← Security & trust

Sub-processors

Every third party that can touch data, what it does, what it actually sees and where it sits. It is a short list on purpose — each addition is a party your data has to trust, so the default answer to “could we bolt on a service for this?” is no.

Last reviewed 9 August 2026. We will tell you before a new sub-processor with access to HR data is added — ask to be on that list and you will be.

Can touch HR data

If you run HumanR on your own servers, the first row does not apply to you at all and the second is your own mail server. A self-hosted instance does not call out.

Amazon Web Services

Asia Pacific (Singapore)
Purpose
Application and database hosting for our cloud, and optionally employee document files
Data
All customer HR data

Email delivery (SMTP)

Provider-managed
Purpose
Sending notifications, expiry alerts, approval requests and account invitations. On our cloud this is our own mailbox provider; on a self-hosted install it is whichever SMTP server you configure, and we are not in the path at all.
Data
Recipient address and message contents — an expiry alert names an employee and a document type

Intuit (QuickBooks Online)

Intuit-managed
Purpose
Posting payroll journals to your ledger. Only where you have connected it yourself through Intuit's own consent screen, and only in that direction
Data
Payroll totals and account codes. No per-employee pay figures leave in this direction

This website only

These see visitors to humanr.online. These see visitors to humanr.online. None of them is loaded by the product, and none of them ever sees an employee record.

Cloudflare

Turnstile bot check on the public forms on this website

IP address and a challenge token. No HR data · Global

Google Analytics 4

Website traffic measurement, loaded only after you accept analytics cookies

Page views and site behaviour on humanr.online. No HR data · Global

Telegram

Notifying our own team when someone submits the contact or demo form

The name, email and message you typed into the form. No HR data · Global

Analytics load only if you accept analytics cookies. See the privacy policy.

Not on the list, and why that matters

A sub-processor list is as informative for what it omits. These are the parties people reasonably assume are involved.

ZKTeco and other biometric devices

Your devices push punches directly to your own HumanR instance over your own network. Nothing is relayed through a device-vendor cloud, and no third party sees who clocked in when. If your instance is self-hosted, attendance data never leaves your building.

Any advertising or data broker

None. Your HR data is not sold, shared, enriched or used as training data — there is no arrangement of that kind to disclose.

Offshore support contractors

Support is handled by the same small team that builds the product. Your data is not passed to an outsourced support desk.

Running a vendor assessment?

Send your questionnaire to hello@humanr.online. We answer every line, including “not yet” where that is the truth. See also data processing and retention & deletion.

Straight answers, in writing

Ask us anything about how your data is held. We would rather lose a deal on an honest answer than win one on an implied certification.

No credit card. No sales call required. A real login, emailed to you.