Skip to content
Exelsys · Data protection

Ensure GDPR compliance with Exelsys

The General Data Protection Regulation (GDPR) is the European Union’s leading data‑protection law, in force since 25 May 2018. It sets strict standards for how organisations handle personal data and applies to any entity worldwide that offers goods or services to people in the EU or monitors their behaviour.

At a glance

The four things every DPO asks first

Our role under the Terms of Use. You are the Controller, and the data submitted to the service is determined by you.
Processor
Microsoft Azure regions you choose at sign-up, with a geo-redundant copy for recovery.
UK · EU
Where feasible, the latest we notify you after becoming aware of a Personal Data Breach.
72 hrs
Of your data encrypted in transit and at rest, as a standing technical measure.
100%
Roles

A shared responsibility, clearly divided

The GDPR splits duties between the Controller and the Processor. Here is where that line falls under the Exelsys Terms of Use.

You - the Controller

Your organisation determines, in its sole discretion, what personal data is submitted to the service and for what purpose.

Decide what personal data is submitted to the service, and for what purpose
Inform your employees that Exelsys stores and processes their data as your Processor
Respond to Data Subject requests — using the tools built into the service, with our assistance
Set security profiles: password rules and what each user account can access
Report breaches to your supervisory authority (the ICO in the UK) within 72 hours

Exelsys - the Processor

We process Customer Data only for the purposes of the service and according to your instructions.

Process Customer Data only according to your instructions — through the service, or in writing for anything else
Have appropriate technical and organisational security measures in place at all times
Notify you of a Personal Data Breach without undue delay and, where feasible, within 72 hours
Assist you in responding to Data Subject requests
Inform you if, in our opinion, an instruction you give infringes the GDPR
Delete or return all your personal data at the end of the service, as you request

Microsoft Azure - the sub-Processor

Provides the Microsoft Azure PaaS infrastructure services on which Customer Data is processed.

The only sub-Processor of Customer Data
No other sub-Processor is engaged without your prior written authorisation, and you are informed of any addition or replacement
Maintains security certifications for Azure including ISO 27001, SOC 1 & 2 Type 2 and ISO 22301
Data subject rights

Your employees' rights, built into the platform

The four rights an HR system has to serve in practice — each one handled by your own administrators, inside Exelsys.

Access

self-service

Through self-service, each Data Subject can view the personal data maintained about them; administrators can produce a complete record for a subject access request.

Rectification

self-service

Employees keep their own details up to date; administrators correct anything else, with every change recorded in the audit log.

The right to be forgotten

delete or anonymise

Erase a Data Subject’s data completely, or anonymise it — removing any personal identification that could link the data to the person who asked to be forgotten.

Portability

export

Export a Data Subject’s data to an XML file on request — for example when personal data moves from one employer to another.

All four are handled inside the service by your own administrators — no request to Exelsys needed.

Security

Technical and organisational measures

The technical and organisational measures we maintain as your Processor, as set out in the Exelsys Terms of Use.

Infrastructure

Microsoft Azure PaaS

Hosted on Microsoft Azure Platform as a Service, designed to provide 99.95% availability.

Encryption

In transit and at rest

Data in transit is protected with HTTPS, activated by default for all users; content stored at rest is encrypted without any action required from you.

Backup & recovery

Daily, geo-replicated

Encrypted data is backed up daily, going back 30 days, with Active Geo-replication to a readable secondary database in a separate region.

Authentication

Your security profiles

Password complexity and other password attributes are controlled by the security profiles your administrators define. Passwords are hashed by the application.

Access control

Role and sensitivity

Access to functions and data is granted through roles you define, with visibility further restricted by data sensitivity level.

Logging

Who, what, when

Detailed audit logs of every data change and of every data processing operation — the user, the function, the data and the date and time — available to you under Article 30(2).

Testing

Independent, annual

Security audited at least once a year by qualified, independent third-party auditors, including vulnerability and penetration tests by Qualified Security Assessors.

People

Bound and trained

Every employee signs a confidentiality agreement, commits to the Exelsys Information Security Policy and attends relevant training.

FAQs

Questions we hear from DPOs and procurement teams

In Microsoft Azure data centres. When you sign up you choose the primary location — the UK or the Netherlands — and a copy for disaster recovery is held in a second Azure data centre in the EU. Your data stays in the UK and EU.

If Exelsys becomes aware of a Personal Data Breach, we notify you without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The notice describes the nature of the breach — including, where possible, the categories and approximate number of Data Subjects and records concerned — gives you a point of contact, and describes the likely consequences, so you can meet your own duty to notify the ICO or your supervisory authority.

Exelsys uses Microsoft as a sub-Processor of Customer Data, through the Microsoft Azure PaaS infrastructure services. No other sub-Processor is used, and Exelsys will not engage one without your prior written authorisation.

Our data processing agreement is Clause 15 (“Privacy”) of the Exelsys Terms of Use, which are public and linked from the footer of the application. It covers our role as Processor, processing on your instructions, sub-Processors, security measures, breach notification, assistance with Data Subject requests, audits, and the return or deletion of your data.

No. Exelsys processes Customer Data only for the purposes of the service and according to your instructions. Your administrators process data using the functionality of the service; any other processing you require must be requested from Exelsys in writing.

Yes. Under the Terms of Use, Exelsys makes available all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by you or on your behalf.

The Exelsys Privacy Statement and Terms of Use are available from within the platform to any individual with access to the service.

While you are a customer, you control retention: administrators can export Customer Data at any time and delete data that is no longer necessary, such as old job applicants. At the end of the service, Exelsys deletes or returns all your personal data as you request; on a complete deletion instruction, the data is deleted from all Exelsys systems within a maximum of 45 days.

