Skip to main content
Everyday HRTime offRequests, approvals and balancesWho's awayThe shared team calendarSickness & absenceRecorded separately from holidayWorking patternsPart-time and zero-hours patterns
Records & compliancePeople recordsOne dependable employee recordDocumentsFiles and expiry-dated requirementsOnboardingPacks, tasks and right-to-work
Open by designImport & exportSpreadsheets in, your data outIntegrationsPayroll and calendar hand-offsAI & APIConnect through our API or MCPAll features →
FeaturedCharities & non-profitsStandard £1 · Plus £2 per personUp to 10 peopleEveryday HR, free with no trial clock
By roleFoundersHR without a full-time HR teamHR managersClear records, workflows and reportingOffice managersLess chasing and fewer spreadsheets
ExploreAll industriesFind the closest fit for your workplaceAll rolesSee HollyHR from your point of viewAll team sizesFit and pricing as your team changes
ComparePricing
LearnHelp centreStep-by-step HollyHR guidesGuidesPractical UK employer guidesHR glossaryPlain-English HR termsBlogProduct and HR updates
DoFree calculatorsHoliday, SSP and working hoursTemplatesReusable HR checklistsMigration guidesMove from spreadsheets or Breathe
Sign inStart free →
Everyday HRTime offWho's awaySickness & absenceWorking patterns
Records & compliancePeople recordsDocumentsOnboarding
Open by designImport & exportIntegrationsAI & APIAll features →
FeaturedCharities & non-profitsUp to 10 people
By roleFoundersHR managersOffice managers
ExploreAll industriesAll rolesAll team sizes
ComparePricing
LearnHelp centreGuidesHR glossaryBlog
DoFree calculatorsTemplatesMigration guides
Sign inStart free →

Sub-processors

Last updated: 29 July 2026

Provider inventory last reviewed: 21 August 2026

Public early-access register: the provider inventory is current. Contracting provider: HollyHR is a trading name of Holly Software Limited, a private company limited by shares registered in England and Wales under company number 17312193. Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

How HollyHR uses sub-processors

Holly Software Limited, trading as HollyHR, uses the providers below to host, secure, support and operate the service. Where HollyHR acts as a processor for customer employee data, these providers may act as sub-processors. HollyHR remains responsible to the customer for sub-processor performance under the approved data processing agreement.

We will update this page before adding or replacing a sub-processor that handles customer personal data and will give customers a reasonable opportunity to object where required by the data processing agreement.

Current provider list

ProviderPurposeData categoriesHosting / transfersEvidence / status
VercelApplication hosting, serverless runtime, deployment, CDN, runtime logs, and cookieless aggregate public-website analytics (Web Analytics and Speed Insights).Customer account data, application metadata, request metadata, limited service logs, and aggregate page-view and performance data points that carry no persistent visitor identifier.

EU/USA

Provider data processing terms and applicable UK transfer safeguards for non-UK processing.

Current deployment platform in repo deployment/runbook docs.
NeonManaged PostgreSQL database hosting, branching, and point-in-time recovery.Customer organisation data, employee HR records, authentication/session metadata, and audit data.

EU (AWS eu-central-1)

Provider data processing terms; production branch hosted in the intended region.

Current database provider in Drizzle/Neon docs and environment schema.
StripeSubscription billing, checkout, billing portal, invoices, and payment records.Customer billing contact, subscription state, invoices, and payment metadata.

EU/USA

Provider data processing terms and UK transfer safeguards for payment processing.

Current billing provider in Stripe integration docs and webhook code.
ResendTransactional email delivery for authentication, invitations, service messages, and consent-gated product-update or launch Broadcasts.Recipient email addresses, opted-in waitlist or customer-admin contact metadata, message metadata, and email body content.

USA

Provider data processing terms and UK transfer safeguards.

