SOC2C

Is this your company? Buyers are checking Hellorider here. Claim hellorider.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Hellorider logo

Hellorider

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Hellorider is SOC 2 compliant. Hellorider also holds GDPR, and ISO 27001.

Framework
SOC 2
Auditor
Last report
Renewal
View official trust center ↗

About

Hellorider's goal is to move 1.000.000 employees from their car onto a bicycle by providing a streamlined platform that connects lease companies, employers, bicycle dealers and employees. Visit [hellorider.com](https://hellorider.com) for more information.

Compliance & infrastructure

Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable information

Documents

10

Subprocessors

31
  • A
    Amazon Web Services · Cloud provider
    Frankfurt, Germany
  • G
    GitLab · Version control
  • Z
    Zendesk · Customer support
  • O
    Office 365 · office
  • S
    Slack · Internal communication
  • 3
    3CX
  • A
    AFAS
  • A
    Arnia
  • B
    Bintime / Gepard
  • H
    HubSpot · Marketing
  • I
    ING
  • J
    JIRA · Collaboration
Show all 31 subprocessors
  • L
    Linear · Collaboration
  • M
    Mailchimp · Marketing
  • M
    Messagebird
  • M
    Metabase · Data analytics
  • M
    Microsoft Sharepoint · sharepoint
  • Z
    Zapier · Collaboration
  • C
    CognitoForms
  • C
    Confluence · Document management
  • C
    CreditDevice
  • e
    eSignatures
  • M
    Mollie
  • A
    Aikido
  • L
    LastPass · Password management
  • P
    Payt
  • P
    POeditor
  • P
    Pro6PP
  • S
    Sirv
  • T
    Thermostat
  • V
    Vanta · Security

Compliance leadership

The person who leads Hellorider's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Hellorider's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Hellorider SOC 2 compliant?
Hellorider is SOC 2 compliant. On SOC2C this listing is Listed.
Is Hellorider GDPR compliant?
According to Hellorider's public trust center, Hellorider is GDPR compliant. On SOC2C this listing is Listed.
Is Hellorider ISO 27001 certified?
According to Hellorider's public trust center, Hellorider is ISO 27001 certified. On SOC2C this listing is Listed.
Can I use Hellorider's SOC 2 for a vendor risk assessment?
Yes. Hellorider's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Hellorider penetration tested?
Hellorider hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.

Answers published by Hellorider

Reproduced from Hellorider's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

With whom does Hellorider share personal data?
Hellorider shares the personal data it collects using cookies, when using its website, with third parties to design its website more effectively. When a rider or (potential) customer contacts Hellorider, we use the data to answer the question and, where appropriate, to make more effective use of communication via chat. More information on this can be found in its privacy statement. Furthermore, Hellorider does not share personal data with third parties outside the parties mentioned in the privacy statement.
Why is there no processor agreement?
Hellorider qualifies as an independent controller. The employer, lease company and dealers also qualify as (independent) controllers. Hellorider, its customers and the dealers are not processors. For this reason, a processor agreement between these organizations is not necessary. This is only mandatory when a controller - processor relationship exists. Naturally, Hellorider has a duty to handle the personal data to be processed with care. A controller such as Hellorider must independently comply with the GDPR. For example, it must determine for itself whether the processing operations meet all the requirements of the GDPR, for example whether there is a valid basis to process the personal data, and it has a duty to ensure an adequate level of protection of personal data.
Is Hellorider willing to enter into a joint controller agreement?
If an organization processes personal data for its own purposes and shares this data with another organization that uses the personal data for its own purposes, there are two independent data controllers applicable. It has already been mentioned above that this applies to Hellorider, its customers and its dealers. There is no joint controller responsibility in this case, as the parties do not jointly determine the purpose and means of processing personal data. For this reason, Article 26 AVG does not apply. There is therefore no legal obligation to establish a mutual arrangement on personal data processing. Because Hellorider does consider it important to agree on some basic principles when it comes to (the processing of) personal data with its customers, it has included an article for this purpose in the agreement it enters into with its customers.
Is personal data processed by Hellorider outside the EEA?
Hellorider processes personal data within the EEA, unless such a transfer meets the exceptions and/or conditions provided for in (privacy) legislation.
How long does Hellorider keep personal data?
Hellorider retains the personal data of leasing contracts concluded for the duration of the contract with an expiry date of 1 year. Personal data of employees specified by their employer and invited by Hellorider is kept by Hellorider for the duration of the invitation with an expiry of 30 days. Personal data of employees who have selected a bike but whose order is cancelled before the contract starts Hellorider retains for 90 days after the cancellation. Invoice data is kept by Hellorider according to the legal retention period (of 7 years).

Retail & Commerce peers that completed SOC 2