Custom HR Office integration development
Appfront builds bespoke HR Office integrations that connect your HR administration with payroll, ATS, accounting, SSO and onboarding. Using the HR API and webhooks, we synchronise employee changes, leave, sickness absence and terms of employment in both directions, with an audit trail, conflict resolution and GDPR-compliant data minimisation. Your HR team enters a change once, and all connected systems stay accurate.
What is an HR Office integration?
HR Office is a Dutch HRIS (HR Information System) that organisations use for personnel administration, recording leave and sickness absence, basic salary data, onboarding and offboarding, and performance reviews. For most small and medium-sized businesses, HR Office is the source of truth for who is employed, on what terms and in what role, but it is rarely the only system that deals with those employees.
In practice, a custom integration means new employees flow automatically from HR Office to your payroll provider, receive an account in Microsoft Entra or Okta, are enrolled in your onboarding platform and appear in your accounts as a payroll cost. Changes (salary increases, contract amendments, leavers) flow in both directions, and HR Office remains the central source for who may do what and who earns what.
Appfront builds these integrations on a GDPR-first principle: only the fields each target system needs, documented purpose limitation, an audit trail for every change to personal data, and clear agreements on the source of truth. See also our wider approach to API integrations and our integration services.
One source of truth for your employees
HR Office leads for personal and contract data. Changes made there flow, verified, to payroll, IAM, ATS and accounting, with no duplicate entry and no drift between systems.
Leave and absence synchronised
Leave requests, sickness notifications and return-to-work milestones sync with time recording, payroll and workforce planning. No more standalone spreadsheet trackers or manual handovers.
GDPR with an audit trail
Every movement of personal data between systems is logged: what was sent, where to, why (purpose limitation) and who changed it. In the event of a data breach or a request from the Dutch Data Protection Authority, your processing register is watertight.
Our development process for HR Office integrations
We work to a method that puts the most sensitive decisions first: which system is the source of truth for each field, which data may and may not flow through, and who can see what. From that analysis through to go-live and ongoing management, every step aims for an integration your HR team can understand themselves and that will not alarm the Dutch Data Protection Authority.
We map which employee fields live in which system, establish the source of truth for each field, and determine which data may or may not be synchronised for GDPR reasons.
We design the event flows, choose between real-time and batch processing, record the purpose limitation for each field and define a retry and error-handling strategy.
Implementation with idempotency keys, structured logging, audit trail and monitoring. You see working integrations per target system along the way.
Controlled go-live for each integration with data validation and safeguards, followed by ongoing management, monitoring and proactive further development.
What an HR Office integration concretely delivers
Every HR Office integration is set up specifically for your connected systems, payroll vendor, ATS and the way your organisation handles onboarding and offboarding. Below are the functionalities we most often deliver for organisations that use HR Office as their central HRIS.
HR Office to payroll
Integration with NMBRS, Visma-Loon, ADP or Loket: basic salary data, contract changes, absence records and cost centre allocations flow automatically into payroll. No more spreadsheet exchanges at every month-end close.
HR Office to ATS
Seamless transition from Recruitee, Homerun or BambooHR to HR Office upon hire: candidate data, contract type, start date and cost centre are transferred once. Hire events trigger the rest of the chain: payroll record, email account, onboarding.
SSO and account provisioning
When someone joins, HR Office automatically triggers an account in Microsoft Entra or Okta with the right groups, licences and application rights based on their role. When someone leaves, the account is deactivated within minutes, so no forgotten accounts.
Onboarding flows
A new employee in HR Office automatically starts an onboarding journey in Appical or a dedicated onboarding app: welcome emails, tasks for the manager and IT, forms for identity verification and a first-day checklist, all triggered by a single hire event.
Accounting integration
Payroll costs, holiday pay provisions, cost centre allocations and pension contributions flow from HR Office (or the payroll layer) into Exact, Twinfield or AFAS. Month-end closes become predictable and the finance team stops adding up figures by hand.
Time registration and workforce
Hours from Mtime, Uren.nl or a custom tool are reconciled with contracted hours in HR Office; leave balances sync with workforce planning in Quinyx or Ortec. Manager dashboards show in real time who is working where, under which contract and with which balance.
Typical use cases in practice
An HR Office integration looks quite different from one organisation to the next. We see a few patterns recur often, and for each we have a working setup with attention to field mapping, GDPR purpose limitation and proper retry and error handling.
SMEs with a growing payroll administration
Organisations that have grown beyond 50 employees and can no longer cope with spreadsheet exchanges between HR and payroll. Salary changes, contract amendments and absence notifications flow automatically from HR Office to NMBRS, Visma-Loon or Loket, with no monthly handover. See also our API integrations.
Recruitment-to-payroll chain
Companies with their own ATS, often Homerun, Recruitee or a bespoke recruitment platform, who want to automate the move from candidate to employee. On hire, data flows from the ATS to HR Office and from there to payroll, SSO and onboarding, without duplicate entry or forgotten accounts.
Healthcare and municipal organisations
Sectors with strict GDPR requirements around absence, reintegration and special category personal data. We build integrations that document purpose limitation per field, send only the necessary data between systems and deliver an auditable processing register, in line with Dutch Data Protection Authority requirements.
Multi-location organisations
Businesses with several branches, varying rostering locations and collective labour agreement (CAO) rules. HR Office consolidates personnel administration centrally; integrations ensure workforce management, time registration and payroll apply the correct rules per location and CAO.
Technology we use
We build HR Office integrations via the REST API and webhooks of your HRIS, combined with the backend stack that suits you. The precise choice depends on your payroll vendor, ATS and IAM provider, so that your own team can manage or further develop the integrations.
If you want to record, per employee, which information about working conditions has been provided, see our page on the duty to inform about employment conditions.
