whats-best.ai
Search Sign in

HR Management

rexx systems

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by rexx systems GmbH · www.rexx-systems.com

Compare with Haufe Talent → Compare with HRworks → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Answers for the most sensitive personal data the company holds, about people who cannot decline the processing. Wants retention that executes rather than promises, a published subprocessor list, and applicant data that deletes itself on the stated date. Treats an unpublished DPA as a finding.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Digital personnel file & data model

How this is scored

The system of record: employee master data, the digital personnel file, org structure, custom fields, and whether history is kept rather than overwritten.

0 — A contact list with job titles; no document storage, no org structure, no history — changes overwrite what was there.

3 — Employee records with document upload, but a flat structure: no org chart, few or no custom fields, and no dated history of contract or salary changes.

5 — Digital personnel file with structured document types, an org chart, custom fields, and change history on the core employment fields.

8 — Complete record: versioned contract and compensation history with effective dates, document templates with e-signature, org structure supporting multiple entities and cost centres, and granular field-level permissions.

10 — The file is the single source of truth an auditor could work from: full effective-dated history on every field, retention rules per document type, delegated administration per entity, and export that reproduces the record intact.

Report an error

The Data Protection Officer

The digital personnel file is substantial: complete historization and revision-safe archiving, salary development and cost-centre data held in the record, personnel documents generated straight into the e-file, batch scanning of paper files, and organisational management that covers subsidiaries. What I could not find on the captured pages is field-level permission control, effective-dated contract and compensation versions, and retention rules per document type — the difference between a good file and one an auditor can defend. 5 2 1

Report an error

Payroll handoff

How this is scored

Whether the month closes cleanly into payroll — DATEV, Lohn und Gehalt, an in-house system or an external tax adviser — and how much of that is automated rather than re-typed.

0 — No payroll path stated at all; whatever leaves the system leaves as a spreadsheet somebody retypes.

3 — Generic CSV export said to be usable for payroll, with no named payroll system, no defined format and no handling of mid-month changes.

5 — A named payroll integration or a documented export format for at least one major system (e.g. DATEV LODAS/Lohn und Gehalt), covering the recurring monthly fields.

8 — Certified or vendor-maintained integration with a named payroll provider, covering variable pay, absences and mid-month joiners and leavers, with a documented pre-payroll check.

10 — Payroll is a first-class part of the product: maintained bidirectional integrations with several named systems, an auditable approval and lock step before transmission, retro-accounting for backdated changes, and the tax adviser given their own access.

Report an error

The Data Protection Officer

This handoff is built as a partnership: official DATEV interface partner status covering Lohn und Gehalt and LODAS, bidirectional transfer of master data, variable pay and absences with change-based delta synchronisation, payslips and tax certificates returned monthly into employee self-service, and further named connections to ADP, Paisy and SAP HR. We found no public information on a documented pre-payroll check, retro-accounting for backdated changes, or an approval and lock step before transmission. 6 7 1

Report an error

Absence & working-time

How this is scored

Vacation, sickness and working-time recording — including whether the product meets the German recording duty (BAG 2022, ArbZG) rather than merely offering a timer.

0 — No absence or time handling; both live in a spreadsheet elsewhere.

3 — Vacation requests with an approval step, but entitlement is manual, carry-over is not handled and there is no working-time recording.

5 — Automatic entitlement and carry-over, sickness recording, an absence calendar, and basic working-time capture with a report per employee.

8 — Configurable per country and contract: pro-rata entitlement, public-holiday calendars per location, break and rest-period rules, overtime accounts, and an export the employer can hand to a labour inspection.

10 — Working-time recording built as a legal obligation rather than a feature: tamper-evident records, documented compliance with the ArbZG recording duty, works-council-configurable monitoring limits, and shift or on-call models handled without add-ons.

Report an error

The Data Protection Officer

Working-time capture is real and multi-channel — browser, app, terminals with QR code or NFC, multiple time accounts, shift and overtime models, pro-rata entitlement on mid-year joiners and leavers, electronic sick certificates imported and matched to absence bookings, and a complete online history of every booking. For the German recording duty the captured pages stop short of the specific answers I look for: we found no public information on public-holiday calendars per location, break and rest-period rules, or works-council-configurable monitoring limits. 8 9 7

Report an error

Recruiting & onboarding

How this is scored

The join path — vacancy to signed contract to a person who has an account, equipment and a plan on day one.

0 — Neither applicant tracking nor onboarding exists; hiring happens in a shared inbox.

3 — A basic applicant list with statuses, or an onboarding checklist — one of the two, without the handover between them.

5 — Applicant tracking with a careers page, structured stages and rejection handling, plus a checklist-driven onboarding that carries the hired candidate over into an employee record without re-entry.

8 — Multi-posting to named job boards, interview scheduling and scorecards, GDPR-conscious applicant retention and deletion, e-signed contracts, and onboarding that triggers tasks in IT and payroll.

