Security & Trust

Payroll data deservesserious protection.

We built MySalaryPal to replace password-protected payslip emails with something materially safer. Here's exactly how we keep your employees' data secure.

EU data residency

All personal data is stored and processed in the European Union. Your payroll never leaves the EU.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Payslip files and database backups are encrypted by default.

Role-based access

Payroll, HR and employee roles are separated. People only see what their role allows — enforced at the database layer.

Passkey sign-in

Face ID, Touch ID, Windows Hello or your device PIN as a second factor — phishing-resistant by design.

Full audit trail

Every payslip view, upload, change request and admin action is logged with user, time and IP.

Daily backups

Point-in-time recovery with daily encrypted backups retained for 30 days.

GDPR ready

DPA available on request. Subject access, export and erasure flows are built into the product — no email tickets required.

Least-privilege internals

Production access is restricted, MFA-enforced, and reviewed. We don't read your payslip data in the course of normal operations.

Security monitoring

Automated monitoring, rate limiting and anomaly detection help identify suspicious activity and protect customer data.

Incident response

Security incidents are investigated promptly and affected customers are notified where required by law.

Data residency

EU — Frankfurt, DE

Database, file storage and backups all stay inside the European Union.

Breach SLA

72 hours

Customer notification within 72 hours of confirmed personal-data breach (GDPR Art. 33).

Encryption

AES-256 / TLS 1.2+

At rest and in transit. Daily encrypted backups with 30-day point-in-time recovery.

Recovery targets

RPO ≤ 5 min · RTO ≤ 4 h

Point-in-time recovery from continuous WAL backups; disaster-recovery runbook tested annually.

Compliance posture

MySalaryPal is designed for employers across Europe. We align with:

  • GDPR (EU 2016/679)
  • UK GDPR & Data Protection Act 2018
  • Irish Data Protection Act 2018
  • ePrivacy Regulations
  • EU Pay Transparency Directive (2023/970) ready
  • PCI-DSS via Paddle (Merchant of Record)
  • Data Processing Agreement signed before production data flows.
  • Sub-processor list reviewed periodically; material changes notified 30 days in advance.
  • International transfers use 2021 Standard Contractual Clauses (Module 3) where applicable.

Sub-processors

A short, deliberate list. All EU-hosted where the option exists.

VendorPurposeRegionAttestations
SupabaseDatabase, auth, file storageEU (Frankfurt)SOC 2 Type II, HIPAA, ISO 27001
CloudflareEdge delivery, DDoS, WAFGlobal edge (EU PoPs)SOC 2 Type II, ISO 27001, PCI-DSS
PaddlePayments (Merchant of Record)EU / UKPCI-DSS Level 1, SOC 2 Type II
ResendTransactional emailEUSOC 2 Type II, GDPR DPA
Google GeminiPayslip explanations (opt-in)EU multi-regionSOC 2/3, ISO 27001/17/18, SCC — no training on inputs
OpenAIPayslip explanations (opt-in)USSOC 2 Type II, SCC, zero-retention API

AI explanations are opt-in per workspace. Inputs and outputs are not used to train public models. Vendor names link to their public trust / security pages so your InfoSec team can pull the latest attestation reports directly.

Paperwork — ready to sign

No NDA required. Download our pre-signed DPA and the DPIA template your DPO can drop straight into your records.

Reporting a security concern

If you believe you've found a vulnerability or have a security question, email hello@mysalarypal.com. We acknowledge reports within one business day.