Current email provider in env schema, email-service code, Resend feedback webhook, and marketing contact sync runbook.
Postmark (ActiveCampaign)DMARC aggregate-report processing and weekly sender-authentication digests.Registered operator email address; sender domains and source IPs; aggregate message counts; SPF, DKIM, DMARC alignment and receiver-report metadata. No HollyHR message bodies or recipient addresses are included in DMARC aggregate reports.

USA

Provider data processing terms incorporating UK GDPR, the UK Addendum, and Standard Contractual Clauses.

The authoritative DMARC record routes aggregate reports to Postmark; the free service advertises seven days of report history and the repo diagnostic emits only redacted aggregate counts.
UpstashRedis-backed rate limiting and abuse prevention for authentication and sensitive routes.Pseudonymous rate-limit keys and request counters.

UK primary region (eu-west-2)

Provider data processing terms and region controls where configured.

Live Upstash database readback for hollyhr-ratelimit-production and limiter code.
WeatherAPI.com (Zoomash Limited)Current weather conditions for the signed-in member's current assigned tenant workplace, or the sole active tenant workplace when none is assigned, on the optional dashboard ornament.Tenant-admin-governed workplace postcode and country used as a weather-location query, plus ordinary provider request metadata. A workplace record may describe a home-based site; this feature does not read an employee's personal-address field, identity, browser location, IP-derived location, or another HR record.

United Kingdom and other locations described by the provider's current privacy and infrastructure terms.

Provider terms and applicable UK transfer safeguards; the capability remains server-side, data-minimised, non-critical, and removable by configuration.

Server-only workplace-weather service, exact-org workplace resolver, strict response projection, and WeatherAPI terms/privacy review recorded in PR-2123.
Amazon Web Services (S3)Private uploaded HR document storage, encrypted Neon database backup storage, and Terraform remote state.Uploaded employee documents, object metadata, encrypted database backup archives, and infrastructure state metadata.

UK (eu-west-2)

AWS data processing terms and configured bucket-region controls.

Document-storage app runtime uses S3; live S3 readback for hollyhr-neon-backups and hollyhr-tfstate is recorded in provider-residency runbook.
Amazon Web Services (Bedrock)Managed inference for Holly, HollyHR's customer-controlled in-app assistant, on the exact approved Claude Sonnet 4.6 EU geographic inference profile.The signed-in member's current question and the minimum permission-projected product-help, employment, time-off, assigned-policy or non-special-category organisation facts needed for an approved answer or explicitly confirmed time-off action. Holly does not send saved prompt history, health or sickness reasons, payroll, bank, government identifiers, document bodies, performance, disciplinary, recruitment or other special-category data.

UK source (eu-west-2) with AWS-declared destinations in eu-central-1, eu-north-1, eu-south-1, eu-south-2, eu-west-1, eu-west-2, and eu-west-3. This is provider geography, not a claim of EU legal-territory exclusivity.

AWS data-processing terms and applicable UK transfer safeguards. The approved account is configured with Bedrock request/response retention mode none and model-invocation logging unconfigured; a route or posture change disables approval pending reassessment.

The route remains bound to ASK-HOLLY-PILOT-2026-07-21-OPS-SANDBOX-V6 and customer audience decision ASK-HOLLY-CUSTOMER-CONTROLLED-EARLY-ACCESS-2026-07-29-V1. Protected Production-OIDC qualification run 29769064271 proved the exact account, role, profile, seven destinations, retention none, no invocation logging, and no fallback.
Anthropic (Claude on Amazon Bedrock)Claude Sonnet 4.6 model licensing and enabling technology for the exact Amazon Bedrock route used by Holly.AWS's approved Bedrock retention mode none states that inference request and response data is not shared with the model provider. Anthropic remains disclosed because its commercial terms, DPA, model technology, and subprocessor-change terms form part of the approved route.

Contractual provider is US-based; the inference route and declared destination resources are the AWS Bedrock European geography listed above.

