Data in the EU
All operations and storage take place on servers in the EU. A data processing agreement is signed as standard, and sub-processors are listed in it.
Security and GDPR
Sick leave, pay, review notes and personality profiles all sit in the same place. That is why access control, retention and traceability are not something bolted on afterwards — they are part of the data model.
All operations and storage take place on servers in the EU. A data processing agreement is signed as standard, and sub-processors are listed in it.
Roles are defined down to field level. A manager sees their own team; a payroll administrator sees pay data; an HR partner sees their own units. Nobody sees more than they need.
Every look at an employee record, every change and every export is logged with user, timestamp and field. The log cannot be edited.
Access
Permissions are set per role and per field — not per module. That is the difference between a team lead seeing that someone is off sick, and seeing the diagnosis.
Retention
GDPR requires that you do not keep personal data longer than necessary. In practice that is the rule most organisations break — not deliberately, but because nobody gets round to clearing up. Komma does it automatically.
Karma and your data
There are good reasons to be sceptical about AI in HR. Here is what we do about them.
Karma works on your own dataset. The content is not used to train models that benefit other customers.
Karma suggests and ranks. Hiring, pay, warnings and dismissals are decided by people — and that is not a setting you can switch off.
Each suggestion is logged with what Karma proposed, what was changed, and who approved it.
Karma can be disabled per module, if you would like it in recruitment but not in payroll processing.
Questions
On servers in the EU. The specific locations and sub-processors are listed in the data processing agreement, which we send before you sign a contract — not after.
Yes, via Microsoft Entra ID, with automatic user provisioning. When an account is closed in Entra, access to Komma closes at the same time.
Yes, at any time and in machine-readable format — not just at termination. When the agreement ends you get a full extract, and data is then deleted according to the deadline you set.
Access to customer data requires a specific support case and is logged. We do not look through your data to see how it is going — and you can see in the audit trail if we have been in.
An employee can pull their own data directly in the platform. If you as data controller need to answer an access request, you can gather everything about one person in a single extract across the modules.
If you need a data processing agreement, security documentation or answers to a vendor questionnaire, we are happy to send it before a demo. Write to hej@kommahr.com.
Security and compliance
Hosted in the EU, built to GDPR, and auditable down to the individual field. Your DPO can see exactly who changed what, and when.
Read how we handle your dataDecide what every role can see and change
Microsoft Entra, one log-in for everyone
Records delete themselves on your schedule
Every change, with a name and a timestamp
See the system exactly as another role sees it
We are happy to meet your IT team or DPO before we show the product at all.