Skip to content
EU hosting & GDPR

Your HR data lives in the EU.

Hexense HR was built in Estonia for European companies. EU hosting is not a tier, a region setting or an enterprise add-on here: it is simply where the product runs, on every plan including the free one.

Data residency

Three places, all of them in the EU.

Database and files

Supabase on AWS eu-west-1, in Ireland.

Application compute

Vercel, pinned to Dublin.

Off-site backups

Cloudflare R2, under EU jurisdiction.

Every processor we use is named on the subprocessor page before it touches customer data, including the few that operate outside the EU and the safeguards that cover them.

In the product, not in a policy

GDPR work you can actually do on a Tuesday.

A subject access request, a deletion, a retention window: each one is a screen in the product rather than an email to support and a wait.

Export is a button, not a support ticket

Any employee can export their complete record as a machine-readable bundle, and an admin can produce one for a subject access request without asking us.

Erasure that keeps what the law makes you keep

An admin can erase an offboarded member: personal data is scrubbed in place, while the employment record an employer has to retain and the audit trail survive.

Retention on a clock you set

Audit history, notifications, rejected candidates' CVs and expiry records each have a window, and scheduled sweeps enforce it. Retention is a setting rather than something an admin has to remember.

Isolation enforced by the database

Row-level security is enabled and forced on every table carrying customer data, with an isolation suite that impersonates users from different organisations on every change.

Sensitive records stay narrow

Work permits, right-to-work documents, certifications and sick notes are readable by admins and by the person they belong to — not by their manager. A database policy enforces that, not a screen.

An anonymous reporting channel

Access-coded and admin-walled, designed for EU Directive 2019/1937, and included on every plan, free included.

The part most vendors leave out

What we do not have yet.

No third-party penetration test. No ISO 27001 certificate and no SOC 2 report: we run an information security management system built to ISO 27001:2022 and have completed an internal gap assessment, and an internal assessment is not an audit.

Recovery point is up to 24 hours, because point-in-time recovery is not yet purchased, and recovery time has not been measured so it is not published. Backups were restore-tested in August 2026 with the isolation suite re-run against the restored copy.

Questions

The ones a data protection officer asks.

Where is our HR data actually stored?
Database and file storage on Supabase in AWS eu-west-1 (Ireland), application compute on Vercel pinned to Dublin, and off-site file backups on Cloudflare R2 under EU jurisdiction. Every vendor with access to customer data is named on our subprocessor page before it processes anything, including the few that operate outside the EU and the safeguards that cover them.
Is there a data processing agreement?
Yes, and you can read it before you talk to anyone. It is published alongside the privacy policy, the subprocessor list and the full security page.
How does a right-to-erasure request work?
An admin erases an offboarded member from inside the product. Personal data is scrubbed in place; the employment record an employer is required to keep and the append-only audit trail survive, because erasing those would break a different obligation.
Do you have ISO 27001 or SOC 2?
No. We run an information security management system built to ISO 27001:2022 and have completed an internal gap assessment, and an internal assessment is not an audit. There is no third-party penetration test yet either. We say so here because you would find out anyway.
Does using Hexense make us GDPR compliant?
No product can do that, and anyone selling you one is overselling. What this one does is put export, erasure, retention windows and access control inside the software instead of in a policy document, so the work your obligations create is something you can actually do.

Read the detail before you talk to anyone.

The security page, the subprocessor list and the DPA are all public. Start free when you have finished reading.

Up to 10 people free · No credit card · No sales call