SecurityMarkdown

Data protection, in plain terms

HRHive keeps each organisation's data apart, encrypts date of birth, National Insurance number and bank details, and shows sensitive fields only to the roles that need them. It gives you a retention schedule, legal holds, a destruction log, and trackers for data requests and complaints. Your organisation decides what to record and stays responsible for its own data protection duties.

This page explains how HRHive looks after the personal data your organisation keeps in it, and the tools it gives you for your own data protection duties. Each fact below is something HRHive does today. Where something is not in place, we say so.

The facts

  • Each organisation's data is kept apart in the database by row-level security, which applies to every table that holds organisation data.
  • Date of birth, National Insurance number and bank details are encrypted individually with AES-256-GCM, using a separate key for each organisation.
  • There are eight roles (owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor), and sensitive fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.
  • After a right to work check, only the last three characters of the share code are kept.
  • Retention periods are set for each kind of record, with legal holds and a destruction log.
  • Privacy notices, a retention schedule, legal holds, a destruction log, data requests with a one-month clock and data protection complaints with a 30-day acknowledgement are tracked.
  • HRHive runs on Cloudflare, with a managed PostgreSQL database and Resend for email. There are no advertising or analytics trackers inside the application.

How it works

Organisations are kept apart. Row-level security is a database feature that controls which rows of data each request can reach. HRHive applies it to every table that holds organisation data, so each organisation's data is kept apart in the database itself.

The most sensitive details are encrypted individually. Date of birth, National Insurance number and bank details are each encrypted with AES-256-GCM, using a separate key for each organisation. The encryption page explains what is encrypted and what is not.

Sensitive fields follow roles. HRHive has eight roles: owner, admin, HR, manager, payroll, compliance, employee and a read-only auditor. Fields such as bank, salary, National Insurance and medical details are shown only to the roles that need them.

Share codes are not kept. After a right to work check, only the last three characters of the share code are kept.

Every kind of record has a retention period. Retention periods are set for each kind of record. A legal hold stops a record being destroyed while it is still needed, and the destruction log is the record of what has been destroyed.

Requests, complaints and notices are tracked. Data requests are tracked against a one-month clock and data protection complaints against a 30-day acknowledgement. Privacy notices are tracked too.

No trackers in the app. There are no advertising or analytics trackers inside the application.

What it means for you

  • When someone asks for a copy of their data, the request and its one-month deadline are tracked in one place.
  • Someone whose role does not need bank or salary details does not see them.
  • Each kind of record has a retention period, and a legal hold stops a record being destroyed while you still need it.
  • Your organisation still decides what to record, tells its people how their data is used and answers their requests. HRHive gives you the tools and keeps the record of what was done.

What we do not claim

  • Automatic redaction. When you export an access request, HRHive flags what may need redacting. It does not redact automatically, so a person needs to check the export.
  • Encryption of everything. HRHive encrypts the three fields named above. Other data is protected by access controls rather than by additional encryption in the application.
  • Where data is stored. We will publish the location of customer data once it is confirmed. Until then, we do not state one.
  • Finished legal documents. Our terms, privacy notice and data processing agreement are being finalised. They will be published on our legal documents page once a solicitor has reviewed them.

Frequently asked questions

Who is responsible for the employee data we keep in HRHive?
Your organisation decides what to record about its people and why, and it remains responsible for its own data protection duties. HRHive keeps the records organised and protected, and gives you tools for retention, data requests and complaints.
How long does HRHive keep records?
Retention periods are set for each kind of record. A legal hold stops a record being destroyed while it is still needed, and destruction is recorded in a destruction log.
Does HRHive help with subject access requests?
Yes. Data requests are tracked with a one-month clock. When you export a request, HRHive flags what may need redacting, but it does not redact automatically. A person checks the export and makes the redactions.

Change history

  1. First published.