Heartpace AI logo
Hr Recruiting · Agents Orchestration Frameworks

Heartpace AI

Heartpace AI adds three role-based agents to the Swedish HR platform Heartpace, handling compliance admin, manager preparation and employee questions. Every action is permission-scoped, human-approved, audit-logged and reversible, with AI inference kept inside the EU.

Active GDPR compliant Contact Sales API available 18+ Verified by Guidaio
Overview

What is Heartpace AI?

Heartpace AI is the agent layer of Heartpace, a Swedish HR platform covering core HR management, performance and pay. It is not sold or used on its own: the agents live inside the surfaces customers already have, with no migration and no separate login. Three agents divide the work by role. The HR Admin Agent serves HR teams. It runs equal pay analyses with job-evaluation context, drafts EU Pay Transparency Directive reports and evidence packs, handles and redacts GDPR access requests, triages whistleblowing intake, checks policies against Nordic labour law and orchestrates DORA incident drills. The Manager Coach Agent serves managers. It assembles preparation packs for one-to-one and quarterly Talks, drafts OKRs and sends progress nudges, summarises 360 reviews, recommends salary review ranges grounded in Market Salary Data, detects trends in anonymous surveys under privacy thresholds and flags burnout or disengagement risk early. The Employee Service Agent serves employees, answering questions on policies, leave, vacation and sick-day balances, eSign, onboarding, OKR drafts and one-to-one preparation, and replying in the employee's own language. The governance model is the product's central argument. An agent reads approved Heartpace data within the user's permissions, drafts the work, requests approval and logs the action, and anything it does can be undone. Pay adjustments, performance ratings, terminations and signed reports always require a human decision. Heartpace MCP, a Model Context Protocol layer, exposes a deliberately narrow toolset — employee search, policy retrieval, pay gap scans, Talks preparation, survey summarisation and approval requests — instead of granting agents full system access. Underneath sit the platform modules: HR Management, Performance, Pay Management, and Insights & Reports. Agents reach people through the Heartpace web application, email, Slack and Microsoft Teams, and mobile applications are published for iOS and Android. The publisher, Heartpace AB of Stockholm, claims more than 1,000 customer companies, eleven languages and a place among Sweden's best-rated HR systems, and dates the platform to 2014. Customer data is never used to train cross-customer models, and AI inference is confined to EU regions.

What it does

  • Run equal pay analyses and flag unexplained pay gaps across roles and departments
  • Draft EU Pay Transparency Directive reports together with their supporting evidence packs
  • Handle and redact GDPR data access requests, with the audit trail preserved
  • Prepare manager Talks from goals, OKR status, 360 feedback and survey signals
  • Recommend salary review ranges grounded in market salary data
  • Answer employee policy, leave and onboarding questions in the employee's own language
  • Triage whistleblowing reports with redaction while protecting the reporter's anonymity
Audience

When to use Heartpace AI / When not to

A quick filter to help you decide if Heartpace AI is the right fit.

When to use Heartpace AI

  • HR and people operations teams in the Nordics and the EU preparing for the EU Pay Transparency Directive deadline announced for June 2026
  • Organisations already running Heartpace, since the agents switch on inside existing surfaces with no migration and no second login
  • Compensation and reward specialists who need equal pay analysis, salary review ranges and market salary data in one place
  • Compliance, GRC and risk teams in financial services that must evidence DORA operational resilience and third-party risk inside HR processes
  • Multi-country employers that want AI assistance kept behind role-based access, approval gates and a complete audit trail

When not to use Heartpace AI

  • Companies unwilling to adopt the wider Heartpace platform, because the AI layer is not sold or usable on its own
  • Buyers who need a published price list, since all four packages are quoted individually after a sales conversation
  • Teams looking for fully autonomous automation, as pay changes, ratings, terminations and signed reports always require human sign-off
  • Organisations outside Europe, the product being explicitly built around EU and Nordic labour law, languages and compliance regimes
  • Very small employers with no structured HR processes, for whom a scoped implementation and migration project is disproportionate
Get started

How to use Heartpace AI

A typical end-to-end flow, from setup to results.

