Data processing agreement
Last updated: 22.07.2026
On this page
- Who is responsible for what
- What we process, and why
- We act on your instructions
- Confidentiality
- Security
- Health and other sensitive data
- Sub-processors
- Where the data is stored
- Helping you answer employee requests
- If something goes wrong
- Impact assessments and consultation
- Keeping, returning and deleting data
- Audits and information
- Marketplace options
- How this fits with our terms
- Changes to this agreement
- Annex 1 - Details of the processing
- Annex 2 - Security measures
- Annex 3 - Sub-processors
- Contact us
This agreement sets out how we handle the personal data you put into Salary.lu - above all, the data of the employees whose payroll you run. It exists because Article 28 of the GDPR requires a written agreement whenever one organisation processes personal data on behalf of another, and it sets out what that agreement has to say.
It forms part of our terms of service and applies from the moment you accept them. You do not need to sign anything separately, though we can provide a signed copy on request. Where it uses a defined term from the GDPR, that term carries its GDPR meaning.
How we handle data where we decide the purposes ourselves - your own contact and billing details - is a different matter, and is covered by our privacy policy rather than by this agreement.
Who is responsible for what
Salary.lu is used in two ways, and which one applies to you determines the roles.
You run your own payroll
You are the controller: you decide why and how your employees' data is processed. We are your processor and act on your instructions.
You run payroll for others
If you are a fiduciary, accountant or payroll provider, the employer is the controller, you are their processor, and we are your sub-processor.
Our obligations under this agreement are the same in both cases. Throughout, "you" means whichever of the two applies to you, and "the controller" means the employer whose payroll is being run.
If you act for other businesses, it is your responsibility to make sure your own agreement with each client permits you to use an external provider, and that they have been told about us.
What we process, and why
The details required by Article 28(3) are set out in Annex 1 below: the subject matter and duration of the processing, its nature and purpose, the types of personal data, and the categories of people the data relates to.
In short: we host and operate the platform on which you prepare payroll, and we process employee data only to make that platform work for you. We do not use it for our own purposes, we do not sell it, and we do not use it to train models or to build products.
We act on your instructions
We process personal data only on your documented instructions. Your instructions consist of this agreement, the terms of service, and what you do in the platform itself - creating a payslip is an instruction to calculate and produce it.
The one exception is where EU or Luxembourg law requires us to process data for another reason. If that happens, we will tell you before we act, unless the law forbids us from telling you.
If we believe an instruction you give us breaks data protection law, we will say so.
Confidentiality
Only the people who need access to do their job get it. Everyone at Salary.lu who can reach personal data is bound by a duty of confidentiality that continues after they stop working with us, and is trained on how to handle it.
Security
We apply appropriate technical and organisational measures to protect personal data, taking into account the state of the art, the cost of implementation, and the risk to the people whose data it is. Those measures are described in Annex 2.
Payroll data is sensitive by nature - it reveals what people earn, and often whether they have been ill - so we treat the whole platform as a high-risk environment rather than applying stronger controls only to selected fields.
Health and other sensitive data
Running payroll in Luxembourg means recording sickness absence, which is health data - a special category under Article 9 of the GDPR, requiring particular care.
The platform also lets you upload an employee's medical certificate. This is optional: nothing in the Service requires it, and payroll can be run without it. Where you do upload one, it is stored as a reference so that you and the employee can go back to it if a question about the absence comes up later. We process it only to store and display it to you - we do not read it, analyse it or use it in any calculation.
Deciding whether to upload certificates at all is yours to make as controller, and so is having a lawful basis for keeping them - normally your obligations under employment and social security law. If you do not need them, the safer course is not to upload them.
Because payroll involves special category data on a regular basis, a data protection impact assessment may be required on your side. We will give you what you need to complete one.
Sub-processors
We use a small number of other providers to deliver the Service - for hosting and backups above all. They are listed in Annex 3. You give us general authorisation to use them, and to appoint others where we need to.
Every sub-processor is bound by written obligations no weaker than the ones in this agreement, and we remain fully responsible to you for what they do.
If we plan to add or replace a sub-processor, we will tell you at least 30 days beforehand, by email and on the News page in the platform. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will look for a workable alternative; if there is none, you may end your subscription without penalty for the remainder of the period you have paid for.
Where the data is stored
Payroll data stays in the European Union. The platform and its database run in the EU region on Heroku, documents are stored in AWS S3 in Paris, email is sent through AWS SES in Frankfurt, and declarations reach the CCSS through a dedicated server in the EU. Annex 3 lists each provider and where it operates.
Two of the tools we use for monitoring and debugging - Sentry and Papertrail - are based in the United States. They receive technical diagnostic data such as error reports and application logs, not payroll data, and we do not use them to transfer employee information out of the EU.
Where a transfer outside the EU is necessary, we only make it on a legal basis permitted by Chapter V of the GDPR - an adequacy decision, or the European Commission's standard contractual clauses with additional safeguards - and we will tell you before introducing a new one.
Helping you answer employee requests
Employees have rights over their data: access, correction, erasure, restriction, portability and objection. Those requests are for you to answer, because you are the controller, not us.
If an employee contacts us directly, we will not answer on your behalf. We will pass the request to you promptly and tell the person we have done so.
We will help you respond, taking into account the nature of the processing and the information available to us. Most of what you need can be exported from the platform yourself; where it cannot, ask us.
If something goes wrong
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours of becoming aware of it.
We will tell you what happened, which categories of data and roughly how many people are affected, what the likely consequences are, and what we are doing about it. Where we do not have the full picture yet, we will give you what we have and follow up rather than waiting.