10 — The whole join is one governed flow: approval-gated requisitions with budget, structured and bias-conscious evaluation, automated applicant deletion at the stated deadline, and provisioning driven from the record so day one needs no HR intervention.

Report an error

The Data Protection Officer

The join path runs end to end: multiposting to named boards including finest-jobs.com and the Bundesagentur, scorecards plus video and WhatsApp channels, digitally signed contracts with automated rejections, and applicant data flowing into an onboarding module that assigns tasks, timelines and equipment without re-entry. The six-month applicant deletion deadline with consent-based extension appears in the vendor's own privacy policy for its own hiring; we found no public information on automated applicant deletion at a configurable deadline inside the product. 10 11 4

Report an error

Employee data protection & co-determination

How this is scored

How the product handles the most sensitive personal data a company holds — retention, deletion, role separation, subject rights — and whether it can pass a works council (BetrVG §87) rather than merely a procurement checklist.

0 — No stated retention or deletion handling, no role model beyond admin-or-not, and no DPA offered on the site.

3 — A DPA exists on request and roles are coarse; retention and deletion are described as something the customer arranges themselves.

5 — A signable DPA is published, roles are configurable per module, applicant and employee retention periods are stated, and deletion can be executed rather than only promised.

8 — Field-level access control with an audit log of who read what, configurable retention per data category with automatic deletion, documented subject-rights support, and monitoring or analytics features that can be switched off for co-determination.

10 — Built for the works council to say yes: published processing documentation and subprocessor list, per-entity data separation, tamper-evident audit trail, evaluation and behavioural-analysis features off by default with their scope documented, and a data-protection impact assessment the customer can build on.

Report an error

The Data Protection Officer

Here I must record findings: we found no public information on a signable data processing agreement, no published subprocessor list for the product, and no evidence that employee-data retention or deletion executes on defined dates rather than ending as revision-safe archiving the customer administers. Encryption, role rights and an audit trail are named, operations are ISO 27001:2022-certified in German and Swiss data centres, and the privacy policy does state automatic deletion for website analytics — but for the most sensitive data about people who cannot decline the processing, that is thin. 4 5 8

Report an error

European sovereignty

How this is scored

Where the data lives, who the contracting entity is, who the subprocessors are, and whether the answer is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as the buyer would weigh it.

0 — US-headquartered vendor, US contracting entity, hosting region unstated or US, subprocessors not named.

3 — EU hosting is offered as an option but the contracting entity is non-EU, or the subprocessor list is incomplete or absent.

5 — EU hosting stated as standard and an EU contracting entity, but the subprocessor chain includes non-EU providers without an explained safeguard.

8 — EU or DACH hosting with a named data-centre provider, an EU contracting entity, the full subprocessor list published, and any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, contracting entity, hosting and every subprocessor in the EU, certification of the data centres published, and an on-premises or private-cloud option for buyers who need it.

Report an error

The Data Protection Officer

The foundations are European: a Hamburg contracting entity with a German register number, hosting in the vendor's own cloud on German and Swiss servers in ISO-certified data centres, and a genuine on-premises option. The chain is where it weakens — the data-centre provider behind the own cloud is not named, we found no public information on product subprocessors or on the vendor's ownership, and the imprint lists Austrian and Swiss sister entities without stating which of them signs customer contracts. 3 2 8 1

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Whether an HR lead can compute the real annual invoice for their headcount — including the modules they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — An entry price per employee exists, but the modules most buyers need are unpriced, or a minimum headcount, setup fee or mandatory onboarding package is not stated publicly.

5 — Per-employee prices are public for the main tiers with the billing period stated, but at least one commonly needed module (payroll, time, recruiting) hides in an unpriced bundle.

8 — Every tier and module priced publicly with per-employee maths, billing period, minimum term and VAT treatment stated; only genuinely custom enterprise work lacks a number.

10 — Complete price computability: a calculator or table that produces the annual invoice for a given headcount and module selection, including setup, minimums and renewal terms.

Report an error

The Data Protection Officer

The pricing page states the software is calculated "individuell und nachvollziehbar" with no standard packages, and even the preconfigured entry package for smaller companies — 32 consulting hours and eight training hours — carries no figure. No per-employee price appears on the captured pages; an HR lead cannot compute one euro of the annual invoice from public information. 2

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (11)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.rexx-systems.com Checked 15 Sep 2026 Details →
  2. 2 Pricing www.rexx-systems.com Checked 15 Sep 2026 Details →
  3. 3 Imprint www.rexx-systems.com Checked 15 Sep 2026 Details →
  4. 4 Privacy policy www.rexx-systems.com Checked 15 Sep 2026 Details →
  5. 5 Digital personnel file & data model — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  6. 6 Payroll handoff — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  7. 7 Payroll handoff — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  8. 8 Absence & working-time — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  9. 9 Absence & working-time — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  10. 10 Recruiting & onboarding — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →
  11. 11 Recruiting & onboarding — found from sitemap www.rexx-systems.com Checked 1 Oct 2026 Details →