GDPR, AI Act
and data security
VeyraHR processes HR data, including pay. We know how important and confidential the data you entrust to us is – which is why we take security and regulatory compliance very seriously, from the way the system is built to day-to-day operations. Here we describe what data we process, how we protect it and what the EU Artificial Intelligence Act (AI Act) and the GDPR mean for your company.
In brief
Data stays in the EEA
We store and process HR data in a data centre in Frankfurt. We do not transfer it outside the European Economic Area.
Your company decides
You are the controller of your employees’ data. We process it only on your instructions, under a data processing agreement.
People make the decisions
VeyraHR points to risks and their causes. It does not make HR decisions or take any action towards employees.
Need-to-know access
Only authorised users can see the pay and risk of individual people. Everyone else works with aggregated data.
What we state and what it is based on
| Statement | What it is based on |
|---|---|
| Data in the EU · Frankfurt | Amazon Web Services servers in the eu-central-1 region (Frankfurt); HR data is not transferred outside the European Economic Area. |
| GDPR · data processing agreement | Controller–processor model (Art. 28 GDPR): we process data only on the Client’s instructions. |
| Explainable prediction | For each person we show the factors that increase the risk and their impact in percentage points. |
| People decide | The system does not make decisions or take actions towards employees (Art. 22 GDPR). |
| Protection of individual data | A separate permission for individual-level data, aggregated views and hiding of groups smaller than 3 people. |
| Preparing for the AI Act 2027 | Compliance plan: technical documentation, equal-treatment testing and conformity assessment before 2 December 2027. |
Who is responsible for the data
Your company is the controller of its employees’ data: it decides what data goes into VeyraHR, for what purpose and who in the company has access to it. VeyraHR is the processor (Art. 28 GDPR) – we process the data only on your instructions, within the scope set out in the data processing agreement, and do not use it for any purposes of our own.
For the data of application users (accounts, sign-ins) and people who contact us, we are the controller – the rules are described in the privacy policy.
Under the AI Act, VeyraHR is the provider of the system and your company is the deployer. Both parties have their own obligations; we describe them in the AI Act section.
What data we process
Data reaches VeyraHR only through a file import prepared by your company. Apart from first and last name, all columns are optional – modules that lack data simply do not calculate.
| Category | Examples | Used for |
|---|---|---|
| Identification and organisational data | first and last name, ID from the HR system, business e-mail, department, position, job level | recognising the person in subsequent imports, analyses by department and position |
| Employment history | hire and leaving date, type of exit (voluntary / involuntary), tenure, time since the last promotion and pay rise, number of manager changes | turnover, retention, succession, attrition prediction |
| Pay | base salary, hourly rate, working time, variable pay (bonuses, awards) | gender pay gap, pay transparency report, cost of turnover, compa-ratio |
| Performance reviews | result of the latest review; VeyraHR calculates the change since the previous import | attrition prediction, burnout risk, succession |
| Absence | only the number of days of absence in the last 90 and 365 days – without reasons | absence rate, burnout risk |
| Sex | female / male | gender pay gap and the pay transparency report required by law |
| VeyraHR users | first and last name, e-mail, role, login history (time, IP address, browser) | login, access control, account security |
- national ID numbers (PESEL), dates of birth or home addresses
- reasons for absence, sick notes or any other health data
- the content of e-mail, instant messaging or calendars – we do not monitor communication
- biometric data, location or recordings
- emotion recognition, voice or image analysis
How we process data
Import and history
The company administrator uploads a CSV file. Every import is recorded in the history and can be rolled back – we then restore the previous state of the data. People who have left remain in the data with their leaving date solely for turnover metrics and do not appear in current analyses.
Analyses
Most modules – HR KPIs, gender pay gap, pay transparency, absence, cost of turnover – are descriptive statistics: sums, averages, medians and percentages. They are not AI systems and do not assess individuals.
Attrition prediction
The prediction estimates the probability that an employee will leave within 12 months. The model is transparent: each factor (e.g. time since the last pay rise, pay compared with the median for the position, change in reviews) has an open, documented weight, and the average risk level is calibrated to the actual turnover in your company. For each person we show the factors that increase their risk and their impact. The model does not use sex, age or any other protected characteristics. The result is a prompt for a conversation and retention measures – not an assessment of the employee.
Where and with whom
The application and the database run in the Amazon Web Services cloud in the Frankfurt region (Germany). System messages (invitations, password resets) are sent via the AWS e-mail service in the same region. During company registration we retrieve data from Polish public registers (the National Court Register and the VAT taxpayer list). The full list of our sub-processors is provided in the data processing agreement, and we inform you of every change.
