Data processing
The standing terms under which we process personal data on a customer's behalf. This page is the agreement — there is nothing separate to sign.
Last updated 20 July 2026
Status of this page
These are the data processing terms required by Article 28 of the GDPR. They form part of the Terms and take effect when you begin using the service. No separate signature is needed and none is offered: a customer buying a shortlist with a card cannot negotiate a bespoke agreement, so the agreement is published instead. It binds us in the same way a signed one would.
If you operate under a master services agreement with its own data processing annex, that annex governs and this page is subordinate to it.
Roles
You are the controller. You decide which role you are filling, which people are researched, and what happens to the result.
We are the processor. Zero One Labs LLC processes candidate personal data on your instructions in order to produce the shortlists you commission.
For data about your own account holders, we act as controller instead; that is covered by the privacy notice and not by this page.
Scope of the processing
Subject matter and duration
Researching, verifying and documenting candidates against role specifications you approve, for as long as you hold an account and for the retention period that follows.
Nature and purpose
Collecting personal data from public and licensed sources; verifying it against independent sources; assessing it against your role specification; writing it up with citations; storing it so that a delivered list stays auditable.
Categories of data subject
Candidates and potential candidates for roles you are filling — working professionals, researched in their professional capacity.
Categories of personal data
- identity and contact: name, public profile URLs, general location;
- professional history: employer, role, tenure, responsibilities, education, public output such as talks, articles and code;
- assessments we generate: the evidence gathered, the sources cited, the verification status of each claim, and the score computed against your specification;
- your own records about the person: the decision you took and the reason you gave.
A profile photograph may be displayed in the console, streamed from its origin at the moment of display. It is never stored by us.
Special category data
We do not seek special category data — health, religion, ethnicity, political opinions, trade union membership, sexual orientation — and it is not part of any assessment. You must not instruct us to research it or write it into a role specification. Where such material appears incidentally on a public page, it does not become evidence for or against a candidate.
Our obligations
- Documented instructions. We process personal data only on your instructions. Your approved role specification and your use of the console are those instructions. If we believe an instruction breaches data protection law, we will tell you and may decline it.
- Confidentiality. Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to operate the service.
- Security. The measures described in the next section.
- Subprocessors. Engaged as listed below, each under a written contract with obligations no weaker than these.
- Assistance. We help you respond to data subject requests, and with your obligations on security, breach notification and impact assessments, taking into account what we know and what you know.
- Deletion and return. On termination, or on your instruction, we delete or return the personal data we hold for you.
- Information. We make available what you need to demonstrate compliance with Article 28, and cooperate with audits you reasonably require.
Security measures
Stated specifically, because a list of adjectives is not a security measure:
- Isolation between customers.Every record carries the practice that owns it, and all access passes through a single scoped data layer. An automated isolation test seeds two practices and checks that no query reaches the other’s rows; it runs as part of the test suite and fails the build if isolation breaks.
- Separate identity records per controller. The records that carry contact history and Article 14 notice state are kept per practice, never shared between customers.
- Access control. No passwords are held. Sign-in is a one-time code to a verified email address. A confirmed account without a membership can open nothing.
- No photograph storage. Candidate images are streamed transiently with caching disabled and are never written to disk, blob storage or the database.
- Encryption in transit for all traffic, and encryption at rest as provided by our database and hosting providers.
- Provenance in the record. Every claim carries its source, so an inaccuracy can be traced to where it came from rather than argued about.
We hold no security certifications and make no claim to any. The measures above are what the system does.
Subprocessors
We engage the following subprocessors. You consent to them by accepting these terms; we will give notice before adding or replacing one, and you may object on reasonable data protection grounds.
| Subprocessor | What it does | Location |
|---|---|---|
| Neon | Postgres database — account data and research artifacts | EU (AWS Frankfurt, eu-central-1) |
| Vercel | Application hosting and request serving | United States / global edge |
| Exa Labs | Search index — finding and reading public pages and professional profiles | United States |
| Bright Data | Public LinkedIn profile data, logged-out view | Israel / United States |
| Anthropic | Language models that perform the research reasoning and write the profiles | United States |
| Mailpace | Transactional email — sign-in codes, invitations, delivery notices | EU (France) / United Kingdom |
| Stripe | Payments for self-serve customers — card data never reaches us; an independent controller for payment data | United States / EU |
Three services are consulted as public sources rather than engaged as subprocessors, because we send them no candidate personal data: Brønnøysundregistrene, the Norwegian business register (public authority data); Cloudflare’s public 1.1.1.1 resolver (we send domain names only, and Cloudflare deletes resolver log data within 25 hours); and GitHub (we read public profile and repository data through the public API, without authentication).
International transfers
Account data and research artifacts are stored in the EU. Several subprocessors above operate outside the EEA, and personal data is transferred to them in the course of the processing — a search query naming a person, a profile URL sent for verification, a document sent to a language model.
The mechanism relied on for each subprocessor, verified against that vendor’s own published terms:
- Neon — Covered by Databricks' active EU-US Data Privacy Framework certification (Neon, LLC is a named covered entity); EU SCCs incorporated in the Databricks data processing terms.
- Vercel — EU SCCs plus the UK addendum in their DPA; also certified under the EU-US Data Privacy Framework.
- Exa Labs — EU SCCs (Module 2) and the UK IDTA, incorporated in their DPA.
- Bright Data — We contract with Bright Data Ltd. (Israel); transfers rest on the European Commission's adequacy decision for Israel.
- Anthropic — EU SCCs with UK and Swiss addenda in their DPA; API inputs and outputs are not used to train models.
- Mailpace — OhMySMTP Ltd (UK) under the UK's EU adequacy decision, renewed December 2025; infrastructure in France and the EU.
- Stripe — EU-US Data Privacy Framework first (Stripe, LLC is certified); EEA SCCs where it does not apply.
Data subject requests
If a candidate contacts us directly, we do not answer on your behalf. We identify the controller and pass the request to you promptly, and we give you what you need to answer it — including the sources relied on for every claim, which are recorded in the deliverable itself.
Where you instruct us to correct, restrict or erase a person’s record, we act on it. Your own decision records are kept as an append-only audit trail of your review process; where erasure requires those to go too, say so and we will action it.
Personal data breach
If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any event within 48 hours of becoming aware, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Notifying a supervisory authority or the affected people is the controller’s decision, which means yours.
Contact
Data protection matters: privacy@01.inc. Zero One Labs LLC, a limited liability company organised in Texas, United States · 5900 Balcones Dr, STE 100, Austin, TX 78731 · Texas Taxpayer No. 32098806634.