What we touch, and how we handle it.

We operate inside your HR systems and see your employees’ data. Here is the plain-language version of how we treat it — access, tooling, retention, and where we draw the line on AI.

Our posture

Four commitments the rest of this page just makes specific.

Data-handling schedule — Part 1 · Posture
  1. Least access, by default

    We take the narrowest access that does the job — scoped to named people, and removed when an engagement or a team member ends.

  2. Your data stays in your systems

    We operate inside the HRIS you own. Your employee records are not copied into a People Street database to run our service.

  3. Never sold, never trained on

    Your data is never sold, never shared beyond the subprocessors that run your own systems, and never used to train a public AI model.

  4. A hard line on AI

    We use AI throughout our own work. Where your data is involved it goes into enterprise tools configured not to train on it, never a consumer one — the specifics are below.

How access works

The narrowest key that opens the right door.

Data-handling schedule — Part 2 · Access
  1. Named, not shared

    Access is tied to specific People Street people. No shared logins, no generic service accounts standing in for a person.

  2. Least privilege

    Each person gets the role the task needs and no more. Admin rights only where the work genuinely requires them.

  3. Multi-factor everywhere

    Every system that touches your data sits behind multi-factor authentication and a managed password vault.

  4. Removed on exit

    When an engagement ends or someone rolls off, revoking their access is on the offboarding checklist we run for our own team.

What touches your data

Your systems, plus the shortest list on top.

Your data lives in the platforms you’ve licensed. We add as few tools as possible on top, and name every one of them in your agreement.

Data-handling schedule — Part 3 · Systems
  1. HR & payroll platforms

    Rippling, HiBob, ADP Workforce Now, Dayforce and Workday — the system of record you’ve licensed and asked us to operate.

  2. Recruiting systems

    Ashby, Gem and Greenhouse, where we run embedded recruiting into your HRIS.

  3. Our own tooling

    A password manager, a ticketing desk, and productivity tools — kept to the shortest list that does the job.

A current subprocessor list and a data processing agreement come with onboarding. Ask for them any time.

How we use AI

Everywhere in our work. Never into a model that trains on your people.

We’re the firm that turns AI on safely — starting with ourselves. Here is exactly where the line sits.

Data-handling schedule — Part 4 · AI

What we will not do

  • Knowingly submit your confidential or personal data to any AI tool that trains third-party models on it
  • Use consumer AI tools where your people’s data is involved
  • Move your records out of the systems you own in order to process them

How we use it

  • Throughout the work, without limitation — research, analysis, drafting, document review, process automation
  • On enterprise or comparably configured tools wherever your data is processed
  • With responsibility for the work ours, regardless of the tools used
  • To configure the AI inside your platform against this same line
Questions

What teams ask before they hand this over.

Do you store our employee data on People Street systems?

No. We operate inside the platforms you license. Your records stay in your system of record; we don’t replicate them into a database of our own to run the service. Where a task needs an export, it’s minimal, time-bound, and deleted when the task is done.

Do you use our data to train AI?

Never. Your data is not used to train any model, ours or a third party’s. We use AI throughout our own work, and where your data is involved we use enterprise tools configured so that what goes in is not used for training.

Who can see our data, and how is that controlled?

Named people on your engagement, each with the least access the work requires, behind multi-factor authentication. No shared logins. When someone rolls off or the engagement ends, revoking their access is part of the offboarding checklist we run for our own team.

Can we get a subprocessor list and a DPA?

Yes. We’ll share the current list of the systems that touch your data and sign a data processing agreement as part of onboarding. Both are named in your agreement rather than described on a call.

What happens to our data if we leave?

You keep everything — it was always in your systems. We hand over documentation and runbooks written as the work happened, transfer to a named internal owner, and remove our access on a schedule you can see.

Still have a question

A security question we didn’t cover?

Ask it directly. We’ll answer in plain language, share the documents, and tell you where the line is — before you’ve signed anything.