If you use Buddee instead of this package, see our page on a Buddee integration.
Why choose Appfront for your HR Office integration?
Appfront has extensive experience building HRIS and payroll integrations for SMEs in the Netherlands. We always begin with a thorough analysis of your existing systems, processes and GDPR implications. An HR integration must not only work technically, but also be legally sound and genuinely valuable to the business.
For less critical scenarios we often recommend an iPaaS solution such as Zapier or Make. However, once the GDPR risk becomes high, the volume is large, or the logic is complex (multiple systems, conflict resolution, audit requirements), iPaaS falls short. That is when we build custom middleware that follows your situation rather than the other way round.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.
See also our broader services in API integrations, middleware, custom software and the wider integration page.
- Experience with HRIS integrations and payroll providers in the Netherlands
- Specialist in event-driven sync (hire, mutate, terminate)
- Experienced in source-of-truth mapping per field
- GDPR-first design: purpose limitation, data minimisation, audit trail
- Secure by default: API key rotation, webhook signature validation
- Idempotency, retry and dead-letter queues from day one
- Honest advice: iPaaS where it works, custom build where it's needed
- A fixed point of contact, no account managers passed around
- Ongoing maintenance and proactive further development
- A way of working aligned with your existing IT landscape
Security and privacy in HR Office integrations
HR data is among the most sensitive personal data within an organisation. Salary information, sickness absence, reintegration reports and contract details partly fall under the category of special category personal data. Appfront builds every HR integration according to the OWASP ASVS standard and a GDPR-first principle. This means, among other things: API keys stored in secure vaults, webhook signature validation, scoped OAuth permissions and regular audits of data flows.
For every field that travels between two systems, we document the purpose limitation: why this data may move from A to B, on what legal basis, and how long it is retained. The resulting audit trail serves as evidence for your record of processing activities and helps you answer any questions from the Dutch Data Protection Authority or respond to a data breach.
More on our security approach: information security policy and CVD policy.
- GDPR-compliant data processing and data minimisation per field
- Purpose limitation documented per integration direction
- Encryption in transit (TLS 1.2+) and at rest
- Role-based access and least-privilege principles
- Audit logs with traceable PII mutations
- Automatic retries and dead-letter queues
- Monitoring and alerting for anomalies
- Secrets management in line with best practice
- Documentation for your record of processing activities
Frequently asked questions about HR Office integrations
Answers to the questions we are asked most often about HR Office integrations.
We regularly integrate HR Office with payroll providers such as NMBRS, Visma-Loon, Loket and ADP; with ATS platforms such as Recruitee, Homerun and BambooHR; with SSO/IAM solutions such as Microsoft Entra and Okta; with accounting packages such as Exact, Twinfield and AFAS; and with onboarding, workforce and time-registration tools. Which system sits on the other side mainly determines how much custom work the middleware layer needs. The approach and the GDPR foundation stay the same.
That depends on the type of event and how sensitive the data is. Hire and terminate events (account creation in SSO, payroll record) are usually built in real time via webhooks so that a new employee can log in straight away. Salary changes to payroll can run in batches at month-end, since the payroll run depends on them anyway. Absence notifications go to workforce planning in real time, with periodic reconciliation to accounting. We make that choice explicitly for each flow, together with your HR and finance teams.
A source-of-truth conflict is by far the biggest pitfall in HR integrations. For each field, we record which system is leading: HR Office is usually the source for personal, contract and role data; payroll is leading for gross salary history and year-to-date totals; SSO is leading for account status and groups. If a change occurs in a non-leading system, the result is either a warning or a forced override to the leading system, depending on what is legally and operationally correct. No implicit "last update wins" logic.
For each integration direction, we document which fields are exchanged and why (purpose limitation). Fields that are not necessary for the target system are not sent, even if the API accepts them. Special category personal data (such as reasons for absence) only travels where legally required and with an explicit legal basis. Every change is recorded in an audit log with timestamp, source system, target system and the fields changed — not the values themselves, to prevent leaks through logging. That material feeds directly into your record of processing activities.
For light, linear integrations between two systems, iPaaS is perfectly adequate and we recommend it. It becomes too limited once: the volume exceeds what Zapier tasks can handle, the logic branches across more than two systems, conflict-resolution rules are needed, purpose limitation per field must be visible, or retry and idempotency guarantees are required that iPaaS does not reliably provide. Custom middleware costs more up front, but avoids the lingering maintenance problem that makes iPaaS flows unmanageable after a year.
Almost every HRIS integration runs into a field that exists in the source or target system but is missing or limited in the API. We then choose between three options: an intermediate layer that manages the data outside the API (for example custom fields or an extension table), a temporary manual step that is explicitly documented in the process, or consultation with the vendor to extend the API. We always document which fields travel outside the standard API, rather than hiding them.
The cost is determined by the number of systems to integrate, the complexity of the field mapping, GDPR requirements (municipalities or healthcare are stricter than an average SME), the required sync frequency, and the amount of custom work in conflict resolution. Ongoing management, monitoring and support also affect the total investment. We always provide a clear quote following a no-obligation analysis of your situation.
Yes. Appfront regularly takes over existing HR integrations, even if they were originally set up by another party or via an iPaaS. We review the data flows, error handling, GDPR documentation and monitoring, record how things currently work, and propose improvements. From then on, we can handle adjustments, extensions and ongoing management — including timely API key rotation and periodic security checks.
Talk to us about your HR Office integration
Tell us which systems you would like to integrate with HR Office, such as payroll, ATS, SSO, accounting or onboarding, and which processes are still handled manually or in Excel. We are happy to think along with you on field mapping, source of truth and GDPR purpose limitation. A no-obligation first conversation will give you a clear picture of the possibilities within half an hour.