Aller au contenu
Vérifié indépendamment · Ré-audit trimestriel
EU VETTED

Factorial

VéRIFIé
RH & personnel · Spain
Founded 2016 · factorialhr.com ↗

Spanish HR + payroll + finance SaaS (Barcelona, est. 2016); 16K+ customers, ISO 27001 + SOC 2 + AWS EU, US-VC-funded.

Pourquoi ce score ?

Factorial (Barcelona ES, founded 2016) is ISO 27001 + SOC 2 Type II certified with AWS EU hosting and 16,000+ customers; cap table includes Tiger Global, CRV, General Catalyst, GGV (all US VCs) plus Atomico (UK) and Creandum (EU) — material US-VC funding flips signal to eu_hq_us_funded and creates CLOUD Act influence.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Factorial

**Factorial** (Barcelona, Spain, founded 2016 by Jordi Romero, Pau Ramon, and Bernat Farrero) is a fast-growing Iberian HR-and-business-management SaaS — 16,000+ customers across HR, payroll, time tracking, talent, finance, and IT modules. Compliance: **ISO 27001 (ENAC), SOC 2 Type II (AICPA)**, AWS EU hosting. The product is genuinely Spanish-built, but the cap table is heavily US: **Tiger Global**, **CRV**, **General Catalyst**, **GGV** lead recent rounds, with Atomico (UK) and Creandum (EU) as European voices. For procurement evaluation Factorial is "Spanish-operating, US-VC-controlled" — similar to Personio's posture.
SUB-PROCESSORS

Carte des sous-traitants · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Référentiels & certifications

ISO/IEC 27001
ACTIVE
SOC 2
ACTIVE
Informational · US framework
FEATURES

Matrice de fonctionnalités

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Tarifs & paliers

PAYANT
à partir de €7/mois
Voir la page tarifs ↗
PUBLIC DOCUMENTS

Documents publics

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives dans cette catégorie