Heartpace AI
Heartpace AI adds three role-based agents to the Swedish HR platform Heartpace, handling compliance admin, manager preparation and employee questions. Every action is permission-scoped, human-approved, audit-logged and reversible, with AI inference kept inside the EU.
What is Heartpace AI?
Heartpace AI is the agent layer of Heartpace, a Swedish HR platform covering core HR management, performance and pay. It is not sold or used on its own: the agents live inside the surfaces customers already have, with no migration and no separate login. Three agents divide the work by role. The HR Admin Agent serves HR teams. It runs equal pay analyses with job-evaluation context, drafts EU Pay Transparency Directive reports and evidence packs, handles and redacts GDPR access requests, triages whistleblowing intake, checks policies against Nordic labour law and orchestrates DORA incident drills. The Manager Coach Agent serves managers. It assembles preparation packs for one-to-one and quarterly Talks, drafts OKRs and sends progress nudges, summarises 360 reviews, recommends salary review ranges grounded in Market Salary Data, detects trends in anonymous surveys under privacy thresholds and flags burnout or disengagement risk early. The Employee Service Agent serves employees, answering questions on policies, leave, vacation and sick-day balances, eSign, onboarding, OKR drafts and one-to-one preparation, and replying in the employee's own language. The governance model is the product's central argument. An agent reads approved Heartpace data within the user's permissions, drafts the work, requests approval and logs the action, and anything it does can be undone. Pay adjustments, performance ratings, terminations and signed reports always require a human decision. Heartpace MCP, a Model Context Protocol layer, exposes a deliberately narrow toolset — employee search, policy retrieval, pay gap scans, Talks preparation, survey summarisation and approval requests — instead of granting agents full system access. Underneath sit the platform modules: HR Management, Performance, Pay Management, and Insights & Reports. Agents reach people through the Heartpace web application, email, Slack and Microsoft Teams, and mobile applications are published for iOS and Android. The publisher, Heartpace AB of Stockholm, claims more than 1,000 customer companies, eleven languages and a place among Sweden's best-rated HR systems, and dates the platform to 2014. Customer data is never used to train cross-customer models, and AI inference is confined to EU regions.
What it does
- Run equal pay analyses and flag unexplained pay gaps across roles and departments
- Draft EU Pay Transparency Directive reports together with their supporting evidence packs
- Handle and redact GDPR data access requests, with the audit trail preserved
- Prepare manager Talks from goals, OKR status, 360 feedback and survey signals
- Recommend salary review ranges grounded in market salary data
- Answer employee policy, leave and onboarding questions in the employee's own language
- Triage whistleblowing reports with redaction while protecting the reporter's anonymity
When to use Heartpace AI / When not to
A quick filter to help you decide if Heartpace AI is the right fit.
When to use Heartpace AI
- HR and people operations teams in the Nordics and the EU preparing for the EU Pay Transparency Directive deadline announced for June 2026
- Organisations already running Heartpace, since the agents switch on inside existing surfaces with no migration and no second login
- Compensation and reward specialists who need equal pay analysis, salary review ranges and market salary data in one place
- Compliance, GRC and risk teams in financial services that must evidence DORA operational resilience and third-party risk inside HR processes
- Multi-country employers that want AI assistance kept behind role-based access, approval gates and a complete audit trail
When not to use Heartpace AI
- Companies unwilling to adopt the wider Heartpace platform, because the AI layer is not sold or usable on its own
- Buyers who need a published price list, since all four packages are quoted individually after a sales conversation
- Teams looking for fully autonomous automation, as pay changes, ratings, terminations and signed reports always require human sign-off
- Organisations outside Europe, the product being explicitly built around EU and Nordic labour law, languages and compliance regimes
- Very small employers with no structured HR processes, for whom a scoped implementation and migration project is disproportionate
How to use Heartpace AI
A typical end-to-end flow, from setup to results.
