Skip to main content
Time & absenceTime offRequests, approvals and balancesWho's awayThe shared team calendarSickness & absenceRecorded separately from holidayWorking patternsPart-time and zero-hours patterns
People & recordsPeople recordsOne dependable employee recordDocumentsFiles and expiry-dated requirementsOnboardingPacks, tasks and right-to-workData exportSpreadsheets in, your data out
ConnectionsIntegrationsPayroll and calendar hand-offsAI & APIConnect through our API or MCP
All features →
FeaturedCharities & non-profitsStandard £1 per person · Plus £2 coming soonUp to 10 peopleEveryday HR, free with no trial clock
By roleFounders, CEOs and business ownersSet up proper HR while you build the businessHR managersClear records, workflows and reportingOffice managersKeep everyday people admin movingFinance managersKeep payroll hand-offs accurateManagers and team leadsApprove leave and see who is awayEmployeesBook leave and find your documents
ExploreAll industriesFind the closest fit for your workplaceAll rolesSee HollyHR from your point of viewAll team sizesFit and pricing as your team changes
ComparePricing
LearnHR topicsGuides, tools and terms by subjectGuidesPractical UK employer guidesHR glossaryPlain-English HR termsBuyer FAQsQuestions before you choose HollyHelp centreStep-by-step HollyHR guidesDevelopersAPI, SDK, webhooks and hosted MCP
DoFree calculatorsHoliday, SSP and working hoursTemplatesReusable HR checklists
Sign inStart free →
Time & absenceTime offWho's awaySickness & absenceWorking patterns
People & recordsPeople recordsDocumentsOnboardingData export
ConnectionsIntegrationsAI & API
All features →
FeaturedCharities & non-profitsUp to 10 people
By roleFounders, CEOs and business ownersHR managersOffice managersFinance managersManagers and team leadsEmployees
ExploreAll industriesAll rolesAll team sizes
ComparePricing
LearnHR topicsGuidesHR glossaryBuyer FAQsHelp centreDevelopers
DoFree calculatorsTemplates
Sign inStart free →

Privacy Policy

Last updated: 28 August 2026

Public early-access privacy notice: self-service account and workspace creation are open. Data controller and service provider: HollyHR is a trading name of Holly Software Limited, a private company limited by shares registered in England and Wales under company number 17312193. Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

1. Who we are

Holly Software Limited, trading as HollyHR, provides HR software for small and medium-sized UK businesses: a people directory, employee records, time-off tracking, and related tools. This notice explains how personal data is handled when you visit our website or use the HollyHR application, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018).

2. Our roles: controller and processor

The provider of HollyHR acts in two distinct roles, and your rights run differently in each:

  • Employee data: HollyHR is a processor. When your employer uses HollyHR to manage your employment records, your employer is the data controller and decides what data is held and for how long. We process that data only on your employer's instructions. If you are an employee and want to access, correct, or erase your data, please contact your employer (usually your HR administrator); we will assist them in responding.
  • Account, billing, and website data: HollyHR is a controller. For the data we collect to run the service itself (customer account details, billing records, support correspondence, waitlist sign-ups and website usage), we decide how and why it is processed, and you can contact us directly about it.

3. The data we process

As processor (for your employer):

  • Identity and contact details (name, work and personal email, phone, home address)
  • Employment details (role, department, start date, working pattern, employment history)
  • Time-off requests, approvals, and absence records
  • Compensation and compensation history
  • Bank account details (for payroll administration)
  • Emergency contacts
  • Documents your employer stores about you (contracts, reviews, right-to-work)
  • Profile photo, if provided

Bank account details, tax and government identifiers, and compensation values are encrypted at the field level in our database, in addition to encryption in transit and at rest.

