Legal
Privacy Policy
How PaySymmetry collects, uses, stores, and protects your data when you use the platform.
Overview
PaySymmetry ("PaySymmetry," "we," "us," or "our") operates the PaySymmetry™ pay equity analysis platform ("Service"). This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding that data.
We are committed to handling compensation data and workforce information with the care and discretion it deserves. Pay equity data is sensitive. We collect only what is necessary to deliver the Service, we do not sell it, and we give you clear controls to delete it.
This policy applies to all users of the PaySymmetry™ platform, including organization administrators and invited team members. It covers both our web application and our API.
Data We Collect
We collect data in three categories:
Account & Identity Data
Name, email address, and organization name collected at signup. Authentication is handled by Clerk (our identity sub-processor); we store only a reference identifier linked to your Clerk account, not your password.
Workforce & Compensation Data
CSV or XLSX files you upload containing employee compensation records. These files may include employee identifiers, salary figures, job titles, pay grades, locations, tenure, department, and demographic categories (gender; race/ethnicity fields are optional and not required by the platform). This is the most sensitive data category we process.
Raw files are stored encrypted in AWS S3 and are only accessed to run your analysis. You may delete raw files at any time from the Account settings page, or configure automatic deletion after 30, 60, or 90 days via the Compliance Hub.
Usage & Technical Data
IP addresses, browser/user-agent strings, and event timestamps recorded in our audit log. This data supports security monitoring, SOC 2 compliance evidence, and debugging. We do not use third-party analytics trackers or advertising cookies.
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data under the following legal bases under the General Data Protection Regulation (GDPR) and applicable national laws:
- Contract performance (Art. 6(1)(b)): Processing account data, uploaded workforce files, and analysis results is necessary to provide the Service you have contracted for.
- Legitimate interests (Art. 6(1)(f)): Security logging (IP addresses, audit events) and fraud prevention serve our legitimate interest in protecting the platform and our customers' data.
- Legal obligation (Art. 6(1)(c)): Retaining billing records to meet tax and accounting obligations.
- Special category data (Art. 9(2)(b)): Where customers upload demographic data (e.g., race/ethnicity) for pay equity analysis, processing is carried out in the context of employment law compliance. Customers are responsible for establishing the appropriate legal basis under their local law for collecting and transferring this data to the Service.
If you are located in the EEA or UK, PaySymmetry acts as a data processor with respect to workforce data uploaded by your organization, and your organization is the data controller. We act as a data controller with respect to account and billing data.
How We Use Your Data
We use the data we collect exclusively to:
- Authenticate users and manage organization accounts
- Run OLS regression analyses on uploaded workforce data and return results to you
- Generate pay transparency disclosure reports as configured
- Store analysis results so you can access them after the analysis completes
- Send transactional emails (invitation links, payment receipts, deletion confirmations)
- Maintain a security and compliance audit trail
- Process billing through Stripe
- Respond to support requests
We do not use your workforce data to train machine learning models, sell to third parties, benchmark against other customers' data, or for any purpose other than running the analyses you initiate.
Sub-processors & Data Transfers
We use the following sub-processors to deliver the Service. Each has been selected for their security and compliance posture.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Clerk | User identity & authentication | US (SOC 2 Type II) |
| AWS (S3, RDS) | Encrypted file storage & database | US (ISO 27001, SOC 2) |
| Stripe | Payment processing & billing | US (PCI-DSS Level 1) |
| SendGrid | Transactional email delivery | US (SOC 2 Type II) |
For EEA/UK users, transfers to US-based sub-processors are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission, or by the UK International Data Transfer Addendum where applicable. We will update this section if transfer mechanisms change.
Data Retention
We retain data for the minimum period necessary:
- Raw workforce files (S3): Until you delete them, or automatically after 30, 60, or 90 days if you configure a retention window in the Compliance Hub. Files are hard-deleted from S3 — they cannot be recovered after deletion.
- Analysis results (JSONB): Retained until you delete the analysis or use the "Delete all data" function in Account settings. Deletion is permanent.
- Audit logs: Retained for a minimum of 7 years to support SOC 2 compliance evidence and legal obligations. Audit logs record that events occurred; they do not contain salary figures.
- Billing records: Retained for 7 years to meet accounting and tax obligations.
- Account data: Retained while your account is active and for 90 days after account closure to allow recovery. After 90 days, account data is permanently deleted.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate personal data (e.g., your name or email).
- Erasure ("Right to be Forgotten"): Organization administrators can permanently delete all workforce data via Account → Delete all data. This hard-deletes all uploaded files and analysis results immediately. To delete your account entirely, contact us at legal@paysymmetry.com.
- Restriction of processing: Request that we limit how we process your data in certain circumstances.
- Data portability: Export your analysis results in JSON or CSV format at any time from the analyses page.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
EEA and UK residents also have the right to lodge a complaint with their local supervisory authority (e.g., the Irish Data Protection Commission, the UK ICO, or your national authority).
To exercise any of these rights, contact us at legal@paysymmetry.com. We will respond within 30 days (or sooner as required by applicable law).
Security
We implement technical and organizational measures appropriate to the sensitivity of compensation and workforce data:
- All data in transit is encrypted using TLS 1.2 or higher
- All data at rest is encrypted using AES-256 (AWS SSE)
- PostgreSQL Row-Level Security policies enforce tenant data isolation at the database layer
- Access is controlled by role-based permissions (Admin, Analyst, Viewer)
- All material platform events are logged to an immutable audit trail
- Workforce files can be hard-deleted at any time; deletion is immediate and permanent
Despite these measures, no system is completely secure. If you discover a security vulnerability, please disclose it responsibly to security@paysymmetry.com.
Children's Privacy
The Service is intended for use by businesses and their HR professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided us with personal data, contact us at legal@paysymmetry.com and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy as the Service evolves or legal requirements change. We will notify organization administrators by email at least 30 days before any material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Service after the effective date of a revised policy constitutes acceptance of the updated terms.
Contact & Data Controller
For privacy inquiries, data subject requests, or questions about this policy, contact:
PaySymmetry
Privacy Inquiries
legal@paysymmetry.com
For EU/UK GDPR inquiries, you may also contact us at the address above. We do not currently have a designated EU or UK representative, as our processing volume does not require one under Article 27 GDPR, but we will appoint one if required by applicable law.
Questions about this document?
Contact us at legal@paysymmetry.com or write to us at:
PaySymmetry
330 Majestic Circle
Dallastown, PA 17313