Skip to content

Privacy policy

How Prolley handles the payroll data you entrust to us, the details of the people who use the app, and what we collect on this website.

Last updated

1. Who we are

Prolley ("we", "us") provides a web application, at app.prolley.com, that companies in Cyprus use to run monthly and weekly payroll: calculating income tax (PAYE), Social Insurance, GESY and employer contributions, producing payslips, and preparing the figures needed for Tax Department and Social Insurance filings. We also run this website, prolley.com.

We are based in Paphos, Cyprus. For anything in this policy, write to hello@prolley.com.

This policy follows the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018 on the protection of personal data.

2. Our two roles

Payroll software holds data about two different groups of people, and our responsibilities differ for each.

  • Payroll data — we are a processor. When a company (our "customer") enters its employees' details and runs payroll in Prolley, the company is the controller of that data: it decides what is entered and why, and it has its own legal duties as an employer. We are its processor: we handle the data only on its instructions and under a data processing agreement, which forms part of our terms of service.
  • Account, website and newsletter data — we are the controller. For the people who sign in to Prolley, visitors to this website and newsletter subscribers, we decide how the data is used, and this policy explains how.

3. Payroll data we process for our customers

To calculate pay correctly under Cyprus rules, the app stores the following about each employee, as entered by the customer:

  • Identity and contact: name, date of birth, gender, nationality, email, phone and address.
  • Identification numbers: Tax Identification Code (TIC), Social Insurance number, ID card or passport number, and Alien Registration Certificate (ARC) number.
  • Employment: employee code, job title, department, start and end dates, contract type, status, and whether the person is an officer of the company.
  • Pay: pay frequency, pay basis and rates with their history, hours worked, bonuses, allowances and other pay items, 13th salary settings, and payment method with bank name and IBAN.
  • Tax and contributions: income tax exemptions, life insurance and other declared reliefs, provident fund percentages, and Social Insurance and GESY applicability.
  • Trade union membership: the union and agreement fund an employee belongs to and the date of their check-off authorisation, used to deduct union fees. This is a special category of personal data under the GDPR; customers should record it only where the employee has authorised the deduction.
  • Payroll results: each run's gross pay, deductions, net pay and employer costs, payslips, year-to-date totals, and the monthly and annual report figures.

What we do with it. We use payroll data only to provide the service to the customer: to calculate pay, warn about missing or inconsistent details, produce payslips and reports, keep the audit trail, and give support when the customer asks for it. Prolley calculates and exports; it does not submit filings to the Tax Department or Social Insurance Services and does not make payments. Any submission or bank payment is made by the customer, outside Prolley.

What we never do with it. We do not sell payroll data, share it with advertisers, use it for marketing, combine it with data from other customers, profile employees, or use it to train AI models.

4. Data about the people who use the app

When a customer's staff sign in to Prolley, we are responsible for:

  • Account details: name, email address, the company (or companies) the account belongs to, and its role (administrator, editor or read-only).
  • Sign-in data: a securely hashed password (we never store or see it in plain text) and sign-in sessions, so you can stay signed in and switch between companies.
  • Audit trail: a record of who changed what and when (for example, a rate change or an approved run). Customers rely on it to show how a payslip was produced, so it is kept as long as the payroll data it describes.
  • Billing details: the company's name, VAT number, billing address and subscription plan. If payments are taken by card, they are handled by a payment provider; we never see or store full card numbers.
  • Messages: what you send us when you ask for support.

The app keeps your sign-in tokens in your browser's local storage so you stay signed in. It does not use advertising or analytics cookies.

5. This website

  • No tracking. prolley.com uses no analytics, advertising cookies, social media pixels or other third-party trackers. Fonts are served from our own domain.
  • Hosting logs. Our hosting provider records technical data such as IP address, browser type and the page requested, for security and to keep the site running.
  • Newsletter and early access. When you sign up, we store your email address, your language, the list you joined and the date. We use it only to send you that newsletter or to tell you when Prolley opens. Your IP address is used briefly to limit repeated sign-ups and is not stored. You can unsubscribe at any time from the link in any email or by writing to us.

6. Why we are allowed to use it

Where we are the controller, we rely on these legal bases:

  • Contract: to provide the app, manage accounts and subscriptions, and give support.
  • Legitimate interests: to keep the service and its data secure, prevent abuse, keep the audit trail, and improve the product. We do not rely on this where your interests outweigh ours.
  • Consent: for the newsletter and early-access emails. You can withdraw consent at any time.
  • Legal obligation: to keep invoices and accounting records, and to respond to lawful requests from authorities.

For payroll data, the legal basis is the customer's, as controller. In most cases it is their obligations as an employer under Cyprus tax, Social Insurance and employment law, and the employment contract.

7. Where your data is stored and who helps us

All data is stored in Microsoft Azure data centres in the European Union. Each customer's data is kept separate from every other customer's, and a customer can have a database of its own.

We use a small number of service providers ("sub-processors"), each bound by a data processing agreement:

  • Microsoft Azure (Microsoft Ireland Operations Ltd): hosting, databases, file storage and backups for the app and this website.
  • Email delivery provider: to send account emails such as invitations and password resets.

We will tell customers before adding or replacing a sub-processor, so they can object. We do not transfer personal data outside the European Economic Area; if that ever becomes necessary, we will use safeguards approved by the European Commission, such as Standard Contractual Clauses.

8. How we protect it

  • All traffic to the app and this website is encrypted with HTTPS.
  • Each customer's data is isolated, and every request is checked against the company the user belongs to.
  • Access inside a company is role-based, so a customer decides who can view, edit or approve payroll.
  • Passwords are hashed; sign-in sessions expire and can be revoked.
  • Every change to employee and payroll data is recorded in the audit trail.
  • Only authorised Prolley staff can reach production systems, and only when needed to run the service or to help a customer who asks.

If a personal data breach affects payroll data, we will notify the customer without undue delay so that it can meet its own obligations. Where we are the controller, we will notify the Commissioner for Personal Data Protection and, where required, the people affected.

9. How long we keep it

  • Payroll data is kept for as long as the customer's subscription is active, because employers in Cyprus must keep payroll and tax records for several years and use earlier periods to calculate the current tax year. When an employee is deleted, their details and pay records are removed and their entries in the audit trail are masked.
  • When a subscription ends, the customer can export its data. We delete it within 90 days, and backups are overwritten in the normal cycle after that.
  • Account data is kept while the account exists. Invoices and accounting records are kept as Cyprus law requires.
  • Newsletter and early-access emails are kept until you unsubscribe or ask us to delete them.
  • Hosting logs are kept for a short period for security and then deleted.

10. Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its use, to receive it in a portable format, and to withdraw consent at any time.

  • If you are an employee of one of our customers, send your request to your employer, who controls your payroll data. If you write to us, we will pass your request to them and help them respond. Note that employers are often required by law to keep payroll records, so some data cannot be deleted on request.
  • If you use the app, visit this website or subscribe to our emails, write to hello@prolley.com. We will answer within one month.

If you believe your data has been mishandled, you can complain to the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy) or to the data protection authority where you live. We would appreciate the chance to put things right first.

11. Changes to this policy

We will update this page when our practices change and show the date at the top. If a change materially affects how we handle customers' payroll data, we will tell customers by email before it takes effect.

12. Contact

Questions about privacy or this policy: hello@prolley.com.

← Back to the home page