As controller:

  • Account and sign-in data (email address, authentication events)
  • Billing details and subscription status (payment cards are handled by Stripe; we never see full card numbers)
  • Support requests and correspondence
  • Contact and walkthrough requests (name, email, organisation where supplied, selected topic and the message or product context you choose to provide)
  • Glossary suggestions (the term supplied)
  • Waitlist and marketing sign-ups (name, email, optional product-news choice, and the optional fixed-choice answer to how you heard about HollyHR)
  • Service logs, server-side product analytics, consent-based browser analytics for signed-in users, and consent-based paid-search measurement for a visitor who allows the matching Google or Microsoft provider

4. Holly AI assistant

Holly is HollyHR's customer-controlled in-app assistant, included with Standard. An authorised workspace admin can disable or enable it for the whole organisation. Each request also requires a fresh active membership and the permission required for the selected capability.

  • It can explain curated HollyHR product guidance, answer bounded questions about the signed-in member's own records, and show permission-authorised non-special-category organisation information. Supported time-off changes are prepared as an exact preview and require explicit confirmation.
  • It cannot silently update records, make or recommend employment decisions, browse the web, read arbitrary files or documents, run general database queries, or switch tenant, person, model, provider or authority from a chat request. It does not interpret policy or provide legal advice.
  • Health and other special-category data, payroll, bank and government identifiers, home addresses, performance, disciplinary, grievance, recruitment, and document content are outside the approved pilot.
  • General chat history is not persisted. HollyHR's audit evidence records allowlisted identifiers, route, tool, timing, token, cost, and outcome metadata without storing the prompt, answer, or tool result.
  • Answer feedback records an allowlisted category only. If a member chooses to add a bounded comment, HollyHR encrypts that comment for human review for at most 30 days. The review queue does not include the reporter, question, answer, citations, or tool output, and the comment is not sent to the AI provider, Resend, or Migadu.
  • The exact approved Amazon Bedrock account uses request/response retention mode none and has model-invocation logging unconfigured. It routes from eu-west-2 through AWS's named EU geographic inference profile; that is a provider-geography statement, not a guarantee that every processing location is within EU legal territory.

AI output can be incomplete or inaccurate and is not legal advice or an employment decision. The product links to the ordinary HollyHR source so the member can check it and continue without AI. Access stops if the global switch, route approval, plan entitlement, organisation setting, active membership, or required permission no longer matches.

External AI connectors and developer access

An authorised workspace administrator can connect a third-party AI assistant to HollyHR through our hosted Model Context Protocol (MCP) endpoint. In this channel, HollyHR supplies permission-scoped tools and remains the processor of the employer's records; the connected assistant and its provider operate under the customer's separate account, instructions, and provider terms.

  • The connector can return only the fields and records allowed by the selected HollyHR workspace, actor, plan, scopes, and positive output projections. Sensitive fields and special-category records remain excluded.
  • Supported changes use a frozen payload and require an explicit approval in the connected assistant before HollyHR commits them. Disabling write mode removes write tools and write scopes as well as rejecting execution.
  • HollyHR records security and audit metadata for API and MCP requests. The connected AI provider may separately process or retain the customer's conversation and returned tool data according to that provider's terms and the customer's settings.
  • Workspace administrators can revoke the connection or its access credential. Revocation stops subsequent requests; data already supplied to the external provider remains subject to the customer's relationship with that provider.

5. Lawful bases for processing

Where we act as controller, we rely on the following lawful bases under Article 6 UK GDPR:

  • Contract: providing the service to your organisation, managing accounts, and billing.
  • Legitimate interests: securing the service, preventing fraud and abuse, responding to general, security and partnership enquiries, improving the product, and limited service analytics.
  • Steps requested before a contract: responding to product, pricing, migration and walkthrough enquiries where you are considering HollyHR for your organisation.
  • Legal obligation: tax, accounting, and regulatory record-keeping.
  • Consent: optional marketing communications, including the retained contact record of anyone who opted into product updates through the former waitlist, product analytics, and paid-search conversion measurement; you can withdraw consent at any time.

Where we act as processor, the lawful basis is your employer's to establish : typically performance of the employment contract, legal obligations as an employer, and their legitimate interests in administering staff.

