GDPR without the paperwork.

A staffing agency processes more personal data than most businesses: applicants, employees, bank details, sick notices. alluvo keeps it on servers in Frankfurt, shows each person only what their role allows, and records who changed what. The GDPR applies across the EU; local labour and data protection rules on top of it are yours to check for your country.

Prüfumfang alluvo

GDPR & data protection

Hosting and data processing
In the data model
Rights per role
Block
Change history
Evidence
Specially protected data
Block
AI with data minimisation
In the data model
Consents
Evidence
Sign-in
In the data model
Proven in code What alluvo does not check is listed further down.

Built in

What alluvo checks, and how strictly.

Every line describes what the software does today. The stamp says whether alluvo prevents something, allows it only with a reason, or just points it out.

  1. Art. 28 GDPR

    Hosting and data processing

    alluvo runs in Frankfurt am Main (Germany), every client with its own database. The data processing agreement is Annex 1 of the terms of use. Which sub-processors are involved, including the AI providers, and with which safeguards, is in the privacy policy.

    In the data model
  2. Art. 25 and 32 GDPR

    Rights per role

    Every role sees only its excerpt: own records, the team, the branch or everything. The AI works with the permissions of the person it belongs to.

    Block
  3. Art. 5 (2) GDPR

    Change history

    Every field has its history with author and time. If the AI changes something, it also records with which tool and from where.

    Evidence
  4. Art. 9 and 32 GDPR

    Specially protected data

    Tax ID and access keys are encrypted in the database, bank details are only shown to the AI masked. The AI may not write health data and other special categories into free-text fields.

    Block
  5. Art. 5 (1) (c) GDPR

    AI with data minimisation

    The AI providers do not train on your data. Automation agents can pseudonymise names and personal data, and the AI can only delete into the recycle bin.

    In the data model
  6. Art. 7 GDPR

    Consents

    The consent for WhatsApp sits on the contact, with time, source and reason, and so does the withdrawal. Campaigns only reach those who have consented.

    Evidence
  7. Art. 32 GDPR

    Sign-in

    Two-factor sign-in with an authenticator app and sign-in through Google or Microsoft are built in.

    In the data model

In the data model Stored once, and everything calculates with it. Block alluvo does not allow it. Evidence alluvo records the state, the time and who did it.

From everyday work

Data protection that holds up day to day.

  1. Mit alluvo 01

    Every role sees its excerpt.

    In alluvo the file hangs on the employee, and the role decides who may see it: own records, team, branch or everything. Every change is in the history.

    A thing of the past

    The employee file sits on the network drive. Everyone has access.

    Résumés, employment contracts and sick notices sit in folders that every branch can access, because the permissions were set up that way once.

    The consequenceWhoever does not restrict access to what is necessary breaches the duty to take suitable technical and organisational measures. With health data it weighs more heavily.1

  2. Mit alluvo 02

    The consent sits on the contact.

    alluvo stores consent and withdrawal with time and source. Messages and campaigns only go to contacts who have consented.

    A thing of the past

    The WhatsApp group has 80 members. Nobody was asked.

    New employees land in the group because it is quick. Whether anyone consented is written down nowhere.

    The consequenceWithout provable consent the basis is missing, and you have to provide the proof.2

To be honest

What alluvo does not take off your plate today.

A piece of software that promises everything ends up checking nothing properly. These points are still yours today.

  1. You compile an access request under Art. 15 GDPR from the data in alluvo. There is no button today that outputs all of a person's data in one file.
  2. Retention periods, for example for applicants after a rejection, you set and carry out yourself. alluvo does not delete automatically after a period.
  3. Two-factor sign-in can be switched on per user. It cannot be made mandatory for everyone today.

Where it happens

These apps enforce it.

Compliance & security

The other laws.

Questions

Questions about the GDPR in alluvo.

Where is my data?

The platform runs in Frankfurt am Main (Germany), with its own database per client. For AI functions the AI providers process data on your behalf; who they are, where, and with which safeguards, is in the privacy policy.

Do I get a data processing agreement?

Yes, it is Annex 1 of the terms of use and applies with the contract. You can download it as a PDF.

Does the AI train on my data?

No. The AI providers process your data on your behalf and do not train on it. You can also set automation agents so that they only see names and personal data pseudonymised.

Who may see which data in alluvo?

You decide through roles: own records, the team, the branch or everything. A user's AI works with exactly that user's permissions.

Seeing is easier than reading.

Start for free, or book 20 minutes: we show you alluvo on real workflows.