hremia
Trust & safeguards

Security, privacy & compliance

Built so people can trust it — and so you can prove it. Private by design, never surveillance.

Book a demo
Aligned with EU frameworks
  • GDPR (Art. 9 & 22)
  • EU AI Act
  • EU Whistleblower Directive
  • ISO 45003
Data stored in the EU

Our commitments to your people

Private by default

Managers cannot browse raw conversations. HR receives a case only when an employee submits a named/anonymous report, or a narrowly-defined legal/safety escalation applies — enforced at the database level.

No automated employment decisions

The system never recommends firing, discipline, promotion or performance actions. Outputs are advisory and reviewed by people.

Sensitive-data controls

GDPR Article 9-style data is minimised and kept separate. Private conversations, wellbeing notes and report content are encrypted with AES-256-GCM using a key per company, and HR cannot read private conversations or wellbeing notes.

Anonymity thresholds

No dashboard for groups below a safe minimum; sensitive quotes are suppressed or redacted. Small teams roll up to larger groups.

Responsible AI

The assistant tells people it is an AI whenever they ask. No emotion recognition and no automated employment decisions. AI use is recorded without conversation content, and you see it only as totals.

Aligned with EU frameworks

GDPR (Art. 9 & 22)

Special-category data handling and protection against solely-automated decisions, by design.

EU AI Act

Transparency first: people are told they are talking to an AI, and the assistant confirms it whenever asked. No emotion recognition and no employment decisions by AI.

EU Whistleblower Directive

A confidential internal reporting channel with acknowledgement, SLA tracking and audit trail.

ISO 45003

Psychosocial-risk evidence and a risk register for occupational health & safety.

Documents to download

Download our material, study it at your own pace and share it with your legal and IT departments.

PDF

Client brochure

The platform at a glance: what it offers employees and HR, how it works and how to get started.

PDF

Legal & Technical Compliance Annex

For legal and IT departments: GDPR, Directive (EU) 2019/1937, Law 4990/2022 for Greece, the EU AI Act, technical and organisational measures.

PDF

Questions and answers

The questions legal departments ask about data protection, the reporting system and the EU AI Act, with documented answers.

Want the DPIA & security pack?

We provide a DPA, DPIA support, a legal-basis matrix and audit materials for your DPO and security review.

Book a demo