Parmetra
Request access

Privacy Policy

How Parmetra collects, uses and protects personal and workforce data. This page describes what we actually do, what each of our sub-processors can see and where, and how long every category of data is kept.

Last updated: ·Binding text, not legal advice about your own obligations.

1. Who we are

Parmetra is a pay-transparency compliance platform for EU employers. The controller is the operator of Parmetra, reachable through the contact form below. For questions about this policy or about how we handle personal data, use our contact form. Our full registered details (registered name, legal form, registered address, company register number and VAT number) are provided to any customer or data subject who asks, free of charge and without needing to give a reason: just ask through our contact form. We have not appointed a Data Protection Officer; in all matters concerning personal data, use our contact form.

2. Controller and processor: which hat we wear

We are the CONTROLLER for the account and billing data you give us directly: your name, work email, organisation and billing details. We are a PROCESSOR for the workforce data your administrators upload: salaries, job categories, gender and everything derived from them. For that data your organisation is the controller and decides what is collected and why; we act only on its documented instructions. If you are an employee of a Parmetra customer, section 9 is written for you.

3. What we collect

As controller: account details (name, work email, organisation, role), authentication metadata from our identity provider, and billing information handled by our payment processor. As processor, on your organisation's instruction: employee names and work emails, salary and complementary pay, working time, job category and valuation scores, gender, start dates and salary history, plus the pay-gap reports, postings and worker requests generated from them.

5. Special categories of data

Gender is processed because the Directive requires the pay gap to be reported by sex; standing alone it is not a special category under Art. 9 GDPR. Parmetra does not collect racial or ethnic origin, health, trade union membership, religion or any other Art. 9 special category, and its intersectional analysis deliberately operates only on non-special attributes. Do not upload special-category data through the import tools: the service is not designed to hold it and doing so would place your organisation, as controller, outside the legal basis described above.

6. Automated processing and human decisions

The pay-decision check screens a proposed salary against a comparable cohort and returns an advisory risk signal. It is decision SUPPORT: it produces no legal or similarly significant effect on its own, nothing is applied automatically, and a person in your organisation makes and records every decision. That is deliberate, so that Art. 22 GDPR is not engaged. The pay-gap and job-valuation engines are statistical calculations over data you supply, not profiling of individuals.

7. Sub-processors and international transfers

We engage the sub-processors listed below, identified by the function each performs. Every one of them is bound by a written contract imposing the same data-protection obligations we owe you. Workforce data is stored in the European Union. Where a sub-processor is established outside the EEA, transfers rely on the EU Standard Contractual Clauses or on an adequacy decision, as stated per entry. If we cannot resolve an objection you raise, you may terminate the affected service.

Sub-processors engaged by Parmetra, by function
FunctionPurposeLocationData categoriesTransfer basis
Database hostingPrimary application database: all workforce and organisation recordsFrankfurt, Germany (EU)Employee names, work emails, salaries, job categories, gender, audit recordsN/A: data remains in the EEA
Application hosting and content deliveryRuns the application and serves it to your browserFrankfurt region (EU); provider established in the United StatesRequest metadata; application data in transitEU Standard Contractual Clauses
Authentication providerSign-in, user accounts and organisation membershipUnited StatesAccount holder name, work email, authentication metadata, never salary dataEU-U.S. Data Privacy Framework
Payment processorSubscription billing, payment processing and EU VAT determinationIreland (EU), with onward processing in the United StatesBilling contact, billing address, VAT number, payment card data (never reaches our servers). No workforce data.EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework
Error and performance monitoringDiagnosing faults in the running applicationGermany (EU): the provider's EU-region ingest endpointOpaque user and organisation identifiers only; emails and numeric values are stripped before transmissionN/A: data remains in the EEA
Transactional email deliverySending account, reminder and information-request notificationsEU sending region; provider account data and message metadata in the United StatesRecipient name and work email, message subject and delivery statusEU Standard Contractual Clauses
AI drafting assistance (optional)Drafts a suggested score for each job-evaluation criterion from a position title. Active only where an organisation has switched the optional assist on; every score is decided by a person.United StatesA position title, and the organisation's own criterion names, descriptions and point scales. No employee records, no pay, no gender, and nothing identifying the organisation.EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework

We identify each sub-processor by function rather than by name on this public page, because an itemised list of our providers is a description of our infrastructure. The named list (legal entity, registered country and the contract we hold with them) forms part of the Data Processing Agreement documentation and is provided, in full and free of charge, to any customer or data subject who asks: just ask through our contact form. We give at least 30 days' notice before adding or replacing a sub-processor, and you may object.

