hremia
Hremia

Data Processing Addendum

Terms under which Hremia processes personal data as a processor on behalf of the customer (the controller).

Last updated: 2026-09-28

Template — review with your counsel before relying on it. This document is provided for information only and is not legal advice.

This document is published in English, which is the authoritative version. If you need it in another language for your procurement or works council, contact [email protected].

1. Roles & scope

This Addendum forms part of the agreement between the customer (the controller) and Hremia (the processor). It applies to Hremia's processing of personal data on the customer's behalf in connection with the service. Hremia processes such data only on the customer's documented instructions, including those set out in the agreement and configuration of the service.

2. Processing details

  • Subject matter & duration — provision of the Hremia service, including the assistant, the reporting channel and related HR features, for the term of the agreement.
  • Nature & purpose — hosting, securing and operating the service, including generating the assistant's replies, translations and training questions through the AI model providers listed as sub-processors.
  • Categories of data — account identifiers and contact details; role, department and employment records; leave records, including health-related leave; training records; survey participation; reports and case notes; usage metadata; and the encrypted, isolated content employees choose to share with the assistant. This may include special categories of data (Art. 9 GDPR), notably health data, and, in reports, data on alleged offences (Art. 10 GDPR).
  • Data subjects — the customer's employees and authorised users, people who report through the customer's reporting channel, and other people named in reports.

3. Security measures

Hremia implements appropriate technical and organisational measures, including:

  • Encryption — connections to the service use TLS; the messages and attachments of private conversations, wellbeing notes and report content are encrypted at rest with AES-256-GCM, using a key per customer.
  • Tenant isolation — schema- and role-level isolation between customers.
  • Row-level security (RLS) — database policies enforcing per-tenant and per-role access at the data layer, including restrictive policies under which an assistant conversation cannot reach another employee's records.
  • Key custody — Hremia holds the encryption keys on its EU servers and can therefore technically decrypt customer data; it does so only where needed to run the service, on the customer's documented instructions or where the law requires it.
  • least-privilege access, audit logging and ongoing monitoring.

4. Sub-processors

The customer authorises Hremia to engage the sub-processors named in Hremia's sub-processor list, including Hetzner Online GmbH (hosting and storage, Falkenstein, Germany) and the AI model providers used for the customer's organisation. Each is bound by written terms, including a data-processing agreement, imposing data-protection obligations no less protective than this Addendum. AI model providers are engaged on paid, business terms under which they do not use the customer's data to train their models and retain it only for a limited period. Hremia maintains a current list and notifies material changes in advance so the customer may object.

5. Storage location and international transfers

Customer data is stored in the EU (Hetzner Online GmbH, Falkenstein, Germany). For the AI features (the assistant's replies, translations and training questions), the text the task needs, such as the conversation and the context needed to answer it, is sent to the AI model provider named in the sub-processor list. Where a provider processes personal data outside the EU/EEA, the transfer relies on a safeguard under Chapter V GDPR, such as an adequacy decision or the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), as stated for each provider in the sub-processor list.

6. Data-subject requests

Taking into account the nature of the processing, Hremia assists the controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where Hremia receives such a request directly, it promptly forwards it to the controller and supports its response, including for employees' private conversations, which the controller cannot read itself.

7. Breach notification

Hremia notifies the controller without undue delay after becoming aware of a personal-data breach affecting the controller's data, providing the information reasonably needed for the controller to meet its own notification obligations.

8. Audit

Hremia makes available the information necessary to demonstrate compliance with this Addendum and allows for and contributes to audits, including inspections, conducted by the controller or an auditor it mandates, subject to reasonable confidentiality and security arrangements.

9. Deletion or return

On termination, and at the controller's choice, Hremia deletes or returns the personal data it processes and deletes existing copies, unless retention is required by law.

10. Contact

To request or execute this Addendum, or for data-processing questions, write to [email protected].

AES-256-GCM · Stored in the EU · Encrypted & isolated by design.