Skip to content

Service Providers

Nap OS · Napblog Limited

Last updated: 1 September 2026

We share personal data only with service providers who process it on our documented instructions, each under a written data processing agreement requiring appropriate security. This page lists every one of them. We update it before adding a new provider, and we notify members and institutional customers when we do.

This page supports our Privacy Policy.


Platform infrastructure

All personal data processed through the Nap OS platform — account data, project submissions, assessment records and verification records — is stored within the European Economic Area.

ProviderPurposeEstablishedData location
Hostinger International LtdApplication and website hostingLithuania (EEA)EU
Google Ireland Limited (Google Workspace)Records, document storage, backups, correspondenceIreland (EEA)EU
Stripe Payments Europe LimitedSubscription billing and payment processingIreland (EEA)Ireland

We do not store card numbers. Payment card details are handled entirely by Stripe.

Business operations

ProviderPurposeEstablishedTransfer basis
HubSpotCustomer relationship management, forms and emailUnited StatesStandard Contractual Clauses / EU–US Data Privacy Framework

Artificial intelligence

ProviderPurposeEstablishedTransfer basis
[PROVIDER NAME]Drafting project briefs and assessment rubrics from employer role descriptions[COUNTRY][BASIS]

Our agreement with this provider prohibits the use of any content we send from being used to train their models. No personal data of members is sent to this provider — only employer role descriptions, which the employer then edits and approves.


What we do not do

We do not sell personal data. We do not share it with advertising networks or data brokers. We do not use member data, or the work members produce, to train public foundational AI models.

International transfers

Where a provider is established outside the European Economic Area, that transfer is governed by European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and by technical measures including encryption in transit and at rest. Where no lawful transfer mechanism can be established for a provider, we do not use that provider.

Questions

Email palani@napblog.com.


Napblog Limited · CRO 812006 · 77 Camden Street Lower, Saint Kevin’s, Dublin, D02 XE80, Ireland

Chat with us
N

Privacy & Data Preferences

Nap OS · napblog.com · Controller: Napblog Limited

Legitimate Interest (Art.6(1)(f)): You may object at any time using the toggles below.
Fraud Prevention & Security
Object

Monitor fraudulent activity, bot traffic and abuse. Log security events for incident response.

IP AddressLogin LogsRequest Frequency
12 months
Transactional Communications
Object

Account confirmations, password resets, billing receipts, and critical product updates.

Email AddressNameAccount Status
Account + 7 years
Market Research & Benchmarking
Object

Aggregated, anonymised reports on skills trends and hiring benchmarks. Individuals are never identifiable.

Aggregated SkillsIndustry CategoryTool Popularity
Indefinite (anonymised)
Recruiter & Employer Matching
Object

Make your verified portfolio discoverable to recruiters via the Nap OS CRM. Control visibility in your profile settings.

Public PortfolioVerified SkillsAvailability Status
Until set to private

All data Nap OS collects and with whom it is shared. International transfers use Standard Contractual Clauses per GDPR Chapter V.

Data CategoryPurposeRecipientsSafeguard
Identity Data
Name, email, photo
Account, auth, commsAuth0, SendGrid, AWSSCCs
Career Profile
Skills, experience, tools
Portfolio, AI, CRMOpenAI, Algolia, ClearbitSCCs+DPAs
Integration Data
GitHub repos, GA, Figma
Portfolio verificationGitHub, Google, FigmaOAuth/SCCs
Usage Data
Clicks, sessions, features
Analytics, A/B, AI trainingMixpanel, Hotjar, PostHogSCCs
Device Data
IP, browser, fingerprint
Security, cross-deviceCloudflare, Sentry, SegmentSCCs
Marketing Data
Ad clicks, UTMs
Advertising, CRMGoogle Ads, Meta, LinkedInSCCs+DPAs
Financial Data
Plan, subscription
Subscription managementStripe (PCI DSS L1)SCCs
AI Interactions
NapAI prompts, responses
AI improvementOpenAI, Anthropic (anon)SCCs+DPA

Controller: Napblog Limited, UK · DPO: privacy@napblog.com · Authority: UK ICO

Under UK & EU GDPR you have the following rights. Contact privacy@napblog.com. We respond within 30 days.

Right to Access

Request a full copy of all personal data including your career profile and processing history.

Right to Rectification

Correct inaccurate data. Update your profile and contact details at any time.

Right to Erasure

Request deletion. Account deletion removes your portfolio within 30 days.

Right to Restriction

Request we restrict processing while a dispute is being resolved.

Right to Portability

Export portfolio, skills, and project history in JSON or CSV from your account settings.

Right to Object

Object to legitimate interest processing via the toggles in the Legitimate Interest tab.

Automated Decision Rights

Request human review of any NapAI recommendation that significantly affects you.

Withdraw Consent

Withdraw consent at any time via the Privacy Settings widget. Does not affect prior lawful processing.

Complaints: UK ICO or local EU authority. Contact us first at privacy@napblog.com.

Consent ID: