Skip to main content
Industry HR tech development · UK GDPR-aware · IR35-aware · RTI-aware

HR tech development your DPO and. your CFO both trust.

HR tech development for UK founders, people teams, and HRO providers. ATS, performance, payroll and onboarding — with UK GDPR-aware employee data, IR35 status awareness, and RTI / FPS sync. Role-scoped across employee, manager, and HRBP before the first candidate record lands.

24hreply, from a senior
200+projects shipped since 2019
Senioronly, on the spine
(Why UK HR-tech founders sign)

You build for the user. We build for the regulator, the acquirer, and the user, all at once.

Custom HR software development isn’t a DSAR export you bolt on the week a candidate files. It’s a data model and an access boundary you decide in week one, or pay 6 weeks of panic to retrofit. We decide them in week one.

0

0

0%

The founder this page is for6-week DSAR · ICO complaint · under 24h

Nadia founded a UK ATS. The hiring worked. The candidate data didn’t hold.

01

An applicant tracking system for SME hiring, launched in 2024. Sixty companies onboarded by month four. Eight thousand candidates processed. Built fast, the way a pre-seed team builds, with the candidate data spread across three tables and an unstructured note field nobody had planned to ship to anyone.

02

Then the first DSAR landed from a candidate who wanted everything held about them. There was no export tool, no audit log of who had read what, and PII scattered through free-text notes. The DSAR took 6 weeks. The ICO complaint followed. The next board call was not a comfortable one.

03

We rebuilt the spine over thirteen weeks. A DSAR-ready candidate model, role-scoped access for recruiter, hiring manager, HRBP, and candidate, an audit log on every data touch, and right-to-erasure for unsuccessful candidates after twelve months. The ICO query resolved on the export evidence. Sixteen more SMEs signed that quarter. This page is for the HR-tech founder who’d rather build with the regulator and the auditor in mind on day one.

UK GDPR-aware since 2019
HR-TECH SURFACES WE’VE SHIPPED IN PRODUCTION

Eight HR-tech surfaces, live on the spine

What lives on the people-data spine. Each one role-scoped, audit-logged, and built so your DPO reads the brief and signs without sending it back.

01

ATS + recruiting

Job posting, candidate pipeline, interview scheduling, offer management, and DSAR-ready exports that run in minutes, not weeks.

02

Performance management

Goals, 1:1s, reviews, calibration. Role-scoped manager, HRBP, and employee access so a review never crosses a team line.

03

Onboarding workflows

Pre-onboarding tasks, document collection, Right to Work via Share Code, DBS checks, and payroll setup, all audit-logged.

04

Payroll integrations

Xero, Sage, QuickBooks, and Iris connections. RTI / FPS audit trail. Idempotent sync with a missed-starter alert before the run.

05

Time + attendance

Clock in and out, leave management, absence tracking, and manager approval workflows scoped to direct reports only.

06

L&D platforms

Learning paths, compliance training, and audit-ready completion records your auditor can pull without a developer in the loop.

07

Employee directories

Role-scoped contact and skills directory. Optional cross-team collaboration features that respect the access boundary.

08

HR analytics

Headcount, attrition, diversity reported in aggregate only, and payroll cost. Live dashboards your board reads cold.

Process

How an HR-tech build actually runs

Three steps from a five-line brief to a DSAR-ready platform. Every compliance decision is made on day one, not retrofitted 6 weeks of panic later. The four seniors who sign your scope are the four who ship.

Step-01

Audit week, £8K fixed

A 30-page brief mapping your build against UK GDPR employee-data duties, DSAR readiness, IR35, and RTI obligations. You walk away with a signed scope, no commitment to build.

Step-02

Build the defensible spine

A DSAR-ready candidate model, role-scoped access for recruiter, manager, and HRBP, schema-level erasure, and an audit log on every data touch. Decided in week one.

Step-03

Ship the surfaces and the proof

ATS, performance, onboarding, payroll sync, and time and attendance, plus the export tool and the audit log your DPO and your acquirer both read cold.

