Zum Inhalt springen
Unabhängig verifiziert · Quartalsweises Re-Audit
EU VETTED

Personio

VERIFIZIERT
HR & Personalwesen · Germany
Founded 2015 · personio.com ↗

Munich-based HR flagship for European SMBs (founded 2015); ISO 27001 + SOC 2 + TISAX; ~$770M US-VC-funded.

Warum diese Bewertung?

Personio (Munich DE, founded 2015) is the European HR flagship — ISO 27001 + SOC 2 + TISAX, AWS Frankfurt hosting, ~14K customers — but $770M+ raised across 8 rounds led by Lightspeed Venture Partners (US), Index Ventures (US/UK), Accel (US), Greenoaks (US), giving US VCs durable control and CLOUD Act-relevant influence; ownership signal eu_hq_us_funded.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Personio

**Personio** (Munich, Germany, founded 2015) is the most-funded European HR-tech company — $770M+ across 8 rounds — and serves ~14,000 European SMBs (10-2,000 employees) with payroll, recruiting, time tracking, and people management. The compliance posture is strong: **ISO 27001 + SOC 2 + TISAX**, AWS Frankfurt hosting, EU-only data residency. The ownership-side caveat is straightforward: cap table is **US-VC-dominated** — Lightspeed Venture Partners (US) led Series C, with Index (UK/US), Accel (US), Greenoaks (US), and Lakestar (CH) all on the books. For DACH compliance buyers this is the canonical "German HR vendor, US capital" trade-off.
SUB-PROCESSORS

Unterauftragsverarbeiter-Karte · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Rahmenwerke & Zertifizierungen

ISO/IEC 27001
ACTIVE
SOC 2
ACTIVE
Informational · US framework
FEATURES

Funktionsmatrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Preise & Tarife

KOSTENPFLICHTIG
Individuelle Preise

Kontaktieren Sie den Anbieter für Staffel- oder Mengenpreise.

Preisseite ansehen ↗
PUBLIC DOCUMENTS

Öffentliche Dokumente

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternativen in dieser Kategorie