Roles and visibility
The employee, supervisor, payroll and admin each see different things. No one sees more than their role requires.
In Kelomo everyone sees only the data their role entitles them to. Changes leave an auditable trace, integration credentials stay encrypted, and the servers and data stay in Finland.
Structural security
The employee, supervisor, payroll and admin each see different things. No one sees more than their role requires.
Confirmed data is never edited in place. Every correction is recorded as its own event, and the original data is preserved.
Payroll and integration credentials are encrypted and never shown in the interface.
The production environment and the data are in Finland – where the system is also designed, built and maintained.
Sign in with your organisation’s own accounts: Microsoft Entra ID, Google Workspace or another OIDC-compatible identity provider.
An open REST API, webhooks (including Slack and Teams), calendar feeds, and CSV import and export.
To support procurement
All traffic is TLS-encrypted, and the database and its backups are encrypted at rest as well. Each customer’s data is isolated at the database level, and the boundary applies to every query.
The database is backed up automatically and can be restored to a point in time when needed. The production environment is in Finland: the database and the applications in Hetzner’s Helsinki data centre.
In the event of a security incident we notify the customer without undue delay, in line with the GDPR and the data processing agreement. The service level description (SLA) is accepted at onboarding and is available to read during procurement itself.
The lifecycle of personal data is managed to the end: after an employment ends, the data is anonymised in stages by data class, and every stage requires an admin’s sign-off. The statutory working-time records are kept for the retention period even though the person’s identifying details are removed.
A data subject’s access request is answered with a machine-readable export and a PDF summary, and the admin can browse the change history as an audit log in settings. Optional AI features, such as receipt text recognition, are off by default and enabled by a deliberate choice.
We provide a data processing agreement (DPA), an up-to-date sub-processor list and a description of roles and access rights. Ask for the materials and we’ll send them.
Opening in September 2026 · 30 days free from launch, no card required