Security and data protection
Last updated: September 11, 2026.
eachr hosts sensitive HR data: employee records, receipts, payslips, contractual documents. Here is concretely how it is protected, without unnecessary jargon.
Hosted in Europe
- Database and authentication: Supabase, Frankfurt region (Germany).
- Files (receipts, payslips, documents): Cloudflare R2 storage restricted to the European Union jurisdiction.
- Application: served by Vercel, with automatic daily database backups provided by the host.
Encryption
- In transit: TLS on every connection, website and application.
- At rest: encryption provided by the database and file hosts.
- Payment: no card data transits through or is stored by eachr, everything goes through Stripe.
Isolation between companies
Every company is compartmentalized: access rules are enforced at the database level and checked server-side on every action. A multi-client office manager only sees the companies that granted them access, and switches between them without ever mixing data.
Access and authentication
- Administrators and managers: sign in with a one-time code received by email or with a Google account, no password to remember or leak.
- Employees: personal access link, revocable at any time by the company, no password.
- Distinct roles (administrator, manager, employee) with rights limited to what each needs to see.
Sealed, traceable documents
Every receipt and HR document gets a SHA-256 fingerprint as soon as it is uploaded. Any change becomes detectable, integrity is verified in one click, and every upload, view or download is written to an audit log the company can consult.
Monitoring and incident response
- Application errors are tracked continuously (Sentry, data in the European Union).
- In the event of a data breach, the companies concerned are informed without undue delay with the information needed for their own notification, as set out in the data processing agreement.
- To report a vulnerability or an incident: contact@eachr.co.
Processors
The full list of processors, their role and location is in the privacy policy. No processor is added without prior notice to client companies.
GDPR compliance
eachr acts as a processor for client companies regarding their employees' data. The data processing agreement (DPA) published on the website formalizes this relationship, and a signed version is provided on request.