Frequently Asked Questions about GDPR, NIS2 and ComplianceHive

Answers to common questions about GDPR compliance, NIS2, data processing records and ComplianceHive. Can't find what you need? Email our support team.

    • How does our pricing work?

      ComplianceHive charges per tool, not per user. That means your whole team gets access, from DPO to developer, without paying per seat. Subscriptions are billed monthly, VAT included. In our billing portal, you can also choose annual billing with a discount.

    • How can I access ComplianceHive?

      You can use ComplianceHive on any device with a web browser by visiting App.compliancehive.eu. You can also install it as an application on your preferred device, check the links at the bottom for more information.

    • What is new with ComplianceHive?

      We continuously improve ComplianceHive based on feedback from teams that use it every day. Think sharper questions, clearer overviews, and updates for frameworks like GDPR, NIS2, and ISO 27001. This helps you improve step by step, without having to overhaul your entire process.

    • What is a software asset manager?

      ComplianceHive helps you keep track of your software, data vendors, and compliance obligations in one place. Think GDPR, NIS2, ePrivacy, the AI Act, and ISO 27001. We ask the right questions, you provide the answers. That keeps compliance clear, manageable, and in your hands.

    • What does the trial period mean?

      You can try our Busy Hive plan for free for 1 month. After that, you will automatically return to the free plan. No strings attached, no credit card required, and no sneaky automatic renewals. Want to stay on the Busy Hive plan? You can do that through our billing portal.

    • I have a question about my account, how can I contact you?

      Send us a message at support@compliancehive.eu or check out our contact page

    • How can I cancel my subscription?

      You can cancel your subscription at any time through our billing portal. You will still have access to your account until the end of the billing period. After that, you will automatically return to the free plan.

    • What data does ComplianceHive receive when a user logs in with Google/Microsoft?

      Only the user’s email address and basic profile information (name). Nothing else.

    • Does ComplianceHive get access to our files, calendars, or emails?

      No, ComplianceHive does not request or receive access to any files, calendars, emails, or other resources.

    • Does ComplianceHive use AI?

      No. ComplianceHive is not an AI tool. We provide structured questions, and you provide the answers. No black box, no algorithmic assumptions, just a clear structure that helps you make the right decisions.

    • Where is my data stored?

      All your data is stored in the European Union, built and hosted in the Netherlands. Designed with GDPR in mind, 100% EU.

    • How can we revoke a user's access?

      Disabling the user in your organization's Google Workspace or Microsoft 365 account immediately revokes their ability to sign into ComplianceHive.

    • How do you generate reports?

      Open the ComplianceHive app and you will find the report button. Here you can generate several reports in Excel and PDF. ComplianceHive has multiple reports with a specific focus for different purposes. Check out all our reports in ComplianceHive.

    • How do I get started with ComplianceHive?

      Head over to our app and create an account. You can start using ComplianceHive for free right away by creating an Organization and adding your software as tools.

    • How do I setup autorenewals?

      You can enable autorenewals in the organisation settings in ComplianceHive. Connect your credit card, SEPA or PayPal to ComplianceHive and we will take care of your subscription automatically.

    • How do I upgrade my account?

      You can upgrade your account in the organisation settings in ComplianceHive. Choose the plan you want to upgrade to and press the button. We will automatically calculate any price differences for you. You will keep access to your current plan until the end of the billing period if you downgrade you plan. Any upgrade will be handled immediately.

Your compliance questions, answered

    • Does my small business need to comply with GDPR?

      If you collect or process personal data of people in the EU, yes, regardless of company size. The scope of what you need to do depends on your risk level. A two-person consultancy won't need the same setup as a multinational. Start by mapping what personal data you collect and why.

    • What is a data processor agreement and when do I need one?

      You need one whenever a third party handles personal data on your behalf. Your email provider, cloud storage, payroll service: all of them process data for you. The agreement defines what data they handle, how they protect it, and what happens when the contract ends. It's required under GDPR.

    • What does NIS2 mean for SMBs?

      NIS2 is an EU directive about cybersecurity for organizations in sectors like energy, healthcare, and digital infrastructure. If you operate in or supply to these sectors, you may need to meet specific security requirements. Smaller suppliers can also fall within scope through supply chain obligations.

    • Where do I start with GDPR compliance?

      Map out what personal data you collect and why. Check whether your privacy policy actually matches what you do in practice. Then look at your vendors: do you have data processor agreements with every party that handles personal data for you? Those three things give you a real starting point.

    • What is a data processing register and do I need one?

      It's a record of what personal data you process, why, and who has access. Most organizations need one under GDPR. It does not have to be complicated. A spreadsheet listing your processing activities, their purposes, and the data categories involved will do the job.

    • How is NIS2 different from GDPR?

      GDPR protects personal data of individuals. NIS2 is about the cybersecurity of organizations and their networks. GDPR applies to nearly any business processing personal data. NIS2 only applies to organizations in designated sectors and focuses on security measures and incident reporting. Simply put: GDPR protects people, NIS2 protects systems.