Notifying the CNPD, and the affected employees where required, is your decision and your responsibility as controller. You have 72 hours from the moment you become aware of a breach to notify the CNPD - which is why we commit to reaching you well inside that window, so that you have time to assess the situation and act.
Impact assessments and consultation
Where you need to carry out a data protection impact assessment, or to consult the CNPD beforehand, we will give you reasonable assistance and the information you need about how we process the data. Annex 2 is usually the starting point.
Keeping, returning and deleting data
We keep personal data for as long as you have an account with us, and afterwards on the basis set out here.
Your account and its documents stay available to you after a subscription ends, so that you can reach your payroll history when you need it. Treat that continued storage as your standing instruction to us to retain the data - it reflects the fact that Luxembourg law requires you to keep payroll and accounting records for ten years, and that responsibility is yours, not ours.
You can ask us at any time to delete your data. Because deletion is permanent and cannot be undone, we only act on a written request sent by email from the address on your account, and we will ask you to confirm before we proceed. We delete from our live systems within 30 days of that confirmation, and from backups as those backups are cycled out. Where a law requires us to keep something for longer, we will tell you what and why.
The GDPR also gives you the choice of having your data returned rather than deleted. In practice you do not need to ask us for that: your documents and payroll history stay exportable from your account, so you can take a copy whenever you want. If you need something the platform cannot export, ask us and we will provide it.
Export what you need before requesting deletion. Once it is gone, we cannot produce it again for you or for an inspection.
Audits and information
We will give you the information you reasonably need to show that we are meeting our obligations under Article 28, and will allow audits carried out by you or by an auditor you appoint.
In practice, we ask you to start with the documentation we can provide, since it answers most questions without an on-site visit. Where an audit is still necessary, give us reasonable notice, keep it to normal working hours, respect the confidentiality of other customers' data, and bear the cost unless the audit uncovers a material failure on our side.
Marketplace options
When you activate an option from our Marketplace, the provider behind it may receive some of your data. Whether they act as our sub-processor or as an independent controller you contract with directly depends on the option, and we tell you which applies before you activate it.
How this fits with our terms
This agreement forms part of our terms of service. The limits on liability set out there apply to this agreement too, except where the GDPR does not allow them to.
If anything in this agreement conflicts with the terms of service on a data protection question, this agreement wins.
Changes to this agreement
We may update this agreement, for instance when a sub-processor changes or the law does. We will tell you at least 30 days before a material change takes effect, by email and on the News page in the platform. The date at the top of this page shows when the current version came into force.
Annex 1 - Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing the Salary.lu payroll platform to you |
| Duration | For as long as you have an account, plus the retention described above |
| Nature | Hosting, storage, calculation, document generation, transmission and deletion |
| Purpose | Preparing and managing payroll and related HR documents for the employer |
| Controller | The employer whose payroll is being run |
Categories of people
- Employees and former employees of the controller
- Directors and officers who are on the payroll
Types of personal data
| Category | Examples |
|---|---|
| Identification | Name, date of birth, national identification number (matricule) |
| Contact | Address, email address |
| Employment | Job title, contract type, start and end dates, working time, work location |
| Pay | Salary, bonuses, benefits in kind, deductions, tax class, allowances |
| Banking | IBAN and account holder, for payment of salaries |
| Tax and social security | CCSS matricule, tax card details, contribution rates |
| Absence | Leave, sickness absence and medical certificates where uploaded (special category data) |
| Family situation | Marital status, where it affects the calculation |
The exact set depends on what you enter. We do not require fields that are not needed for the calculation.
Annex 2 - Security measures
The measures below are the ones we apply under Article 32. They are reviewed regularly and may be improved over time, but never reduced below the level described here.
| Area | Measure |
|---|---|
| Hosting | The platform and its database run on Heroku in the EU region, on AWS-backed data centres. Documents are stored in AWS S3 (Paris) and email is sent through AWS SES (Frankfurt). Heroku holds SOC 2 Type II certification and aligns with ISO 27001. We keep no servers in our own office. |
| Encryption | All connections use TLS. The database, file storage and backups are encrypted at rest. |
| Access control | Role-based access within the platform, least-privilege access for our staff, and two-factor authentication available on every account. |
| Separation | Each customer's data is logically separated from every other customer's. |
| CCSS transmission | Declarations are sent to the CCSS over the SECUline channel through a dedicated server used for no other purpose. |
| Backups | Automated database backups, retained and recoverable. |
| Monitoring | Errors are monitored through Sentry and application logs through Papertrail, limited to technical diagnostic data. |
| People | Confidentiality undertakings, data protection training, and access removed on departure. |
| Maintenance and incidents | Dependencies are monitored and patched, security updates are applied promptly, and we follow a documented procedure for detecting, assessing and reporting breaches. |
Annex 3 - Sub-processors
The providers below process personal data on our behalf in order to deliver the Service.
| Provider | Purpose | Location |
|---|---|---|
| Heroku (Salesforce) | Application hosting and production database (Heroku Postgres) | European Union |
| Amazon Web Services | Document and attachment storage (S3) | European Union |
| Amazon Web Services | Transactional and notification email delivery (SES) | European Union |
| Amazon Web Services | Dedicated server transmitting payroll declarations to the CCSS over SECUline (EC2) | European Union |
| Sentry | Error and performance monitoring - technical diagnostic data only | United States |
| SolarWinds Papertrail | Log management - technical diagnostic data only | United States |
Note that the tools listed in our privacy policy for analytics and advertising - Google, LinkedIn and Facebook - relate to data for which we are the controller, such as how you use our website. They are not sub-processors of payroll data.
Contact us
For anything about this agreement, write to us at info@salary.lu