Anthropic commercial terms and DPA incorporate EU SCCs and the UK Addendum where applicable; the paid route prohibits training on customer content. Development Partner Mode and provider data sharing are not enabled.

Anthropic usage-based commercial terms for the exact Sonnet 4.6 Bedrock offer were accepted on 20 July 2026. Customer-controlled early access is recorded in ASK-HOLLY-CUSTOMER-CONTROLLED-EARLY-ACCESS-2026-07-29-V1; any broader model route remains separately gated.
PostHogConsent-gated Product analytics for signed-in tenant users, including manual pageview capture, scalar Web Vitals, and organisation-level usage grouping.Account identifiers, product usage events, sanitized pageview metadata, and scalar performance measurements. Browser/device metadata, performance entries, DOM attribution, query strings, raw URLs, and browser metric identifiers are excluded from Product browser analytics events.

EU (PostHog Cloud EU, AWS eu-central-1)

Provider data processing terms; EU project host and IP anonymisation verified by API on 16 June 2026.

Current analytics provider in PostHog provider, API readback, and privacy/cookies runbook.
MigaduHuman mailbox hosting for HollyHR team mailboxes.Mailbox content, sender/recipient metadata, and mailbox account metadata.

EU/Switzerland/other provider locations subject to Migadu terms

Provider data processing terms and applicable UK transfer safeguards for non-UK processing.

MX, SPF, DMARC, and DKIM posture documented in mailbox-posture runbook; separate from Resend app mail.
SentryError tracking, CSP violation reporting, source maps, and operational alerting.Sanitised error metadata, stack traces, release/environment metadata, and CSP report metadata.

EU (Sentry Germany region)

Provider data processing terms; production DSN is hosted on the provider's EU ingest region.

Current production environment readback and live response security policy both identify the Sentry Germany ingest host; code-level event scrubbing remains active.
Help ScoutFounder-operated email support ticketing and customer correspondence.Customer contact details, support requests, correspondence, attachments, and support-account audit metadata.

United States and other listed subprocessor locations

May 2026 Data Processing Amendment incorporated into the service terms, UK Extension to the EU-US Data Privacy Framework, EU Standard Contractual Clauses, and UK International Data Transfer Addendum.

Verified support@hollyhr.com forwarding, Help Scout DKIM records, current DPA, security statement, and subprocessor list reviewed on 10 August 2026.
Freshdesk / Freshworks (legacy)Historical support-provider record checks during retirement; no new support intake.Any legacy customer contact details or support correspondence retained by the provider.

EU/USA

Provider data processing terms; remove this legacy entry after account-closure and deletion evidence is recorded.

The account is expired and customer intake moved to Help Scout on 10 August 2026; provider-side DSAR and erasure checks remain until retirement is proven.

Related legal materials

This page is intended to be referenced by HollyHR's data processing agreement and customer legal materials.

  • Privacy Policy
  • Terms of Service

Legal entity

HollyHR is a trading name of Holly Software Limited, a private company limited by shares registered in England and Wales under company number 17312193. Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. View the Companies House record.

Back to Home

Simple HR your growing team will love

Product

Product overviewPricingWho's awayTime offPeople recordsDocumentsIntegrationsAI, API & MCP

Solutions

Charities & non-profitsTeams up to 10FoundersHR managersOffice managersAll industriesAll rolesPartners

Compare

Compare HR softwarevs Breathevs CharlieHRvs BrightHRBest HR software UKBuying guidesAlternatives guides

Resources

Help centreHR guidesCalculators & toolsTemplatesHR glossaryMigration guidesBlog

Company

AboutWhy HollyHRSecurityNo lock-inRequest a walkthroughContact
© 2026 HollyHR · Made within London
HollyHR on LinkedInHollyHR on GitHub
PrivacyTermsDPASub-processorsAcceptable useCookies

HollyHR is a trading name of Holly Software Limited · Registered in England and Wales · Company no. 17312193 · 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.