Data Flow and Storage in Classic Chatbot

What is Classic Chatbot (CC)?

CC is an AI-powered assistant integrated into Simployer Classic HRM. CC helps employees, managers, and HR administrators interact with HR data and company information through natural language. Users can ask questions about their own HR data, request and approve time off, access team insights, explore analytics – all through a conversational interface.

CC is available through the web and mobile interface of Simployer Classic. 

CC connects to the same backend infrastructure and applies identical processing logic, security controls, and privacy safeguards as the Simployer Classic application. CC does not change the categories of personal data processed, the sub-processor chain, or Simployer’s role as data processor.

How does data flow in CC?

When a user interacts with CC, the following sequence takes place:

  1. The user sends a message through CC's interphase.

  2. The user is authenticated and mapped to their Simployer identity. CC determines the user’s role and permissions within the customer’s Simployer Classic tenant.

  3. CC interprets the user’s intent using Simployer's AI engine (Microsoft Azure OpenAI Services or Google Cloud Vertex AI; see the AI infrastructure table below for the current sub-processor list) and retrieves relevant information from the customer’s tenant data.

  4. CC generates a response and returns it to the user through the same channel. If the user requested an action (e.g., a leave request), CC translates this into the appropriate HRM operation.

  5. The response is displayed in CC's interphase. All AI outputs are assistive and require human review or confirmation for actions that modify data.

All processing in steps 2–4 occurs within Simployer’s infrastructure, hosted exclusively in the EU/EEA.

Where is data stored?

CC uses two types of storage within Simployer’s infrastructure:

Storage

What is stored

Location

Simployer HRM database

All customer data processed by CC is stored in the same database as Simployer Classic HRM. This includes any data CC reads or writes as part of HRM operations.

Microsoft Azure and GCP, EU/EEA

Vector database (Qdrant)

Vectorised representations of content used for semantic search. Vectorised data is anonymised and does not contain directly identifiable customer data.

EU/EEA

 

Data is not mixed between customers. Each customer’s data is strictly isolated within their own tenant.

Important: Customer data is not used to train or modify the underlying AI models. User feedback (thumbs up or thumbs down) is collected solely by Simployer for statistical purposes to improve the solution.

AI infrastructure

CC’s AI processing is powered by the following components:

Component

Provider

Purpose

Location

Large Language Model

Microsoft Azure OpenAI Services

Natural language understanding, intent interpretation, response generation

Microsoft Azure, EU/EEA (Microsoft Ireland)

Large Language Model

Google Cloud Vertex AI

Natural language understanding, intent interpretation, response generation

Google Cloud, EU/EEA (Google Ireland Ltd)

Vector database

Qdrant

Semantic search over vectorised content

EU/EEA

Application APIs

Simployer (internal)

Authentication, data retrieval, HRM operations

Microsoft Azure, GCP, EU/EEA

 

The sub-processors for AI inference are Microsoft Ireland (Azure OpenAI) and Google Ireland Ltd (Vertex AI). See the sub-processors page for the complete list.

What personal data does SIA process?

CC can access and process the same categories of personal data available in Simployer Classic HRM, limited by the individual user’s role and permissions. Depending on the customer’s configuration, this may include:

  • Contact information (name, email, phone number)

  • National identification numbers

  • Employment information (position, department, manager, start date)

  • Absence and time management data

  • Financial information (salary data, where applicable)

  • Special categories of personal data (e.g., health-related absence data, where applicable)

CC does not have broader access than the authenticated user. A user can only retrieve information they are already authorised to see in Simployer Classic.

Delivery channel

CC is only available through the web-application channel (a web browser). The user interacts with CC directly within the Simployer Classic interface. All data – including chat history, prompts, and responses – is stored and managed within Simployer’s infrastructure, governed by the Data Processing Agreement between Simployer and the customer.

Security and privacy safeguards

The following safeguards apply to all C interactions:

  • Role-based access control: CC enforces the same role and permission model as Simployer Classic. Users only receive information they are authorised to access.

  • Tenant isolation: Data is strictly isolated between customer tenants. CC cannot access data belonging to other customers.

  • No model training: Customer data is not used to train, fine-tune, or modify the underlying AI models.

  • EU/EEA processing: All AI processing occurs exclusively within the EU/EEA.

  • Encryption in transit: All communication between the end users browser and Simployer’s backend is encrypted using TLS/HTTPS.

  • Assistive AI only: CC does not make autonomous decisions. All outputs are assistive and require human review or confirmation.

  • Audit logging: Interactions with CC are logged for security and compliance purposes.

Related pages

How can we help?

We’re here for every step of your employee journey. From intuitive software for people management to hands-on learning programs and expert support from our legal team — we've got you covered.

Vector Get HR news straight to your inbox

Stay updated on HR, leadership, and work life. Choose between our Norwegian and Swedish newsletters.
Get HR updates

Vector Need a hand? We’re here to help!

Find FAQs, release notes, and more in our Support Center. We're here for you!
Go to support