Exelsys backs up the encrypted data daily, going back 30 days using the Azure Point-in-time restore mechanism. In addition, Exelsys uses Active Geo-replication. Using Active Geo-Replication, a separate readable secondary database in a separate region to that of the primary data centre is used and can be switched over in the case a disaster happens in the primary data centre.

Our customers and regulators expect independent verification of security, privacy, and compliance controls. Exelsys does regular vulnerability and penetration tests at least once a year, conducted by companies who are Qualified Security Assessors (QSA).

Data Controller Administrators can export customer data, via the functionality of Exelsys HCM, at any time during the term of the agreement. We have included data export commitments in our data processing terms for several years, and we will continue offering those after the GDPR comes into force, and working to enhance the robustness of the data export capabilities. Data Controller Administrators can also delete customer data, via the functionality of Exelsys HCM Online Service, at any time. When Exelsys receives a complete deletion instruction from a customer who terminates the service, Exelsys will delete the relevant customer data from all its systems within a maximum period of 45 days. Data Controller Administrators have at their disposal several functions allowing them to delete data that is no longer necessary to the company, such as old job applicants.

Exelsys is built to deliver 99.95% service availability with exceptionally fast transaction performance. When subscribing to the service, customers can choose to host their data in a Microsoft Azure Data Centre located either in the UK or the Netherlands. As part of our disaster recovery policy, customer data is also replicated to a secondary Azure Data Centre within the EU, typically in Ireland. If a technical or physical incident affects the primary data centre, the system can seamlessly switch to the backup site, ensuring timely restoration of access and uninterrupted service continuity.

The Exelsys Privacy Statement as well as the Terms of Service are readily available from within the platform and can be viewed by any individual who has a right to access the Exelsys Online Service. The Exelsys Policies have been updated to be GDPR compliant.

Exelsys employees are required to sign a confidentiality agreement and commit to abide by the Exelsys Information Security Policy as well as to attend relevant trainings. The Exelsys Information Security Policy outlines expected behaviour with respect to the protection of information.

Exelsys is based on Windows Azure PaaS, an infrastructure from Microsoft that provides the security, performance, and reliability normally found in only the most sophisticated IT departments. The cloud model allows companies of all shapes and sizes to leverage this infrastructure, which would otherwise be out of reach for most. Azure is a secure, rock solid, open and flexible cloud platform managed by Microsoft. Azure helps us to provide highly secure, available, scalable applications and deliver great SaaS solutions to customers anywhere around the world.

Exelsys’ Terms of Service include a commitment to notify the Data Controller of any data breach within 72 hours, in line with regulatory requirements.

According to the GDPR, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Exelsys operates global infrastructure designed to provide state-of-the-art security through the entire information processing lifecycle. This infrastructure is built to provide secure deployment of services, secure storage of data with end-user privacy safeguards, secure communications between services, secure and private communication, and safe operation by administrators. Exelsys is committed to maintain a high level of security, to meet all GDPR expectations which apply to Data Processors. Exelsys is utilises the Microsoft Azure platform and uses the Azure PaaS model. It therefore takes full advantage of the security features available in Windows Azure Cloud Services. Microsoft has achieved security compliance audit certifications for Windows Azure services from various compliance regulators (ISO 27001, SSAE 16, ISAE 3402, ISO 22301:2012, EU Model Clauses and HIPAA BAA). Exelsys customers can be confident that their data is safely guarded during transmission, storage and processing in the cloud. In addition to the above features and functionality, Azure SQL Database also participates in regular audits and has been certified against a number of compliance standards. For more information, see the Microsoft Azure Trust Center, where you can find the most current list of SQL Database compliance certifications. Exelsys uses encryption to protect data in transit and at rest. Data in transit to Exelsys is protected using HTTPS, which is activated by default for all users. Exelsys HCM encrypts content stored at rest, without any action required from customers, using one or more encryption mechanisms. Exelsys HCM is a multi-tier application where information travels through different layers. With N-Tier architecture, where “n” is any number of distinct tiers that an application is broken into. By deconstructing the main building blocks into tiers, each tier can be separated, distributing the processing load and increasing the security and scalability of the application. Windows Azure runs in geographically-dispersed data centres managed and operated by Microsoft, delivering a 99.95% service-level agreement for high availability. Microsoft operations staff have years of experience in delivering the world's largest online services with 24/7 continuity.

Users access the Exelsys application by providing a user code and password. Password complexity and other password attributes are controlled by the security profile associated with the user account. Each company administrator can create a number of security profiles and associate them with user accounts. Passwords are doubly encrypted, firstly by the application using hash algorithms and then by the SSL/TLS transmission protocol.

Exelsys maintains detailed audit logs of any data changes recording the user, the data changed and the date and time that the change occurred. In addition, Exelsys keeps a detailed log of all the data processing operations, showing the function used to access or process data, the user who executed it and the date and time it occurred.

Exelsys HCM processes data according to the instructions of Data Controller Administrators. Data Controller Administrators execute functions of the system to process data. For any other processing required by the customer (Data Controller) that cannot be done by the Data Controller Administrators using the Exelsys HCM Platform functionality, customers are required to submit clear instructions to Exelsys in writing.

For your DPO

What we can provide for your review

Our data processing terms are public. The rest of a data protection review usually comes down to a handful of documents — ask and we will send the current versions.

Available on request

Data Processing Agreement
Clause 15 of the Exelsys Terms of Use, public and linked from the application footer
Security overview
The technical and organisational measures listed above
Audit and penetration test summary
Latest independent third-party assessment
Azure compliance
Microsoft’s published certifications and GDPR documentation
Privacy statement and terms
Also available inside the platform

Questions about data protection?

We are happy to answer them - and to show you how Exelsys handles personal data in practice.