Europe Alternatives
Personio logo

Personio

Munich-based HR SaaS for European SMBs with EU-only AWS Frankfurt hosting; German SE & Co. KG with no US parent.

🇩🇪 Germany

Profile last updated: · View sources

Talk to PersonioVisit website

About Personio

Personio is a Munich-based HR SaaS for European SMBs and mid-market employers, founded in June 2015 by Hanno Renner, Arseniy Vershinin, Jonas Rieke and Roman Schumacher. Contracting entity Personio SE & Co. KG (Amtsgericht München HRA 115934, Seidlstr. 3, 80335 München, VAT DE351718597); general partner Personio Group SE (HRB 281581).

Cumulative funding ~724-772M USD across eight rounds, anchored by a Series E first close in Oct 2021 (270M USD at 6.3B USD lead Greenoaks) and a Series E extension in Jun 2022 (200M USD at 8.5B USD, Greenoaks). About 15,000 customer organisations across 80+ countries. After full US-market exit in Oct-Nov 2025 (165 layoffs incl. 47 in New York), the European footprint covers UK, Ireland, Spain and the Netherlands.

Features

  • Personio Core HR + ATS (600+ job boards) + Performance + Compensation + Surveys + Conversations (from the May 2022 Back acquisition)
  • DE Payroll live since 2023 with DATEV integration; EU payroll expansion on roadmap
  • AI Assistant + Conversations Answers run on AWS Bedrock (also EU-region)
  • All customer HR data hosted on AWS Frankfurt (eu-central-1) contracted via AWS EMEA SARL Luxembourg
  • ISO/IEC 27001:2022 + Statement of Applicability + ISO/IEC 27017:2015 + annual third-party pen test + GDPR TOMs
  • Trust Center at trust.personio.com (SafeBase): cert reports, TOM doc, BC/DR plan, security-training overview
  • DNS on AWS Route 53; corporate email on Google Workspace; marketing site www.personio.com fronted by Vercel (Frankfurt fra1 edge)

Sovereignty Scorecard

Procurement-grade signals on data sovereignty, ownership, and EU residency.

The SHIELD framework

We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.

S
Subprocessors

The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.

H
Headquarters & ownership

Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.

I
Infrastructure & residency

Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.

E
Exposure

Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.

L
Legal documents

Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.

D
Diligence

Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.

Ownership

Venture-backed

Minority European

Parent: Personio Group SE (Komplementär) (Germany)

Cumulative funding of approximately 724-772 million USD across eight rounds. Series A Aug 2017 (12 million USD, lead Northzone). Series C Jan 2020 (75 million USD at 500 million USD, lead Accel with Lightspeed). Series D Jan 2021 (125 million USD at 1.7 billion USD unicorn round, lead Index Ventures with Meritech, Accel, Lightspeed, Northzone, Global Founders Capital, Picus). Series E Oct 2021 (270 million USD at 6.3 billion USD, lead Greenoaks Capital). Series E extension Jun 2022 (200 million USD at 8.5 billion USD, lead Greenoaks). Reported undisclosed round Jun 2025 (25.9 million USD per Tracxn; UNCONFIRMED). Cap table is US-investor-heavy: Greenoaks, Index Ventures, Accel, Meritech, Lightspeed, Global Founders Capital, Picus Capital, Eight Roads, KKR. Co-founders Hanno Renner (CEO), Arseniy Vershinin, Jonas Rieke and Roman Schumacher founded the company in Munich in June 2015 (Ignaz Forstmeier is sometimes co-credited in third-party sources).

Headquarters

🇩🇪 Munich, Germany

Personio SE & Co. KG

Subsidiaries
  • Personio Group SE -- UK Establishment 🇬🇧 United KingdomUK overseas-company establishment at Companies House FC037967 (active since 1 January 2020); operating UK address historically Shaftesbury House, 151 Covent Garden, London WC2H 8AL
  • Personio SE & Co. KG -- Netherlands Establishment 🇳🇱 NetherlandsDutch secondary establishment at Van Diemenstraat 298, 1013 CR Amsterdam (KvK 87101416); not a separate Dutch BV
Data residency
DE

Fixed region

All customer HR data is stored on Amazon Web Services in Frankfurt (AWS eu-central-1) per Personio's published Trust Center and the support documentation: "Personio uses Amazon Web Services (AWS) as a hosting provider and stores all customer data on ISO/IEC 27001-certified servers in Frankfurt. The data doesn't leave the EU." The AWS contracting entity is AWS EMEA SARL in Luxembourg. AI features (Personio AI Assistant, Conversations Answers) run on AWS Bedrock, also in an EU region. DNS authority is AWS Route 53; the marketing site (www.personio.com) is served by Vercel from the Frankfurt fra1 edge.

