Casework is personal data. We treat it that way.
Claimants, residents, applicants — the people in your cases never chose Hendl. So the platform is built to hold their data carefully, use it only for the case, and let it go when the case is done.
Six rules the platform enforces.
Agents collect what the case needs — not everything they can reach.
Case data is used for the case. No secondary use, no profiling, no ads — obviously.
Personal data is never used to train shared models. Contractual, not configurable.
Each case type carries its retention rule; deletion happens on time and verifiably.
People and agents see a person’s data only when their role and the case require it.
Every access to personal data is logged — who, what, when, and why.
Rights requests, made practical.
Per-case data maps mean a person's data can actually be found — which turns rights requests from projects into tasks.
Locate and export everything held about a person across cases, with the search itself logged.
Correct the record once; the change propagates to every place the data is used.
Verifiable deletion across cases and backups, within retention and legal-hold rules.
Structured, open-format exports of a person’s data, ready to pass on.
Your organisation decides why and how case data is processed. Hendl gives you the controls to honour that responsibility — retention schedules, access rules, and exports.
Hendl processes case data only on your instructions, under a DPA with every contract — in your chosen region, with subprocessors listed and changes notified in advance.