Data Processing Agreement

Last updated: 23 June 2026 · Forms part of the Terms of Service

1. Parties & scope

This Data Processing Agreement ("DPA") is entered into between MySalaryPal (operated by Gary Curran, Ireland) ("Processor") and the employer customer ("Controller") who has accepted the MySalaryPal Terms of Service. It governs the processing of personal data carried out by MySalaryPal on the Controller's behalf when the Controller uploads, manages or distributes payroll data through the Service.

It is concluded under Article 28 GDPR and the equivalent UK GDPR. By using the Service in an employer capacity, the Controller accepts this DPA on behalf of itself and its affiliated entities.

2. Subject matter & duration

The Processor processes personal data solely to provide the MySalaryPal service: storing payslip files, extracting payroll figures, generating explanations, delivering notifications, and supporting employees and admins. Processing continues for the duration of the Controller's subscription and any wind-down period defined in clause 9.

3. Nature of processing

CategoryDetails
Data subjectsController's employees, contractors and payroll admins
Categories of personal dataName, email, employee ID, payslip files, gross/net pay, tax & social-contribution figures, pension figures, employment status, audit log entries
Special categoriesNone expected. Controller must not upload health, biometric, trade-union or other Article 9 data through payslip free-text fields.
Processing operationsStorage, retrieval, indexing, AI-based explanation, email/push delivery, access logging, deletion

4. Processor obligations

  • Process personal data only on documented instructions from the Controller, including those given through the Service's interface and API.
  • Ensure that personnel authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures described in clause 6.
  • Assist the Controller in responding to data-subject requests, including via the in-app privacy request tools.
  • Assist the Controller with DPIAs and prior consultations where reasonably required.
  • Make available all information necessary to demonstrate compliance with Article 28 GDPR.

5. Sub-processors

The Controller authorises the Processor to engage the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, object storageEU (Ireland)
CloudflareCDN, DDoS protection, Turnstile CAPTCHA, edge runtimeGlobal (EU PoPs)
ResendTransactional email deliveryEU / US (SCCs)
Google (Gemini)AI payslip explanationsEU / US (SCCs)
OpenAIAI payslip explanationsUS (SCCs)
PaddleMerchant of Record (billing, tax, invoicing)UK / EU

The Processor will give the Controller at least 30 days' notice of any new or replacement sub-processor by posting an update to this page and emailing workspace admins. The Controller may object on reasonable data-protection grounds; in that event the parties will work in good faith to find a solution, failing which the Controller may terminate the affected service.

6. Security measures

  • TLS 1.2+ in transit; AES-256 at rest for database and object storage.
  • Row-level security policies enforced at the database layer; least-privilege role separation between employees, payroll admins and platform operators.
  • Passkey (WebAuthn) sign-in available for both admins and employees.
  • Tamper-evident audit logs covering all admin actions and payslip access.
  • Encrypted off-site backups retained for 30 days.
  • Regular dependency and vulnerability scanning; security patches applied on a risk-based schedule.
  • Workspace-scoped tenant isolation: data from one Controller is never returned to another.

7. International transfers

Primary processing takes place in the European Union. Where personal data is transferred to a sub-processor outside the EEA or UK, the transfer is protected by the European Commission's Standard Contractual Clauses (2021) and, where applicable, the UK International Data Transfer Addendum.

8. Breach notification & security contact

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Controller data. The notice will describe the nature of the breach, categories and approximate numbers of affected data subjects and records, likely consequences, and measures taken or proposed.

Named security contact: Gary Curran, Head of Security, MySalaryPal — security@mysalarypal.com (acknowledgement within 1 business day). Backup: hello@mysalarypal.com. Public disclosure policy: /.well-known/security.txt.

9. Return & deletion

On termination of the subscription, the Controller may export workspace data via the in-app tools for 30 days. After that period the Processor will delete or anonymise Controller data within a further 30 days, except where retention is required by law (e.g. statutory payroll records, audit logs).

10. Audits & right to audit

The Controller has a right to audit the Processor's compliance with this DPA. To exercise it:

  • Documentary audit (standard): the Processor will respond within 30 days to written questionnaires (including CAIQ, SIG Lite, or a customer's own template) and provide the latest sub-processor SOC 2 / ISO 27001 reports, penetration-test executive summaries, and its own security documentation under NDA.
  • Third-party audit: the Controller may commission an independent auditor (bound by confidentiality) to review the Processor's controls no more than once per twelve-month period, on 30 days' written notice, during business hours, at the Controller's cost, and in a manner that does not disrupt the Processor's operations or breach the confidentiality of other customers.
  • Regulator-mandated audit: where a supervisory authority (e.g. DPC, ICO, CNIL) specifically requires an on-site audit, the Processor will cooperate without the frequency or cost restrictions above.
  • Response commitment: the Processor will treat findings of any audit in good faith and agree a written remediation plan for any material non-conformity within 30 days.

10. Audits

The Controller may, no more than once per year and on reasonable notice, request information reasonably necessary to demonstrate compliance with this DPA. The Processor may satisfy such requests by providing up-to-date security documentation, sub-processor information and answers to a written questionnaire. On-site audits are limited to cases where a regulator specifically requires it.

11. Liability & order of precedence

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. In the event of any conflict between this DPA and the Terms, this DPA prevails with respect to the processing of personal data.

12. Contact

Questions about this DPA or to request a counter-signed copy on company letterhead: hello@mysalarypal.com.