HR software development stack · MERN + AWS

Three tiers, one defensible people-data spine.

The stack we ship every UK HR-tech build on. Tier 1 runs every build. Tier 2 is what we reach for when the brief needs it. Tier 3 scales it to enterprise headcount without a rebuild.

T1

What we build every HR-tech platform on

MERN + Flutter
MongoDBExpress.jsReact + Next.jsNode.jsTypeScriptFlutterPostgreSQLClerk / Auth.jsMixpanelTailwindPlaywright
T2

When your brief actually calls for it

reach when needed
PythonJavaOnfido / VeriffXero / SageQuickBooks / IrisNEST / People’s Pension
T3

The infrastructure that scales it

AWS + cloud-native
AWSKubernetes (EKS)DockerAWS LambdaAWS RDS / AuroraAWS KMSS3 + CloudFrontRedisTerraformDatadog + SentryVanta / Drata
The pains we fix

The HR-tech pain. The architectural answer.

Every HR-tech founder who emails us is fighting one of these. Each one is impossible to fix cheaply once employee data is live. Each one is a single architectural decision made on day one.

6wk <24h

DSAR turnaround after the rebuild

16+

SMEs signed the next quarter

“The DSAR export and the audit log were the documents that closed the ICO query. They read them once and stopped asking.”

Nadia

Founder, UK HR-tech ATS

001

DSAR-ready data model

A candidate filed a DSAR and you couldn’t produce the export in 30 days. The export tool ships in week one, candidate data unified, and the export runs in minutes.

002

Role-scoped access at the database

A manager could view another team’s reviews. A manager only sees their reports, the HRBP is scoped to a cohort, and a cross-team leak is architecturally impossible.

003

IR35 SDS generation and audit

You hired contractors and HMRC asks for the SDS you don’t have. A CEST-aligned questionnaire runs at onboarding, the SDS is stored, and a status change regenerates the contract.

004

Idempotent payroll sync and RTI

A Sage FPS submission missed a starter and HMRC sent a penalty. Idempotent sync to Xero, Sage, QuickBooks, and Iris, with a missed-starter alert before the run, not after.

005

RTW, DBS, and auto-enrolment tracking

A Right to Work expiry or an auto-enrolment birthday slipped through. Expiry is tracked per employee, reminders fire at 90, 60, and 30 days, and the eligibility engine runs daily.

DSAR-ready

6-week DSAR to
under 24 hours, in thirteen weeks

Nadia’s ATS, in real numbers. The spine rebuilt on a UK GDPR-aware data model behind a flag, role-scoped access for recruiter, hiring manager, and HRBP, schema-level erasure, and an audit log on every data touch. Zero downtime at cutover. The ICO query resolved on the export.

The rebuild

13wk
GDPR-aware ATS rebuild
0
Downtime at cutover

The outcome

<24h
DSAR turnaround
16
SMEs signed next quarter

Track record

3
HR-tech platforms since 2019
100%
IR35 SDS audits defendable
How we work with UK people teams

Three ways to start. Pricing in the email back.

We don’t publish prices on a page. Every HR-tech scope carries different compliance weight. Pick the shape that fits and Mohit will send your real number inside 24 hours.

AStart here

HR-tech audit week

One week, fixed at £8K. A 30-page brief mapping your build against UK GDPR employee-data duties, DSAR readiness, IR35, and RTI obligations.

  • 5-day senior audit
  • UK GDPR + IR35 mapping
  • Architecture brief + ADRs
  • No commitment to build
BMost common

HR-tech build sprint

8 to 14 weeks. A full HR-tech surface end-to-end. ATS, performance, onboarding, payroll sync, time and attendance, role-scoped access, DSAR-ready exports.

  • MERN + Python + AWS
  • UK GDPR + IR35 + RTI designed in
  • 30-day walk-away both ways
  • IP assigns on every commit
CRescue

Compliance rebuild

7 to 12 weeks. Your existing HR-tech with the DSAR backlog or the ICO query. We rebuild the gaps and ship the audit log and the export tool.

