How Hremia handles personal data for its AI wellbeing companion and confidential speak-up channel — EU-first and GDPR-by-design.
Last updated: 2026-09-28
Template — review with your counsel before relying on it. This document is provided for information only and is not legal advice.
This document is published in English, which is the authoritative version. If you need it in another language for your procurement or works council, contact [email protected].
Hremia provides an AI wellbeing companion and a confidential speak-up channel for employers and their teams across the EU. Where we determine the purposes and means of processing our own service and account data, we act as a data controller. When we process workforce data on behalf of an employer customer, we act as a data processor under that customer's instructions (see our Data Processing Addendum). You can reach us at [email protected].
We deliberately minimise what we collect:
Where Hremia is a controller (for example, our customers' account and billing data), we rely on: contract (Art. 6(1)(b)) to deliver the service you request; legitimate interests (Art. 6(1)(f)) to secure, maintain and improve it; and legal obligation (Art. 6(1)(c)) where the law requires.
For workforce data that we process on an employer's behalf, the employer, as controller, determines the lawful basis: typically a legal obligation under the applicable whistleblowing law for reports, and legitimate interests, the employment contract or a legal obligation under employment law for other features. Special-category data (Art. 9), such as health-related leave records or wellbeing matters an employee chooses to share, also requires an Art. 9(2) condition, which the employer determines and documents. We process such data with heightened safeguards.
Customer data (the database, reports, conversations and files) is stored in the European Union, with Hetzner Online GmbH in Falkenstein, Germany.
The assistant's replies, and other AI features such as translating announcements, are generated by AI models from established providers, chosen for each customer organisation and named in our sub-processor list. For customer organisations, these providers work on paid, business terms under which they do not use the data to train their models and keep it only for a limited period. Where a provider processes personal data outside the EU/EEA, the transfer relies on a safeguard under Chapter V GDPR, such as an adequacy decision or the Standard Contractual Clauses.
Our public demonstration contains only fictitious sample data. Please do not enter real personal data into it.
We use a small, vetted set of sub-processors: Hetzner Online GmbH (Germany) for hosting and storage, the AI model providers used for each customer organisation, and operational tooling. Each is bound by a written data-processing agreement with confidentiality and security obligations no less protective than ours. A current list, with each sub-processor's location and transfer safeguard, is available on request, and material changes are notified in advance so customers may object.
We keep personal data only as long as necessary for the purposes above or as required by law, then delete or irreversibly anonymise it. Retention periods follow the customer's configuration and instructions for workforce data; account data is retained for the life of the relationship and a limited period thereafter. Automatic deletion at the end of the retention period a customer configures is being introduced.
Subject to the GDPR, you have the right to access, erasure, portability and objection, as well as rectification and restriction. To exercise these rights or submit a data-subject access request (DSAR), contact [email protected]. Where Hremia acts as a processor, we will route your request to the relevant employer controller and support its response. You may also lodge a complaint with your supervisory authority.
We use strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising or cross-site tracking cookies.
For any privacy question, or to reach our Data Protection Officer, write to [email protected].
EU-first · GDPR-by-design · Support, not surveillance.