Trust
Built for payroll data from the ground up.
Pay data is the most sensitive thing an employer holds, and a wrong answer about someone’s pay destroys trust for good. Netto is designed around both facts.
Last updated 20 September 2026 · questions to security@gnetto.com

Netto is preparing for its first UK customers. Our data processing agreement, DPIA template and transfer risk assessment are being finalised with our data protection adviser, and will be in place before any customer data is loaded. This page describes how Netto is designed to operate.
How the AI works
The AI explains. Code calculates. Every figure shows its source.
An AI assistant bolted onto payroll will eventually invent a tax rate. Netto's architecture makes that structurally impossible.
Grounded.
Every answer comes only from the employee's own payslip, their previous payslip, and vetted statutory rules for their country. No open web, no guessing.
Cited.
Every figure carries a citation to its payslip line, checked in code before the reply is sent. If a number can't be cited, the reply isn't sent.
Guarded.
The AI never does arithmetic. Any number that is not on the payslip comes from a tested rules engine with dated official rates, and the AI cannot state a figure the engine did not produce. Anything the payslip can't answer is handed to a named human in HR.
Approved.
Resolve never changes a payroll record. It raises an evidenced query with the employee's explicit tap; your team makes the correction. Every action is logged for both sides.
Roles
Controller and processor
The employer is the data controller. Netto is designed to process only on documented instruction, under an Article 28 DPA agreed before any data is loaded. Netto never sells data and never uses it to train models. Third parties are limited to the sub-processors listed below.
Consent
Consent, opt-out and audit trail
- · Delivery is backed by a recorded opt-in from each employee
- · Replying STOP ends delivery immediately
- · Every import, send, receipt, query, escalation and export is logged and exportable
Data
Minimised and protected data
- · Only the fields needed to deliver and explain a payslip
- · Bank details, tax IDs and addresses can be stripped at import
- · Payslips are password-protected; hosting region is confirmed in writing before any data is loaded
- · Encrypted in transit and at rest; access limited to named Netto staff on a need-to-know basis
Sub-processors
Who else touches the data
| Sub-processor | Purpose | Data |
|---|---|---|
| Twilio | WhatsApp Business API delivery of payslips and Q&A messages | Mobile number, message content, delivery status |
| Meta Platforms (WhatsApp) | Message carriage to the employee's device | Mobile number, message content |
| Supabase | Application database, authentication and encrypted document storage | Employee record, payslip data, audit log |
| Google (Gemini models, via AI gateway) | Extracting payslip lines and generating grounded explanations | Payslip figures and the employee's question, at inference time only |
| Lovable / Cloudflare | Application hosting and edge delivery | Request metadata, in-transit application traffic |
| Resend | Transactional email to employer administrators (never to employees) | Administrator name and work email |
Hosting regions and international transfer safeguards for each sub-processor are being confirmed, and will be set out in the compliance pack before any customer data is loaded.
Certifications
We show what we do and evidence it
Netto is designed to support UK GDPR, the Data Protection Act 2018 and US state privacy obligations. We don't claim certifications we haven't obtained.