Hosting infrastructure

Website: Vercel (US) -- www.personio.com served from the Frankfurt fra1 edge; HTTP responses return `server: Vercel`, `x-vercel-id: fra1::...`

Application: AWS Frankfurt (eu-central-1) contracted via AWS EMEA SARL (Luxembourg); app.personio.com resolves to AWS edge IPs in 18.245.86.0/24

Email: Google Workspace (US) -- MX records on personio.com return the aspmx.l.google.com cluster

CDN: AWS Route 53 DNS + AWS edge for the application; Vercel edge for the marketing site

Subprocessors
NameCountryPurpose
Amazon Web Services EMEA SARL🇱🇺 LuxembourgPrimary hosting contracting entity for Personio: customer HR data stored on AWS Frankfurt eu-central-1; Standard Contractual Clauses between Personio and AWS Sarl per the AWS sub-processor change log
Amazon Web Services, Inc.🇺🇸 United StatesUpstream cloud provider beneath AWS Sarl; relevant to US CLOUD Act exposure regardless of the EU regional contracting layer
AWS Bedrock🇺🇸 United StatesLLM-hosting service for Personio's AI Assistant + Conversations Answers; per AWS sub-processor change log: "AWS Sarl information has been complemented to cover LLM Hosting/AWS Bedrock"
Google LLC (Google Workspace)🇺🇸 United StatesCorporate email + productivity suite for personio.com; MX records confirm aspmx.l.google.com cluster
Atlassian Corporation AustraliaLikely Jira / Confluence; domain-verification TXT record present on personio.com
Vercel Inc.🇺🇸 United StatesHosts the marketing site www.personio.com (Frankfurt fra1 edge); HTTP headers show `server: Vercel`
Contentful GmbH🇩🇪 GermanyAsset CDN for Personio brochures and whitepapers via assets.ctfassets.net
SafeBase Inc.🇺🇸 United StatesTrust-center platform at trust.personio.com -- the public document index + gated SafeBase access for DPA / cert downloads
Certifications
iso-27001
Certified

ISO/IEC 27001:2022 certification across the Personio HR SaaS platform; certificate + Statement of Applicability listed on trust.personio.com

iso-27017
Certified

ISO/IEC 27017:2015 cloud-security extension on top of ISO/IEC 27001; certificate listed on trust.personio.com

US CLOUD Act exposure
Partial, via US subprocessors
Open source
Closed source

Pricing

Essential

~6 USD / employee / month

annual contract; per-employee, per-month
  • Core HR records, time-off and document management
  • Self-service for employees and managers
  • Standard reports and integrations
Visit website
Professional

~8 USD / employee / month

annual contract
  • Adds applicant tracking (ATS, 600+ job boards), performance, surveys
  • Workflow automation and approval chains
  • Open API + Marketplace integrations
Visit website
Enterprise

~15 USD / employee / month, custom

annual contract
  • Adds compensation management + AI Assistant (AWS Bedrock)
  • SSO/SAML, advanced audit and access controls
  • DE Payroll (DATEV-integrated) + EU payroll roadmap as add-ons
Visit website

Questions & Answers

5 questions

Where is Personio headquartered, and which entity is the contracting party on my MSA?

Personio is headquartered in Munich, Germany. The contracting entity is Personio SE & Co. KG (Amtsgericht München HRA 115934, Seidlstr. 3, 80335 München, VAT DE351718597, LEI 8945001OIB4XWY7NNA54), spun off from the original Personio GmbH on 1 July 2022. The general partner of the KG is Personio Group SE (Amtsgericht München HRB 281581) -- a Societas Europaea since 13 January 2023; the holding has been renamed multiple times since 2014 (Bladebyte UG -> Bladebyte GmbH -> Personio GmbH -> Personio Group GmbH -> Personio Group AG -> Personio Group SE). Vorstand is Hanno F. Renner (CEO and co-founder); chair of the Supervisory Board is co-founder Roman Schumacher. The Dutch entry at Van Diemenstraat 298, Amsterdam (KvK 87101416) is a secondary establishment of the SE & Co. KG, not a separate Dutch BV.