6. Sub-processors

We use a small number of service providers (sub-processors) to run HollyHR. Each is bound by contractual data protection terms, and transfers outside the UK rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or UK adequacy regulations. The standalone sub-processor page is the linkable inventory for customer legal materials. Last reviewed: 21 August 2026.

ProviderPurposeData categoriesHosting / transfers
VercelApplication hosting, serverless runtime, deployment, CDN, runtime logs, and cookieless aggregate public-website analytics (Web Analytics and Speed Insights).Customer account data, application metadata, request metadata, limited service logs, and aggregate page-view and performance data points that carry no persistent visitor identifier.

EU/USA

Provider data processing terms and applicable UK transfer safeguards for non-UK processing.

NeonManaged PostgreSQL database hosting, branching, and point-in-time recovery.Customer organisation data, employee HR records, authentication/session metadata, and audit data.

EU (AWS eu-central-1)

Provider data processing terms; production branch hosted in the intended region.

StripeSubscription billing, checkout, billing portal, invoices, and payment records.Customer billing contact, subscription state, invoices, and payment metadata.

EU/USA

Provider data processing terms and UK transfer safeguards for payment processing.

ResendTransactional email delivery for authentication, invitations, service messages, and consent-gated product-update or launch Broadcasts.Recipient email addresses, opted-in waitlist or customer-admin contact metadata, message metadata, and email body content.

USA

Provider data processing terms and UK transfer safeguards.

Postmark (ActiveCampaign)DMARC aggregate-report processing and weekly sender-authentication digests.Registered operator email address; sender domains and source IPs; aggregate message counts; SPF, DKIM, DMARC alignment and receiver-report metadata. No HollyHR message bodies or recipient addresses are included in DMARC aggregate reports.

USA

Provider data processing terms incorporating UK GDPR, the UK Addendum, and Standard Contractual Clauses.

UpstashRedis-backed rate limiting and abuse prevention for authentication and sensitive routes.Pseudonymous rate-limit keys and request counters.

UK primary region (eu-west-2)

Provider data processing terms and region controls where configured.

WeatherAPI.com (Zoomash Limited)Current weather conditions for the signed-in member's current assigned tenant workplace, or the sole active tenant workplace when none is assigned, on the optional dashboard ornament.Tenant-admin-governed workplace postcode and country used as a weather-location query, plus ordinary provider request metadata. A workplace record may describe a home-based site; this feature does not read an employee's personal-address field, identity, browser location, IP-derived location, or another HR record.

United Kingdom and other locations described by the provider's current privacy and infrastructure terms.

Provider terms and applicable UK transfer safeguards; the capability remains server-side, data-minimised, non-critical, and removable by configuration.

Amazon Web Services (S3)Private uploaded HR document storage, encrypted Neon database backup storage, and Terraform remote state.Uploaded employee documents, object metadata, encrypted database backup archives, and infrastructure state metadata.

UK (eu-west-2)

AWS data processing terms and configured bucket-region controls.

Amazon Web Services (Bedrock)Managed inference for Holly, HollyHR's customer-controlled in-app assistant, on the exact approved Claude Sonnet 4.6 EU geographic inference profile.The signed-in member's current question and the minimum permission-projected product-help, employment, time-off, assigned-policy or non-special-category organisation facts needed for an approved answer or explicitly confirmed time-off action. Holly does not send saved prompt history, health or sickness reasons, payroll, bank, government identifiers, document bodies, performance, disciplinary, recruitment or other special-category data.

UK source (eu-west-2) with AWS-declared destinations in eu-central-1, eu-north-1, eu-south-1, eu-south-2, eu-west-1, eu-west-2, and eu-west-3. This is provider geography, not a claim of EU legal-territory exclusivity.

AWS data-processing terms and applicable UK transfer safeguards. The approved account is configured with Bedrock request/response retention mode none and model-invocation logging unconfigured; a route or posture change disables approval pending reassessment.

