Providers and subprocessors

Concise register for the JOOOOB service. It keeps transparent where website, email, feedback and operational data may pass.

Register

ProviderRoleStatusPotential dataUseNote
Aruba S.p.A.Hosting, domain, emailActiveWebsite technical data, voluntarily sent emailWebsite publishing and mailboxesNot used for marketing analytics.
Google Search ConsoleIndexingActiveTechnical data and public URLsDomain verification, sitemap and Google presenceNot a replacement for marketing analytics.
Microsoft ClarityBehavioural analytics and usabilityOnly after Measurement consentTechnical interactions, clicks, scrolling and recordings with sensitive fields maskedIdentify friction on public pages and in the purchase pathExcluded from the questionnaire, private dashboards, administration and storage.
Google Forms / SheetsService feedbackOptionalClient ID and non-sensitive feedback answersMeasure usefulness, clarity, personalisation and willingness to purchaseThe form must not ask for CVs, phone numbers, LinkedIn or sensitive data.
Configured AI/API providerAnalysis and assisted writing supportTo be confirmed based on operationsMinimised CV/profile, questionnaire and candidate-provided contextGenerate or improve requested reportsPurpose-limited use. No automated eligibility decision.
GitHubCode repository and technical documentationActive for codeNo real candidate dataVersioning website, templates and principlesReal data, CVs, questionnaires and reports must not be committed.
LinkedInOptional candidate-provided sourceNot a default subprocessorOnly public profile/link if explicitly providedVoluntary professional contextNo hidden scraping, credentials, cookies, spam or automation.

Update rule

If a new provider starts processing client data, this register must be updated before operational use or as soon as the provider becomes stable.

When in doubt, treat the item as USER_CONFIRMATION_REQUIRED until verified.