sends neither.
- GTJ uses those three things only to create and run your account, on the same basis as the rest of your account data: necessary for the contract between you and the operator (UK GDPR and EU GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- The provider learns that you signed in to Global Talent Journey, because you do it on that provider’s own page. What happens on that page is the provider’s own business with you, under its own privacy notice, not this one.
- Both companies are in the United States, so this is a transfer abroad — and the two are not in the same position. Their rows in the table above say so plainly, in the “Transfer safeguard” and “Agreement status” columns, and they are worth reading before you choose one. Neither company has an agreement with GTJ about this, and neither states what role it takes; that is what the table records, rather than a gap left blank.
- You never have to use either one. Signing in with an e-mail address and a password keeps working, and an account made one way is the same account.
How changes are announced
- A new provider is added to this list before it receives any personal data, and a change is published here with its date.
- Where possible, GTJ publishes a change at least 30 days before it takes effect. The providers themselves give GTJ advance notice of their own sub-processor changes: Railway 10 days and Cloudflare 30 days, so a change announced by Railway may reach this page with less than 30 days to go.
- A change that affects what data is used or why is also announced in the app before it takes effect.
- If you object to a new provider, tell GTJ through the contact form; you can also delete your account at any time.
List last checked: .
More
What each provider processes as part of GTJ’s wider data use, transfer safeguards and your rights: privacy notice, contact.