This notice explains how PayFlow Ireland (“PayFlow”, “we”, “us”) handles personal data when you visit our website, use PayFlow Ireland payroll software, or are an employee whose employer uses it. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
PayFlow Ireland is operated by PayFlow Ireland. For anything about your personal data, email info@payflowireland.ie. We are not required to appoint a Data Protection Officer; this address reaches the person responsible for data protection.
Controller for data about our own customers and visitors: the people who sign up, sign in, pay us, contact us or browse our website. We decide why and how that data is used.
Processor for the payroll data an employer (or their accountant) puts into PayFlow: their employees’ details, pay and tax. The employer is the controller of that data. We use it only to provide the service, on the employer’s instructions, under our Data Processing Agreement.
If you are an employee whose payroll is run on PayFlow, your employer decides what is collected about you and why. Please contact your employer first about your data; if you contact us, we will pass your request to them and help them answer it.
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account details: name, email, password (stored only as a one-way hash), two-factor settings, the organisations you belong to and your role | To create and secure your account and let you use the service | Contract (6(1)(b)) |
| Business and billing details: company name, billing contact, plan, invoices. Card details are entered on Stripe’s pages and never reach us | To charge for the service and keep accounting records | Contract (6(1)(b)); legal obligation (6(1)(c)) for tax records |
| Security and audit records: sign-ins, actions taken in the software, and a keyed fingerprint of your IP address and browser (not the address itself) | To protect accounts, detect misuse, and give employers an audit trail of who did what | Legitimate interests (6(1)(f)): keeping the service and payroll data secure |
| Support tickets, enquiries and emails you send us | To answer you | Legitimate interests (6(1)(f)); contract where you are a customer |
| Service emails: payroll reminders, notices about your account | To run the service. Reminders can be turned off in Administration | Contract (6(1)(b)) |
We do not use advertising or analytics trackers, we do not sell personal data, and we do not send marketing email without your consent.
Depending on what the employer uses, this can include: employees’ names, dates of birth, contact details and addresses; PPS numbers and bank details (both stored encrypted); employment details, pay rates, hours and pay; tax credits and rate bands from Revenue (RPNs); auto-enrolment details from NAERSA (AEPNs); pension, benefit and deduction details; leave and absence records; and payslips.
Some leave records (for example certified sick leave) can reveal health information, which is special category data under GDPR Article 9. The employer is responsible for having a lawful basis for it; typically Article 9(2)(b), obligations in employment and social protection law. PayFlow restricts who can see such records and, for sensitive leave types, hides them from payslips.
Employers process this data mainly to meet their legal obligations as an employer (GDPR Article 6(1)(c)) and to perform employment contracts (Article 6(1)(b)).
Payroll submissions go to the Revenue Commissioners, and auto-enrolment contributions to the National Automatic Enrolment Retirement Savings Authority (NAERSA), only when the employer or their accountant sends them. We may also disclose data where Irish or EU law requires it.
| Provider | What they do | Location |
|---|---|---|
| Laravel Cloud and Amazon Web Services | Hosting, database, backups, and secure storage of ROS certificates | Laravel Cloud, running on Amazon Web Services in the European Union |
| Brevo (Sendinblue SAS) | Sending email: invitations, payslip emails, reminders | European Union (France) |
| Stripe Payments Europe Ltd | Taking payment from our customers. Stripe sees billing details, not payroll data | Ireland / EU, with transfers under Stripe’s safeguards |
| Anthropic PBC | The optional AI features described in section 7 | United States |
Xero: if an employer connects Xero, PayFlow sends payroll journals (account totals, optionally by department, never individual employees’ details) to the employer’s own Xero account. Xero then acts for the employer, not for us.
We will tell customers before adding or replacing a sub-processor, as set out in the Data Processing Agreement.
Payroll data is hosted in the EU. Where a provider processes data outside the European Economic Area (Anthropic in the United States, and Stripe for some payment operations), the transfer is protected by the European Commission’s Standard Contractual Clauses in that provider’s data processing terms, or by an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified.
Two optional features use Anthropic’s Claude models:
Nothing is sent unless someone uses the feature. Under Anthropic’s commercial terms, data sent through its API is not used to train its models. The AI never makes payroll decisions: every figure is calculated by PayFlow’s own rules and reviewed by a person before approval.
| Data | How long |
|---|---|
| Payroll records: pay, tax, payslips, submissions | While the customer’s account is open. After it closes, we keep them for 6 years from the end of the tax year of the last payroll, because employers must be able to produce them to Revenue for that long. Earlier deletion on the employer’s written instruction, after they have exported their data. |
| Leave and working time records | For the periods set by employment law (for example 3 years for working time records, 8 years for parental leave), or longer while the account is open. |
| Audit trails | For as long as the payroll records they relate to. They cannot be edited or deleted early. |
| Customer account and billing records | While the account is open, then 6 years for tax and legal claims. |
| Enquiries from people who did not become customers | 2 years. |
| Backups | Overwritten on a rolling basis by our hosting provider. |
Data is encrypted in transit (HTTPS) and at rest. PPS numbers and bank details are additionally encrypted field by field. Staff accounts can use two-factor authentication; access is limited by role; every change to payroll and every opening of a payslip is recorded in an audit trail that cannot be altered. Revenue certificates are held in a dedicated secrets store. PayFlow staff can view a customer’s records only for a stated support reason, for one hour at a time, and the customer can see each such access in their own audit trail.
If a personal data breach affects payroll data, we tell the employer without undue delay so they can meet their own duty to notify the Data Protection Commission within 72 hours.
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; receive it in a portable format; and withdraw consent where processing is based on consent. Some rights are limited where the law requires records to be kept (for example payroll records Revenue may audit).
Email info@payflowireland.ie. We reply within one month. For payroll data, employees should ask their employer, who can export it from PayFlow; we will help the employer respond.
Please tell us first and we will try to put it right. You can also complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, at www.dataprotection.ie.
We will post any change here with a new version date and, for significant changes, email account owners beforehand. Cookies are covered in our Cookie Notice.