We built MySalaryPal to replace password-protected payslip emails with something materially safer. Here's exactly how we keep your employees' data secure.
All personal data is stored and processed in the European Union. Your payroll never leaves the EU.
TLS 1.2+ in transit, AES-256 at rest. Payslip files and database backups are encrypted by default.
Payroll, HR and employee roles are separated. People only see what their role allows — enforced at the database layer.
Face ID, Touch ID, Windows Hello or your device PIN as a second factor — phishing-resistant by design.
Every payslip view, upload, change request and admin action is logged with user, time and IP.
Point-in-time recovery with daily encrypted backups retained for 30 days.
DPA available on request. Subject access, export and erasure flows are built into the product — no email tickets required.
Production access is restricted, MFA-enforced, and reviewed. We don't read your payslip data in the course of normal operations.
Automated monitoring, rate limiting and anomaly detection help identify suspicious activity and protect customer data.
Security incidents are investigated promptly and affected customers are notified where required by law.
Data residency
EU — Frankfurt, DE
Database, file storage and backups all stay inside the European Union.
Breach SLA
72 hours
Customer notification within 72 hours of confirmed personal-data breach (GDPR Art. 33).
Encryption
AES-256 / TLS 1.2+
At rest and in transit. Daily encrypted backups with 30-day point-in-time recovery.
Recovery targets
RPO ≤ 5 min · RTO ≤ 4 h
Point-in-time recovery from continuous WAL backups; disaster-recovery runbook tested annually.
MySalaryPal is designed for employers across Europe. We align with:
A short, deliberate list. All EU-hosted where the option exists.
| Vendor | Purpose | Region | Attestations |
|---|---|---|---|
| Supabase | Database, auth, file storage | EU (Frankfurt) | SOC 2 Type II, HIPAA, ISO 27001 |
| Cloudflare | Edge delivery, DDoS, WAF | Global edge (EU PoPs) | SOC 2 Type II, ISO 27001, PCI-DSS |
| Paddle | Payments (Merchant of Record) | EU / UK | PCI-DSS Level 1, SOC 2 Type II |
| Resend | Transactional email | EU | SOC 2 Type II, GDPR DPA |
| Google Gemini | Payslip explanations (opt-in) | EU multi-region | SOC 2/3, ISO 27001/17/18, SCC — no training on inputs |
| OpenAI | Payslip explanations (opt-in) | US | SOC 2 Type II, SCC, zero-retention API |
AI explanations are opt-in per workspace. Inputs and outputs are not used to train public models. Vendor names link to their public trust / security pages so your InfoSec team can pull the latest attestation reports directly.
No NDA required. Download our pre-signed DPA and the DPIA template your DPO can drop straight into your records.
GDPR Art. 28-compliant DPA with sub-processor list, SCC reference and Annex II technical measures. Pre-signed for the Processor — counter-sign and return.
PDF · ~4 pages · v1.0
Article 35 DPIA pre-filled with the MySalaryPal context — your DPO only fills in the bracketed sections specific to your rollout.
PDF · ~2 pages · v1.0
Pre-filled answers to standard InfoSec and procurement questions. Search, print or copy directly into your vendor review.
Web · always current
If you believe you've found a vulnerability or have a security question, email hello@mysalarypal.com. We acknowledge reports within one business day.