Technical and Organizational Security Measures (TOMs)
TOMs are essential safeguards for protecting personal data. Here is a detailed overview of the security measures we implement at FunnelBridge.
Risk assessment of the FunnelBridge chatbot (EU AI Act)
This risk assessment evaluates the FunnelBridge chatbot in accordance with the requirements of the EU AI Act.
It includes information about the chatbot’s functionality, areas of use, and compliance with regulatory standards. The full assessment can be viewed here.
List of sub-processors
Below is the list of sub-processors and how we use their services.
Definitions
End users: Applicants and candidates interacting with the WhatsApp bot.
Company customers: Employees of companies using WhatsApp Hiring (formerly FunnelBridge).
Internal company data: Non-personal data such as source code and documentation used for development.
Microsoft Corporation
Purpose of data processing | Scope |
Microsoft Azure OpenAI Service for processing WhatsApp messages during the application process | Processing and storage |
Type of data | Location |
Personal data of end users generated during WhatsApp communication with the FunnelBridge bot | Germany and France |
DigitalOcean, LLC
Purpose of data processing | Scope |
Provider of cloud infrastructure and data center for the FunnelBridge platform | Processing and storage |
Type of data | Location |
Personal data of end users generated and stored during the use of FunnelBridge | Germany |
Hubspot, Inc.
Purpose of data processing | Scope |
Customer Relationship Management (CRM) | Processing and storage |
Type of data | Location |
Personal data of company customers who communicate with FunnelBridge employees via email | European Union |
Stripe, Inc.
Purpose of data processing | Scope |
Payment processing | Processing and storage |
Type of data | Location |
Personal data of FunnelBridge customers that is necessary for payment processing, including payment information | Ireland |
Plus Five Five, Inc.
Purpose of data processing | Scope |
Sending e-mail notifications | Processing and storage |
Type of data | Location |
Personal data of FunnelBridge customers needed for email notifications | Ireland |
Meta Platforms, Inc.
Purpose of data processing | Scope |
WhatsApp Business API | Processing only, no storage |
Type of data | Location |
Personal data of end users generated during WhatsApp communication with the FunnelBridge Bot | Germany |
ChartMogul GmbH & Co. KG
Purpose of data processing | Scope |
Internal business reporting | Processing and storage |
Type of data | Location |
Contact details and accounting data of company customers | Ireland (AWS eu-west-1) |
DeepL SE
Purpose of data processing | Scope |
Translation of processed conversations | Processing only, no storage |
Type of data | Location |
Personal data of end users generated during WhatsApp communication with the FunnelBridge Bot | Sweden, Finland |