Payroll, HR and hiring on one platform. Built for teams everywhere.Get pricing
Legal

Data Processing Addendum.

The terms that apply when Softra processes personal data on a customer's behalf.

Last updated: August 23, 2026

This addendum forms part of the Terms of Service between Softra Global and the customer. A countersigned copy is available on request from legal@softraglobal.com.

1. Roles

The customer is the controller of personal data in its workspace. Softra is the processor and processes that data only on the customer's documented instructions, including the instructions expressed through use of platform features. Softra tells the customer if an instruction appears to conflict with applicable data protection law.

2. Subject matter and duration

Processing lasts for the subscription term plus the retention periods described below. The subject matter is the provision of HR, payroll, and recruitment software.

3. Categories of data subjects

  • Customer administrators and platform users.
  • Employees and contractors of the customer.
  • Job applicants and candidates.
  • Emergency contacts and dependants where the customer records them.

4. Types of personal data

  • Identity and contact details, national and tax identifiers, and employment records.
  • Compensation, deductions, reliefs, benefits, banking details for pay, and payslip history.
  • Time, attendance, leave, and performance data.
  • Application materials, interview schedules, scorecards, and hiring outcomes.
  • Authentication, access, and audit records.

Special category data is processed only where the customer chooses to record it, for example health-related leave. The customer is responsible for having a lawful basis for that data.

5. Softra obligations

  • Process personal data only on documented instructions.
  • Bind personnel with access to duties of confidentiality and grant access on a least-privilege basis.
  • Implement and maintain the technical and organizational measures in section 6.
  • Assist the customer with data subject requests, impact assessments, and regulator consultations, taking into account the nature of the processing.
  • Make available the information needed to demonstrate compliance and allow audits as described in section 10.

6. Security measures

  • Encryption in transit (TLS) and at rest for stored data and backups.
  • Workspace-level data separation enforced at the database layer, with row-level access rules on every tenant table.
  • Role-based access control, optional multi-factor authentication, and session inactivity timeout.
  • Audit history of privileged and payroll-affecting actions.
  • Least-privilege internal access, reviewed periodically, with production access limited to named engineers.
  • Automated dependency and configuration scanning, monitored error reporting, and change review before release.
  • Encrypted, access-controlled backups with a documented restore procedure.

7. Sub-processors

The customer gives general authorization for Softra to engage the sub-processors listed on the sub-processor page. Softra imposes data protection terms no less protective than this addendum on each of them and remains liable for their performance. We aim to give at least 30 days' notice before a new sub-processor begins processing, so the customer can raise a reasonable objection.

8. International transfers

Where personal data is transferred outside the country of origin, Softra relies on appropriate safeguards, including standard contractual clauses with its providers and, where relevant, supplementary technical measures such as encryption.

9. Personal data breaches

Softra notifies the customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting that customer's data, with the nature of the breach, categories and approximate volume of records, likely consequences, and remediation steps taken or planned.

10. Audit and evidence

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, Softra provides its security documentation and responds to a security questionnaire. On-site audits are available where legally required, at reasonable times, subject to confidentiality and to not disrupting the service.

11. Return and deletion

The customer can export its data from the platform at any time during the term. After termination, data is available for export for 30 days, then deleted or de-identified within 90 days, and removed from backups on the normal backup cycle of up to 35 days, unless law requires longer retention.

12. Assistance with data subject requests

The platform provides self-service access, correction, export, and deletion tools for controller use. Where a data subject contacts Softra directly, we route the request to the customer and support their response.

13. Contact

Data protection contact: privacy@softraglobal.com. Related pages: Privacy Notice, Sub-processors, Security.