Legal Resources at PeopleForce
Last updated: June 01, 2025
At PeopleForce, we are fully committed to complying with the General Data Protection Regulation (GDPR) and supporting our customers and users in the European Union (EU) with transparency, control, and accountability. This page explains how we protect your personal data, what rights you have, and how our platform helps your organization stay compliant.
We align our data handling practices with the core principles of the GDPR:
Lawfulness, Fairness & Transparency
Purpose Limitation & Minimisation
Accuracy & Storage Limitation
Integrity & Confidentiality
We implement a comprehensive set of technical and organizational measures to safeguard data, including:
PeopleForce has successfully undergone an external GDPR compliance audit and was issued a formal GDPR compliance certificate by an independent third-party assessor.
This certification confirms that:
A summary of our certification is available to customers under NDA upon request.
All PeopleForce data is stored and processed exclusively within the European Union, using secure infrastructure located in Frankfurt, Germany.
We do not transfer personal data outside the EU under normal operations. If international transfers become necessary (e.g., for customer-authorized integrations or support), they will be executed strictly in line with Chapter V of the GDPR, including:
More details are available on our Trust Hub.
As a data subject, you have the right to:
How to Exercise Your Rights
Since PeopleForce is a Data Processor, we act on behalf of the Data Controller (typically your employer). You can:
We retain data only for as long as necessary to fulfill its original purpose or comply with legal and contractual obligations. Retention periods may vary by data type.
No. PeopleForce hosts all customer data in Frankfurt, Germany. If a cross-border transfer becomes necessary, we apply SCCs or other lawful safeguards.
We are a Data Processor. Our customers define the purpose and means of processing as Data Controllers.
We apply industry-standard security measures, including encryption, RBAC, and continuous monitoring. For full details, visit our Trust Hub.
Report it to security@peopleforce.io. We will investigate and notify the Data Controller in accordance with our incident response process.
For any GDPR-related inquiries or to submit a request: