Hone uses the third-party processors listed below to deliver the service. Changes to this list ship with a deployment of the application. For our Data Processing Addendum, see privacy@hone.co.uk.
| Provider | Purpose | Data shared | Location | DPA |
|---|---|---|---|---|
| Anthropic (Claude API) | AI summaries, intel extraction, candidate/job classification | Candidate CV text, candidate communications, framework + tender notice text, FOI response text | USA | View |
| Supabase | Primary data persistence (Postgres + Storage + Auth) | All workspace data | EU (Ireland, aws eu-west-1) | View |
| Cloudflare Workers | Compute + edge delivery | In-transit application data | Global edge | View |
| Stripe | Subscription billing | Workspace owner email, billing details, workspace name | Ireland + USA | View |
| Resend | Transactional + outbound email | Email recipient addresses, message content | USA | View |
| Twilio | SMS delivery (per-workspace via BYO credentials) | Phone numbers, message content | Per-workspace Twilio account | View |
| Google Workspace (Gmail / Drive OAuth) | Optional integration when workspace connects | Per-user inbox + selected Drive folders | Per-user Google account | View |
| Microsoft 365 (Outlook OAuth) | Optional integration when workspace connects | Per-user inbox | Per-user Microsoft account | View |
| Companies House API | Company profile lookup | Company names and numbers queried | UK | — |
| Care Quality Commission (CQC) API | Care provider lookup | Provider names queried | UK | — |
| NHS Digital ODS API | NHS organisation lookup | Organisation names queried | UK | — |
| Firecrawl | Notice text fetching from Contracts Finder / Find a Tender | Outbound URLs only | USA | View |
| Voyage AI | Text embeddings for semantic search and matching | Candidate CV text, job/tender text passed for embedding | USA | View |
| Google (Gemini API) | AI classification, embeddings, and enrichment fallbacks | Candidate CV text, job/tender text, framework/FOI notice text (no billing identifiers) | USA / EU (per Google Cloud region) | View |
| Sentry | Application error and performance monitoring | Error events and diagnostic metadata (stack traces, request context); PII scrubbed before send | USA | View |
| PostHog | Product analytics | Product usage events with pseudonymous user and workspace identifiers | USA | View |