Security and GDPR

HR data is the most personal data you hold

Sick leave, pay, review notes and personality profiles all sit in the same place. That is why access control, retention and traceability are not something bolted on afterwards — they are part of the data model.

Data in the EU

All operations and storage take place on servers in the EU. A data processing agreement is signed as standard, and sub-processors are listed in it.

Role-based access

Roles are defined down to field level. A manager sees their own team; a payroll administrator sees pay data; an HR partner sees their own units. Nobody sees more than they need.

Full audit trail

Every look at an employee record, every change and every export is logged with user, timestamp and field. The log cannot be edited.

Access

The least access that still gets the work done

Permissions are set per role and per field — not per module. That is the difference between a team lead seeing that someone is off sick, and seeing the diagnosis.

  • Roles with permissions down to individual fields
  • Scoping to your own departments, locations or legal entities
  • Single sign-on via Microsoft Entra ID
  • Automatic user provisioning and revocation on exit
  • Anonymity thresholds on pulse surveys that managers cannot bypass
  • Simulation view: see exactly what a given role can see
Settings · RolesRolesUsersAudit log
RoleScopeUsers
HRHR administratorWhole org3
PAPayroll administratorPay data2
TLTeam leadOwn team18
EMEmployeeOwn data304

Retention

Deletion that happens on its own

GDPR requires that you do not keep personal data longer than necessary. In practice that is the rule most organisations break — not deliberately, but because nobody gets round to clearing up. Komma does it automatically.

  • Retention deadlines per data type: applicants, leavers, documents
  • Automatic deletion or anonymisation once the deadline passes
  • Exceptions where legislation requires longer retention
  • Consent handling for applicants, with expiry and renewal
  • Export of your own data in machine-readable format at any time
  • Full extract and deletion when the agreement ends
Settings · Data retentionPoliciesUpcoming
Deleting this month
128
applicant profiles
Anonymising
14
leavers
Policies
9
active
Data typeDeadlineAction
Applicants, not hired6 monthsDelete
Former employees5 yearsAnonymise
Payroll records5 yearsRetain (accounting act)

Karma and your data

The AI is an assistant, not a decision-maker

There are good reasons to be sceptical about AI in HR. Here is what we do about them.

Your data does not train anyone else's models

Karma works on your own dataset. The content is not used to train models that benefit other customers.

No automated decisions

Karma suggests and ranks. Hiring, pay, warnings and dismissals are decided by people — and that is not a setting you can switch off.

Everything is traceable

Each suggestion is logged with what Karma proposed, what was changed, and who approved it.

It can be switched off

Karma can be disabled per module, if you would like it in recruitment but not in payroll processing.

Questions

What your IT and compliance teams usually ask

Where exactly is the data stored?

On servers in the EU. The specific locations and sub-processors are listed in the data processing agreement, which we send before you sign a contract — not after.

Do you support single sign-on?

Yes, via Microsoft Entra ID, with automatic user provisioning. When an account is closed in Entra, access to Komma closes at the same time.

Can we get our data back out?

Yes, at any time and in machine-readable format — not just at termination. When the agreement ends you get a full extract, and data is then deleted according to the deadline you set.

Who at Komma can see our data?

Access to customer data requires a specific support case and is logged. We do not look through your data to see how it is going — and you can see in the audit trail if we have been in.

How do you handle subject access requests?

An employee can pull their own data directly in the platform. If you as data controller need to answer an access request, you can gather everything about one person in a single extract across the modules.

If you need a data processing agreement, security documentation or answers to a vendor questionnaire, we are happy to send it before a demo. Write to hej@kommahr.com.

Security and compliance

Your data stays in Europe.

Hosted in the EU, built to GDPR, and auditable down to the individual field. Your DPO can see exactly who changed what, and when.

Read how we handle your data
Hosted in the EU
GDPR ready
ISO 27001 certified
99.9%
Uptime SLA

Roles and permissions

Decide what every role can see and change

Single sign-on

Microsoft Entra, one log-in for everyone

Data retention

Records delete themselves on your schedule

Audit log

Every change, with a name and a timestamp

Simulate access

See the system exactly as another role sees it

Want to do the compliance conversation first?

We are happy to meet your IT team or DPO before we show the product at all.