Legal
Data processing agreement.
DRAFT — not yet in effect. A working draft summary pending legal review. Not legal advice and not a contract. The executable DPA is provided on request and forms part of our customer terms.
This page summarises how Paritir processes personal data on behalf of customers when they use the product. Visitors to this website should read the privacy notice instead.
1. Roles
When you use Paritir to meet your obligations under the EU Pay Transparency Directive, you (the customer) are the controller of your employees' personal data and Paritir is the processor, acting on your documented instructions. Where a consultancy delivers Paritir to its own clients, [[counsel to confirm the controller/processor/sub-processor chain for the reseller model]].
2. Subject matter and duration
Processing covers the provision of the Paritir service for the term of the customer agreement, plus the limited period needed to return or delete data afterwards.
3. Nature and purpose
To host the customer's workforce data and compute the outputs the Directive requires — job evaluation, the statutory pay-gap report (Art. 9), and the joint pay assessment (Art. 10).
4. Types of personal data
Employee identifiers and employment attributes provided by the customer, which may include name, role/job family, seniority, location/legal entity, sex or gender, pay components, and job-evaluation survey responses. Personal identifiers are pseudonymised per organisation before analysis. [[Counsel to confirm treatment of sex/gender and any special-category considerations under Art. 9.]]
5. Categories of data subjects
The customer's employees and workers (and, where applicable, applicants).
6. Our obligations as processor (Art. 28(3))
Under the DPA we commit to:
- process personal data only on the customer's documented instructions;
- ensure personnel are bound by confidentiality;
- implement appropriate technical and organisational measures (Art. 32) — see our security page;
- engage sub-processors only under written terms with equivalent obligations, and give notice of changes with a right to object;
- assist the customer with data-subject requests and with Art. 32–36 obligations;
- delete or return personal data at the end of the service; and
- make available the information needed to demonstrate compliance and allow for audits.
7. AI and data minimisation
Where AI is used (for narrative drafting and role classification), requests pass through a single server-side gateway that removes personal identifiers, with a redaction backstop, so no personal data is sent to the model. We are moving model inference to EU-region processing. See the security page for detail.
8. Sub-processors
We currently use the following sub-processors to provide the service:
- Supabase — application database and authentication. [[Confirm region — EU.]]
- Vercel, Inc. — application hosting and serverless functions.
- Anthropic, PBC — AI model inference (no personal data sent; EU-region inference being adopted).
- Cloudflare, Inc. — DNS, edge security and the marketing site.
- Resend (Plus Five Five, Inc.) — transactional email, EU region.
- Functional Software, Inc. (Sentry) — error monitoring. [[Confirm whether PII is scrubbed.]]
- Stripe, Inc. — billing and payments. [[Confirm once billing is live (KAN-191).]]
[[Counsel to confirm each entity's legal name, role, processing location and safeguard, and keep this list current.]]
9. International transfers
Where a sub-processor processes data outside the EEA, transfers are governed by the European Commission's Standard Contractual Clauses together with supplementary measures. [[Counsel to confirm mechanisms and transfer-impact assessments.]]
10. Security
Our technical and organisational measures are described on the security page and form part of the DPA (encryption in transit and at rest, SSL-enforced database connections, per-tenant row-level isolation, per-organisation pseudonymisation and k-anonymity).
11. Getting the signed DPA
Request our executable DPA (and sub-processor list, SCCs and TOMs) at hello@paritir.com or via the contact form. For security-specific questions, contact security@paritir.com.