hremia
Hremia

Privacy Policy

How Hremia handles personal data for its AI wellbeing companion and confidential speak-up channel — EU-first and GDPR-by-design.

Last updated: 2026-09-28

Template — review with your counsel before relying on it. This document is provided for information only and is not legal advice.

This document is published in English, which is the authoritative version. If you need it in another language for your procurement or works council, contact [email protected].

1. Who we are

Hremia provides an AI wellbeing companion and a confidential speak-up channel for employers and their teams across the EU. Where we determine the purposes and means of processing our own service and account data, we act as a data controller. When we process workforce data on behalf of an employer customer, we act as a data processor under that customer's instructions (see our Data Processing Addendum). You can reach us at [email protected].

2. Data we process

We deliberately minimise what we collect:

  • Account data — names, work email addresses, organisation, role and authentication credentials needed to provision and secure access.
  • Usage metadata — records of feature use, timing and volume, such as when an employee used the assistant and how much, without the content of conversations; used to operate, secure, meter and improve the service. Employers see these only as totals.
  • Workforce data — the records an employer keeps in the service, such as employment, leave and training records and reports, which we process as a processor on the employer's instructions.
  • Employee chat content. The content of an employee's conversations with the assistant is encrypted and isolated: the employer's HR staff and managers cannot read it, and it is not used to build profiles. Hremia holds the encryption keys on its EU servers, so it can technically access the content; it does so only where running the service requires it. To generate replies, the content is sent to the AI model provider used for that organisation (see sections 4 and 5).

3. Lawful bases (GDPR Art. 6 / 9)

Where Hremia is a controller (for example, our customers' account and billing data), we rely on: contract (Art. 6(1)(b)) to deliver the service you request; legitimate interests (Art. 6(1)(f)) to secure, maintain and improve it; and legal obligation (Art. 6(1)(c)) where the law requires.

For workforce data that we process on an employer's behalf, the employer, as controller, determines the lawful basis: typically a legal obligation under the applicable whistleblowing law for reports, and legitimate interests, the employment contract or a legal obligation under employment law for other features. Special-category data (Art. 9), such as health-related leave records or wellbeing matters an employee chooses to share, also requires an Art. 9(2) condition, which the employer determines and documents. We process such data with heightened safeguards.

4. Where data is stored and processed

Customer data (the database, reports, conversations and files) is stored in the European Union, with Hetzner Online GmbH in Falkenstein, Germany.

The assistant's replies, and other AI features such as translating announcements, are generated by AI models from established providers, chosen for each customer organisation and named in our sub-processor list. For customer organisations, these providers work on paid, business terms under which they do not use the data to train their models and keep it only for a limited period. Where a provider processes personal data outside the EU/EEA, the transfer relies on a safeguard under Chapter V GDPR, such as an adequacy decision or the Standard Contractual Clauses.

Our public demonstration contains only fictitious sample data. Please do not enter real personal data into it.

5. Sub-processors

We use a small, vetted set of sub-processors: Hetzner Online GmbH (Germany) for hosting and storage, the AI model providers used for each customer organisation, and operational tooling. Each is bound by a written data-processing agreement with confidentiality and security obligations no less protective than ours. A current list, with each sub-processor's location and transfer safeguard, is available on request, and material changes are notified in advance so customers may object.

6. Retention

We keep personal data only as long as necessary for the purposes above or as required by law, then delete or irreversibly anonymise it. Retention periods follow the customer's configuration and instructions for workforce data; account data is retained for the life of the relationship and a limited period thereafter. Automatic deletion at the end of the retention period a customer configures is being introduced.

7. Your rights

Subject to the GDPR, you have the right to access, erasure, portability and objection, as well as rectification and restriction. To exercise these rights or submit a data-subject access request (DSAR), contact [email protected]. Where Hremia acts as a processor, we will route your request to the relevant employer controller and support its response. You may also lodge a complaint with your supervisory authority.

8. Cookies (essential only)

We use strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising or cross-site tracking cookies.

9. Contact

For any privacy question, or to reach our Data Protection Officer, write to [email protected].

EU-first · GDPR-by-design · Support, not surveillance.