Built for trust. Designed for people.
How Persohap protects employee data: EU-based hosting, TLS 1.3 in transit, encrypted storage, role-based access, GDPR-aligned processing and responsible AI.
Impressum (Legal Disclosure)
- Company
- Persohap GmbH
- Address
- Grünsteinweg 44D, 12349 Berlin, Germany
- Representative
- Martin Hesterberg (Managing Director)
Built for trust. Designed for people.
Employee data is among the most sensitive information an organisation manages. Persohap is built with privacy, security and transparency at its core — from encrypted communication and secure cloud infrastructure to GDPR-compliant data processing.
Our security principles
Privacy by design
Security and privacy are built into every stage of product development, not added afterwards. We continuously evaluate our systems, processes and infrastructure.
Human-centered security
Technology alone does not create trust. Secure systems are paired with responsible data handling, so employee information stays protected, confidential and under your control.
Transparency
You should always know what is collected, why, how it is processed, who can access it and how long it is stored. No hidden processes, no unnecessary collection.
How we protect your data
All customer data is hosted in the European Union on trusted cloud infrastructure.
EU-based processingGDPR-aligned operationsHigh availabilityRedundant backupsAll data is protected with modern encryption standards, in transit and at rest.
TLS 1.3 in transitEncrypted storageSecure database architectureAccess protectionOnly authorised individuals can reach customer environments.
Role-based permissionsAuthentication controlsLeast privilegeSecure administrative accessModern cloud infrastructure, built for reliability and resilience.
Continuous monitoringNetwork protectionThreat detectionRegular security updatesBackup and recoveryPersohap is designed around GDPR requirements, and supports organisations in meeting their own privacy obligations.
Data processing agreementsClear data ownershipConsent managementData deletionData exportAccess and transparency controlsYour organisation remains the owner of its data at all times.Persohap uses AI to support HR processes, not to replace human judgement.
Human oversightTransparencyExplainability where applicableFair and responsible useEmployee privacy protectedOrganisations remain in control of decisions and workflows.We take proactive measures to keep the platform available and operations continuous.
Infrastructure redundancyAutomated backupsDisaster recoveryContinuous monitoringA stable, dependable experience for every customer.Technology evolves. Threats evolve. Security must evolve too. Persohap continuously reviews and improves its security practices, infrastructure and operational procedures as the platform grows.
Our team is happy to go further on security, privacy, data processing and GDPR compliance.
Talk to our teamPrivacy Policy
Last updated: August 2026
Who is responsible
The controller for this website is Persohap GmbH, Grünsteinweg 44D, 12349 Berlin. When your employer uses Persohap as a platform, your employer is the controller for the data in their workspace and we act as processor on their instructions under a data processing agreement (Art. 28 GDPR). Questions either way: martin.hesterberg@persohap.com.
Conversation transcripts and audio
Spoken conversations are transcribed and the transcript is stored, because the report, the per-turn analysis and the interview scorecard are all produced from it and remain readable afterwards. Storing it is also what makes an interview record tamper-evident: it is taken from the session server-side rather than accepted from a browser. Conversation audio and video are not recorded — the stream is processed live and not retained. Coaching is walled off from performance review: nothing produced in a coaching session is exposed to a review.
How we use your data
To provide the service, produce the analysis and reports your organisation asked for, and keep the platform secure and available. We do not sell your data. We do not use customer conversation data, transcripts or uploaded documents to train AI models.
Where it is stored and how it is protected
Entirely in the EU, hosted in Frankfurt, Germany — logins, records, files and keys. Data is encrypted in transit and at rest. One organisation's workspace cannot be read by another. Access by our staff is limited to what is needed to operate and support the service.
Service providers we use
A small number of processors act on our behalf: our hosting provider in Frankfurt, an avatar and speech provider for the live conversation and its transcription, and a language-model provider for generating and analysing text. Each processes only what its function requires, under contract. All of them are named, with their locations and safeguards, in the data processing agreement — we will share it and walk your security reviewer through it under NDA.
Candidates and applicants
If you are interviewed through Persohap, the employer that invited you is the controller of your application data and decides how long it is kept. Screening is instructed to disregard name, gender, age and origin. Scores and recommendations are exactly that: a person makes the hiring decision, and every criterion carries the passage of transcript it came from so that judgement can be checked. Your invitation link is single-use and expires. To access or delete your data, contact the employer, or write to martin.hesterberg@persohap.com and we will route it.
Speak Up reports
A report can be filed anonymously; if you file anonymously we do not attach your identity to it. Visibility is set by the reporter at submission and snapshotted then, so a later reorganisation cannot widen who can read an old case. Access is recorded in an append-only log that includes passive views. Attachments are stored under an anonymised key.
How long we keep it
Workspace data is kept for as long as your organisation's contract runs, and deleted or returned when it ends, subject to German statutory retention periods for commercial and tax records. Within that, retention of session and candidate data follows what your organisation configures. You can ask for deletion at any time.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection (Art. 15–21), and the right to withdraw consent where processing rests on it. Write to martin.hesterberg@persohap.com. We answer without undue delay and within one month, as Art. 12(3) requires; if a request is complex we will tell you and may extend by two further months. You may also complain to a supervisory authority — for us, the Berlin Commissioner for Data Protection and Freedom of Information.
Cookies
This website sets only what is technically necessary: authentication, session state, and remembering your language and light or dark theme. No advertising cookies, no third-party tracking, no analytics profiling — which is why you are not being asked for consent to any.
Video on this website
Our product videos are hosted on YouTube (Google Ireland Limited). Nothing is loaded from YouTube until you press play: until then the page shows a still image stored on our own servers. When you start a video, YouTube receives your IP address and may store information on your device in order to play it. We embed in YouTube's extended data protection mode (youtube-nocookie.com), which limits that to what playback requires. The legal basis is your consent, given by pressing play (Art. 6(1)(a) GDPR); Google's own privacy policy applies to the playback itself.
Terms of Service
Use of the platform
Persohap is a professional training and HR platform for business use. You may not use it to unlawfully monitor individuals, and you may not attempt to reverse-engineer, extract or circumvent the platform or the AI systems behind it.
AI output and human decisions
Persohap produces scores, summaries, lessons and recommendations. They are decision support, not decisions. A person must make and remain accountable for any decision about hiring, performance, pay or employment, and the evidence behind every score is shown so that it can be checked. AI-generated lessons are drafts until a person publishes them. Output can be wrong; treat it as an input to your judgement, not a substitute for it.
Your responsibilities as an employer
You are responsible for having a lawful basis to process your employees' and candidates' data, for informing them that Persohap is used and how, and for involving your works council and data protection officer where your law requires it. Configuration choices — what is collected, who may see it, how long it is kept — are yours to make.
Subscriptions & billing
Persohap is sold as a subscription with a shared pool of sessions for the organisation rather than per seat. Term, price and renewal are set out in your order form or agreement, which prevails over this page. Statutory withdrawal rights for consumers do not apply to business customers.
Availability and support
We aim for continuous availability but the service may be interrupted for maintenance, updates, or reasons outside our control. Any committed service levels are those in your agreement.
Intellectual property
Persohap owns the platform, its software and its interfaces. The underlying AI models are licensed from third-party providers and remain theirs. You retain ownership of your content, your employee data and your session data, and you keep the right to export it.
Governing law
German law applies. Place of jurisdiction for business customers is Berlin.
Questions a policy page cannot answer.
Security review, DPA, works council, retention — bring them to a call and we will go through them with your reviewer under NDA.

