Privacy & data protection
What this system actually does with confidential payroll information.
In place today
Company data separation
Users see only the companies they are authorised for. Scoping is applied in the database query, so records outside a user's access are never loaded, not merely hidden in the interface. Verified against the live site: a company administrator requesting another company's payroll by direct URL receives a 404.
Role-based access
One owner account sees the whole portfolio. Preparers see only the clients assigned to them, and company administrators only their own companies. Every server action re-checks access rather than trusting the page that called it.
Session expiry
Sessions last eight hours and refresh hourly, rather than the framework default of thirty days.
Failed-login protection
Five failed attempts against an address within fifteen minutes lock it out; a correct password clears the count. Failed attempts are recorded. The sign-in form does not reveal whether an address exists.
Audit history
Every edit to a pay line records the user, the field, the value and the statutory rule pack that produced the resulting figures. Sign-ins and sign-outs, password and session events, account changes, pay run stage changes, every return, report and payment file downloaded, and every opening of an employee record, payslip or print sheet are recorded.
Database-level separation
Row-level security in the database refuses one client's records to anyone not entitled to that client, even if application code were to omit a filter.
Two-step verification
Optional per account: a code from an authenticator app after the password, with single-use recovery codes. An administrator can reset it.
Suspending an account
An account can be suspended: it keeps its record and history, cannot sign in, and every open session ends.
Time-limited support access
The owner can give a preparer access to one client for a set time, with a reason. It ends by itself and can be revoked; granting and revoking are recorded.
Masking and disclosure
Identification numbers and bank accounts are masked on screen; showing one in full is recorded with who, which employee and which field.
Export and erasure
Everything held about an employee can be exported as one file. After the retention period the owner sets, a leaver's identity can be erased while their pay figures remain.
Session revocation
Every session can be ended on demand — by the user from their own account page, or by an administrator for anyone. Outstanding sign-ins stop working immediately rather than lasting until they expire, and a password change ends them too.
Password change and reset
A password can be changed from the account page, or reset through a single-use link an administrator issues that expires after two hours. Only the hash of a reset link is stored, so the link cannot be recovered from the database.
Transport security
Served only over HTTPS with strict transport security, a content security policy, and framing denied. Encryption at rest is provided by the database platform.
Outstanding
| Control | Current state | Area |
|---|---|---|
| Legal documentation | Privacy notice, processing agreements, retention schedule, sub-processor list and breach procedure are not written. | Legal |
Statutory calculation
Relevant to accuracy rather than privacy, and stated for the same reason.