The most sensitive data
a company holds.
Salaries, sick days, bank details, contracts. Anyone moving data like this automatically has to be able to explain where it sits, who sees it and what happens when something goes wrong. This page answers exactly that, without marketing language.
27001

We are a start-up. And that is exactly why our architecture is built so that your data never has to reach us in the first place.
Established vendors carry old systems with them, built at a time when data protection was a footnote. What counts as a security concept there today has usually been retrofitted. We started from nothing, with the GDPR as the starting point rather than an obligation. The fact that HR data does not sit with us permanently is therefore not a setting, it is the architecture itself.
There is something else a large group cannot offer structurally: speed. When your data protection officer raises a requirement, we decide on it the same day, not in the next quarterly committee. And when a question goes deep into the technology, you talk to the people who built the software.
What is at stake for us is far greater. A large vendor survives an incident with a press release. For us it would be the end. That asymmetry is our strongest security mechanism, and it works every day, in every decision.
If your IT team or your data protection officer has questions this page does not answer, write to me directly. Not to support, to me.
What every review
asks first.
We know these questions from every project. So the answers are here before you have to ask.
Where does our data sit?
Permanently, nowhere with us. The autopilot receives data, translates it and passes it on, after which it is removed from the platform. The processing takes place in data centres in Germany, certified to ISO 27001.
Who can see it?
Only whoever you allow. Roles and permissions can be tailored right down to field level. We do not access your HR data ourselves, and in a support case only with your express approval and with everything logged.
What if something goes wrong?
Every execution is logged: which value, from which programme, where to, when. If a step fails, the workflow repeats it automatically. Only if the error persists are you told, with the point where it stopped.
And what if you no longer exist?
A fair question, and one we are often asked. Because we keep no permanent copy, your data sits in your own systems anyway. We will export your workflows and field mappings for you at any time.
Like a parcel hub.
With no storage.
HR-Autopilot is not a data store. It receives, translates and passes on, and is empty again afterwards. That is exactly the difference from any solution that mirrors your HR data.
What is not held by us cannot be lost by us either.
What we can evidence.
Four areas where a review usually goes into detail.
Everything your IT team
and works council need.
You do not have to hunt anything down. We supply the documents you can work with internally.
Security review
- A data processing agreement under Art. 28 GDPR
- Technical and organisational measures in detail
- A list of sub-processors
- The data centre certificates
- A description of the data flow and the deletion policy
- A question catalogue with our answers, pre-filled
Co-determination
- A template works agreement you can edit
- An overview of which data is processed in which workflow
- An explanation of the question of performance and conduct monitoring
- Logging as evidence for co-determination
- Support through the procedure, we have been through it several times
- A contact who knows the questions a works council asks
“Integrations that used to be maintained by hand now run automatically and securely, an enormous advantage for our HR and IT teams.”
IT review passed
Bring your IT team
along to the call.
30 minutes going through the architecture, permissions, logging and deletion policy. Any question we cannot answer on the spot we answer afterwards in writing.

