Security
Treeline holds names, job titles, reporting lines and photographs. That is personal data about people who never chose us, and most of them will never log in. This page is what we can tell you about how it is held, written so your IT lead or data protection officer can hold us to it.
Last updated 13 August 2026
Your data is hosted in the United Kingdom, on DigitalOcean's London region. The only routine copy held elsewhere is an encrypted offsite backup in the European Union. That is covered by the UK adequacy regulations, so no additional transfer safeguard is needed, and nothing moves beyond the UK or EEA without your written instruction.
You are the data controller. We are your processor, and we act only on your documented instructions. Our data processing agreement sets this out in the standard form your legal team will expect, and you can have it before you upload anything.
Permissions are role-based, and a published directory is a read-only view with no admin surface attached to it. On the plans that include it, access is scoped per company and per division, so a subsidiary's HR lead sees their own people and nobody either side of them.
From the Starter plan up, each change is written to an audit log with the person who made it, what they changed, when, and the address they made it from. The product provides no way to alter or remove that record - there is no edit and no delete.
People sign in with a password, and can add a second factor - either an authenticator app or a one-time code by email. That is available on every plan. Most of the people in your directory will never have an account at all: they are there because you uploaded them.
Backed up daily and kept for at least 30 days, with weekly copies held for 12 weeks and monthly copies for 12 months. An encrypted offsite copy is held in the EU with 12 months' retention. We restore production into a development environment regularly, so the backups are known to work rather than assumed to.
You can export everything in an open format, whenever you like, on any plan including the free one. It is what you uploaded plus what you built on top of it, and there is no proprietary file you would need us to open. If you leave, your structure leaves with you.
A short list, deliberately. Every company below is bound by written terms that impose the same obligations we owe you, and we stay responsible to you for what they do. We will give you at least 30 days' notice before adding or replacing any of them, and if you object on data protection grounds you can leave without penalty.
What we do not claim
Those are a different order of cost and we have not spent it yet. What you get instead is this page, our data processing agreement, and specific answers to specific questions - ask anything not covered here and you will get a straight answer rather than a badge. If your procurement process requires one of them by name, say so early rather than late.
We do not control the infrastructure underneath us, and passing through a number we cannot honour would be worse than not offering one. If uptime commitments are a hard requirement for you, say so early and we will tell you honestly whether we can meet them.
We restore production into development regularly, and that is how we know the backups work. We do not currently keep a signed record of each test. If you need evidenced restore testing, tell us and we will start recording it rather than claim we already do.
Send the question, or send your DPO's checklist and we will work through it. We would rather answer twenty awkward questions before you upload a staff list than one after.