- Book the 30-minute demonstration offered on the contact page, run on your own data rather than slides
- Discuss scope with sales: modules needed, headcount, countries, implementation depth, integrations and support level
- Receive a tailored quote, since no package carries a published price
- Scope the data import before rollout: employee records, historical Talks, salary data, organisational structure and documents
- Connect your Heartpace data, keeping your existing tenancy, EU residency and login
- Choose which agents to switch on among Compliance, Coaching and Service
- Set the approval gates: what each agent may do alone and what must be reviewed by a human
- Keep your own role-based access model, which the agents inherit rather than replace
- Let agents work where teams already are: Heartpace web, email, Slack and Microsoft Teams
- Monitor the audit log, and stop, undo or take over any agent action at any time
Pros & Cons
Pros
- Governance is explicit and documented: role-based access, human approval gates, audit logging by default and reversible actions
- Clear commitment that customer data is never used to train cross-customer models
- AI inference and data residency kept inside the EU, across Stockholm and Frankfurt regions
- Genuine specialisation in European compliance: EU Pay Transparency Directive, DORA, GDPR and the whistleblowing directive
- No migration for existing Heartpace customers, since agents are added to surfaces already in use
- Eighteen named connectors alongside a REST API, webhooks and an MCP tool surface
- Established publisher: a Swedish company registered in 1999, with named customers and their sectors and headcounts published
Cons
- No public pricing at all: the four packages are quoted individually, so no budget can be estimated without contacting sales
- The AI layer cannot be bought alone, which means committing to the wider Heartpace platform
- ISO 27001 is claimed on both security pages without naming a certification body or a certificate number
- The claim of eleven supported languages is never enumerated, and the website interface itself serves only six
- No public API documentation: the API is included in packages rather than openly documented
- The Terms of service link in the site footer is broken, and the YouTube channel published by the publisher no longer exists
- Impact figures such as 60% less admin or three times faster salary review cycles are published without method or period
Pricing & Plans
Heartpace AI publishes no price. All four packages, Core HR, Performance, Pay & Compliance and Enterprise AI, are quoted individually, and there is no permanent free plan among them. The quote reflects the modules required, the number of employees, the countries covered, the implementation scope, the integrations and the support level, with data import and migration scoped separately before rollout. The publisher justifies this by stating that a tailored quote avoids giving a figure that does not match the customer's actual setup. Prospects are routed to a 30-minute demonstration and then to sales. A public ROI calculator is offered, but it estimates potential savings rather than the price of the product. No free trial is advertised anywhere on the site.
- Core HR (tailored quote) — employee data
- workflows and permissions
- document management
- eSign and policies
- onboarding
- vacation and employee self-service
- Employee Service Agent
- GDPR-native setup with EU data residency
- Performance (tailored quote
- marked most popular) — everything in Core HR
- plus Talks
- OKR
- 360
- anonymous eNPS
- Pulse and Surveys
- Manager Coach Agent
- Pay & Compliance (tailored quote) — everything in Performance
- plus Salary Review
- Equal Pay analysis and Salary Analysis
- Market Salary Data and calibration support
- EU Pay Transparency reporting and evidence packs
- HR Admin Agent
- audit trails
- approvals and regulator-ready documentation
- Enterprise AI (custom scope) — everything in Pay & Compliance
- plus MCP-ready agent tool design
- custom integrations
- API and webhooks
- dedicated implementation and migration support
- security review
- DPIA support and custom SLAs
- multi-country rollout and change enablement
Data, GDPR & hosting
A consolidated view of how Heartpace AI handles your data.
GDPR overview
GDPR compliance is claimed explicitly and repeatedly. The security pages describe native flows for data subject access, rectification, erasure and portability, with the HR Admin Agent automating redaction, and state that GDPR erasure cascades into AI memory and audit trails. Data residency is EU by default, across Stockholm and Frankfurt regions, and AI inference stays within EU borders. Heartpace positions itself as processor and says it signs an agreement with every client. Adjacent regimes are addressed too: DORA operational resilience, incident reporting and a third-party risk register, EU Pay Transparency Directive reporting, and whistleblowing intake aligned with the EU directive. No Article 27 representative is designated, which is consistent with a publisher established inside the Union. Privacy enquiries go to privacy@heartpace.com.
Who owns the data?
Customers keep ownership of their HR data. In its GDPR notes Heartpace describes itself as the processor, calling the client the data controller and itself the "Personal Data Adviser", and states that it always signs an agreement with clients governing that relationship. Each tenant is logically isolated, and role-based access is applied before an agent reads sensitive records. A data protection officer is named inside every customer account, under personal settings. Individuals may ask for their personal data to be deleted at any time by writing to privacy@heartpace.com, and the request is handled under applicable data protection law.
Reuse rights
Heartpace states that customer data is never used to train cross-customer models and that AI inference runs in EU regions, with no data leaving the EU for AI processing. Agents may only read what the current user's permissions allow, and every tool call is logged with what was done, why, and which data was read. Separately, the privacy policy confirms that no Google user data, including authentication tokens or email metadata, is used to develop or train any AI or machine learning model. Named sub-processors include AWS and Mandrill (Mailchimp); the full list is supplied on request. Customers are not told they may freely reuse platform data beyond the service itself.
