Legal
Data processing and sub-processors
Last updated · Document version 1.0.0 · Policy set 2026-09-10.710ed20a
Every third party this application sends data to, what reaches each one, and the agency controller/processor position.
Controller and processor
For an executive using BuildPersona for themselves, TODO(legal): registered legal entity name decides how account data is handled in order to run the service.
For an agency workspace, the agency decides what is collected about each executive it represents and what is published in their name. In that arrangement BuildPersona acts on the agency’s instructions and the sub-processors below are engaged to deliver the service. The terms of that arrangement, including whether a written data processing agreement and standard contractual clauses are put in place and how much notice is given before a sub-processor is added, are TODO(legal): agency data processing agreement, transfer mechanism and sub-processor change notice period.
Sub-processors
This is every third party the application sends data to. A service only receives data when the feature that uses it is configured and used.
| Sub-processor | Purpose | What reaches it |
|---|---|---|
| Cloudflare | Hosting, the application database and private file storage. | Everything. All records and all uploaded or received files are held on Cloudflare infrastructure. |
| Apify | Retrieving a public LinkedIn profile for evaluation. | The LinkedIn profile URL you enter. Apify returns the public profile content and keeps the run dataset under its own retention, which BuildPersona cannot delete. |
| OpenRouter, or OpenAI where the deployment is configured for it | Drafting and analysis. | The prompt: profile fields, the extracted profile material that has not been marked private or removed, the interview answers the profile allows to be shared, and the idea or transcript the draft is built from. Material marked private is withheld before the request is made. |
| OpenAI | Transcribing voice notes. | The audio file itself, uploaded to the transcription endpoint, and the transcript returned. |
| LinkedIn (Microsoft) | Sign-in for publishing, and publishing itself. | The OAuth exchange, your member identifier and display name, and the text, images or documents of anything you publish. |
| Meta (WhatsApp Cloud API) | Receiving ideas and voice notes over WhatsApp. | Messages you send to the BuildPersona business number and their media, plus the sender identifier Meta supplies. Meta keeps its own message history. |
| Resend | Transactional email. | Recipient address, subject and body of verification, password-reset and invitation emails. No marketing email is sent. In local development, email is written to a development outbox instead and never leaves the machine. |
| Dodo Payments | Subscriptions and payment. | The billing contact email address, the workspace name, and the subscription and payment records it creates. Card details go to the payment provider directly and never reach BuildPersona. |
There is nothing else. No analytics service, no advertising or tracking network, no session recording, no customer-relationship or support tool receives your data from this application.
International transfers
These services operate internationally. The processing locations relied on, and the transfer mechanism for each, are TODO(legal): per-sub-processor processing locations and transfer mechanism.
Changes to this list
This page carries a version. Adding or replacing a sub-processor is a version change, which the application asks you to review.