Authorized Third-Party
Sub-Processors List.
Last Updated: January 2026. In accordance with Section 8 of the Indian DPDP Act 2023 and Article 28 of the GDPR, this page explicitly discloses the third-party service providers authorized to process data on behalf of Ascent.
Minimalist Sub-Processor Architecture (Sovereign Data Storage)
Ascent is engineered with a strict Zero Third-Party Bloat Architecture. Unlike legacy platforms that bundle numerous tracking scripts and third-party vendor dependencies, your candidate database, resume files, and billing records reside strictly on your designated sovereign infrastructure. We only transmit ephemeral text payloads to external AI inference engines strictly when necessary for automated parsing.
Authorized External Data Processors
The following vendor is the sole external third party authorized to receive and process ephemeral data for specific algorithmic services:
| Third-Party Entity | Processing Function | Data Location | Legal & Privacy Safeguards |
|---|---|---|---|
Google LLC (Google AI / Gemini API) Artificial Intelligence & Natural Language Processing | Processes text snippets from job descriptions and candidate resumes for semantic skills extraction and match scoring. | Enterprise Cloud Infrastructure (USA / Global via Encrypted HTTPS API) | Google Cloud Data Processing Addendum (Cloud DPA), SOC 2 Type II, ISO 27001, Zero Customer Data Training Guarantee |
First-Party & Customer-Controlled Infrastructure
The following essential operational components operate as direct first-party systems or under direct customer configuration, and are not third-party sub-processors:
Candidate resumes, notes, and database records are stored directly within sovereign server storage / local database disks under the primary host deployment. No external database vendors hold unencrypted copies of your candidate resumes.
Emails (OTP codes, candidate links, client approvals) are transmitted through the agency's authenticated SMTP mail server or dedicated relay configured in System Settings, ensuring direct end-to-end transport encryption (TLS 1.3).
Sub-Processor Change Notifications
If Legion Hiresoft India Private Limited intends to engage any new external sub-processor to handle customer personal data, account administrators will be notified at least thirty (30) days in advance, with statutory rights to object or review the updated data protection safeguards.
Data Protection Desk: admin@hiresoft.in
Corporate Entity: Legion Hiresoft India Private Limited
Sovereign, Secure Staffing Infrastructure.
Engineered with zero third-party bloat and transparent data protection standards.