Legal

Privacy Policy

Last updated: June 5, 2026

1. Introduction

Pavroll ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our HR and payroll management platform. By using Pavroll, you consent to the data practices described in this policy.

2. Information We Collect

We collect information you provide directly to us, including: - Company information (name, address, TIN, SSNIT employer code) - Employee information (name, email, phone, Ghana Card number, SSNIT number, bank details, salary) - Account credentials and authentication data via Clerk - Payment information processed through Paystack - Usage data and audit logs within the platform

3. How We Use Your Information

We use the information we collect to: - Process and manage your payroll calculations - Generate PDF payslips and SSNIT schedules - Send payslips to employees via email - Comply with Ghana Revenue Authority (GRA) regulations - Provide customer support and respond to inquiries - Improve and optimize our platform - Send important service notifications

4. Data Storage & Security

Your data is stored securely on Supabase (PostgreSQL database hosted in West EU - Ireland). We implement industry-standard security measures including: - Row Level Security (RLS) on all database tables - Encrypted data transmission via HTTPS/TLS - Authentication handled by Clerk with MFA support - Regular security audits and monitoring - Automated backups to prevent data loss

5. Ghana Data Protection Act Compliance

Pavroll complies with the Ghana Data Protection Act, 2012 (Act 843). We are registered with the Data Protection Commission of Ghana. You have the right to access, correct, and delete your personal data. To exercise these rights, contact us at privacy@pavroll.app.

6. Data Sharing

We do not sell your personal data. We may share data with: - Supabase (database hosting) - Clerk (authentication) - Paystack (payment processing) - Resend (email delivery) - Vercel (hosting infrastructure) All third-party providers are bound by data processing agreements and maintain appropriate security standards.

7. Employee Data

As an HR and payroll platform, we process employee personal data on behalf of your company. Your company acts as the Data Controller and Pavroll acts as the Data Processor. You are responsible for obtaining appropriate consent from your employees for data processing activities.

8. Data Retention

We retain your data for as long as your account is active. Payroll records are retained for 7 years in compliance with Ghana's tax regulations. Upon account deletion, we will delete or anonymize your data within 30 days, except where retention is required by law.

9. Cookies

We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. You can control cookies through your browser settings.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our platform. Continued use of Pavroll after changes constitutes acceptance of the updated policy.

11. Contact Us

For privacy-related questions or to exercise your data rights, contact us at: Email: privacy@pavroll.app Address: Accra, Ghana Data Protection Officer: Samuel Mensah