Anthropic (Claude on Amazon Bedrock)Claude Sonnet 4.6 model licensing and enabling technology for the exact Amazon Bedrock route used by Holly.AWS's approved Bedrock retention mode none states that inference request and response data is not shared with the model provider. Anthropic remains disclosed because its commercial terms, DPA, model technology, and subprocessor-change terms form part of the approved route.

Contractual provider is US-based; the inference route and declared destination resources are the AWS Bedrock European geography listed above.

Anthropic commercial terms and DPA incorporate EU SCCs and the UK Addendum where applicable; the paid route prohibits training on customer content. Development Partner Mode and provider data sharing are not enabled.

PostHogConsent-gated Product analytics for signed-in tenant users, including manual pageview capture, scalar Web Vitals, and organisation-level usage grouping.Account identifiers, product usage events, sanitized pageview metadata, and scalar performance measurements. Browser/device metadata, performance entries, DOM attribution, query strings, raw URLs, and browser metric identifiers are excluded from Product browser analytics events.

EU (PostHog Cloud EU, AWS eu-central-1)

Provider data processing terms; EU project host and IP anonymisation verified by API on 16 June 2026.

MigaduHuman mailbox hosting for HollyHR team mailboxes.Mailbox content, sender/recipient metadata, and mailbox account metadata.

EU/Switzerland/other provider locations subject to Migadu terms

Provider data processing terms and applicable UK transfer safeguards for non-UK processing.

SentryError tracking, CSP violation reporting, source maps, and operational alerting.Sanitised error metadata, stack traces, release/environment metadata, and CSP report metadata.

EU (Sentry Germany region)

Provider data processing terms; production DSN is hosted on the provider's EU ingest region.

Help ScoutFounder-operated email support ticketing and customer correspondence.Customer contact details, support requests, correspondence, attachments, and support-account audit metadata.

United States and other listed subprocessor locations

May 2026 Data Processing Amendment incorporated into the service terms, UK Extension to the EU-US Data Privacy Framework, EU Standard Contractual Clauses, and UK International Data Transfer Addendum.

Freshdesk / Freshworks (legacy)Historical support-provider record checks during retirement; no new support intake.Any legacy customer contact details or support correspondence retained by the provider.

EU/USA

Provider data processing terms; remove this legacy entry after account-closure and deletion evidence is recorded.

We will update this list before adding or replacing a sub-processor that handles customer personal data.

If a paid-search visitor separately allows advertising measurement, Google Ads or Microsoft Advertising receives the matching validated advertising click identifier and the limited measurement events described below. These advertising providers are independent controllers for their own processing under their published privacy terms; they are not used to receive employee records, names, email addresses, free text, or internal HollyHR identifiers.

7. Data retention

  • Employee data is retained for as long as your employer instructs us to hold it. Employers typically retain employment records for statutory periods after employment ends (for example, HMRC payroll record-keeping and limitation periods for employment claims).
  • Deleted data is removed from live systems immediately when deleted in the application. Isolated encrypted backup copies use a 35-day recovery window and are then scheduled for deletion through provider lifecycle processing.
  • Account and billing records are retained for up to 6 years after the end of the customer relationship, to meet tax and accounting obligations.
  • Audit logs of security-relevant actions are retained as compliance evidence; where a person's data is erased, identifying details in audit records are anonymised rather than the event history being destroyed.
  • Contact and walkthrough correspondence is held in our transactional email logs and human mailbox systems rather than the HollyHR waitlist database. We retain it only for as long as needed to handle the enquiry, reply where needed, and meet any related legal or security obligations.
  • Glossary suggestions are held in HollyHR's delivery and mailbox systems only for as long as needed to review the suggested term and meet any related legal or security obligations. We handle access or deletion requests across those providers.
  • Former waitlist records that were never approved or joined and had no product-updates consent were retired after public self-service opened. An opted-in contact record is retained only while that consent and purpose remain, and is not treated as an active customer account.
  • Paid-search measurement state is retained for no more than 30 days from the paid visit and is removed earlier after the first successful organisation-creation conversion, withdrawal, expiry, or a source mismatch. The separate signed consent choice is retained for up to 180 days so the application can respect it.

