GDPR without the paperwork.
A staffing agency processes more personal data than most businesses: applicants, employees, bank details, sick notices. alluvo keeps it on servers in Frankfurt, shows each person only what their role allows, and records who changed what. The GDPR applies across the EU; local labour and data protection rules on top of it are yours to check for your country.
GDPR & data protection
- Hosting and data processing
- In the data model
- Rights per role
- Block
- Change history
- Evidence
- Specially protected data
- Block
- AI with data minimisation
- In the data model
- Consents
- Evidence
- Sign-in
- In the data model
Built in
What alluvo checks, and how strictly.
Every line describes what the software does today. The stamp says whether alluvo prevents something, allows it only with a reason, or just points it out.
-
Art. 28 GDPR
In the data model
Hosting and data processing
alluvo runs in Frankfurt am Main (Germany), every client with its own database. The data processing agreement is Annex 1 of the terms of use. Which sub-processors are involved, including the AI providers, and with which safeguards, is in the privacy policy.
-
Art. 25 and 32 GDPR
Block
Rights per role
Every role sees only its excerpt: own records, the team, the branch or everything. The AI works with the permissions of the person it belongs to.
-
Art. 5 (2) GDPR
Evidence
Change history
Every field has its history with author and time. If the AI changes something, it also records with which tool and from where.
-
Art. 9 and 32 GDPR
Block
Specially protected data
Tax ID and access keys are encrypted in the database, bank details are only shown to the AI masked. The AI may not write health data and other special categories into free-text fields.
-
Art. 5 (1) (c) GDPR
In the data model
AI with data minimisation
The AI providers do not train on your data. Automation agents can pseudonymise names and personal data, and the AI can only delete into the recycle bin.
-
Art. 7 GDPR
Evidence
Consents
The consent for WhatsApp sits on the contact, with time, source and reason, and so does the withdrawal. Campaigns only reach those who have consented.
-
Art. 32 GDPR
In the data model
Sign-in
Two-factor sign-in with an authenticator app and sign-in through Google or Microsoft are built in.
In the data model Stored once, and everything calculates with it. Block alluvo does not allow it. Evidence alluvo records the state, the time and who did it.
From everyday work
Data protection that holds up day to day.
-
Mit alluvo 01
Every role sees its excerpt.
In alluvo the file hangs on the employee, and the role decides who may see it: own records, team, branch or everything. Every change is in the history.
A thing of the past
The employee file sits on the network drive. Everyone has access.
Résumés, employment contracts and sick notices sit in folders that every branch can access, because the permissions were set up that way once.
The consequenceWhoever does not restrict access to what is necessary breaches the duty to take suitable technical and organisational measures. With health data it weighs more heavily.1
-
Mit alluvo 02
The consent sits on the contact.
alluvo stores consent and withdrawal with time and source. Messages and campaigns only go to contacts who have consented.
A thing of the past
The WhatsApp group has 80 members. Nobody was asked.
New employees land in the group because it is quick. Whether anyone consented is written down nowhere.
The consequenceWithout provable consent the basis is missing, and you have to provide the proof.2
To be honest
What alluvo does not take off your plate today.
A piece of software that promises everything ends up checking nothing properly. These points are still yours today.
- You compile an access request under Art. 15 GDPR from the data in alluvo. There is no button today that outputs all of a person's data in one file.
- Retention periods, for example for applicants after a rejection, you set and carry out yourself. alluvo does not delete automatically after a period.
- Two-factor sign-in can be switched on per user. It cannot be made mandatory for everyone today.
Where it happens
These apps enforce it.
-
Identities
One company. One record. Even when it shows up in five places.
- Companies, contacts, accounts and suppliers live in one place, and every app works on the same records.
- Sites hang off the parent company as accounts, instead of standing next to each other as ten companies.
- Included in the price per employee on assignment, like every module.
-
Employee app
One app. The whole employment relationship.
- Today view, assignments, shift plan, working time account, vacation account and an estimate for the next pay.
- Sick note, vacation request, timesheet, expenses, academy, knowledge base, all from the same app.
- Runs in the browser, installable without an app store, and also when there is no network on assignment.
-
Inbox
Four channels, one inbox — and agents that help out.
- Email, chat, WhatsApp and phone land as tickets in one place.
- Rules, assignments and response times per inbox.
- AI agents work through tickets on their own — each one is enabled individually.
-
Data quality
The duplicate gets noticed before anyone else notices it.
- Duplicates, inconsistent formatting and missing details are detected, not reported and left lying around.
- Part of it is fixed automatically; you get the rest as an incident on your desk.
- Runs alongside daily work instead of happening once a year as a clean-up project.
Compliance & security
The other laws.
Questions
Questions about the GDPR in alluvo.
Where is my data?
The platform runs in Frankfurt am Main (Germany), with its own database per client. For AI functions the AI providers process data on your behalf; who they are, where, and with which safeguards, is in the privacy policy.
Do I get a data processing agreement?
Yes, it is Annex 1 of the terms of use and applies with the contract. You can download it as a PDF.
Does the AI train on my data?
No. The AI providers process your data on your behalf and do not train on it. You can also set automation agents so that they only see names and personal data pseudonymised.
Who may see which data in alluvo?
You decide through roles: own records, the team, the branch or everything. A user's AI works with exactly that user's permissions.
Seeing is easier than reading.
Start for free, or book 20 minutes: we show you alluvo on real workflows.