Your people data deserves the highest level of protection.
Hosted on Hetzner infrastructure in Finland (Helsinki datacenter). All data stays within the European Union.
Automated backups every 8 hours, encrypted at rest, with 14-day retention. Restore is drill-tested end to end.
All data in transit is encrypted with TLS/SSL. No unencrypted connections accepted.
UFW firewall with restricted port access. Fail2ban monitors and blocks brute-force attempts.
Each organization's data is logically separated. Queries are scoped to your tenant at every layer.
Granular permissions system with owner, admin, HR manager, manager, and employee roles.
Authentication and sensitive endpoints are rate-limited to prevent brute-force and abuse.
CSV formula injection protection, parameterized queries, and strict input validation throughout.
Cross-origin requests are restricted to hrchronica.com. No third-party domain access.
Your data is yours. We never sell, rent, or share your personal data with third parties for marketing purposes, and we never use it to train AI models. Processing relies on a short list of sub-processors — hosting, backups and the AI provider — each named in our Privacy Policy with its country and transfer basis.
Data is processed only to deliver the features you use. Nothing more.
Export your data at any time. Request full deletion and we'll remove everything within 30 days.
Data Processing Agreement available on request for enterprise customers.
Built from day one with EU data protection requirements in mind.
All customer data is stored and processed within the European Union.
Dependencies are scanned automatically on every push and weekly. Findings are tracked and triaged; the current scan is not passing and its open items are under review.
We're happy to answer any questions about how we protect your data.
Contact contact@hrchronica.com