whats-best.ai
Search Sign in

HR Management

HeavenHR

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by HeavenHR GmbH · www.heavenhr.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Answers for the most sensitive personal data the company holds, about people who cannot decline the processing. Wants retention that executes rather than promises, a published subprocessor list, and applicant data that deletes itself on the stated date. Treats an unpublished DPA as a finding.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Digital personnel file & data model

How this is scored

The system of record: employee master data, the digital personnel file, org structure, custom fields, and whether history is kept rather than overwritten.

0 — A contact list with job titles; no document storage, no org structure, no history — changes overwrite what was there.

3 — Employee records with document upload, but a flat structure: no org chart, few or no custom fields, and no dated history of contract or salary changes.

5 — Digital personnel file with structured document types, an org chart, custom fields, and change history on the core employment fields.

8 — Complete record: versioned contract and compensation history with effective dates, document templates with e-signature, org structure supporting multiple entities and cost centres, and granular field-level permissions.

10 — The file is the single source of truth an auditor could work from: full effective-dated history on every field, retention rules per document type, delegated administration per entity, and export that reproduces the record intact.

Report an error

The Data Protection Officer

The homepage promises a 'digital employee file' with centralised employee data management, but says nothing about org structure, custom fields, dated change history, or retention per document type. That is the flat-file anchor: the file exists on paper, its depth and its history are unevidenced. 1

Report an error

Payroll handoff

How this is scored

Whether the month closes cleanly into payroll — DATEV, Lohn und Gehalt, an in-house system or an external tax adviser — and how much of that is automated rather than re-typed.

0 — No payroll path stated at all; whatever leaves the system leaves as a spreadsheet somebody retypes.

3 — Generic CSV export said to be usable for payroll, with no named payroll system, no defined format and no handling of mid-month changes.

5 — A named payroll integration or a documented export format for at least one major system (e.g. DATEV LODAS/Lohn und Gehalt), covering the recurring monthly fields.

8 — Certified or vendor-maintained integration with a named payroll provider, covering variable pay, absences and mid-month joiners and leavers, with a documented pre-payroll check.

10 — Payroll is a first-class part of the product: maintained bidirectional integrations with several named systems, an auditable approval and lock step before transmission, retro-accounting for backdated changes, and the tax adviser given their own access.

Report an error

The Data Protection Officer

Payroll runs natively on the same platform — 'from employee setup and time tracking to payroll' — with certification for DEÜV and social-security transmissions, so the month does not leave the system as a re-typed spreadsheet. But nothing documents an approval and lock step, retro-accounting, or access for the external tax adviser, which keeps it below the certified-integration anchor. 1

Report an error

Absence & working-time

How this is scored

Vacation, sickness and working-time recording — including whether the product meets the German recording duty (BAG 2022, ArbZG) rather than merely offering a timer.

0 — No absence or time handling; both live in a spreadsheet elsewhere.

3 — Vacation requests with an approval step, but entitlement is manual, carry-over is not handled and there is no working-time recording.

5 — Automatic entitlement and carry-over, sickness recording, an absence calendar, and basic working-time capture with a report per employee.

8 — Configurable per country and contract: pro-rata entitlement, public-holiday calendars per location, break and rest-period rules, overtime accounts, and an export the employer can hand to a labour inspection.

10 — Working-time recording built as a legal obligation rather than a feature: tamper-evident records, documented compliance with the ArbZG recording duty, works-council-configurable monitoring limits, and shift or on-call models handled without add-ons.

Report an error

The Data Protection Officer

Absence management with self-service and approval workflows plus working-time capture via browser, stopwatch or terminal is claimed 'in compliance with legal requirements', but no evidence of automatic entitlement, carry-over, sickness recording, holiday calendars, or an inspection-ready export. The compliance claim is a slogan; I see no documented ArbZG posture, no tamper-evidence, nothing a works council could examine. 1

Report an error

Recruiting & onboarding

How this is scored

The join path — vacancy to signed contract to a person who has an account, equipment and a plan on day one.

0 — Neither applicant tracking nor onboarding exists; hiring happens in a shared inbox.

3 — A basic applicant list with statuses, or an onboarding checklist — one of the two, without the handover between them.

