Security
Data privacy and security Q&A.
Answers to the questions security, privacy and procurement teams ask about datascalehr.
Data Privacy & GDPR
- Is datascalehr a data controller or a data processor under GDPR?
datascalehr is a data processor. The client is the data controller and decides the purposes and means of processing.
datascalehr provides the technical and organizational measures that support the client’s GDPR compliance, as set out in the Data Processing Agreement.
- What personal data does datascalehr process?
datascalehr processes the Personal Data that each client chooses to upload, typically worker, HR and payroll records.
The client decides what Personal Data is processed, as the data controller, and datascalehr processes the data only to deliver the Service.
- How does datascalehr handle GDPR data subject requests?
datascalehr supports every GDPR data subject right: access, rectification, erasure, restriction, objection and portability.
When a data subject contacts datascalehr directly, datascalehr forwards the request to the client, because the client is the data controller.
- What is the client responsible for under GDPR when using datascalehr?
As data controller, the client decides which Personal Data to upload, for what purpose and on what lawful basis, and answers data subject requests, which datascalehr forwards to the client.
The client also manages users and roles in the application, chooses the encryption level for imported data, and sets field-level retention rules per country. The datascalehr Data Processing Agreement sets out the obligations of both parties.
Data Security & Encryption
- What encryption does datascalehr use?
The Mendix platform encrypts data at rest with AES-256 (disk and database) and data in transit with TLS 1.2 or higher.
datascalehr adds field-level (column-level) encryption with AES-256-GCM and encrypts uploaded files. Clients choose the encryption level for imported data: disk, or disk plus column level.
- How does datascalehr manage encryption keys?
datascalehr stores encryption keys outside the database, at environment level.
Key generation, storage, backup and restoration are fully automated, and no datascalehr staff member views or handles key values.
Mendix manages the keys for platform-level disk and database encryption.
- Is our data shared with other datascalehr clients?
No. Each client has a separate database instance on Mendix Cloud (AWS, Germany and Ireland), and no data is shared between clients.
- Who can access our data in datascalehr?
Only the client’s own users, listed in the application’s user management screens, can log in to the client’s environment.
datascalehr or Mendix staff can access raw data only at the data owner’s explicit written request, under strict administrative control, recorded through the in-app data access request function.
Back-end access is limited to three named engineers, requires client permission, and is logged for the life of the environment.
Data Ownership & Retention
- Who owns the data we upload to datascalehr?
The client owns the data. The client is the data controller, and datascalehr acts as a data processor on the client’s behalf.
Client Data, including any version of the data transformed through the Service, remains the client’s property.
- How long does datascalehr keep our data?
datascalehr deletes all client data from online systems 30 days after the contract ends.
Completed reports are kept as long as each jurisdiction’s audit rules require, and clients set field-level retention rules per country.
- How is data destroyed when storage hardware is retired?
datascalehr relies on AWS processes to destroy data on physical media when AWS replaces or recycles devices, following AWS compliance protocols for secure deletion.
KMod™ AI
- How does datascalehr's AI learn from payroll data?
datascalehr’s AI, KMod™, learns from the decisions of payroll experts in four steps.
First, a file arrives and datascalehr reads the file’s structure (headers, field names and data types). Second, KMod™ proposes mappings, for example “Field A likely corresponds to Field B”, based on relationships experts confirmed before. Third, a payroll expert confirms or rejects each proposal. Fourth, KMod™ stores the confirmed relationship.
The confirmed relationship is available immediately, with no retraining cycle, so a correction made in Munich improves the next suggestion in Vienna. KMod™ never stores file content or Personal Data.
- Does datascalehr train its AI on our payroll or personal data?
No. datascalehr’s Service learns from the validated decisions of human experts who confirm field relationships. Client Data is processed only to deliver the Service.
Every client benefits from the confirmed relationships, so mapping suggestions get more accurate over time at no additional cost.
- What is KMod™, and does KMod™ store personal data?
KMod™ is datascalehr’s AI-powered knowledge model. KMod™ suggests field mappings between HR systems and payroll systems, and learns from payroll experts who confirm or reject each suggestion.
KMod™ stores header, contextual, behavioral and categorization rules. KMod™ never stores Personal Data or data values.
- What categories of data does datascalehr's AI process?
datascalehr’s AI works with five categories of data.
Personal data (worker, HR and payroll data) is processed by internal algorithms only and is never sent to an LLM or stored in KMod™.
Header data (column and table names), contextual data (country, grouping, pay run dates) and categorization data (data type, format, validation rules) feed the mapping suggestions and may be sent to an LLM.
Behavioral data, the expert’s confirmation or rejection of each suggestion, is the training signal that KMod™ stores.
- Does datascalehr send payroll or personal data to external AI models?
No. datascalehr sends only header and contextual metadata, such as column names, country and pay frequency, to large language models.
Personal Data and data values never leave the datascalehr environment.
datascalehr is LLM-agnostic and currently uses Anthropic Sonnet 4.6 and QWEN 3 235B, both hosted in Germany.
- Can other clients learn anything about our payroll data through KMod™?
No. Shared KMod™ holds only abstract, expert-confirmed field relationships, such as “Dept_Code corresponds to Cost_Center”, with a confidence score.
datascalehr removes the client name, system identifiers, timestamps and user information before a confirmed relationship enters the shared KMod™, so no shared relationship can be traced back to the source client.
Client-specific relationships stay in the client’s local KMod™.
Data Breach Response
- How does datascalehr handle a data breach?
datascalehr follows a formal breach notification protocol.
The datascalehr incident response team, made up of Luke Zawadzki (VP Engineering), Nicolas Delord (CTO) and Jerome Gouvernel (CEO), investigates each incident, takes mitigation steps, and notifies affected clients and authorities as applicable law requires.
- Who do we contact about a potential data breach?
Report any potential data breach immediately to Luke Zawadzki, VP Engineering and Data Protection Officer, at luke.zawadzki@datascalehr.com.
Compliance & Third Parties
- Which sub-processors does datascalehr use for client data?
datascalehr uses two sub-processors.
Mendix (Siemens Industry Software) hosts the application in Germany and Ireland. Amazon Web Services provides the SES email gateway and Textract OCR in Ireland.
Both sub-processors operate under Standard Contractual Clauses.
LLM providers are not sub-processors, because datascalehr sends no Personal Data to any LLM provider.
- Which data protection laws does datascalehr comply with?
datascalehr complies with GDPR (EU, UK and Swiss) and with applicable US data protection laws, including HIPAA, COPPA, GLBA, FCRA, FERPA and CCPA.
- What platform does datascalehr run on, and how is the platform certified?
datascalehr runs entirely on Mendix Cloud, operated by Siemens Industry Software (Mendix) on AWS data centers in Germany and Ireland.
The Mendix platform holds SOC 2 Type II and ISAE 3000/3402 Type II attestations, ISO/IEC 27001, 27017, 27018 and 27701 certifications, ISO 22301, PCI DSS Level 1, FedRAMP Moderate and CSA STAR.
datascalehr owns and operates the application-level controls on top of the Mendix platform.
- How can we verify datascalehr's security and compliance?
On request, datascalehr provides the third-party attestations and certificates for the Mendix platform, including the SOC 2 Type II and ISO/IEC 27001 reports, together with datascalehr’s own compliance documentation.
datascalehr also provides additional information to supervisory authorities when an authority requires the information.