Security & compliance
Payroll data, handled like payroll data.
Netto is a processor acting on the employer's instruction. This page sets out our sub-processors, where data sits, how transfers are covered, and the answers procurement and works councils ask for before a pilot starts.
Last updated 20 August 2026 · questions to security@gnetto.com
Controls
What we do, and what we deliberately don't do
Netto explains payslips. It does not recalculate them, does not advise, and does not need most of the data a payroll system holds.
Encryption
Data is encrypted in transit with TLS and at rest by the storage layer. Payslip documents are held in access-controlled storage, never in a public bucket.
Access control
Employer administrators see only their own organisation, enforced at the database layer with row-level security rather than in application code alone. Netto staff access is role-based and limited to named accounts.
Data minimisation
Imports carry only the fields needed to deliver and explain a payslip. Bank details, tax identifiers and home addresses are not required and can be stripped at import.
Audit logging
Every import, opt-in, opt-out, send, delivery receipt and administrator action is written to an immutable audit trail that the employer can export.
AI boundaries
The model explains and cites; it never recalculates a figure or gives advice. Answers are grounded in the supplied payslip, with zero-retention inference and no training on client data.
Segregation and deletion
Client data is logically segregated per organisation. On termination, data is deleted or returned within the period set in the DPA.
Vulnerability reporting
Report a suspected vulnerability to security@gnetto.com. We acknowledge within one business day and will not pursue good-faith researchers who avoid privacy violations and service disruption.
Pilot stage disclosure
Netto is an early-stage company running its first pilots. We hold no formal certification today; we tell you what we do and evidence it, rather than implying an audit we have not completed.
Sub-processors
Everyone who touches the data
Employers are notified before a new sub-processor is added, with the right to object as set out in the data processing agreement.
| Sub-processor | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Twilio | WhatsApp Business API delivery of payslips and Q&A messages | Mobile number, message content, delivery status | United States / EU | SCCs + UK Addendum |
| Meta Platforms (WhatsApp) | Message carriage to the employee's device | Mobile number, message content | United States / Ireland | SCCs + UK Addendum |
| Supabase | Application database, authentication and encrypted document storage | Employee record, payslip data, audit log | EU region | No transfer — data at rest held in the EU |
| Google (Gemini models, via AI gateway) | Extracting payslip lines and generating grounded explanations | Payslip figures and the employee's question, at inference time only | United States / EU | SCCs + UK Addendum; no training on client data, no retention |
| Lovable / Cloudflare | Application hosting and edge delivery | Request metadata, in-transit application traffic | Global edge, EU-primary | SCCs + UK Addendum |
| Resend | Transactional email to employer administrators (never to employees) | Administrator name and work email | United States / EU | SCCs + UK Addendum |
International transfers
SCCs and the UK Addendum
Message delivery and model inference involve providers that may process data outside the UK and EEA. Here is exactly how that is covered.
EU / EEA
Employee records, payslips and audit logs are held at rest in the EU. Where a sub-processor processes data in the United States, the European Commission's Standard Contractual Clauses (Module 3, processor to processor) apply, supported by a transfer risk assessment.
United Kingdom
UK transfers rely on the same SCCs as modified by the ICO's International Data Transfer Addendum (UK Addendum), incorporated into every sub-processor agreement and flowed down through our DPA with the employer.
Supplementary measures
Encryption in transit and at rest, data minimisation before any transfer, no training or retention on the AI side, and contractual commitments to challenge and notify on government access requests where legally permitted.
GDPR FAQ
The questions procurement always asks
Short answers you can paste into a supplier assessment. The full DPA, sub-processor list and DPIA template are available on request.
▸Who is the controller and who is the processor?
The employer is the data controller for its payroll data. Netto acts solely as a processor, on documented instruction, under an Article 28 data processing agreement signed at registration. Netto never uses employee data for its own purposes.
▸What is the lawful basis for sending a payslip over WhatsApp?
Issuing an itemised pay statement is a legal obligation of the employer, and the employment contract is the basis for processing the underlying payroll data. Because employee consent is rarely freely given, Netto does not rely on it for the payslip itself. Netto does rely on a recorded opt-in for the WhatsApp channel and for any optional service such as earned wage access, and every opt-in and opt-out is timestamped in the audit log.
▸How does an employee opt out?
Replying STOP on WhatsApp ends delivery immediately and is recorded in the audit trail. The employer is notified so it can fall back to its previous delivery method. Opting out of the channel never affects the employee's right to receive a payslip.
▸Is any of this an automated decision with legal effect?
No. Netto explains payslips; it does not recalculate them, does not change pay, and does not make decisions about a person. Every figure in an answer is cited back to the source line on the payslip so the employee can verify it. Article 22 does not apply.
▸Does the AI model train on our payroll data?
No. Payslip data is sent to the model at inference time only, under a zero-retention, no-training configuration. Model outputs are grounded in the supplied payslip and are not used to improve any model.
▸What data does Netto actually need?
The minimum to deliver and explain a payslip: name, employee reference, mobile number, job title, and the payslip itself. Netto does not require bank account numbers, national insurance or social security numbers, or home addresses, and identifiers that are not needed can be stripped at import.
▸Where is the data held, and are there international transfers?
Employee records, payslips and audit logs are held at rest in the EU. Message delivery and model inference involve sub-processors that may process data in the United States, covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, with a transfer risk assessment on file.
▸How long is data retained?
Payslip content is retained on a rolling period agreed with the employer — 13 months by default — after which it is deleted. Consent and delivery audit records are kept for the longer of the pilot term or the employer's statutory retention period, because they evidence that the payslip was issued. Retention is configurable per client and deletion on termination is contractual.
▸How are subject access, rectification and erasure requests handled?
Requests are made to the employer as controller. Netto supports the employer within 72 hours: records can be exported or deleted per employee from the console, and the audit log shows exactly what was delivered and when.
▸What happens in the event of a personal data breach?
Netto notifies the employer without undue delay after becoming aware, with the facts known at that point, so the employer can meet its own 72-hour regulatory deadline. Netto supports the employer's assessment and any communication to affected employees.
▸Do we need a DPIA?
Most employers will, because this is systematic processing of employee data through a new channel. Netto provides a pre-filled DPIA template covering the processing described here, which the employer completes and owns.
▸Can our works council or union review this first?
Yes, and we encourage it. The DPA, sub-processor list, DPIA template and a walkthrough of the employee experience are available before any data is loaded, and pilots can start with a volunteer group.
Next step
Need the full pack before you can pilot?
We'll send the data processing agreement, sub-processor list, DPIA template and a walkthrough of the employee experience — before any data is loaded.