Skip to content

Security · GDPR · EU

Your payroll data never leaves Europe.

This tool is designed to the security standard expected of an approved Belgian social secretariat: EU hosting, GDPR by design, strict isolation per organisation, full access traceability.

EU hosting

Frankfurt data centre, ISO 27001-certified processor. No transfer outside the European Union. No US Cloud Act.

End-to-end encryption

TLS 1.3 in transit, AES-256 at rest, keys managed in a separate KMS. Encrypted backup, rolling 30-day retention.

Isolation per organisation

Postgres + Row Level Security on 100% of customer tables. A malformed query can never return another organisation's data.

Passwordless authentication

Sign-in via email magic link (Supabase Auth). No stored password, no risk of leakage through credential stuffing.

No AI training

Your data is never used to train a model. No third-party LLM provider receives your audits.

Deletion on request

Full export + permanent deletion in 1 click from Settings > Privacy. Data purged from backup within 30 days.

Operational practices

Annual pentest

Independent external firm, report available under NDA for Enterprise customers.

Continuous scanning

Dependencies continuously scanned (Snyk + Dependabot). Critical patches < 48 h.

DPA ready to sign

Data Processing Agreement aligned with GDPR art. 28, available on request at dpo@groups.be.

Cookies & analytics

No advertising cookie. No third-party tracker (Google Analytics, Meta Pixel, etc.).

Only strictly necessary cookies: authentication session, language preference, banner consent. First-party product analytics, anonymised, hosted on the same EU infrastructure.

You can withdraw your consent at any time via the 'Cookies' link in the footer.

FAQ — security

Security, data & privacy

Is my data shared with third parties?

No. EU hosting (Frankfurt), GDPR, TLS 1.3 encryption in transit and AES-256 at rest. No data is shared with any third party without your explicit consent. No AI model training on your data.

Where is the data hosted?

Frankfurt (Germany) with an ISO 27001 certified sub-processor. No transfers outside the EU. The DPA (Data Processing Agreement) is available upon request at dpo@groups.be.

How long is my data stored?

Audit sessions: 36 months after the last activity (aligned with the Belgian Social Criminal Code's statute of limitations). PDF reports: kept as long as your account exists. You can export and delete all your data at any time from Settings > Privacy.

Who can access my company's audits?

Strictly the users invited to your organisation (with admin or user roles). Group S never accesses your data except upon explicit support request (with consent via a ticket).

Has the application been security audited?

Annual pentest by an external firm, continuous dependency scans, ISO 27001 certificate undergoing renewal. See /security for details.

Is the Group S audit compliant with the AI Act?

Yes. The tool does not make any automated decisions on your behalf: it presents legal rules audited by legal experts. No scoring of individuals, no profiling, not a high-risk AI system within the meaning of EU Regulation 2024/1689.

DPA, register, ISO?

Documents available on request at dpo@groups.be or via your usual Group S contact.

Request documents