Trust
Built for payroll data from the ground up.
Pay data is the most sensitive thing an employer holds, and a wrong answer about someone's pay destroys trust for good. Netto is designed around both facts.
Last updated 20 August 2026 · questions to security@gnetto.com
How the AI works
Explains. Never calculates.
An AI assistant bolted onto payroll will eventually invent a tax rate. Netto's architecture makes that structurally impossible.
Grounded.
Every answer comes only from the employee's own payslip, their previous payslip, and vetted statutory rules for their country. No open web, no guessing.
Cited.
Every figure carries a citation to its payslip line, checked in code before the reply is sent. If a number can't be cited, the reply isn't sent.
Guarded.
The AI explains; it never calculates. Anything the payslip can't answer is handed to a named human in HR.
Approved.
Resolve never changes a payroll record. It raises an evidenced query with the employee's explicit tap; your team makes the correction. Every action is logged for both sides.
Roles
Controller and processor
The employer is the data controller. Netto processes only on documented instruction under an Article 28 DPA signed at registration. We never sell data, never use it to train models, and never share it with a third party except the sub-processors listed below.
Consent
Consent, opt-out and audit trail
- · Delivery is backed by a recorded opt-in from each employee
- · Replying STOP ends delivery immediately
- · Every import, send, receipt, query, escalation and export is logged and exportable
Data
Minimised and protected data
- · Only the fields needed to deliver and explain a payslip
- · Bank details, tax IDs and addresses can be stripped at import
- · Payslips are password-protected; data at rest sits in the EU
- · Encrypted in transit and at rest; access limited to named Netto staff on a need-to-know basis
Sub-processors
Who else touches the data
| Sub-processor | Purpose | Data | Region | Transfer |
|---|---|---|---|---|
| Twilio | WhatsApp Business API delivery of payslips and Q&A messages | Mobile number, message content, delivery status | United States / EU | SCCs + UK Addendum |
| Meta Platforms (WhatsApp) | Message carriage to the employee's device | Mobile number, message content | United States / Ireland | SCCs + UK Addendum |
| Supabase | Application database, authentication and encrypted document storage | Employee record, payslip data, audit log | EU region | No transfer — data at rest held in the EU |
| Google (Gemini models, via AI gateway) | Extracting payslip lines and generating grounded explanations | Payslip figures and the employee's question, at inference time only | United States / EU | SCCs + UK Addendum; no training on client data, no retention |
| Lovable / Cloudflare | Application hosting and edge delivery | Request metadata, in-transit application traffic | Global edge, EU-primary | SCCs + UK Addendum |
| Resend | Transactional email to employer administrators (never to employees) | Administrator name and work email | United States / EU | SCCs + UK Addendum |
Certifications
We show what we do and evidence it
Netto is designed to support UK GDPR, the Data Protection Act 2018 and US state privacy obligations. We don't claim certifications we haven't obtained.