  1. Book the 30-minute demonstration offered on the contact page, run on your own data rather than slides
  2. Discuss scope with sales: modules needed, headcount, countries, implementation depth, integrations and support level
  3. Receive a tailored quote, since no package carries a published price
  4. Scope the data import before rollout: employee records, historical Talks, salary data, organisational structure and documents
  5. Connect your Heartpace data, keeping your existing tenancy, EU residency and login
  6. Choose which agents to switch on among Compliance, Coaching and Service
  7. Set the approval gates: what each agent may do alone and what must be reviewed by a human
  8. Keep your own role-based access model, which the agents inherit rather than replace
  9. Let agents work where teams already are: Heartpace web, email, Slack and Microsoft Teams
  10. Monitor the audit log, and stop, undo or take over any agent action at any time
Quick read

Pros & Cons

Pros

  • Governance is explicit and documented: role-based access, human approval gates, audit logging by default and reversible actions
  • Clear commitment that customer data is never used to train cross-customer models
  • AI inference and data residency kept inside the EU, across Stockholm and Frankfurt regions
  • Genuine specialisation in European compliance: EU Pay Transparency Directive, DORA, GDPR and the whistleblowing directive
  • No migration for existing Heartpace customers, since agents are added to surfaces already in use
  • Eighteen named connectors alongside a REST API, webhooks and an MCP tool surface
  • Established publisher: a Swedish company registered in 1999, with named customers and their sectors and headcounts published

Cons

  • No public pricing at all: the four packages are quoted individually, so no budget can be estimated without contacting sales
  • The AI layer cannot be bought alone, which means committing to the wider Heartpace platform
  • ISO 27001 is claimed on both security pages without naming a certification body or a certificate number
  • The claim of eleven supported languages is never enumerated, and the website interface itself serves only six
  • No public API documentation: the API is included in packages rather than openly documented
  • The Terms of service link in the site footer is broken, and the YouTube channel published by the publisher no longer exists
  • Impact figures such as 60% less admin or three times faster salary review cycles are published without method or period
Pricing

Pricing & Plans

Heartpace AI publishes no price. All four packages, Core HR, Performance, Pay & Compliance and Enterprise AI, are quoted individually, and there is no permanent free plan among them. The quote reflects the modules required, the number of employees, the countries covered, the implementation scope, the integrations and the support level, with data import and migration scoped separately before rollout. The publisher justifies this by stating that a tailored quote avoids giving a figure that does not match the customer's actual setup. Prospects are routed to a 30-minute demonstration and then to sales. A public ROI calculator is offered, but it estimates potential savings rather than the price of the product. No free trial is advertised anywhere on the site.

Plan 1
  • Core HR (tailored quote) — employee data
  • workflows and permissions
  • document management
  • eSign and policies
  • onboarding
  • vacation and employee self-service
  • Employee Service Agent
  • GDPR-native setup with EU data residency
Plan 3
  • Pay & Compliance (tailored quote) — everything in Performance
  • plus Salary Review
  • Equal Pay analysis and Salary Analysis
  • Market Salary Data and calibration support
  • EU Pay Transparency reporting and evidence packs
  • HR Admin Agent
  • audit trails
  • approvals and regulator-ready documentation
Plan 4
  • Enterprise AI (custom scope) — everything in Pay & Compliance
  • plus MCP-ready agent tool design
  • custom integrations
  • API and webhooks
  • dedicated implementation and migration support
  • security review
  • DPIA support and custom SLAs
  • multi-country rollout and change enablement
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Heartpace AI handles your data.

GDPR overview

GDPR compliance is claimed explicitly and repeatedly. The security pages describe native flows for data subject access, rectification, erasure and portability, with the HR Admin Agent automating redaction, and state that GDPR erasure cascades into AI memory and audit trails. Data residency is EU by default, across Stockholm and Frankfurt regions, and AI inference stays within EU borders. Heartpace positions itself as processor and says it signs an agreement with every client. Adjacent regimes are addressed too: DORA operational resilience, incident reporting and a third-party risk register, EU Pay Transparency Directive reporting, and whistleblowing intake aligned with the EU directive. No Article 27 representative is designated, which is consistent with a publisher established inside the Union. Privacy enquiries go to privacy@heartpace.com.

Who owns the data?