After the agreement ends
When our cooperation ends, we delete the company’s data – its entire dedicated area of the database together with user accounts – within the period set out in the data processing agreement. Backups expire automatically.
Security
We apply the technical and organisational measures required by Art. 32 GDPR, chosen with the fact that we process HR and pay data in mind. We make configuration details available to Clients for audit purposes under the data processing agreement.
Encryption
- The entire connection to the application is encrypted (TLS 1.2 and 1.3), and browsers are required to use HTTPS only.
- The database and its backups are encrypted at rest.
- Passwords are stored only as irreversible hashes – nobody, including the VeyraHR team, can read them.
Separation of company data
- Each company’s data is kept in a separate, dedicated area of the database.
- Every request is assigned on the server to the logged-in user’s company – the application does not allow access to another Client’s data.
Infrastructure
- Managed Amazon Web Services cloud in the Frankfurt region (Germany), with ISO 27001 and SOC 2 certifications on the provider’s side.
- The database runs in a private network with no access from the internet.
- Automatic daily database backups.
- System keys and passwords are kept in a dedicated secrets manager, and deployments are automated without long-lived access keys.
Accounts and access
- User roles: administrator, HR manager, viewer. Only the company administrator manages users and imports data.
- A separate permission for individual-level data: without it, a user sees only aggregated data, and groups smaller than 3 people are hidden so that no individual’s data can be inferred.
- Blocking a user or changing their permissions takes effect immediately, including in sessions that are already open.
- Sessions expire automatically, and changing a password logs out all devices.
- Login attempt limits protect accounts against password guessing.
Accountability
- We log sign-ins, failed attempts, lockouts and password changes, with time and IP address.
- Every import is recorded in the history – the company administrator can roll it back.
- Every prediction is stored with its date and model version.
- Actions of the VeyraHR team in the administration panel are logged: who changed what and when.
VeyraHR team access
- The service administration panel is available only to designated people, from trusted networks, on separate accounts.
- The panel is used to manage company accounts (activation, blocking, support) and shows organisational data – not employee records.
- We do not use Client data for our own purposes, we do not combine data from different companies and we do not train shared models on it.
Application
- Security headers and a content security policy (CSP) reduce the risk of browser-based attacks.
- Code changes are covered by automated security analysis.
- The application contains no third-party analytics or advertising tools – Google Analytics runs only on the public website and only with consent.
In the event of a personal data breach, we notify your company without undue delay and no later than 72 hours after becoming aware of it, providing the information needed to report it to the supervisory authority where required.
AI Act
Is VeyraHR a high-risk AI system?
The AI Act classifies as high-risk, among others, AI systems used in employment to make decisions on working conditions, promotion and termination and to evaluate employee behaviour (Annex III, point 4). A system on that list that profiles individuals is always considered high-risk (Art. 6(3)).
This is why we design and document predictions for individual employees – attrition risk and burnout risk shown next to a name – as the AI Act requires for high-risk systems. Descriptive statistics (KPIs, gender pay gap, pay transparency report, absence) are not AI systems.
Predictions next to names
Users with the individual-level data permission see the risk and its causes for specific people. This is a high-risk use: it requires human oversight, informing employees and an impact assessment.
Departments and teams only
Users without that permission see only the distribution of risk across departments and job levels, and groups smaller than 3 people are hidden. A company that grants the permission to no one significantly limits the profiling of employees – it is worth confirming the classification of such a deployment with a lawyer.
Deadlines
- 2 February 2025Prohibited AI practices (including emotion recognition in the workplace) and the AI literacy obligation (Art. 4).
- 27 July 2026Regulation (EU) 2026/1744 (the “Digital Omnibus”) enters into force – it postpones the deadlines for high-risk systems.
- August 2026The Polish Act on artificial intelligence systems applies. The supervisory authority is the Commission for the Development and Security of Artificial Intelligence (KRiBSI).
- 28 October 2026KRiBSI may carry out inspections and impose administrative fines.
- 2 December 2027Full obligations for high-risk systems listed in Annex III, including AI systems used in employment – for providers and for employers.
The AI Act is a regulation – it applies directly to every employer in the EU that uses a high-risk AI system, regardless of company size, industry and whether it has work rules, an AI policy or an agreement with trade unions. There is no exemption for small and medium-sized enterprises that deploy such systems.
Internal policies do, however, determine how you meet the obligations: if your company has trade unions or a works council, inform them before deployment; if not, inform employees directly. It is also worth adding the rules for using VeyraHR to your existing data protection policy instead of creating a separate document.
