Security & Trust

Payroll data deservesserious protection.

MySalaryPal is an early-stage platform, and we'd rather be precise than impressive. Below is what is in place today, what our infrastructure providers give us, and what is still on the roadmap.

EU data residency

Payroll data is stored in the European Union (Frankfurt) and served from EU edge locations. Only routing and log metadata may pass through non-EU edge points of presence, under SCCs.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Payslip files and database backups are encrypted by default.

Role-based access

Payroll, HR and employee roles are separated. People only see what their role allows — enforced at the database layer.

Passkey sign-in

Face ID, Touch ID, Windows Hello or your device PIN as a second factor — phishing-resistant by design.

Full audit trail

Every payslip view, upload, change request and admin action is logged with user, time and IP.

Daily backups

Managed database backups with point-in-time recovery, provided by our EU-hosted infrastructure provider.

Built around GDPR

DPA available on request. Subject access, export and erasure flows are built into the product — no email tickets required.

Least-privilege internals

Production access is restricted, MFA-enforced, and reviewed. We don't read your payslip data in the course of normal operations.

Security monitoring

Automated monitoring, rate limiting and anomaly detection help identify suspicious activity and protect customer data.

Incident response

Security incidents are investigated promptly and affected customers are notified where required by law.

Data residency

EU — Frankfurt, DE

Database, file storage and backups all stay inside the European Union.

Breach SLA

72 hours

Customer notification within 72 hours of confirmed personal-data breach (GDPR Art. 33).

Encryption

AES-256 / TLS 1.2+

At rest and in transit, as provided by our EU-hosted infrastructure and storage providers.

Backup & recovery

Point-in-time recovery

Managed backups with point-in-time recovery. Formal recovery-time objectives will be published once independently validated.

Compliance posture

MySalaryPal is designed for employers across Europe, and built to align with:

  • GDPR (EU 2016/679)
  • UK GDPR & Data Protection Act 2018
  • Irish Data Protection Act 2018
  • ePrivacy Regulations
  • Designed to support EU Pay Transparency Directive (2023/970) workflows
  • PCI-DSS via Paddle (Merchant of Record)
  • Data Processing Agreement signed before production data flows.
  • Sub-processor list reviewed periodically; material changes notified 30 days in advance.
  • International transfers use 2021 Standard Contractual Clauses (Module 3) where applicable.
Where we are today. MySalaryPal does not hold ISO 27001, SOC 2 or Cyber Essentials certification. Independent penetration testing is planned prior to wider production deployment. Certifications listed for sub-processors below are theirs, not ours. Alignment with the regulations above describes how the platform is designed; it is not a certification and does not by itself make an employer legally compliant. The Service is operated by Gary Curran, an individual based in Ireland trading as MySalaryPal; we intend to incorporate an Irish limited company and will notify customers if the contracting entity changes.

Sub-processors

A short, deliberate list. All EU-hosted where the option exists.

VendorPurposeRegionAttestations
SupabaseDatabase, auth, file storageEU (Frankfurt)SOC 2 Type II, HIPAA, ISO 27001
CloudflareEdge delivery, DDoS, WAFGlobal edge (EU PoPs)SOC 2 Type II, ISO 27001, PCI-DSS
PaddlePayments (Merchant of Record)EU / UKPCI-DSS Level 1, SOC 2 Type II
LovableApplication platform, transactional email & AI GatewayEU edgeDPA
Google GeminiPayslip data extraction & explanations (via Lovable AI Gateway)EU multi-regionSOC 2/3, ISO 27001/17/18, SCC — no training on inputs

AI explanations are opt-in per workspace. Inputs and outputs are not used to train public models. Vendor names link to their public trust / security pages so your InfoSec team can pull the latest attestation reports directly.

Paperwork — ready to sign

No NDA required. Download our pre-signed DPA and the DPIA template your DPO can drop straight into your records.

Reporting a security concern

If you believe you've found a vulnerability or have a security question, email hello@mysalarypal.com. We acknowledge reports within one business day.