Security and privacy

Know where your people data lives. Know who can reach it.

HollyHR checks the organisation and permission before serving a record, protects selected sensitive fields, and publishes the providers involved so you can check the service against your own requirements.

One request, three checksIdentity, membership and permission
Active membershipThe person still belongs to the selected organisation.
Specific permissionThe action and record are allowed for this role and relationship.
Organisation scopeThe data operation carries the organisation boundary.
The checks stay attached to the selected organisation and requested action.
Access

Access is checked for each organisation and action.

HollyHR starts with an authenticated session, then checks membership, permission and organisation scope for the work being requested.

Every people-data operation is limited to the selected organisation in HollyHR's application layer.

Platform-admin workspace entry is MFA-gated, and selected sensitive System Admin and HR Admin actions ask for fresh proof. Approved organisation-wide read-only view-as can happen with customer approval; there is no blanket staff impersonation route.

1
Current sessionSigned in and not revoked
2
Selected organisationActive membership confirmed
3
Requested actionPermission and resource scope checked
Access narrows from the signed-in person to one organisation and one allowed action.
Data location

See where each part of HollyHR is processed.

Primary HR records are in EU (AWS eu-central-1); uploaded documents and database backup copies are in UK (eu-west-2). Product analytics use EU (PostHog Cloud EU, AWS eu-central-1), error reporting uses EU (Sentry Germany region), and the application runtime is listed as EU/USA.

Email, billing and support providers have their own locations and transfer terms.

Primary database
EU (AWS eu-central-1)
Documents and backup copies
UK (eu-west-2)
Product analytics
EU (PostHog Cloud EU, AWS eu-central-1)
Error reporting
EU (Sentry Germany region)
Current provider locations, copied from HollyHR's public subprocessor register.
Protection

How HollyHR protects sensitive data.

HollyHR combines encrypted transport and storage with field-level encryption and access checks for more sensitive records.
  • HTTPS protects data in transit and managed providers encrypt storage at rest.
  • Selected bank, tax, government identifier and compensation values get additional application encryption above managed encrypted storage.
  • Private employee documents use authorised, short-lived links that expire after 60 seconds.

In transit and at rest

HTTPS and managed encrypted storage.

Selected fields

An additional application-encryption layer.

Private documents

Short-lived authorised attachment access.

Sensitive data protection combines storage, field and access controls.
Recovery and exit

Backups and data export.

HollyHR schedules a nightly PostgreSQL archive in versioned London storage and has restored a prior S3 dump into a disposable Neon branch.

Leaver offboarding archives access. Erasure and provider-side records need separate handling. An authorised System Admin can prepare an organisation export without opening a support ticket.

Settings · Data export
HollyHR organisation export settings showing the self-service export action and included data
A System Admin can prepare the organisation export from Settings.
Evidence and limits

What you can verify today.

The controls and independent assurance currently available for HollyHR.

Active controls

Scoped access, encrypted transport and storage, private documents, backups, export, incident procedures and public status.

Independent certification

HollyHR is not currently certified to ISO 27001, SOC 2 or Cyber Essentials, and does not currently publish an external penetration-test claim.

Recovery targets

Public SLA, RPO and RTO targets are not currently published.

Bring us your people-data checklist.
Security FAQ

The questions buyers ask before they share people data.

How does HollyHR protect employee data?

HollyHR combines server-side sessions, active-organisation membership checks, permission-aware services, application-scoped database queries, extra encryption for selected high-sensitivity values, private signed document access and audit records for sensitive actions.

Where is HollyHR data stored, and does it leave the UK?

Primary HR records and the application runtime are in the EU, while uploaded documents and HollyHR database backup copies are stored in AWS London. Supporting providers, including email, billing, support and human mailbox services, have their own regions and transfer terms, so HollyHR does not claim that all processing stays in the UK.

Who owns the employee data in HollyHR?

The customer controls its organisation data. HollyHR processes that data to provide the service under its Data Processing Agreement. Customers can prepare an organisation export without opening a support ticket, but some provider records and legal-retention evidence have separate handling boundaries.

Does HollyHR support MFA?

Yes, but the policy is deliberately described by scope. Platform-admin workspace entry is MFA-gated. Selected sensitive System Admin and HR Admin actions require a fresh step-up, and tenant users may enrol a second factor. HollyHR does not yet claim universal MFA enforcement whenever every privileged tenant user signs in.

Can HollyHR staff see employee data?

Not through blanket tenant impersonation. Support or security access is capability-gated, purpose-bound, time-limited and organisation-bound, and person-bound where applicable. Platform-admin workspace entry is MFA-gated; selected sensitive reveals and actions require fresh step-up. Approved organisation-wide read-only view-as can occur with customer approval, so HollyHR does not claim that staff can never see customer data.

Is data encrypted in transit and at rest?

HTTPS protects service traffic and the managed database and object-storage providers encrypt data at rest. HollyHR also applies authenticated application encryption to selected bank, tax or government identifier and compensation values.

How do backups and recovery work?

HollyHR schedules a nightly PostgreSQL archive, checks the compressed archive and stores it in a versioned AWS S3 bucket in London. A prior S3 dump has been restored into a disposable Neon branch.

What happens if there is a security incident?

HollyHR has documented incident and personal-data-breach procedures, production health checks and a public status page. Affected customers would be contacted according to the contractual and legal circumstances.

Is HollyHR certified or independently penetration-tested?

No. HollyHR is not currently certified to ISO 27001, SOC 2 or Cyber Essentials, and it has not completed an external penetration test.

What happens to our data if we leave?

An authorised customer can prepare a structured organisation export with named CSV areas, eligible uploaded files and a manifest. Ordinary leaver offboarding archives access; it is not data erasure, and the person's records remain. Verified erasure removes or anonymises identifying live data, queues known document and avatar objects for deletion, and retains justified referential, audit, statutory and operational records. Provider-side records need separate handling, while backup copies age out rather than disappearing instantly.

Does using HollyHR make us UK GDPR compliant?

No software makes an employer automatically compliant. HollyHR provides a DPA, sub-processor register, access controls, export, DSAR and erasure routes to support UK GDPR duties. The customer still decides lawful basis, notices, permissions, retention and how the service is used.

Is employee data used to train AI?

Holly uses an approved Claude model through Amazon Bedrock. The current route has request and response retention set to none, invocation logging unconfigured and commercial terms that prohibit training on customer content. A customer-selected agent connected through API or MCP remains subject to that provider's own retention, training, region and sub-processor terms.

Start free with up to 10 active employees.

See HollyHR with your own team, or bring us a security question first. You can start without a card or sales call.

Public privacy terms, DPA, subprocessor register and organisation export.