HiBob
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Israeli-founded modern HRIS for mid-market (Tel Aviv + London); 5,000+ customers, heavy US VC, mostly listed for completeness.
HiBob offers EU hosting in the United Kingdom, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under HR & people.
Assessment notes
HiBob is Israeli-headquartered (Tel Aviv) with London as a major secondary office and offices in NYC, Amsterdam, Berlin, Lisbon, Sydney, Zagreb. country_iso set to GB reflects EU-buyer-facing brand but ownership_signal is eu_hq_us_funded due to Israeli HQ + heavy US VC funding (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures); CLOUD Act exposure material. HiBob does publish a sub-processor register, but the DPA is only obtainable through a DocuSign signature flow rather than as readable public text, the group includes the US-incorporated Hi Bob Inc. (New York), and the privacy policy states personal data is stored in the US as well as the EU, UK, Australia, Canada and Israel: non-EU HQ, US-VC-controlled, US data storage, the weakest sovereignty profile in the HR set.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded This listing EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 19 · 17 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About HiBob
HiBob (the "bob" platform) was founded in Tel Aviv in 2015 and operates a significant London office, with additional presence in New York, Amsterdam, Berlin, Lisbon, Sydney, and Zagreb. Targets mid-market (50-2,000 employees) with a modern HRIS UX. Compliance: ISO 27001 + SOC 2 certified. But the sovereignty / procurement story is weak: Israeli HQ + heavy US VC funding (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures) means HiBob is the least "European" entry in this HR set. Listed for completeness and to flag the misperception that "London office" implies "European company". The published register and privacy policy sharpen the picture: personal data is stated to be maintained, processed and stored in the US as well as the EU, UK, Australia, Canada and Israel, the group includes the US-incorporated Hi Bob Inc. (New York), and the register does not say which entity contracts with EU customers. Zendesk Inc. sits in the default sub-processor tier, so support-ticket contents, which in an HRIS routinely carry employee case detail, reach a US-owned processor with no opt-in. A DPA exists but is obtainable only through a DocuSign signature flow rather than as readable public text. For compliance-driven EU procurement HiBob fits the alternative-to-BambooHR slot but with material caveats.
Sub-processor map · 19
-
Amazon Web Services EMEA SARL US
DEFAULT. Cloud computing and storage provider (EU region)
-
Box, Inc. US
DEFAULT for UK payroll. Secure file transfer of payroll data
-
Cloudflare, Inc. US
DEFAULT. Cloud security provider used to scan for and prevent malicious cyber attacks (EU region)
-
Cloudinary Ltd. US
DEFAULT. Image processing for platform uploads (EU region)
-
Descope Technologies US
OPTIONAL. Identity and SSO services (EU region); also DEFAULT for the finance module
-
Freshworks / Freshdesk US
DEFAULT for the finance module. Support
-
Google Cloud / Google Workspace US
OPTIONAL for UK payroll. Payroll calculations
-
Microsoft Azure OpenAI US
OPTIONAL for the finance module. Arc AI analytics
-
Nylas, Inc. US
OPTIONAL. Calendar scheduling API integration (EU region)
-
Okta / Auth0 US
DEFAULT for UK payroll. Identity management
-
OneSignal, Inc. US
OPTIONAL. Mobile app notifications (EU region)
-
OpenAI, L.L.C. US
OPTIONAL. LLM processing and generative AI (EU region); also optional for UK payroll journal entry structuring
-
PlanSource USUnited States
OPTIONAL for US payroll. Benefits administration
-
SingleStore, Inc. US
DEFAULT. Analytics database enabling high-volume analytical queries (EU region)
-
Superblocks US
OPTIONAL for UK payroll. RTI preview
-
Twilio / SendGrid US
DEFAULT for the finance module. Email notifications
-
Zendesk, Inc. US
DEFAULT. Support ticketing system (EU region); in an HRIS this routinely carries employee case detail
-
AccessPay non-USUnited Kingdom
OPTIONAL for UK payroll. BACS payments
-
Forest Admin EUFrance
OPTIONAL for UK payroll. Payslip analysis
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services EMEA SARL | — | DEFAULT. Cloud computing and storage provider (EU region) | US |
| Box, Inc. | — | DEFAULT for UK payroll. Secure file transfer of payroll data | US |
| Cloudflare, Inc. | — | DEFAULT. Cloud security provider used to scan for and prevent malicious cyber attacks (EU region) | US |
| Cloudinary Ltd. | — | DEFAULT. Image processing for platform uploads (EU region) | US |
| Descope Technologies | — | OPTIONAL. Identity and SSO services (EU region); also DEFAULT for the finance module | US |
| Freshworks / Freshdesk | — | DEFAULT for the finance module. Support | US |
| Google Cloud / Google Workspace | — | OPTIONAL for UK payroll. Payroll calculations | US |
| Microsoft Azure OpenAI | — | OPTIONAL for the finance module. Arc AI analytics | US |
| Nylas, Inc. | — | OPTIONAL. Calendar scheduling API integration (EU region) | US |
| Okta / Auth0 | — | DEFAULT for UK payroll. Identity management | US |
| OneSignal, Inc. | — | OPTIONAL. Mobile app notifications (EU region) | US |
| OpenAI, L.L.C. | — | OPTIONAL. LLM processing and generative AI (EU region); also optional for UK payroll journal entry structuring | US |
| PlanSource | United States | OPTIONAL for US payroll. Benefits administration | US |
| SingleStore, Inc. | — | DEFAULT. Analytics database enabling high-volume analytical queries (EU region) | US |
| Superblocks | — | OPTIONAL for UK payroll. RTI preview | US |
| Twilio / SendGrid | — | DEFAULT for the finance module. Email notifications | US |
| Zendesk, Inc. | — | DEFAULT. Support ticketing system (EU region); in an HRIS this routinely carries employee case detail | US |
| AccessPay | United Kingdom | OPTIONAL for UK payroll. BACS payments | non-US |
| Forest Admin | France | OPTIONAL for UK payroll. Payslip analysis | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of HiBob
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Spain · €7/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
-
FranceEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: Yes Open source: No -
-
GermanyEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€7/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
— |
| Personio Germany | EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
— |