Data retention & training
Hosting summary
Data is hosted on Amazon Web Services in EU regions, named as Stockholm and Frankfurt, and the publisher's own security page states that hosting is in Sweden. EU data residency is presented as the default rather than an option, and AI inference is said to run inside EU borders so that no data leaves the Union for AI processing. Each customer tenant is logically isolated. Encryption is claimed in transit and at rest, with HTTPS and TLS between the mobile application, the web application and the servers, and mobile authentication tokens stored in the iOS Keychain and the Android Keystore. Named sub-processors are AWS and Mandrill (Mailchimp); the complete list, along with penetration test summaries and a DPIA template, is offered on request rather than published. The jurisdiction governing the contract is Swedish law. Note that the hosting provider's own certifications belong to that provider and should not be read as certifications of Heartpace.
Things to keep in mind
Risks and trade-offs to weigh before adopting Heartpace AI.
- Drafting is not deciding: because the agents produce polished pay reports, salary recommendations and manager talking points, reviewers may approve them with less scrutiny over time, which is exactly the deskilling the approval gate exists to prevent
- Salary and equal pay recommendations rest on market data and job architecture the tool cannot validate for you; an unexamined suggestion can entrench a bias while looking like an objective analysis
- Whistleblowing triage handled by an agent touches the most sensitive data an employer holds, and any redaction failure or misrouting carries a real risk to a reporter's anonymity
- Burnout and disengagement early warnings turn survey and behavioural signals into management alerts, which can drift from support into surveillance if the privacy thresholds are not enforced
- ISO 27001 is claimed without a named certification body or a certificate number, so the security assurance a buyer thinks they are getting should be verified before it is relied upon
- The absence of any published price, combined with the AI layer being inseparable from the platform, creates real dependence on the vendor and makes renewal leverage hard to assess in advance
- Data ownership stays with the customer, but a data protection officer named only inside the account and a sub-processor list supplied only on request mean some accountability details are invisible until you are already a client
Setup & Integrations
Technical difficulty
Low for existing Heartpace customers: the agents switch on inside surfaces already in use, with no migration and no separate login, and the customer's own role-based access model is inherited rather than rebuilt. The real work is configuration rather than engineering, namely choosing which agents run and setting the approval gates. New customers face a heavier project, since employee data, historical Talks, salary data, organisational structure and documents are scoped and imported before rollout. Optional payroll, SSO, ATS, e-learning, API, webhook and MCP integrations add effort. The Enterprise AI tier includes dedicated implementation, security review, DPIA support and multi-country change enablement.
Deployment
Apps stores
Integrations
Supported languages
Behind Heartpace AI
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Heartpace AI.
Frequently asked questions
What does "agentic" actually mean for an HR system?
Where is my data stored?
Is my data used to train AI models?
Do I have to migrate from my current HR system?
How much does it cost?
Which languages do the agents speak?
Is there a mobile application?
Is there an API?
Is there a minimum age to use the service?
How does it differ from Sympa, HiBob or Personio?
Should you pick Heartpace AI?
Heartpace AI is a considered, narrowly scoped product rather than a general assistant bolted onto an HR database. Its argument is governance as much as automation: agents read only what a user's permissions allow, draft rather than decide, request approval, log every tool call and can be undone. Pay changes, ratings, terminations and signed reports are explicitly kept in human hands, and the MCP layer exposes a short, named list of tools instead of open system access. For HR teams facing the EU Pay Transparency Directive, DORA and ordinary GDPR workload, that combination is coherent and unusually well documented. The publisher is not a newcomer. Heartpace AB was registered in Sweden in 1999, the platform is dated to 2014, and named customers are published with their sector and headcount. Data residency in Stockholm and Frankfurt, and the plain statement that customer data never trains cross-customer models, are meaningful commitments for an HR system. Two reservations deserve weight. First, nothing is priced: all four packages are quoted individually, the AI cannot be bought without the wider platform, and a buyer cannot size a budget from the site alone. Second, the ISO 27001 certification is asserted on both security pages without naming a certification body or a certificate number, and no attestation is linked; it should be treated as a claim to verify rather than an established fact. Smaller inconsistencies point the same way: the eleven-language claim is never enumerated while the site serves six, the footer's terms link is broken, and the published YouTube channel no longer exists. The right approach is to take the governance design seriously, ask for the certificate, the sub-processor list and the pen test summaries that the publisher says are available on request, and treat the impact percentages as marketing until they are substantiated.
- Choosing a selection results in a full page refresh.
- Opens in a new window.