Privacy / Security

PayrollCompare AI processes payroll documents that contain personal and confidential information. Security is therefore built into the service architecture rather than added as operational policy. The core design principles are simple:

  • Client payroll documents are processed entirely in memory and are never written to persistent storage.
  • Client documents are never used to train, fine-tune, or improve AI models.

 These are architectural properties of the platform rather than configurable settings.


Data handling

  • Memory-only processingPayroll documents exist only in application memory while a comparison is running. They are never written to persistent storage, and therefore never appear in backups or database snapshots. 
  • Temporary results Comparison results remain available only in memory for up to 24 hours to allow retrieval. They are removed immediately after the first successful download or automatically expire after 24 hours, whichever comes first. A background cleanup process periodically removes expired results.
  • No training on client data: AI models are trained exclusively on synthetic payroll data generated for that purpose. Client payroll documents are used only to produce the requested comparison and are never retained for learning.


Transport & access

  • Encrypted communication All communication uses HTTPS with current TLS and strict transport security. Plain HTTP connections are rejected.
  • API key authentication Every API request requires a client-specific API key. There are no shared or default credentials. API keys can be rotated or revoked independently without affecting other clients.
  • Minimal exposure Only the reverse proxy is accessible from the public Internet. The processing service itself is not directly exposed.


Privacy  & logging

Operational logs contain only metadata required to operate the service, such as timestamps, processing duration, status and job identifiers. Payroll content, extracted values and document fields are never written to logs.


Hosting

The public service is hosted within the European Union (Finland).


Regulatory posture

ZingfulTech GmbH, the operator of PayrollCompare AI, acts as a data processor on behalf of its clients, who remain the controllers of their own payroll data. The platform is designed to support the principles of the Swiss revFADP and the EU GDPR, particularly data minimisation and limited retention. A Data Processing Agreement (DPA) is available on request.


At a glance

  • Processing: Memory only
  • Persistent document storage: None
  • Result retention: Memory only; deleted after first download or within 24 hours
  • Model training: Never uses client documents
  • Authentication: Per-client API keys
  • In transit: HTTPS with strict transport security
  • Logging: Operational metadata only, never document content
  • Hosting: European Union (Finland)
  • Data controller: Client
  • Data processor: ZingfulTech GmbH
Search