Privacy & data protection

Confidential payroll information, access and accountability.

Trust centre

Privacy by design

PayrollGrid is being designed around confidentiality, the Mauritius Data Protection Act and GDPR-level privacy principles. This page describes the intended product controls; formal compliance requires legal, technical and operational verification before production release.

Company data separation

Users see only authorised companies. Employee payroll records remain inside the correct company environment and are not copied into general practice dashboards.

Role-based access

Preparation, review, approval, finalisation, export and administration permissions are separated and recorded.

Audit history

Views, edits, imports, approvals, finalisation, reopening, exports and temporary support access should be logged.

Data minimisation

Dashboards and notifications display only what is necessary. Salary, bank and identification details are masked where full visibility is not required.

Retention and requests

Retention periods, access requests, correction, export, deletion or anonymisation processes must be defined before commercial launch.

Secure support

Temporary access is explicit, time-limited, restricted, revocable and fully audited. Support staff receive no automatic payroll access.

Production controls still required

These items are outside this static interface prototype.

!
Authentication and MFASecure login, privileged-user MFA, session expiry and failed-login protection.
Backend
!
Encryption and secure storageEncryption in transit and at rest, protected backups and controlled document access.
Backend
!
Legal documentationPrivacy notice, processing agreements, retention schedule, sub-processors and breach procedures.
Legal