Privacy & data

Privacy & data protection

What this system actually does with confidential payroll information.

In place today

14 controls

Company data separation

Users see only the companies they are authorised for. Scoping is applied in the database query, so records outside a user's access are never loaded, not merely hidden in the interface. Verified against the live site: a company administrator requesting another company's payroll by direct URL receives a 404.

Role-based access

One owner account sees the whole portfolio. Preparers see only the clients assigned to them, and company administrators only their own companies. Every server action re-checks access rather than trusting the page that called it.

Session expiry

Sessions last eight hours and refresh hourly, rather than the framework default of thirty days.

Failed-login protection

Five failed attempts against an address within fifteen minutes lock it out; a correct password clears the count. Failed attempts are recorded. The sign-in form does not reveal whether an address exists.

Audit history

Every edit to a pay line records the user, the field, the value and the statutory rule pack that produced the resulting figures. Sign-ins and sign-outs, password and session events, account changes, pay run stage changes, every return, report and payment file downloaded, and every opening of an employee record, payslip or print sheet are recorded.

Database-level separation

Row-level security in the database refuses one client's records to anyone not entitled to that client, even if application code were to omit a filter.

Two-step verification

Optional per account: a code from an authenticator app after the password, with single-use recovery codes. An administrator can reset it.

Suspending an account

An account can be suspended: it keeps its record and history, cannot sign in, and every open session ends.

Time-limited support access

The owner can give a preparer access to one client for a set time, with a reason. It ends by itself and can be revoked; granting and revoking are recorded.

Masking and disclosure

Identification numbers and bank accounts are masked on screen; showing one in full is recorded with who, which employee and which field.

Export and erasure

Everything held about an employee can be exported as one file. After the retention period the owner sets, a leaver's identity can be erased while their pay figures remain.

Session revocation

Every session can be ended on demand — by the user from their own account page, or by an administrator for anyone. Outstanding sign-ins stop working immediately rather than lasting until they expire, and a password change ends them too.

Password change and reset

A password can be changed from the account page, or reset through a single-use link an administrator issues that expires after two hours. Only the hash of a reset link is stored, so the link cannot be recovered from the database.

Transport security

Served only over HTTPS with strict transport security, a content security policy, and framing denied. Encryption at rest is provided by the database platform.

Outstanding

1 outstanding
ControlCurrent stateArea
Legal documentationPrivacy notice, processing agreements, retention schedule, sub-processor list and breach procedure are not written.Legal

Statutory calculation

Relevant to accuracy rather than privacy, and stated for the same reason.

PAYE, CSG, NSF and the training levy are calculated from rule packs sourced from published Mauritius Revenue Authority material. PAYE is currently non-cumulative, while real MRA PAYE is cumulative across the income year and depends on each employee’s Employee Declaration Form reliefs. Figures produced by this system have not been through independent payroll review and must not be treated as final without it.