Security & compliance

Payroll data, handled like payroll data.

Netto is a processor acting on the employer's instruction. This page sets out our sub-processors, where data sits, how transfers are covered, and the answers procurement and works councils ask for before a pilot starts.

Last updated 20 August 2026 · questions to security@gnetto.com

Controls

What we do, and what we deliberately don't do

Netto explains payslips. It does not recalculate them, does not advise, and does not need most of the data a payroll system holds.

Encryption

Data is encrypted in transit with TLS and at rest by the storage layer. Payslip documents are held in access-controlled storage, never in a public bucket.

Access control

Employer administrators see only their own organisation, enforced at the database layer with row-level security rather than in application code alone. Netto staff access is role-based and limited to named accounts.

Data minimisation

Imports carry only the fields needed to deliver and explain a payslip. Bank details, tax identifiers and home addresses are not required and can be stripped at import.

Audit logging

Every import, opt-in, opt-out, send, delivery receipt and administrator action is written to an immutable audit trail that the employer can export.

AI boundaries

The model explains and cites; it never recalculates a figure or gives advice. Answers are grounded in the supplied payslip, with zero-retention inference and no training on client data.

Segregation and deletion

Client data is logically segregated per organisation. On termination, data is deleted or returned within the period set in the DPA.

Vulnerability reporting

Report a suspected vulnerability to security@gnetto.com. We acknowledge within one business day and will not pursue good-faith researchers who avoid privacy violations and service disruption.

Pilot stage disclosure

Netto is an early-stage company running its first pilots. We hold no formal certification today; we tell you what we do and evidence it, rather than implying an audit we have not completed.

Sub-processors

Everyone who touches the data

Employers are notified before a new sub-processor is added, with the right to object as set out in the data processing agreement.

Sub-processorPurposeDataLocationTransfer safeguard
TwilioWhatsApp Business API delivery of payslips and Q&A messagesMobile number, message content, delivery statusUnited States / EUSCCs + UK Addendum
Meta Platforms (WhatsApp)Message carriage to the employee's deviceMobile number, message contentUnited States / IrelandSCCs + UK Addendum
SupabaseApplication database, authentication and encrypted document storageEmployee record, payslip data, audit logEU regionNo transfer — data at rest held in the EU
Google (Gemini models, via AI gateway)Extracting payslip lines and generating grounded explanationsPayslip figures and the employee's question, at inference time onlyUnited States / EUSCCs + UK Addendum; no training on client data, no retention
Lovable / CloudflareApplication hosting and edge deliveryRequest metadata, in-transit application trafficGlobal edge, EU-primarySCCs + UK Addendum
ResendTransactional email to employer administrators (never to employees)Administrator name and work emailUnited States / EUSCCs + UK Addendum

International transfers

SCCs and the UK Addendum

Message delivery and model inference involve providers that may process data outside the UK and EEA. Here is exactly how that is covered.

EU / EEA

Employee records, payslips and audit logs are held at rest in the EU. Where a sub-processor processes data in the United States, the European Commission's Standard Contractual Clauses (Module 3, processor to processor) apply, supported by a transfer risk assessment.

United Kingdom

UK transfers rely on the same SCCs as modified by the ICO's International Data Transfer Addendum (UK Addendum), incorporated into every sub-processor agreement and flowed down through our DPA with the employer.

Supplementary measures

Encryption in transit and at rest, data minimisation before any transfer, no training or retention on the AI side, and contractual commitments to challenge and notify on government access requests where legally permitted.

GDPR FAQ

The questions procurement always asks

Short answers you can paste into a supplier assessment. The full DPA, sub-processor list and DPIA template are available on request.

Who is the controller and who is the processor?

The employer is the data controller for its payroll data. Netto acts solely as a processor, on documented instruction, under an Article 28 data processing agreement signed at registration. Netto never uses employee data for its own purposes.

What is the lawful basis for sending a payslip over WhatsApp?

Issuing an itemised pay statement is a legal obligation of the employer, and the employment contract is the basis for processing the underlying payroll data. Because employee consent is rarely freely given, Netto does not rely on it for the payslip itself. Netto does rely on a recorded opt-in for the WhatsApp channel and for any optional service such as earned wage access, and every opt-in and opt-out is timestamped in the audit log.

How does an employee opt out?

Replying STOP on WhatsApp ends delivery immediately and is recorded in the audit trail. The employer is notified so it can fall back to its previous delivery method. Opting out of the channel never affects the employee's right to receive a payslip.

Is any of this an automated decision with legal effect?

No. Netto explains payslips; it does not recalculate them, does not change pay, and does not make decisions about a person. Every figure in an answer is cited back to the source line on the payslip so the employee can verify it. Article 22 does not apply.

Does the AI model train on our payroll data?

No. Payslip data is sent to the model at inference time only, under a zero-retention, no-training configuration. Model outputs are grounded in the supplied payslip and are not used to improve any model.

What data does Netto actually need?

The minimum to deliver and explain a payslip: name, employee reference, mobile number, job title, and the payslip itself. Netto does not require bank account numbers, national insurance or social security numbers, or home addresses, and identifiers that are not needed can be stripped at import.

Where is the data held, and are there international transfers?

Employee records, payslips and audit logs are held at rest in the EU. Message delivery and model inference involve sub-processors that may process data in the United States, covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, with a transfer risk assessment on file.

How long is data retained?

Payslip content is retained on a rolling period agreed with the employer — 13 months by default — after which it is deleted. Consent and delivery audit records are kept for the longer of the pilot term or the employer's statutory retention period, because they evidence that the payslip was issued. Retention is configurable per client and deletion on termination is contractual.

How are subject access, rectification and erasure requests handled?

Requests are made to the employer as controller. Netto supports the employer within 72 hours: records can be exported or deleted per employee from the console, and the audit log shows exactly what was delivered and when.

What happens in the event of a personal data breach?

Netto notifies the employer without undue delay after becoming aware, with the facts known at that point, so the employer can meet its own 72-hour regulatory deadline. Netto supports the employer's assessment and any communication to affected employees.

Do we need a DPIA?

Most employers will, because this is systematic processing of employee data through a new channel. Netto provides a pre-filled DPIA template covering the processing described here, which the employer completes and owns.

Can our works council or union review this first?

Yes, and we encourage it. The DPA, sub-processor list, DPIA template and a walkthrough of the employee experience are available before any data is loaded, and pilots can start with a volunteer group.

Next step

Need the full pack before you can pilot?

We'll send the data processing agreement, sub-processor list, DPIA template and a walkthrough of the employee experience — before any data is loaded.