5 — Applicant tracking with a careers page, structured stages and rejection handling, plus a checklist-driven onboarding that carries the hired candidate over into an employee record without re-entry.

8 — Multi-posting to named job boards, interview scheduling and scorecards, GDPR-conscious applicant retention and deletion, e-signed contracts, and onboarding that triggers tasks in IT and payroll.

10 — The whole join is one governed flow: approval-gated requisitions with budget, structured and bias-conscious evaluation, automated applicant deletion at the stated deadline, and provisioning driven from the record so day one needs no HR intervention.

Report an error

The Data Protection Officer

The evidence says nothing at all about applicant tracking or onboarding, so as far as this evaluation is concerned neither exists. Applicant data is exactly where deletion deadlines get missed, and here I cannot even find the module, let alone an automated deletion date. 1

Report an error

Employee data protection & co-determination

How this is scored

How the product handles the most sensitive personal data a company holds — retention, deletion, role separation, subject rights — and whether it can pass a works council (BetrVG §87) rather than merely a procurement checklist.

0 — No stated retention or deletion handling, no role model beyond admin-or-not, and no DPA offered on the site.

3 — A DPA exists on request and roles are coarse; retention and deletion are described as something the customer arranges themselves.

5 — A signable DPA is published, roles are configurable per module, applicant and employee retention periods are stated, and deletion can be executed rather than only promised.

8 — Field-level access control with an audit log of who read what, configurable retention per data category with automatic deletion, documented subject-rights support, and monitoring or analytics features that can be switched off for co-determination.

10 — Built for the works council to say yes: published processing documentation and subprocessor list, per-entity data separation, tamper-evident audit trail, evaluation and behavioural-analysis features off by default with their scope documented, and a data-protection impact assessment the customer can build on.

Report an error

The Data Protection Officer

The site lists a Privacy Policy and separate Terms for companies and employees, but no DPA is published — that is itself a finding — and nothing states retention periods, executable deletion, a role model, or an audit log of who read what. The certified social-security exchange secures the pipe to the providers, not the most sensitive employee data at rest. 1

Report an error

European sovereignty

How this is scored

Where the data lives, who the contracting entity is, who the subprocessors are, and whether the answer is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as the buyer would weigh it.

0 — US-headquartered vendor, US contracting entity, hosting region unstated or US, subprocessors not named.

3 — EU hosting is offered as an option but the contracting entity is non-EU, or the subprocessor list is incomplete or absent.

5 — EU hosting stated as standard and an EU contracting entity, but the subprocessor chain includes non-EU providers without an explained safeguard.

8 — EU or DACH hosting with a named data-centre provider, an EU contracting entity, the full subprocessor list published, and any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, contracting entity, hosting and every subprocessor in the EU, certification of the data centres published, and an on-premises or private-cloud option for buyers who need it.

Report an error

The Data Protection Officer

The contracting entity is HeavenHR GmbH in Berlin with no US vendor behind it, but the record carries no sovereignty attributes: hosting region unstated and subprocessors not named. An EU imprint does not tell me where the payroll data actually sleeps, and undocumented is not sovereign. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Whether an HR lead can compute the real annual invoice for their headcount — including the modules they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — An entry price per employee exists, but the modules most buyers need are unpriced, or a minimum headcount, setup fee or mandatory onboarding package is not stated publicly.

5 — Per-employee prices are public for the main tiers with the billing period stated, but at least one commonly needed module (payroll, time, recruiting) hides in an unpriced bundle.

8 — Every tier and module priced publicly with per-employee maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.

10 — Complete price computability: a calculator or table that produces the annual invoice for a given headcount and module selection, including setup, minimums and renewal terms.

Report an error

The Data Protection Officer

No price appears anywhere on the page — only the claim of being 'more affordable than comparable HR and payroll solutions' behind a demo gate. The annual invoice is a sales conversation, which is the zero anchor. 1

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (4)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.heavenhr.com Checked 15 Sep 2026 Details →
  2. 2 Payroll handoff — found from sitemap www.heavenhr.com Checked 1 Oct 2026 Details →
  3. 3 Absence & working-time — found from sitemap www.heavenhr.com Checked 1 Oct 2026 Details →
  4. 4 Employee data protection & co-determination — found from sitemap www.heavenhr.com Checked 1 Oct 2026 Details →