Is Personio subject to the US CLOUD Act?

Exposure is classified as "partial-via-subprocessors". The contracting entity Personio SE & Co. KG is a German SE & Co. KG with no US parent, and customer HR data is physically stored on AWS Frankfurt (eu-central-1) under a contract with AWS EMEA SARL in Luxembourg. The US sales subsidiary Personio Inc. is being wound down following the announced full US-market exit in October-November 2025 (165 layoffs including 47 in New York). However, the upstream parent of the EU-AWS contracting entity (Amazon.com, Inc.) is US-headquartered, so CLOUD Act compulsion theoretically reaches AWS-held customer data even when contracted via Luxembourg. AWS Bedrock (the LLM service powering AI Assistant and Conversations Answers), Google Workspace (corporate email), Vercel (marketing site) and other US-controlled subprocessors (Atlassian is Australia-headquartered but its Jira/Confluence Cloud regions remain US-based for most tenants) are part of the operational stack. There is no US CLOUD-Act-free sovereign posture available.

Where can I find Personio's subprocessor list and DPA?

Personio does not publish a fully public, exhaustive subprocessor list. The authoritative list is delivered inside the customer tenant at Settings -> Account -> Subscription & billing -> Data protection information tab. The DPA is downloadable through the customer's Trust Center session at https://trust.personio.com/ -- the public Trust Center index surfaces the asset names (DPA, AWS Infrastructure Details, ISO/IEC 27001:2022 certificate, Statement of Applicability, ISO/IEC 27017:2015 certificate, pen-test report, BC/DR documentation, GDPR TOMs, security-training overview) but requires a SafeBase access flow to download specific PDFs. A third-party mirror exists via Openli (https://explore.openli.com/privacy/personio/subprocessors). Indirectly confirmed subprocessors include AWS EMEA SARL (Luxembourg) + upstream AWS Inc. (US) + AWS Bedrock for LLM hosting, Google LLC for corporate email, Atlassian, Vercel, Contentful and SafeBase itself.

Which certifications does Personio currently hold, and what is the audit cadence?

The public Trust Center at trust.personio.com lists ISO/IEC 27001:2022 + the corresponding Statement of Applicability, ISO/IEC 27017:2015 (cloud-security extension), GDPR Technical and Organisational Measures (TOMs), an external penetration-test report (Cobalt or equivalent third-party tester), Business Continuity / Disaster Recovery documentation, and an employee-security-training overview. SOC 2 Type II, BSI C5 and TISAX are NOT visible on the public Trust Center index and are flagged UNCONFIRMED for this preview profile -- a Personio sales contact can confirm any non-listed attestation if material to the deal. The ISO/IEC 27001 audit cadence is annual third-party (standard for ISO scheme); penetration testing is also annual.

Has Personio's customer or workforce footprint changed materially in 2025?

Yes. Three significant layoff rounds happened in 2024-2025 (January 2024: about 100 product/engineering roles or ~5%; November 2024: about 115 employees; October-November 2025: 165 jobs including 47 in New York coinciding with full US-market exit). Headcount fell from a 2024 peak of about 2,000-2,300 to about 1,200-1,500 by July 2025. Customer growth continued in parallel: about 3,000 customers in 2021, 12,000+ in 2024 and roughly 15,000 across 80+ countries by 2026. Personio remained profitable in Germany per third-party reporting from Contrary. The US-market exit means new customer acquisition is now restricted to European markets; existing US customers were migrated or off-boarded as part of the 2025 wind-down.

Alternatives

Other European companies in the same category as Personio.

Quick facts

Languages supported
Deutsch
English
Español
Français
Italiano
Nederlands
Categories

Sources & verification

Every fact on this page is backed by a primary or independent source. Most recent verification: May 20, 2026.

Found an error? Report it

Citations

Profile content

Tagline
Pricing
  • tertiary · otherresearch.contrary.com/company/personioPer-employee/month prices are widely-reported Contrary Research estimates; personio.com /pricing returned HTTP 429 to fetcher and is gated for direct verification
Features
Q&A
Languages
  • primary · about-pagewww.personio.comLanguage switcher on the marketing site enumerates the supported product locales

Sovereignty (SHIELD)

SSubprocessors
HHeadquarters
HSubsidiaries
IData residency
IHosting infrastructure
EUS CLOUD Act exposure
LLegal documents
DCertifications