Data processing

The standing terms under which we process personal data on a customer's behalf. This page is the agreement — there is nothing separate to sign.

Last updated 20 July 2026

Status of this page

These are the data processing terms required by Article 28 of the GDPR. They form part of the Terms and take effect when you begin using the service. No separate signature is needed and none is offered: a customer buying a shortlist with a card cannot negotiate a bespoke agreement, so the agreement is published instead. It binds us in the same way a signed one would.

If you operate under a master services agreement with its own data processing annex, that annex governs and this page is subordinate to it.

Roles

You are the controller. You decide which role you are filling, which people are researched, and what happens to the result.

We are the processor. Zero One Labs LLC processes candidate personal data on your instructions in order to produce the shortlists you commission.

For data about your own account holders, we act as controller instead; that is covered by the privacy notice and not by this page.

Scope of the processing

Subject matter and duration

Researching, verifying and documenting candidates against role specifications you approve, for as long as you hold an account and for the retention period that follows.

Nature and purpose

Collecting personal data from public and licensed sources; verifying it against independent sources; assessing it against your role specification; writing it up with citations; storing it so that a delivered list stays auditable.

Categories of data subject

Candidates and potential candidates for roles you are filling — working professionals, researched in their professional capacity.

Categories of personal data

  • identity and contact: name, public profile URLs, general location;
  • professional history: employer, role, tenure, responsibilities, education, public output such as talks, articles and code;
  • assessments we generate: the evidence gathered, the sources cited, the verification status of each claim, and the score computed against your specification;
  • your own records about the person: the decision you took and the reason you gave.

A profile photograph may be displayed in the console, streamed from its origin at the moment of display. It is never stored by us.

Special category data

We do not seek special category data — health, religion, ethnicity, political opinions, trade union membership, sexual orientation — and it is not part of any assessment. You must not instruct us to research it or write it into a role specification. Where such material appears incidentally on a public page, it does not become evidence for or against a candidate.

Our obligations

  • Documented instructions. We process personal data only on your instructions. Your approved role specification and your use of the console are those instructions. If we believe an instruction breaches data protection law, we will tell you and may decline it.
  • Confidentiality. Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to operate the service.
  • Security. The measures described in the next section.
  • Subprocessors. Engaged as listed below, each under a written contract with obligations no weaker than these.
  • Assistance. We help you respond to data subject requests, and with your obligations on security, breach notification and impact assessments, taking into account what we know and what you know.
  • Deletion and return. On termination, or on your instruction, we delete or return the personal data we hold for you.
  • Information. We make available what you need to demonstrate compliance with Article 28, and cooperate with audits you reasonably require.

Security measures

Stated specifically, because a list of adjectives is not a security measure:

  • Isolation between customers.Every record carries the practice that owns it, and all access passes through a single scoped data layer. An automated isolation test seeds two practices and checks that no query reaches the other’s rows; it runs as part of the test suite and fails the build if isolation breaks.
  • Separate identity records per controller. The records that carry contact history and Article 14 notice state are kept per practice, never shared between customers.
  • Access control. No passwords are held. Sign-in is a one-time code to a verified email address. A confirmed account without a membership can open nothing.
  • No photograph storage. Candidate images are streamed transiently with caching disabled and are never written to disk, blob storage or the database.
  • Encryption in transit for all traffic, and encryption at rest as provided by our database and hosting providers.
  • Provenance in the record. Every claim carries its source, so an inaccuracy can be traced to where it came from rather than argued about.

We hold no security certifications and make no claim to any. The measures above are what the system does.

Subprocessors

We engage the following subprocessors. You consent to them by accepting these terms; we will give notice before adding or replacing one, and you may object on reasonable data protection grounds.

SubprocessorWhat it doesLocation
NeonPostgres database — account data and research artifactsEU (AWS Frankfurt, eu-central-1)
VercelApplication hosting and request servingUnited States / global edge
Exa LabsSearch index — finding and reading public pages and professional profilesUnited States
Bright DataPublic LinkedIn profile data, logged-out viewIsrael / United States
AnthropicLanguage models that perform the research reasoning and write the profilesUnited States
MailpaceTransactional email — sign-in codes, invitations, delivery noticesEU (France) / United Kingdom
StripePayments for self-serve customers — card data never reaches us; an independent controller for payment dataUnited States / EU

Three services are consulted as public sources rather than engaged as subprocessors, because we send them no candidate personal data: Brønnøysundregistrene, the Norwegian business register (public authority data); Cloudflare’s public 1.1.1.1 resolver (we send domain names only, and Cloudflare deletes resolver log data within 25 hours); and GitHub (we read public profile and repository data through the public API, without authentication).

International transfers

Account data and research artifacts are stored in the EU. Several subprocessors above operate outside the EEA, and personal data is transferred to them in the course of the processing — a search query naming a person, a profile URL sent for verification, a document sent to a language model.

The mechanism relied on for each subprocessor, verified against that vendor’s own published terms:

  • NeonCovered by Databricks' active EU-US Data Privacy Framework certification (Neon, LLC is a named covered entity); EU SCCs incorporated in the Databricks data processing terms.
  • VercelEU SCCs plus the UK addendum in their DPA; also certified under the EU-US Data Privacy Framework.
  • Exa LabsEU SCCs (Module 2) and the UK IDTA, incorporated in their DPA.
  • Bright DataWe contract with Bright Data Ltd. (Israel); transfers rest on the European Commission's adequacy decision for Israel.
  • AnthropicEU SCCs with UK and Swiss addenda in their DPA; API inputs and outputs are not used to train models.
  • MailpaceOhMySMTP Ltd (UK) under the UK's EU adequacy decision, renewed December 2025; infrastructure in France and the EU.
  • StripeEU-US Data Privacy Framework first (Stripe, LLC is certified); EEA SCCs where it does not apply.

Data subject requests

If a candidate contacts us directly, we do not answer on your behalf. We identify the controller and pass the request to you promptly, and we give you what you need to answer it — including the sources relied on for every claim, which are recorded in the deliverable itself.

Where you instruct us to correct, restrict or erase a person’s record, we act on it. Your own decision records are kept as an append-only audit trail of your review process; where erasure requires those to go too, say so and we will action it.

Personal data breach

If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any event within 48 hours of becoming aware, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Notifying a supervisory authority or the affected people is the controller’s decision, which means yours.

Contact

Data protection matters: privacy@01.inc. Zero One Labs LLC, a limited liability company organised in Texas, United States · 5900 Balcones Dr, STE 100, Austin, TX 78731 · Texas Taxpayer No. 32098806634.