Legal

Privacy Policy

How PaySymmetry collects, uses, stores, and protects your data when you use the platform.

Effective: June 1, 2026Last updated: May 27, 2026
01

Overview

PaySymmetry ("PaySymmetry," "we," "us," or "our") operates the PaySymmetry™ pay equity analysis platform ("Service"). This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding that data.

We are committed to handling compensation data and workforce information with the care and discretion it deserves. Pay equity data is sensitive. We collect only what is necessary to deliver the Service, we do not sell it, and we give you clear controls to delete it.

This policy applies to all users of the PaySymmetry™ platform, including organization administrators and invited team members. It covers both our web application and our API.

02

Data We Collect

We collect data in three categories:

Account & Identity Data

Name, email address, and organization name collected at signup. Authentication is handled by Clerk (our identity sub-processor); we store only a reference identifier linked to your Clerk account, not your password.

Workforce & Compensation Data

CSV or XLSX files you upload containing employee compensation records. These files may include employee identifiers, salary figures, job titles, pay grades, locations, tenure, department, and demographic categories (gender; race/ethnicity fields are optional and not required by the platform). This is the most sensitive data category we process.

Raw files are stored encrypted in AWS S3 and are only accessed to run your analysis. You may delete raw files at any time from the Account settings page, or configure automatic deletion after 30, 60, or 90 days via the Compliance Hub.

Usage & Technical Data

IP addresses, browser/user-agent strings, and event timestamps recorded in our audit log. This data supports security monitoring, SOC 2 compliance evidence, and debugging. We do not use third-party analytics trackers or advertising cookies.

04

How We Use Your Data

We use the data we collect exclusively to:

  • Authenticate users and manage organization accounts
  • Run OLS regression analyses on uploaded workforce data and return results to you
  • Generate pay transparency disclosure reports as configured
  • Store analysis results so you can access them after the analysis completes
  • Send transactional emails (invitation links, payment receipts, deletion confirmations)
  • Maintain a security and compliance audit trail
  • Process billing through Stripe
  • Respond to support requests

We do not use your workforce data to train machine learning models, sell to third parties, benchmark against other customers' data, or for any purpose other than running the analyses you initiate.

05

Sub-processors & Data Transfers

We use the following sub-processors to deliver the Service. Each has been selected for their security and compliance posture.

Sub-processorPurposeData location
ClerkUser identity & authenticationUS (SOC 2 Type II)
AWS (S3, RDS)Encrypted file storage & databaseUS (ISO 27001, SOC 2)
StripePayment processing & billingUS (PCI-DSS Level 1)
SendGridTransactional email deliveryUS (SOC 2 Type II)

For EEA/UK users, transfers to US-based sub-processors are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission, or by the UK International Data Transfer Addendum where applicable. We will update this section if transfer mechanisms change.

06

Data Retention

We retain data for the minimum period necessary:

  • Raw workforce files (S3): Until you delete them, or automatically after 30, 60, or 90 days if you configure a retention window in the Compliance Hub. Files are hard-deleted from S3 — they cannot be recovered after deletion.
  • Analysis results (JSONB): Retained until you delete the analysis or use the "Delete all data" function in Account settings. Deletion is permanent.
  • Audit logs: Retained for a minimum of 7 years to support SOC 2 compliance evidence and legal obligations. Audit logs record that events occurred; they do not contain salary figures.
  • Billing records: Retained for 7 years to meet accounting and tax obligations.
  • Account data: Retained while your account is active and for 90 days after account closure to allow recovery. After 90 days, account data is permanently deleted.
07

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate personal data (e.g., your name or email).
  • Erasure ("Right to be Forgotten"): Organization administrators can permanently delete all workforce data via Account → Delete all data. This hard-deletes all uploaded files and analysis results immediately. To delete your account entirely, contact us at legal@paysymmetry.com.
  • Restriction of processing: Request that we limit how we process your data in certain circumstances.
  • Data portability: Export your analysis results in JSON or CSV format at any time from the analyses page.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

EEA and UK residents also have the right to lodge a complaint with their local supervisory authority (e.g., the Irish Data Protection Commission, the UK ICO, or your national authority).

To exercise any of these rights, contact us at legal@paysymmetry.com. We will respond within 30 days (or sooner as required by applicable law).

08

Security

We implement technical and organizational measures appropriate to the sensitivity of compensation and workforce data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • All data at rest is encrypted using AES-256 (AWS SSE)
  • PostgreSQL Row-Level Security policies enforce tenant data isolation at the database layer
  • Access is controlled by role-based permissions (Admin, Analyst, Viewer)
  • All material platform events are logged to an immutable audit trail
  • Workforce files can be hard-deleted at any time; deletion is immediate and permanent

Despite these measures, no system is completely secure. If you discover a security vulnerability, please disclose it responsibly to security@paysymmetry.com.

09

Cookies & Tracking

PaySymmetry™ uses only functional cookies necessary for authentication session management (set by Clerk). We do not use advertising cookies, third-party analytics trackers, or cross-site tracking technologies.

You can disable cookies in your browser settings, but doing so will prevent you from signing in to the platform.

10

Children's Privacy

The Service is intended for use by businesses and their HR professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided us with personal data, contact us at legal@paysymmetry.com and we will delete it promptly.

11

Changes to This Policy

We may update this Privacy Policy as the Service evolves or legal requirements change. We will notify organization administrators by email at least 30 days before any material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the Service after the effective date of a revised policy constitutes acceptance of the updated terms.

12

Contact & Data Controller

For privacy inquiries, data subject requests, or questions about this policy, contact:

PaySymmetry

Privacy Inquiries
legal@paysymmetry.com

For EU/UK GDPR inquiries, you may also contact us at the address above. We do not currently have a designated EU or UK representative, as our processing volume does not require one under Article 27 GDPR, but we will appoint one if required by applicable law.

Questions about this document?

Contact us at legal@paysymmetry.com or write to us at:

PaySymmetry
330 Majestic Circle
Dallastown, PA 17313