Division of responsibilities (RACI)
R responsible (does the work)A accountable for the outcomeC consulted, provides supportI informed
| Area | VeyraHR (provider) | Your company (deployer) |
|---|---|---|
| AI literacyArt. 4 | CMaterials and onboarding training: how to read the results, the model’s limitations, what not to do. | A/RMake sure the people using VeyraHR understand what predictions are and how to use them. This applies already. |
| Informing employeesArt. 26(7) | CA template notice for employees and their representatives. | A/RBefore enabling individual-level predictions, inform your employees – and, if your company has trade unions or a works council, inform them as well. |
| Human oversightArt. 14 and 26 | RResults are recommendations with an explanation of the causes. The system does not make decisions or take actions towards employees. | AAppoint the people responsible for using the results, with the right knowledge and authority. HR decisions are always made by a person. |
| Transparency and explainabilityArt. 13 and 86 | A/RFor each person we show the factors that increase the risk and their impact in percentage points. The model has open, documented rules. | RWhen a VeyraHR result influences a decision about an employee, explain its role at the employee’s request. |
| Input dataArt. 26(4) | CImport validation, an error report and the option to roll back an import. | A/RImport up-to-date and complete data, limited to what the selected analyses need. |
| Record-keepingArt. 12 and 26(6) | RWe store predictions with their date and model version, sign-ins and imports. | AEnsure the logs are kept for at least 6 months – in VeyraHR this is part of the service. |
| Impact assessmentArt. 35 GDPR, Art. 26(9) | CA description of the system, data and safeguards for use in the impact assessment. | A/RCarry out a data protection impact assessment before deploying individual-level predictions. |
| Risk management, documentation, conformity assessmentArt. 9–17, 43, 49 | A/RTechnical documentation, accuracy and equal-treatment testing (including by sex), conformity assessment, CE marking and registration in the EU database – being prepared before 2 December 2027. | IUse the system in line with the instructions for use and report any irregularities you notice to us. |
What VeyraHR does not do
It does not recognise emotions, analyse communication or images, use biometrics or assess employees based on their private behaviour – these are prohibited or high-risk practices that we deliberately do not offer. It does not assess candidates in recruitment either.
GDPR checklist for employers
These steps apply today, regardless of the AI Act deadlines.
- Sign a data processing agreement. VeyraHR processes your employees’ data as a processor (Art. 28 GDPR). The agreement is concluded together with the service agreement.
- Determine the legal basis. For HR analytics this is usually the employer’s legitimate interest (Art. 6(1)(f) GDPR), and for pay gap reporting – a legal obligation (Art. 6(1)(c)).
- Inform your employees. Update your privacy notice (Art. 13–14 GDPR) with the purpose of HR analytics, the categories of data and the recipient – VeyraHR as a processor.
- Carry out an impact assessment. Systematic evaluation and prediction of employee behaviour usually requires a data protection impact assessment (Art. 35 GDPR). We will provide a description of the system to help you prepare it.
- Limit the scope of data. All columns except first and last name are optional. Import only what the selected modules need, and give access to individual-level data only to people who need it.
- Do not base decisions solely on the result. Art. 22 GDPR prohibits decisions with legal effects based solely on automated processing. A VeyraHR result is a prompt for a conversation, not a decision.
- Handle employees’ rights. As the controller, you handle requests for access, rectification, objection or erasure – you upload corrected data with the next import, and we help with unusual cases.
Pay transparency
Directive (EU) 2023/970 requires employers with at least 100 employees to report on the gender pay gap. Companies with 150 or more employees submit their first report for 2026 by 7 June 2027, and companies with 100–149 employees by 7 June 2031. If the pay gap in any category of workers is at least 5% and cannot be justified by objective criteria, a joint pay assessment with workers’ representatives is required.
The Pay Transparency module calculates the indicators under Art. 9 of the Directive and flags categories that require assessment. The Polish act implementing the Directive is still in the legislative process – we will adapt the report to its final definitions.
Documents and contact
For implementation and audit purposes we provide Clients with the following documents (in Polish):
- the data processing agreement with the list of sub-processors (annex to the Terms of Service),
- a description of the system, data and safeguards for the data protection impact assessment (PDF),
- a template notice for employees and their representatives – editable DOCX or PDF,
- instructions for use of the prediction modules (PDF).
Questions about data protection and compliance: iod@veyrahr.pl or via the contact form.
This page is for information purposes only and does not constitute legal advice. Legal status as of September 2026. The information on how VeyraHR works reflects the actual state of the service, and we update it whenever something changes. In case of any discrepancy, the Polish version prevails.