Skip to content
Paritir
ProductYour obligationsInsightsFor advisors Log in
EN ▾
  • English
  • Deutsch
  • Français
  • Italiano
  • Español
  • Nederlands
  • Português
Become a design partner

Legal

Data processing agreement.

This page summarises how Paritir Ltd processes personal data on behalf of customers when they use the product. It is a summary, not the contract: the executable DPA is provided on request and forms part of our customer terms. Visitors to this website should read the privacy notice instead.

1. Roles

When you use Paritir to meet your obligations under the EU Pay Transparency Directive, you (the customer) are the controller of your employees' personal data and Paritir Ltd is the processor, acting on your documented instructions. Where an advisory firm delivers Paritir to its own clients, each client remains the controller, the firm acts as its processor, and Paritir acts as the firm's sub-processor under the DPA we sign with the firm.

2. Subject matter and duration

Processing covers the provision of the Paritir service for the term of the customer agreement, plus the limited period needed to return or delete data afterwards.

3. Nature and purpose

To host the customer's workforce data and compute the outputs the Directive requires — job evaluation, the statutory pay-gap report (Art. 9), and the joint pay assessment (Art. 10).

4. Types of personal data

Employee identifiers and employment attributes provided by the customer, which may include name, role/job family, seniority, location/legal entity, sex or gender, pay components, and job-evaluation survey responses. Personal identifiers are pseudonymised per organisation before analysis. Sex or gender is processed because the Directive requires pay gaps to be reported by sex. The service does not require special categories of personal data under Article 9 GDPR, and customers should not upload them.

5. Categories of data subjects

The customer's employees and workers (and, where applicable, applicants).

6. Our obligations as processor (Art. 28(3))

Under the DPA we commit to:

  • process personal data only on the customer's documented instructions;
  • ensure personnel are bound by confidentiality;
  • implement appropriate technical and organisational measures (Art. 32) — see our security page;
  • engage sub-processors only under written terms with equivalent obligations, and give notice of changes with a right to object;
  • assist the customer with data-subject requests and with Art. 32–36 obligations;
  • delete or return personal data at the end of the service; and
  • make available the information needed to demonstrate compliance and allow for audits.

7. AI and data minimisation

AI is used across the service: report narratives, role and attribute classification, translation, the in-product assistant and the recruitment pay-history audit. Every request passes through a single server-side gateway, the only place model access is configured, logged and rate-limited. Requests are minimised: reports and classifications carry non-identifying attributes keyed to an ephemeral index, and an outbound check removes email addresses. Features that work on text the customer writes or uploads (assistant questions, interview transcripts, documents, and survey text for translation) send that text as written; the transcript audit first requires the customer's separate written acknowledgement. Search embeddings are computed on our EU infrastructure; no third-party embedding provider is used. We are moving model inference to EU-region processing. See the security page for detail.

8. Sub-processors

We currently use the following sub-processors to provide the service:

  • Supabase — application database and authentication. EU region.
  • Vercel, Inc. — application hosting and serverless functions. Functions run in an EU region.
  • Anthropic, PBC — AI model inference. United States. Requests minimised as described in §7; EU-region inference being adopted.
  • Cloudflare, Inc. — DNS, edge security and the marketing site.
  • Resend (Plus Five Five, Inc.) — transactional email. EU region.
  • Functional Software, Inc. (Sentry) — error monitoring. EU region; personal-data scrubbing for error reports is being configured.

We give customers notice before adding or replacing a sub-processor.

9. International transfers

Customer data is hosted in the EU. AI model requests, minimised as described in §7, are processed by Anthropic in the United States until EU-region inference is in place. Paritir Ltd is established in the United Kingdom, which the European Commission recognises as providing an adequate level of data protection. Where a sub-processor processes personal data outside the UK and EEA, the transfer is protected by the EU–US Data Privacy Framework and its UK Extension where the provider is certified, or otherwise by the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum.

10. Security

Our technical and organisational measures are described on the security page and form part of the DPA (encryption in transit and at rest, SSL-enforced database connections, per-tenant row-level isolation, per-organisation pseudonymisation and k-anonymity).

11. Getting the signed DPA

Request our executable DPA (and sub-processor list, SCCs and TOMs) at hello@paritir.com or via the contact form. For security-specific questions, contact security@paritir.com.

Paritir

Pay-equity compliance for the EU Pay Transparency Directive — in your country, in your language.

Product

Product Your obligations For advisors Insights Methodology How we know the law For works councils Developers

Company

About Contact Trust Security Advisory partner sign in

Legal

Privacy Company information Data processing (DPA)
© 2026 Paritir. All rights reserved. paritir.com