Trust

Built for payroll data from the ground up.

Pay data is the most sensitive thing an employer holds, and a wrong answer about someone’s pay destroys trust for good. Netto is designed around both facts.

Last updated 20 September 2026 · questions to security@gnetto.com

Two construction workers comparing pay messages on their phones

Netto is preparing for its first UK customers. Our data processing agreement, DPIA template and transfer risk assessment are being finalised with our data protection adviser, and will be in place before any customer data is loaded. This page describes how Netto is designed to operate.

How the AI works

The AI explains. Code calculates. Every figure shows its source.

An AI assistant bolted onto payroll will eventually invent a tax rate. Netto's architecture makes that structurally impossible.

Grounded.

Every answer comes only from the employee's own payslip, their previous payslip, and vetted statutory rules for their country. No open web, no guessing.

Cited.

Every figure carries a citation to its payslip line, checked in code before the reply is sent. If a number can't be cited, the reply isn't sent.

Guarded.

The AI never does arithmetic. Any number that is not on the payslip comes from a tested rules engine with dated official rates, and the AI cannot state a figure the engine did not produce. Anything the payslip can't answer is handed to a named human in HR.

Approved.

Resolve never changes a payroll record. It raises an evidenced query with the employee's explicit tap; your team makes the correction. Every action is logged for both sides.

Roles

Controller and processor

The employer is the data controller. Netto is designed to process only on documented instruction, under an Article 28 DPA agreed before any data is loaded. Netto never sells data and never uses it to train models. Third parties are limited to the sub-processors listed below.

Data

Minimised and protected data

  • · Only the fields needed to deliver and explain a payslip
  • · Bank details, tax IDs and addresses can be stripped at import
  • · Payslips are password-protected; hosting region is confirmed in writing before any data is loaded
  • · Encrypted in transit and at rest; access limited to named Netto staff on a need-to-know basis

Sub-processors

Who else touches the data

Sub-processorPurposeData
TwilioWhatsApp Business API delivery of payslips and Q&A messagesMobile number, message content, delivery status
Meta Platforms (WhatsApp)Message carriage to the employee's deviceMobile number, message content
SupabaseApplication database, authentication and encrypted document storageEmployee record, payslip data, audit log
Google (Gemini models, via AI gateway)Extracting payslip lines and generating grounded explanationsPayslip figures and the employee's question, at inference time only
Lovable / CloudflareApplication hosting and edge deliveryRequest metadata, in-transit application traffic
ResendTransactional email to employer administrators (never to employees)Administrator name and work email

Hosting regions and international transfer safeguards for each sub-processor are being confirmed, and will be set out in the compliance pack before any customer data is loaded.

Certifications

We show what we do and evidence it

Netto is designed to support UK GDPR, the Data Protection Act 2018 and US state privacy obligations. We don't claim certifications we haven't obtained.

Ready when your next run is.