PayFlow Ireland

Data Processing Agreement

In force from 2 October 2026 · Version 2026-10-02

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (the controller) and PayFlow Ireland (the processor, “PayFlow”). It sets out the terms required by Article 28(3) of the GDPR. Where a practice uses PayFlow for a client, the client is the controller, the practice is its processor, and PayFlow is the practice’s sub-processor on these same terms.

1. Details of the processing

Subject matterProviding PayFlow Ireland payroll software and related services.
DurationFor as long as the customer uses the service, and afterwards until the data is deleted or returned under section 9.
Nature and purposeStoring, calculating and organising payroll data; producing payslips, reports and payment files; sending submissions to Revenue and NAERSA and journals to accounting software when the controller instructs; giving employees access to their own payslips and leave.
Categories of data subjectsThe controller’s employees, former employees and directors; the controller’s staff and advisers who use the service.
Types of personal dataIdentity and contact details; date of birth; PPS number; bank details; employment, pay, tax, PRSI, USC, LPT, pension and benefit details; Revenue RPN and NAERSA AEPN data; leave, absence and working time records; payslips; audit records of actions in the software.
Special categoriesLeave and absence records that may reveal health information (Article 9). Processed only as the controller’s employment-law obligations require.

2. Instructions

PayFlow processes the personal data only on the controller’s documented instructions. Those instructions are these terms and the controller’s use of the service’s features. The exception is where EU or Irish law requires otherwise, in which case PayFlow will tell the controller first unless the law forbids it. PayFlow will tell the controller if it believes an instruction breaks data protection law.

3. Confidentiality

Everyone at PayFlow who can access the personal data is bound by a duty of confidentiality. Access by PayFlow staff to a customer’s records requires a stated support reason, lasts one hour, and is shown to the controller in its own audit trail.

4. Security (Article 32)

PayFlow maintains appropriate technical and organisational measures, including:

5. Sub-processors

The controller gives general authorisation for PayFlow to use the sub-processors listed in the Privacy Notice. PayFlow will give at least 30 days’ notice by email before adding or replacing one. The controller may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the controller may end the agreement without penalty. PayFlow imposes the same data protection obligations on each sub-processor and remains responsible for them.

Revenue, NAERSA and the controller’s own connected accounting software receive data because the controller instructs it. They are not PayFlow’s sub-processors.

6. International transfers

PayFlow hosts the data in the EU. Any transfer outside the EEA by a sub-processor is protected by an adequacy decision or the European Commission’s Standard Contractual Clauses.

7. Helping the controller

Taking into account the nature of the processing, PayFlow will:

8. Personal data breaches

PayFlow will notify the controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting its data. The notice will include what is known about the nature of the breach, the data and people affected, likely consequences, and the measures taken. Further information will follow as it becomes available.

9. End of processing

When the service ends, the controller can export its data for at least 90 days. After that, PayFlow keeps payroll records for 6 years from the end of the tax year of the last payroll, so the controller can meet its record-keeping obligations, and then deletes them. The controller may instead instruct earlier deletion in writing. Copies in backups are overwritten on the hosting provider’s rolling schedule.

10. Audits

PayFlow will make available the information needed to show compliance with Article 28. It will allow and contribute to audits by the controller or an auditor it appoints, on at least 30 days’ notice, during working hours, and no more than once a year unless a breach or a regulator requires it. Any auditor must be bound by confidentiality.

11. Liability and order of precedence

Liability under this DPA is subject to the limits in the Terms of Service, except where the GDPR does not allow it to be limited. If this DPA and the Terms conflict on data protection, this DPA wins.