Customers keep ownership of their HR data. In its GDPR notes Heartpace describes itself as the processor, calling the client the data controller and itself the "Personal Data Adviser", and states that it always signs an agreement with clients governing that relationship. Each tenant is logically isolated, and role-based access is applied before an agent reads sensitive records. A data protection officer is named inside every customer account, under personal settings. Individuals may ask for their personal data to be deleted at any time by writing to privacy@heartpace.com, and the request is handled under applicable data protection law.

Reuse rights

Heartpace states that customer data is never used to train cross-customer models and that AI inference runs in EU regions, with no data leaving the EU for AI processing. Agents may only read what the current user's permissions allow, and every tool call is logged with what was done, why, and which data was read. Separately, the privacy policy confirms that no Google user data, including authentication tokens or email metadata, is used to develop or train any AI or machine learning model. Named sub-processors include AWS and Mandrill (Mailchimp); the full list is supplied on request. Customers are not told they may freely reuse platform data beyond the service itself.

Data retention & training

Retention summary
Personal information is kept for as long as needed to fulfil the purposes set out in the privacy policy, unless a longer period is required or permitted by law. Once the retention period for a given type of data expires, that data is deleted or destroyed. Individuals may request deletion of their personal data at any time by writing to privacy@heartpace.com, and the request is processed under applicable data protection law. GDPR erasure is said to cascade into AI memory and audit trails as well as the records themselves. Where Gmail access has been granted, revoking it immediately deletes the authentication token. No specific retention periods are published in figures, and the privacy policy carries no visible effective or last-updated date.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Data is hosted on Amazon Web Services in EU regions, named as Stockholm and Frankfurt, and the publisher's own security page states that hosting is in Sweden. EU data residency is presented as the default rather than an option, and AI inference is said to run inside EU borders so that no data leaves the Union for AI processing. Each customer tenant is logically isolated. Encryption is claimed in transit and at rest, with HTTPS and TLS between the mobile application, the web application and the servers, and mobile authentication tokens stored in the iOS Keychain and the Android Keystore. Named sub-processors are AWS and Mandrill (Mailchimp); the complete list, along with penetration test summaries and a DPIA template, is offered on request rather than published. The jurisdiction governing the contract is Swedish law. Note that the hosting provider's own certifications belong to that provider and should not be read as certifications of Heartpace.

Hosting countries
🇸🇪 Sweden🇩🇩 Germany
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Heartpace AI.

  • Drafting is not deciding: because the agents produce polished pay reports, salary recommendations and manager talking points, reviewers may approve them with less scrutiny over time, which is exactly the deskilling the approval gate exists to prevent
  • Salary and equal pay recommendations rest on market data and job architecture the tool cannot validate for you; an unexamined suggestion can entrench a bias while looking like an objective analysis
  • Whistleblowing triage handled by an agent touches the most sensitive data an employer holds, and any redaction failure or misrouting carries a real risk to a reporter's anonymity
  • Burnout and disengagement early warnings turn survey and behavioural signals into management alerts, which can drift from support into surveillance if the privacy thresholds are not enforced
  • ISO 27001 is claimed without a named certification body or a certificate number, so the security assurance a buyer thinks they are getting should be verified before it is relied upon
  • The absence of any published price, combined with the AI layer being inseparable from the platform, creates real dependence on the vendor and makes renewal leverage hard to assess in advance
  • Data ownership stays with the customer, but a data protection officer named only inside the account and a sub-processor list supplied only on request mean some accountability details are invisible until you are already a client
Setup

Setup & Integrations

Technical difficulty

Low for existing Heartpace customers: the agents switch on inside surfaces already in use, with no migration and no separate login, and the customer's own role-based access model is inherited rather than rebuilt. The real work is configuration rather than engineering, namely choosing which agents run and setting the approval gates. New customers face a heavier project, since employee data, historical Talks, salary data, organisational structure and documents are scoped and imported before rollout. Optional payroll, SSO, ATS, e-learning, API, webhook and MCP integrations add effort. The Enterprise AI tier includes dedicated implementation, security review, DPIA support and multi-country change enablement.

