Product docs

Platform & security

Security and GDPR

Onboardly processes employees' personal data and document scans. Below we describe how we isolate and encrypt them, and how we fulfill our GDPR obligations.

Data isolation between organizations

Onboardly is a multi-tenant application: data for many organizations lives in a single database, but each organization is separated from the others at the database level through Postgres RLS (Row Level Security). A query running in the context of one organization has no access to another organization's rows — isolation is enforced by the database engine, not just by application code.

Data encryption

We encrypt personal data and document scans with the AES-256-GCM algorithm. We use envelope encryption: there is a master key and a separate data key for each organization. An organization's data key is encrypted with the master key — so compromising a single data key does not expose the other organizations.

  • Master key — the top-level key that protects the data keys.
  • Per-organization data key — used to encrypt that organization's personal data and scans.
  • AES-256-GCM — authenticated encryption (detects tampering with the data).

Account protection

  • 2FA (TOTP) — two-factor sign-in based on an authenticator app (time-based codes).
  • Form protection (captcha) — protects forms against automated abuse.
  • “log in as user” audit — whenever the support team enters a client's account in “as user” mode, each such entry is recorded in the audit log.

GDPR — how we fulfill our obligations

AreaHow it works in Onboardly
Data retentionSoft delete after 90 days, hard delete after 7 years.
Right to be forgottenFulfillment of a request to delete a person's data.
Data processing agreement (DPA)Onboardly processes data as a processor on the basis of a DPA.
Access log (art. 30)A record of access to personal data in line with art. 30 GDPR.

Scans of identity documents

We do not store scans of Polish citizens' ID cards — in line with UODO (the Polish data protection authority) guidance. We do store foreign workers' residence documents (e.g. residence card, visa), because the law requires it — the employer is obliged to document the legality of stay and work.

You'll find the details of the processing arrangement and the data catalog in the DPA and in the privacy policy.

Related: Developer integrations · Foreign worker legalization

§08 · Zacznij teraz

Twój następny pracownik
onboarding zajmie 15 minut.

14-dniowy trial z pełnym dostępem. Zatrudnij 3 osoby z prawdziwymi danymi: KYC, podpis z pieczątką, teczka w Drive, eksport do kadr.

Jeśli nie zobaczysz wartości, nie kupujesz. Bez karty kredytowej.