Privacy & Security

Treams adheres to the highest standards in the field of security and privacy. We know how important it is to handle your employees’ information securely.

Trusted by HR teams across the Netherlands

The mid-term reviews, in particular, have become more valuable. A check-in now focuses on actual performance and how you’re getting on. It’s not a review of what happened in the past, but a discussion

Mireille Teekens
Head of HR
iPSiPS
MoneybirdMoneybird
WesselmanWesselman
IlionxIlionx
Van OersVan Oers
The short version

Where we start.

-35%

ISO27001 certified

Audited every year against the ISO/IEC 27001 standard by an external party. The certificate and the statement of applicability are available on request.

-35%

Secure AI

Our AI is trained on our beliefs about performance, so you can trust it is aligned with your vision. It runs inside a European AWS region, it never trains on your data, and it only ever suggests.

-35%

EU data hosting

Your data is stored and processed on Amazon Web Services in Ireland. All sub-processors sit inside the European Economic Area.

The Treams way

Performance data is what people said when they trusted the room.

The details

Forward this section to IT. It is written for them.

Encryption and access

All traffic is encrypted with TLS 1.2 or 1.3. Disk encryption on every machine with access to data or source code. Access runs through AWS IAM on least privilege, tables are separated by workspace, and logs are kept 90 days at most.

Back-ups and availability

A full back-up is created daily, stored encrypted with Amazon Web Services, and kept for seven days. We can test a restore with you on request. We target 99.9% availability.

Testing and environments

An external party runs a penetration test at least once a year, and the results are available on request. Critical components are reviewed as part of development, and functionality is tested in a staging environment holding no personal data.

Incident response

Incidents and threats are logged and analysed, and what we learn goes back into the policy. If a breach affects you, we notify you within 12 hours, with the full picture within 24.

The people behind it

Everyone at Treams takes part in a security awareness programme. Developers are tested on their knowledge and complete a trial assignment before they are hired. Our Security Officer owns the management system, day to day.

Leaving, and finding problems

When the agreement ends, we return your data within 30 days in a structured format, or you retrieve it yourself. Remaining copies and back-ups are destroyed within 90 days. Found a vulnerability? See our responsible disclosure policy.

What our
clients say.

Image placeholder
Treams is a small-scale business and therefore very approachable. You simply ring someone who speaks Dutch, and they’ll even come round in person.
Mireille Teekens
Head of HR
iPS Powerful People
Treams is a small-scale business and therefore very approachable. You simply ring someone who speaks Dutch, and they’ll even come round in person.
Image placeholder
Marlie and Aafke guided us through the onboarding process. It went really well. If there’s anything I need, I just have to send an email and I get a quick reply.
Joyce Vissers
Director
ANB
Marlie and Aafke guided us through the onboarding process. It went really well. If there’s anything I need, I just have to send an email and I get a quick reply.

Ready to see it
for yourself?

HallmarkHallmark
ConsumentenbondConsumentenbond
MoneybirdMoneybird
WesselmanWesselman
Van OersVan Oers

Questions.
Answers.

Feel free to share your questions with Sander, our security officer.

How does Treams handle backups and availability?

We use encrypted backups to support the availability and recoverability of the Treams platform. Backups are made daily and retained for a maximum of 7 days. We also continuously monitor the availability of the platform, so that we can respond promptly to any disruptions.

Where is our data stored and processed?

Treams uses carefully selected subprocessors for, among other things, hosting, storage, support, product features, and payment processing. The subprocessors page describes, for each subprocessor, the purpose for which it is used, what data is processed, where the data is stored, and the applicable retention period.

The primary hosting and processing of data in OnTreams takes place within Europe, including via Amazon Web Services and Microsoft Azure. The current list of subprocessors is available at: https://treams.com/hr-software/security-privacy/subverwerkers/

Is Treams ISO 27001 certified?

Yes. Treams is ISO 27001 certified. This demonstrates that information security is structurally embedded and part of our day-to-day way of working. Our Information Security Management System is actively managed by our Security Officer. We continuously monitor risks, areas for improvement, incidents, and changes relevant to the security of customer and employee data. Upon request, we can share the ISO 27001 certificate and additional security documentation.

How is access to Treams secured?

Treams supports Single Sign-On and two-factor authentication to prevent unwanted access to the system. In addition, Treams works with various roles and authorization levels. This allows a customer to determine which users have access to which parts and data within the platform.

Is customer data used for AI training?

No. Customer data processed via the AI functionality is, according to Treams, not used to train or improve the underlying AI model. The AI functionality is optional, only generates suggestions, and does not make independent decisions. The user remains responsible for reviewing and, if applicable, adopting AI output. Treams uses Anthropic Claude via AWS's Amazon Bedrock, with processing set up within a European AWS region.

Does Treams use AI to write evaluations?

No. Treams uses AI to surface insights and help managers prepare. Not to write evaluation text for them. The conversation stays human. AI supports the manager; it doesn't replace them.