Deployment

Web appMobile appIOS appAndroid appAPISlack app

Apps stores

Integrations

Microsoft Entra Okta Google Learnster Scrive Oneflow Hogia Agda PS S&P Payroll Payap PE Accounting Twine Teamtailor Jobylon Quinyx Slack Microsoft Teams REST API Webhooks

Supported languages

EnglishSwedishDanishNorwegianDutchGerman
Company

Behind Heartpace AI

Company name
Heartpace AB
Founded
14/09/1999
Country of origin
🇸🇪 Sweden
Headquarters
Malmskillnadsgatan 32, 111 51 Stockholm, Sweden
UBO
Per-Olof Ragnar Söderberg
UBO country
🇸🇪 Sweden
Domain registrar country
🇩🇰 Denmark
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Heartpace AI.

B BambooHRP PersonioH HiBobW WorkdayS SympaS Simployer
FAQ

Frequently asked questions

What does "agentic" actually mean for an HR system?
The agents do more than answer questions: they take real actions inside Heartpace. Each one reads approved data within the user's permissions, drafts the work, asks for approval and writes the action to an audit trail. Every action is reversible, and sensitive decisions stay behind explicit approval gates.
Where is my data stored?
In EU regions, specifically Stockholm and Frankfurt, on Amazon Web Services. The publisher states that AI inference also runs inside EU borders and that data does not leave the Union for AI processing.
Is my data used to train AI models?
No. Heartpace states that customer data is never used to train cross-customer models and that each tenant is logically isolated. Because the commitment is unconditional, no separate opt-out mechanism is described.
Do I have to migrate from my current HR system?
For existing Heartpace customers, no: the agents run inside the platform with no migration and no separate login. New customers go through a scoped import covering employee data, historical Talks, salary data, organisational structure and documents before rollout.
How much does it cost?
No price is published. Each of the four packages is quoted individually, based on the modules required, headcount, countries, implementation scope, integrations and support needs. A public ROI calculator estimates potential savings rather than price.
Which languages do the agents speak?
The publisher claims eleven Nordic and EU languages, but never lists them. What can be verified is the website interface itself, which is served in six: English, Swedish, Danish, Norwegian, Dutch and German.
Is there a mobile application?
Yes. An application called Heartpace HR is published on both the Apple App Store and Google Play, though it belongs to the wider platform rather than to the AI layer specifically.
Is there an API?
Yes. A REST API, webhooks and MCP tools are offered within the packages, and custom integrations sit in the Enterprise AI tier. However, no public API documentation page could be found on the site.
Is there a minimum age to use the service?
Yes. The terms and conditions state that customers must not allow individuals under 18 to use the service.
How does it differ from Sympa, HiBob or Personio?
The publisher argues on native EU Pay Transparency reporting, built-in equal pay analysis, Nordic and EU labour-law fluency, EU data residency and GDPR, DORA and ISO 27001 alignment. Comparison pages are published against BambooHR, Personio, HiBob, Workday, Sympa and Simployer.
Conclusion

Should you pick Heartpace AI?

Heartpace AI is a considered, narrowly scoped product rather than a general assistant bolted onto an HR database. Its argument is governance as much as automation: agents read only what a user's permissions allow, draft rather than decide, request approval, log every tool call and can be undone. Pay changes, ratings, terminations and signed reports are explicitly kept in human hands, and the MCP layer exposes a short, named list of tools instead of open system access. For HR teams facing the EU Pay Transparency Directive, DORA and ordinary GDPR workload, that combination is coherent and unusually well documented. The publisher is not a newcomer. Heartpace AB was registered in Sweden in 1999, the platform is dated to 2014, and named customers are published with their sector and headcount. Data residency in Stockholm and Frankfurt, and the plain statement that customer data never trains cross-customer models, are meaningful commitments for an HR system. Two reservations deserve weight. First, nothing is priced: all four packages are quoted individually, the AI cannot be bought without the wider platform, and a buyer cannot size a budget from the site alone. Second, the ISO 27001 certification is asserted on both security pages without naming a certification body or a certificate number, and no attestation is linked; it should be treated as a claim to verify rather than an established fact. Smaller inconsistencies point the same way: the eleven-language claim is never enumerated while the site serves six, the footer's terms link is broken, and the published YouTube channel no longer exists. The right approach is to take the governance design seriously, ask for the certificate, the sub-processor list and the pen test summaries that the publisher says are available on request, and treat the impact percentages as marketing until they are substantiated.