This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (the controller) and PayFlow Ireland (the processor, “PayFlow”). It sets out the terms required by Article 28(3) of the GDPR. Where a practice uses PayFlow for a client, the client is the controller, the practice is its processor, and PayFlow is the practice’s sub-processor on these same terms.
| Subject matter | Providing PayFlow Ireland payroll software and related services. |
|---|---|
| Duration | For as long as the customer uses the service, and afterwards until the data is deleted or returned under section 9. |
| Nature and purpose | Storing, calculating and organising payroll data; producing payslips, reports and payment files; sending submissions to Revenue and NAERSA and journals to accounting software when the controller instructs; giving employees access to their own payslips and leave. |
| Categories of data subjects | The controller’s employees, former employees and directors; the controller’s staff and advisers who use the service. |
| Types of personal data | Identity and contact details; date of birth; PPS number; bank details; employment, pay, tax, PRSI, USC, LPT, pension and benefit details; Revenue RPN and NAERSA AEPN data; leave, absence and working time records; payslips; audit records of actions in the software. |
| Special categories | Leave and absence records that may reveal health information (Article 9). Processed only as the controller’s employment-law obligations require. |
PayFlow processes the personal data only on the controller’s documented instructions. Those instructions are these terms and the controller’s use of the service’s features. The exception is where EU or Irish law requires otherwise, in which case PayFlow will tell the controller first unless the law forbids it. PayFlow will tell the controller if it believes an instruction breaks data protection law.
Everyone at PayFlow who can access the personal data is bound by a duty of confidentiality. Access by PayFlow staff to a customer’s records requires a stated support reason, lasts one hour, and is shown to the controller in its own audit trail.
PayFlow maintains appropriate technical and organisational measures, including:
The controller gives general authorisation for PayFlow to use the sub-processors listed in the Privacy Notice. PayFlow will give at least 30 days’ notice by email before adding or replacing one. The controller may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the controller may end the agreement without penalty. PayFlow imposes the same data protection obligations on each sub-processor and remains responsible for them.
Revenue, NAERSA and the controller’s own connected accounting software receive data because the controller instructs it. They are not PayFlow’s sub-processors.
PayFlow hosts the data in the EU. Any transfer outside the EEA by a sub-processor is protected by an adequacy decision or the European Commission’s Standard Contractual Clauses.
Taking into account the nature of the processing, PayFlow will:
PayFlow will notify the controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting its data. The notice will include what is known about the nature of the breach, the data and people affected, likely consequences, and the measures taken. Further information will follow as it becomes available.
When the service ends, the controller can export its data for at least 90 days. After that, PayFlow keeps payroll records for 6 years from the end of the tax year of the last payroll, so the controller can meet its record-keeping obligations, and then deletes them. The controller may instead instruct earlier deletion in writing. Copies in backups are overwritten on the hosting provider’s rolling schedule.
PayFlow will make available the information needed to show compliance with Article 28. It will allow and contribute to audits by the controller or an auditor it appoints, on at least 30 days’ notice, during working hours, and no more than once a year unless a breach or a regulator requires it. Any auditor must be bound by confidentiality.
Liability under this DPA is subject to the limits in the Terms of Service, except where the GDPR does not allow it to be limited. If this DPA and the Terms conflict on data protection, this DPA wins.