We meet legal requirements
- GDPR compliance - we meet the requirements of Regulation (EU) 2016/679 on the protection of personal data.
- Data Privacy Framework - data transfers to the US rely on the EU-US Data Privacy Framework.
- Whistleblower Protection Directive - our "Whistleblowing" module meets the requirements of EU Directive 2019/1937.
Review our agreements
tomHRM Terms of Service
The document governing the scope, parameters and mutual rights and obligations of the provider and the customer.
View document →Data Processing Agreement
Terms for the processing of personal data between the data controller and the processor.
View document →Privacy policy
Rules for data processing when using the website and newsletter.
View document →Comprehensive data protection
- Data encryption - AES-256 for data at rest and TLS for data in transit, guaranteeing an encrypted connection between the server and the browser.
- Backups - performed twice a day, with an additional backup of the backup, stored in two separate regions with two independent providers.
- Multi-tenant architecture - separate databases and files accessible only via keys assigned to the customer's account.
- Deletion and anonymization - clear procedures for test and production accounts; we use pseudonymization and permanent file deletion.
- 2FA and strong passwords - two-factor authentication and a password policy across all systems supporting the service.
Where we host the application
The tomHRM application and customer data are stored within the European Union, in data centers located in France and Ireland. Server infrastructure is provided by OVH, and secure file storage is provided by Amazon Web Services (AWS) S3.
All data centers we use hold ISO 27001, SOC 2 and SOC 3 certifications and meet the requirements of Regulation (EU) 2016/679 (GDPR).
Data after subscription ends
- Data remains on the account for 6 months from the date of termination or expiration of the agreement.
- After that period, the account and all its data are permanently deleted.
- At the customer's request, within up to 21 business days, we can export user and candidate profile data in CSV format.
- The customer may also request, in documentary form, a shorter data deletion period.
Data after a trial account expires
A trial account is active for a maximum of 30 calendar days from its creation. After a further 30 days from expiration, the account and all data it contains are permanently deleted, with no possibility of recovery.
Backups
- Two backups per day plus an additional backup of the backup.
- Backups stored in two separate regions.
- Two independent backup storage providers.
- Regular backup restoration tests.
- Backups are used solely to restore data in case of the most severe failures.
Supporting GDPR obligations
tomHRM was designed with GDPR requirements in mind. The application supports:
- exercising the right of access to data,
- managing and withdrawing consents,
- correcting personal data,
- exercising the right to erasure ("right to be forgotten"),
- exporting data in a structured CSV format,
- tracking the processing history of data.
We support the data controller in fulfilling data subject requests through dedicated technical and organizational measures.
Transfers to third countries
We primarily store data in data centers within the EU. If we use sub-processors located outside the EU, transfers are carried out with appropriate safeguards:
- the use of standard contractual clauses,
- for the US - transfers rely on the EU-US Data Privacy Framework.
The data controller is informed about new sub-processors and has 21 days from receiving such notice to object.