Do you replace Visma YouForce, AFAS or Personio?
No, not for standard use. YouForce, AFAS Profit, Personio, Nmbrs and Loket are all solid payroll packages, and we will happily recommend them where they fit your needs. We only build a custom employee portal if you use several HR systems at once, need a sector-specific workflow that no package offers, or want your own brand look. In almost all cases your existing payroll package remains the source of truth and our portal sits on top as a layer.
How exactly does a Visma YouForce integration work?
Visma YouForce offers a Web API and SFTP integrations for master data, leave balances, payslips and changes. We build a two-way sync so the portal shows in real time what is recorded in YouForce, and changes (address change, leave request, personal details update) are automatically written back to YouForce once approved. The integration runs through your own tenant, and we have no access to production data.
How does Personio handle expense claims and audit trails for compliance?
Since 2023 Personio has had its own expenses module with workflow and audit log, plus API endpoints to retrieve or submit claims. For stricter compliance requirements (healthcare, government, financial services) we build the expense process into the portal itself, with OCR extraction, VAT categorisation, fraud detection and an audit trail that meets your records-retention or NEN requirements. Personio then remains the source for approval roles, while the claim flow and logging run with us.
How do we arrange access and SSO?
SSO through your existing identity provider: Azure AD, Google Workspace, Okta or Auth0. For frontline staff without email (healthcare, retail, manufacturing), a magic link or a 6-digit access code by SMS is possible. Roles and permissions run through your IdP, so joiners and leavers are handled automatically when IT adds or removes someone in AD.
Does the portal comply with NEN 7510 for healthcare employers?
Yes, provided we build it that way. NEN 7510 sets requirements for logging, access management, encryption, availability and risk analysis. In that case we run the portal in your own healthcare cloud (often Azure or a NEN-certified Dutch cloud), implement role-based access, encryption at rest and in transit, and a DPIA in the pre-launch phase. For government the same applies with BIO; for the financial sector, DORA. We work alongside your security officer, not around them.
Do you work together with our IT department and HR supplier?
Almost always. Your IT team is responsible for SSO, hosting decisions and the runbook. Your HR supplier (Visma, AFAS, Personio, and so on) is party to the API integration. We coordinate between the two and, in the final sprint, deliver a knowledge transfer plus an incident runbook so your own team can take over management, or we can agree an ongoing maintenance arrangement for it.
What determines the cost of an employee portal?
Four factors: the number of modules (a payslip and leave-only portal is much smaller than a full portal with rostering, expense claims, performance and LMS), the number of integrations (connecting one payroll package is different from connecting four HR systems from several vendors), the compliance level (NEN 7510 or BIO requirements add extra work), and whether a native mobile app is needed. In the introductory call we'll give you an honest recommendation; for fully worked-out enterprise projects we refer you to our
enterprise software approach.
Can you build just the portal, or also the mobile app?
Both. For employers with many frontline staff (healthcare, retail, manufacturing), a native iOS/Android app is almost always worthwhile. Push notifications, biometric login, offline caching and deep links to the rota simply work better in an app than in a mobile browser. We build the web version and native apps on the same backend, so HR only has to configure things once.
How do you handle privacy-sensitive HR data?
As standard, we encrypt all personal data at rest (database) and in transit (TLS 1.3). Payslip files and tax documents are kept in object storage with separate encryption keys. An audit log records who viewed which data and when, which is particularly relevant in healthcare and government, where this is mandatory. At the start of the project we provide a DPIA document to your Data Protection Officer or privacy officer.