Skip to main content
    Security & privacy

    Payroll Africa Trust Centre

    Payroll data is the most sensitive data an employer holds — ID numbers, banking details and what every person earns. This page explains, in plain language, the controls that are live in Payroll Africa today and how responsibility is split between us and you as the employer.

    This page is maintained by Payroll Africa Technologies (Pty) Ltd and describes our own practices. It is not an independent audit, certification or assurance report.

    Controls in place today

    Encryption in transit and at rest

    Every request to Payroll Africa is served over HTTPS (TLS 1.2+). Payroll records, employee master data and payslips are stored in an encrypted managed Postgres database, and generated payslip files are served through expiring signed links rather than public URLs.

    Tenant isolation by design

    Payroll Africa is multi-tenant. Every table that holds company data enforces row-level access rules in the database itself, scoped to the signed-in user's company membership and role. Isolation does not depend on application code remembering to filter — the database rejects cross-company reads.

    Role-based access control

    Access is granted per company and per role — owner, payroll administrator, manager and employee self-service. Employees can only see their own payslips, leave and profile. Roles are stored separately from user profiles so they cannot be escalated from the browser.

    Audit trail

    Payroll runs, employee changes, approvals and administrative actions are written to an immutable audit log with the acting user and timestamp, so you can reconstruct who changed what before a SARS or Department of Employment and Labour query.

    Verified registration

    New accounts require a verified mobile number via one-time PIN, and disposable email domains are blocked at registration. This keeps throwaway accounts out of a system that holds real employee ID numbers and banking details.

    Secure payslip delivery

    Payslips are delivered by email and WhatsApp using single-use, expiring links to a secure portal rather than as open attachments, so a forwarded message does not expose an employee's earnings permanently.

    Shared responsibility

    What Payroll Africa does

    • Keeps the platform patched, encrypted and backed up.
    • Enforces company isolation and role permissions in the database.
    • Maintains the SARS tax engine against published tax tables each year.
    • Logs administrative and payroll actions for audit.
    • Responds to reported security issues and notifies affected customers.

    What you as the employer do

    • Grant the minimum role each staff member needs, and remove leavers promptly.
    • Use strong, unique passwords and keep OTP-verified numbers current.
    • Confirm employee banking changes out of band before approving them.
    • Verify your own SARS, UIF and COIDA registration details are correct.
    • Handle employee POPIA requests as the responsible party.

    POPIA questions employers ask

    What personal information does Payroll Africa process?
    As an operator on your behalf we process employee names, ID or passport numbers, tax reference numbers, contact details, banking details, earnings, deductions and leave records — the minimum required to run payroll and meet SARS, UIF, SDL and BCEA obligations.
    Who is the responsible party under POPIA?
    You, the employer, remain the responsible party for your employees' personal information. Payroll Africa acts as an operator processing that information under your instruction, and does not sell, rent or share it with third parties for marketing.
    Where is the data hosted?
    Payroll Africa runs on managed cloud infrastructure with encrypted storage and automated backups. We will confirm the specific hosting region in writing on request for tenders and due-diligence questionnaires.
    How long is data retained?
    Payroll records are retained for the five-year period the Income Tax Act and BCEA require employers to keep them. On written request after account closure, and once that statutory period has passed, we delete your tenant data.
    Can employees request their own information?
    Yes. Employee self-service gives each employee live access to their own payslips, IRP5 data, leave balances and profile, which satisfies most POPIA access requests without an administrator having to intervene.
    How do I report a security issue?
    Email sales@payrollafrica.co.za with the subject line 'Security'. We acknowledge reports within one business day and will keep you updated until the issue is resolved. Please do not publicly disclose an unpatched issue.

    Compliance documentation

    For tenders and vendor due diligence we provide a written security questionnaire response, our operator agreement for POPIA purposes, and confirmation of hosting and retention arrangements. Read our privacy policy, terms of service, compliance & accuracy page and SARS compliance guides, or request documents directly.