WebHR

Security, privacy and roles

Roles and permissions, single sign-on and provisioning, sessions and devices, encryption, the audit log, privacy requests and data retention.

Applies to:
WebHR
For:
Admins, IT
Last reviewed:

Who can see and do what

  • Roles & Access (Workspace Settings): each role’s modules and permissions, and overrides for individual users.
  • Managers see only their own teams; HR and admins see the workspace; each employee sees their own record.
  • SSO & Provisioning (Integrations & Security): sign in with your identity provider (SAML), and create and remove users automatically (SCIM).
  • Devices & Sessions: which devices and sessions are signed in, device limits, and ending sessions.

How the data is protected

  • Encrypted in transit (HTTPS only) and, for sensitive fields such as bank and identity numbers, at rest.
  • An audit log records sign-ins, changes and reads of sensitive records; it cannot be edited.
  • Privacy requests (HR Operations → Privacy Requests): employees ask for access, correction or erasure; HR handles them with the statutory records kept.
  • Retention: records past their statutory periods are pseudonymised or removed by the retention job.
  • Our security page, privacy policy, data processing agreement and sub-processors describe our side in full.

Related

Plain-language guidance for HR teams, not legal advice. Checked against the sources above on 29 September 2026; the notification or your authority’s portal is final. Spotted something out of date? Tell us.