This policy explains how personal data is handled when your organisation uses the Ledra Pay platform to run payroll. It is written for our business customers and for the people whose payroll data is processed (employees and data subjects). It is general information, not legal advice.
When your organisation uses Ledra Pay to run payroll, your organisation is the data controller — you decide why and how employee data is processed. Ledra Pay acts as a processor on your behalf, under your instructions and your data processing agreement with us.
Because the pay calculation is performed by an accredited third-party payroll engine, that engine provider acts as a sub-processor where it processes your payroll data to compute pay. We remain accountable to you for our sub-processors.
For our own website and business contacts (for example, marketing enquiries), Ledra Pay is the controller.
Payroll is sensitive by nature. The personal data processed to run payroll typically includes: name and contact details; employment details; pay, hours and leave; bank account details; tax and social-security identifiers (for example a tax file number, National Insurance number, social-security number, or IdNr); and superannuation or pension details. The exact fields depend on the country and your configuration.
We process payroll personal data only to provide the service to your organisation: to move data to and from the accredited engine, to produce statutory outputs, and to transmit and file to the relevant authorities.
We use sub-processors to deliver the service, including an accredited third-party payroll engine provider (which computes payroll and holds the relevant government accreditation) and infrastructure/hosting providers. We impose data-protection obligations on our sub-processors consistent with this policy and your data processing agreement.
A current list of sub-processors, including the identity of the payroll engine provider, is available to our customers on request and via their data processing agreement. We will give notice of any intended change to our sub-processors as set out in that agreement.
We share payroll data with the accredited engine (to compute pay), with the relevant government gateways (to file), and with infrastructure providers (to host and secure the service). We do not sell personal data.
Where personal data is transferred across borders — for example, data from the EU/UK processed outside the EEA — we rely on an appropriate transfer mechanism, such as Standard Contractual Clauses (GDPR Articles 44–46), and the Australian and New Zealand cross-border rules where those apply. We rely on an appropriate safeguard such as Standard Contractual Clauses.
We keep payroll personal data for as long as needed to provide the service and to meet applicable statutory record-keeping periods, which differ by country. Records are kept in line with the statutory payroll-record retention period in each country. After that, we return or delete it as described in your data processing agreement.
We maintain appropriate technical and organisational measures to protect personal data (GDPR Article 32 sets the standard we work to), and we require our sub-processors to do the same.
Depending on where you are, you have rights over your personal data — which may include access, rectification, erasure, restriction, portability, and objection (GDPR Articles 12–22), and equivalent rights under the Australian APPs and the New Zealand IPPs.
If your data is processed because your employer uses Ledra Pay, your employer is the controller — please direct requests to your employer, who we will support as their processor. For data we control directly, contact us using the details below.
If a personal-data breach occurs, we notify affected controllers without undue delay so they can meet their notification duties (for example, to a supervisory authority under GDPR Article 33, to the OAIC under the Australian scheme, or to the Privacy Commissioner under the New Zealand scheme).
Privacy questions and requests: privacy@ledrapay.com. Where a Data Protection Officer or an Article 27 EU/UK representative is required, their contact details will be published here..
You may also complain to your local supervisory authority — for example, your EU data protection authority, the UK ICO, the Australian OAIC, or the New Zealand Privacy Commissioner.
We may update this policy from time to time; where a change is material we will take reasonable steps to let you know.
Ledra Pay processes payroll data as a processor for your organisation and integrates an accredited third-party engine as a sub-processor. This page is general information, not legal advice; confirm your own obligations with your adviser or the relevant authority.