The following are not our sub-processors (they are systems you already control and instruct us to read from), but we list them for transparency:

  • Personio: HRIS synchronisation, only where an administrator connects their own Personio tenant. Credentials are sealed with AES-256-GCM before storage.

8. How long we keep it

Retention periods are set out per data category in the table below. In every case we delete or return workforce data when your subscription ends. You are not required to ask, though you can ask sooner.

Retention periods by data category
Data categoryRetention period
Workforce data (employees, salaries, valuations, snapshots)For the term of the subscription. Deleted or returned within 30 days of termination; residual backup copies are purged within a further 90 days.
Audit log entriesFor the term of the subscription, then deleted with the organisation within 30 days of termination. Exportable at any time: they are your evidence trail, so export before you close the account.
Account and authentication recordsFor the term of the subscription, deleted within 30 days of termination.
Billing records and invoicesRetained after termination for as long as tax and accounting law requires, commonly 7 to 10 years depending on member state.
Error monitoring events90 days, then automatically deleted.

9. If you are an employee of a Parmetra customer

Your employer, not Parmetra, decides what data about you is held here and why; your employer is the controller and your rights are exercised against it in the first instance. We hold your data only to run the analyses it asks for and to answer the pay-information requests you are entitled to make under Article 7 of the Directive. If you contact us directly we will not act on your data ourselves. We will route your request to your employer without undue delay and tell you that we have done so. Your pay-gap figures are always reported in aggregate, and small groups are suppressed so that individuals cannot be identified from a published report.

10. Your rights

You may request access, rectification, erasure, restriction of processing, portability, and object to processing. Where we are the processor, we forward the request to the controller and assist them in answering it. You also have the right to lodge a complaint with a supervisory authority. Ours is the supervisory authority of the member state in which we are established, whose details we provide on request, and you may equally complain to the authority in your own country of residence or workplace.

11. Security

Data is encrypted in transit and at rest. Every record is scoped to a single organisation and every query filters on that scope. Third-party credentials, such as HRIS API keys, are additionally sealed with AES-256-GCM before storage. Error monitoring strips emails and numeric values before an event leaves the application, and screen recording is disabled entirely on production so that salary data on screen is never captured. Access is role-separated between system administrators and HR managers, enforced on the server rather than in the interface.

12. Personal data breaches

If we become aware of a personal data breach affecting data we process on your behalf, we will notify your organisation without undue delay and give you the information you need to make your own Art. 33 notification to your supervisory authority within 72 hours. Where we are the controller, we notify the competent authority ourselves and, where the breach is likely to result in a high risk to individuals, we notify them too.

13. Cookies

We run a privacy-focused, cookieless analytics tool that counts page views, referrers and an approximate location derived from IP address. It sets no cookie, stores no persistent identifier and cannot follow you across sites or between visits; the data is aggregated and cannot be tied back to you individually. We set no advertising or tracking cookies, and we run no advertising pixel or tag manager on this site. Because every cookie below is either strictly necessary or a preference you set yourself, and our analytics tool sets none, no consent banner is required, and we would rather not show you one.

Cookies set by this site
CookiePurposeCategoryRetention
NEXT_LOCALERemembers the language you chose so the site reopens in it.Preference (user-initiated)1 year
__session, __client_uatSet by our authentication provider at sign-in. Keeps you signed in and protects the session; without these, sign-in cannot work.Strictly necessarySession to 7 days

14. Changes to this policy

This policy is versioned by date; the version you are reading was last updated on 2026-08-05. We will notify customers of material changes before they take effect. The English text is the authoritative version.

This document is published in English, which is the authoritative version. Translations may be provided for convenience; in the event of any discrepancy, the English text prevails.

Questions about this policy, or exercising a right? Use our contact form. Our processor terms are published in full in the Data Processing Agreement.