Data principles

It is your data. We are just holding it.

HR data is about as personal as data gets: sick leave, pay, review notes and personality profiles, all in one place. These are the rules that decide how it is stored, who can reach it, and when it stops existing.

01You own it, and you can take it with you

Your data is exportable in a machine-readable format at any time — not only when you leave. When an agreement ends you get a full extract, and what remains is deleted on the schedule you set rather than kept as leverage.

02It stays in the EU, and the sub-processors are named

All operations and storage happen on servers in the EU. The data processing agreement is signed as standard and lists every sub-processor — we send it before you sign a contract, not after.

03The least access that still gets the work done

Roles are defined down to field level and scoped to departments, locations or legal entities. That is the difference between a team lead seeing that somebody is off sick and seeing the diagnosis. A simulation view shows exactly what a given role can see before you grant it.

04Deletion is a deadline, not an intention

Retention deadlines are set per data type — applicants, leavers, documents — and deletion or anonymisation happens automatically when the deadline passes. Not keeping data too long is the rule most organisations break by accident, so the system does it rather than a person remembering to.

05One record, not five copies

Every module reads from the same employee record. That is a data-protection position as much as a product one: a fact that exists once can be corrected once, restricted once and deleted once — where five synchronised copies leave a trail nobody can fully account for.

06We handle gross pay. Tax and net stay with the engine

Komma builds and validates gross pay lines and hands them to Zenegy, Danløn, Dataløn, Visma, Lessor or Intect. A-skat, AM-bidrag, holiday pay calculation, eIndkomst and payslips belong to the payroll engine, which stays the authoritative source. Net and tax appear in Komma only as data the engine sent back.

07Every read, change and export is logged

The audit trail records who looked at an employee record, what changed, which field it was and when. The log cannot be edited. That includes us: our access to customer data requires a specific support case, and you can see in the log if we have been in.

08Data only leaves through a key with a role

Nothing goes out through a nightly CSV sitting on a share. The API issues keys against a data role, and the role decides which objects and which fields that key may read — so a reporting key cannot return a salary or a CPR number, whatever the caller asks for. See how the API works.

The awkward parts

Where these principles cost us something

Field-level roles make setup slower than a system with three permission levels. Automatic deletion means data a manager wanted to keep "just in case" is gone. An anonymity threshold on pulse surveys means a small team's results sometimes cannot be shown at all — including to the person who commissioned the survey.

We have been asked to make each of those configurable. The answer has been no, because a threshold with an override is not a threshold, and a deletion rule somebody can postpone indefinitely is a preference.

If you need something on this page to work differently, tell us before you buy. It is a fair thing to want, and a bad thing to discover in month four.

Send it to your DPO first.

We are happy to hand over the data processing agreement, the sub-processor list and security documentation before there is any talk of a demo.