  • Gap audit + remediation
  • DSAR + erasure tool retrofit
  • Role-scoping rebuild
  • ICO-style brief shipped
From £45K · 8-14 weeks · fixed scope

“The DSAR export and the audit log were the documents that closed the ICO query. They read them once and stopped asking.”

— Nadia, founder, UK HR-tech ATS
HR tech development · honest answers

What people teams actually ask before signing the contract

Pain-first, soft-second. The questions every founder asks after their third bad agency experience.

The DSAR export tool is built into the platform from week one. Candidate data is unified across pipeline tables, so the export runs in minutes, not the 6 weeks Nadia spent before we rebuilt her ATS. In our HR software development work we’ve never had a client miss the 30-day deadline after handover. The audit log shows exactly who accessed what, which is the evidence the ICO actually asks for.

We don’t price by salesperson mood. The audit week is fixed at £8K. After that, every custom HR software development build is line-itemed: ATS, performance, onboarding, payroll sync, role-scoped access, DSAR export. You see the cost of each piece and you can cut any piece. Most builds we sign land between £45K and £90K on an 8-to-14 week fixed-price sprint. If we can’t hit your budget, we tell you in week one and you walk away with the audit brief, no commitment.

Xero, Sage, QuickBooks, and Iris are all wired in the build sprint, not promised for later. The sync is idempotent, so a payroll run can’t double-submit, and the RTI / FPS audit trail logs every submission. A missed starter alerts you before the run, not after HMRC sends the penalty.

A CEST-aligned questionnaire runs at contractor onboarding. The SDS is generated, stored, and re-evaluated quarterly. An IR35 status change triggers contract regeneration. The whole trail is HMRC audit-defendable, which is the point of IR35-compliant HR software, rather than a status flag nobody can evidence later.

Stored separately from operational data, with restricted access. Reporting is aggregate only, and the recruiter pipeline view excludes it entirely. UK ICO and Equality Act compliant by design, not by a policy document that depends on every recruiter behaving. This is the part a generic SaaS build always gets wrong.

No. Role-scoped access is enforced at the data layer, not in front-end code. A manager only sees direct and indirect reports. An HRBP is scoped to an assigned cohort. A cross-team leak is architecturally impossible, so it can’t happen because someone forgot to hide a button.

Three things make it hard to fake. The 30-day walk-away clause goes both ways and refunds the unused portion. Payments are milestoned 25/25/25/25, so you never pay more than a quarter ahead of working software. And we’ve been shipping since 2019, listed on Companies House, UK VAT registered. You can check us before you sign a thing.

Yes, with 14 days’ notice. The engineers move to other projects, your repo stays where it is, your spend pauses. Pick it back up with 14 days’ notice and we resume on the same sprint board with the same engineers. No cancellation fee, no restart fee. We did this six times in 2025.

Yes, signed inside 30 minutes via DocuSign. We keep a mutual NDA template ready. After that the audit week can start the following Monday in most cases, and you have a signed scope with line-item GBP at the end of it.

Hr tech development — product screenshot / UI
In context

Inside the work.

A look at the kind of hr tech development surface we hand over — real screens, real data, documented and yours from day one.

Build the HR platform your people and your regulator both trust

One paragraph. That’s it.

Tell us what you’re building, who your buyers are, and the employee-data or compliance question you’re most worried about. Mohit reads every first email and replies inside 24 hours: a clear yes, a clear no, or the one question that decides it.

Write to mohit@empyrealinfotech.com Replies in 24hUK GDPR-aware from day 1DSAR-ready
What happens after the email lands
  1. < 24h

    A personal reply.

    Yes, no, or the deciding question. Straight to your inbox, not a team thread.

  2. Week 1

    Audit week begins.

    We map your build against UK GDPR employee-data duties, write the trade-offs, hand you a signed scope.

  3. Week 14

    DSAR-ready HR-tech.

    ATS, payroll sync, role-scoped access, and the brief your DPO and your acquirer both read cold.