8. Your rights

Under UK GDPR you have the right to access your personal data, to have inaccurate data corrected, to erasure, to restrict or object to processing, and to data portability. Controllers must respond to these requests within one month.

  • For employee data, send your request to your employer. They are the controller and we will assist them.
  • For account, billing, or website data, contact us directly using the details below.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): ico.org.uk or 0303 123 1113.

9. Security

We protect personal data with encryption in transit (TLS) and at rest, additional field-level encryption for banking, identifier, and compensation data, role-based access controls within each organisation, organisation-level data isolation, audit logging of sensitive actions, and encrypted backups.

10. Cookies and analytics

HollyHR uses cookies that are necessary to operate the service: session authentication, your organisation selection, and theme preference. Browser product analytics through PostHog Cloud EU is limited to signed-in tenant users and only runs after you allow analytics; this can use browser storage or cookies to remember analytics identifiers. We do not sell personal data or send HR record contents, free-text fields, employee names, or email addresses to PostHog. Beyond the consented internal account context described above, performance event data is limited to scalar Web Vitals and sanitized page families; it excludes browser/device metadata, performance entries, DOM attribution, raw URLs, query strings, and browser metric identifiers.

On our public website we measure page views, page performance and public signup link clicks with Vercel Web Analytics and Vercel Speed Insights. These events do not include your name, email, free text, query string, full referrer URL, or an advertising click identifier. These tools set no analytics cookies: visitors are counted using a hash derived from the incoming request, which is discarded within 24 hours, your IP address is not stored, and the resulting data points are aggregate only. We use them solely to improve the website under the UK PECR statistical-purpose exception and provide a simple objection control. If you object, one browser-local preference remembers the choice and suppresses both Web Analytics and Speed Insights events. Full detail and the control are in our cookie policy.

The public website loads no Google or Microsoft advertising code and writes no advertising identifier to browser storage. For a canonical paid-search visit, a validated click identifier can be placed in the fragment of the application signup link. URL fragments are not sent in the application's document request. The application removes the fragment immediately. If the matching advertising provider is configured, it then asks before retaining the identifier or contacting that provider.

If you allow paid-search measurement, the application loads only Google Ads or Microsoft Advertising according to the paid source. It initialises limited conversion measurement and, if you create an organisation, sends one organisation_created conversion. These events contain no name, email, employee data, HR record, free text, search term, or internal HollyHR identifier. The launch setup is not used for remarketing or personalised ads. You can decline without affecting signup and withdraw later through the application's ad-measurement choices.

11. International transfers

Some sub-processors listed above store data outside the UK. Where that happens, we rely on UK adequacy regulations or appropriate safeguards (such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses), together with the providers' own security commitments.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified to customer organisations and reflected in the "Last updated" date above.

13. Contact us

For privacy questions, data subject requests relating to data we control, or to reach our data protection contact:

Email: info@hollyhr.com

HollyHR is a trading name of Holly Software Limited, a private company limited by shares registered in England and Wales under company number 17312193. Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. View the Companies House record.

← Back to Home

Simple HR your growing team will love

Product

Product overviewPricingWho's awayTime offPeople recordsDocumentsIntegrationsAI, API & MCP

Solutions

Charities & non-profitsTeams up to 10FoundersHR managersOffice managersAll industriesAll rolesPartners

Compare

Compare HR softwarevs Breathevs CharlieHRvs BrightHRBest HR software UKBuying guidesAlternatives guides

Resources

Buyer FAQsHR topicsHelp centreHR guidesCalculators & toolsTemplatesHR glossaryMigration guidesDevelopers

Company

AboutSecurityNo lock-inRequest a walkthroughContactService status
© 2026 HollyHR · Made within London
HollyHR on LinkedInHollyHR on GitHub
PrivacyTermsDPASub-processorsAcceptable useCookies

HollyHR is a trading name of Holly Software Limited · Registered in England and Wales · Company no. 17312193 · 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.