Frequently asked questions
Everything we hear regularly from HR directors and Total Rewards managers, answered in plain language.
Data and security
All data is processed and stored in AWS Frankfurt (eu-central-1). No employee data is transferred outside the European Economic Area. We do not use US-based subprocessors for storage or processing of personal data.
Yes. You, as the employer, are the data controller. Toduba S.r.l. acts as a data processor on your behalf. We provide a standard Data Processing Agreement (DPA) to all customers, compliant with GDPR Article 28 requirements. The DPA is included in the Starter tier and above.
The modeling engine works on anonymised cohort-level data. Individual employees are replaced with a pseudonymous identifier at ingestion. Toduba's output reports show cohort-level patterns and recommendations, not individual employee records. If your minimum cohort size is fewer than 5 employees, that cohort is automatically excluded from analysis to prevent re-identification.
Within 30 days of contract termination, all your data (raw ingestion files, modeling outputs, cohort configurations) is permanently deleted from our systems. We provide a deletion certificate on request. You can export your analysis reports and configurations at any time before termination.
Integrations
Toduba supports CSV upload for all tiers. Growth tier includes native connectors for Personio and HiBob. Enterprise customers can use the Workday connector or request a custom connector via the REST API. We are building direct connectors for DATEV, SAP SuccessFactors, and Sage HR, targeted for release by end of 2026.
Yes. You can add named viewer accounts for your broker or TPA at no additional charge. Viewer accounts have read-only access to analysis reports and cannot modify configurations or trigger new runs. All viewer access is logged for your audit trail.
Yes. If you are between systems, you can export a CSV from either your current or legacy HRIS and upload it directly. We have documented CSV templates for the most common HRIS export formats. If your data is split across two systems, our onboarding team can merge the extracts before ingestion at no extra cost.
Methodology
Toduba uses a combination of unsupervised clustering (to identify cohorts with similar utilisation patterns) and a preferences inference model (trained on anonymised pan-European benefit utilisation data, updated quarterly). We do not use a third-party large language model to produce recommendations. The output is deterministic given the same input data.
A minimum of 12 months of claim data produces a reliable cohort segmentation. 18 to 24 months gives the model enough longitudinal signal to identify seasonal patterns and multi-year utilisation trends. If you only have 6 to 12 months, we can still run a partial analysis with confidence intervals clearly flagged in the output.
In most cases, no. The preference inference model relies on observed utilisation patterns. However, if you are setting up a benefits programme for the first time (no history), we can run a peer-benchmark mode where your workforce demographics are matched against similar cohorts in our anonymised reference dataset. The output carries wider confidence bands but is useful as a starting point.
Toduba runs a separate analysis per country entity by default, respecting local statutory minimums for each jurisdiction. The dashboard surfaces results at both entity and group level. Budget scenarios can be built either per-entity or at group level with entity-level allocation suggested by the model. Currently supported: Italy, Germany, France, Austria, the Netherlands, and Belgium.
Billing
All published prices are exclusive of Italian VAT (IVA at 22%). If you are an EU business providing a valid VAT number, the reverse charge mechanism applies and no Italian IVA is charged on the invoice. If you are based outside the EU, no VAT is charged. We issue invoices via our accounting system within 5 days of each billing event.
Monthly billing is available on the Starter tier at the monthly rate (approximately 17% higher than the equivalent annual rate). Growth and Enterprise customers are billed annually. We accept SEPA credit transfer, bank transfer, and major corporate credit cards.
Upgrades take effect immediately and are prorated for the remaining contract term. Downgrades take effect at the next renewal date. We do not issue partial refunds for unused prepaid periods if you downgrade mid-year.
Still have a question?
Send your question to [email protected] and we will get back to you promptly. For technical or compliance questions, we can arrange a short call with the relevant team member.