Privacy Policy
Last updated: 30 July 2026
This Privacy Policy explains how Nexus Sentry Ltd ("we", "us", "our") collects, uses, shares and protects personal data when you use PaySentry (the "Service"), visit paysentry.uk, or otherwise deal with us. We've written it to be clear and honest — if anything is unclear, please ask.
We are committed to protecting your personal data and handling it in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Nexus Sentry Ltd is the company behind PaySentry.
- Company number: 14957041 (registered in England & Wales)
- Registered office: 124 City Road, London, England, EC1V 2NX
- ICO registration number: ZC189098 (you can verify this on the ICO register at https://ico.org.uk/ESDWebPages/Search)
- Data-protection contact: privacy@paysentry.uk
If you have any question about this policy or about how we use your personal data, please contact us at privacy@paysentry.uk. We treat every privacy query seriously and will respond promptly.
Data Protection Officer. Because of our size and the nature of our processing, we are not legally required to appoint a Data Protection Officer (DPO) under UK GDPR Article 37, and we have not appointed one. Responsibility for data protection sits with our management, and all data-protection queries should go to privacy@paysentry.uk. (We keep this position under review as we grow.)
2. About PaySentry, and our role (controller vs processor)
PaySentry is a compliance-intelligence platform for the UK umbrella-payroll supply chain. It helps umbrella companies and recruitment agencies check payroll compliance — for example by forensically re-computing payslips against HMRC and employment-law rules, screening companies against public watchlists, producing due-diligence reports, and generating Key Information Documents.
Your relationship with us — and our data-protection role — depends on who you are:
When you are our customer (an umbrella company or recruitment agency that subscribes to PaySentry), and for your account, billing and marketing data, and for personal data of visitors to our website, we act as a data controller — we decide how and why that data is processed.
When our customer uploads worker or payroll data (for example a worker's payslip, name or National Insurance number) so that we can perform a compliance audit on the customer's behalf and instructions, we act as a data processor. In that case the customer is the controller and their own privacy notice governs that data. Our processing is governed by our Data Processing Agreement (see section 12).
This policy focuses on the personal data for which we are the controller, and explains the rest for transparency.
3. The personal data we collect
Depending on how you use PaySentry, we may process the following categories of personal data:
a) Account and customer data (we are controller)
- Name, work email address, job role and the organisation you represent.
- Login credentials (passwords are stored only as secure cryptographic hashes — we never store or see your plain-text password).
- Multi-factor authentication settings and recovery codes (stored encrypted / hashed).
- Contact and communication history with our support team.
b) Billing data (we are controller)
- Subscription plan, billing records and invoices.
- Payment card details are handled directly by our payment provider (see section 8) — we do not store your full card number.
c) Worker and payroll data (usually processed on our customer's behalf — we are processor)
- Worker identity data: name, work email, National Insurance number, phone number.
- Payslip and payroll data: gross/net pay, tax, National Insurance, pension contributions, student-loan deductions, holiday pay and similar figures.
- Documents uploaded for audit (payslips, Key Information Documents, contracts, insurance certificates, HMRC correspondence).
d) Company and supply-chain data
- Publicly-available company information (from Companies House and credit-reference sources), and information about directors and persons of significant control, used for due-diligence and compliance screening.
e) Website and technical data (we are controller)
- IP address, device and browser information, and pages visited.
- Cookies and similar technologies (see our Cookie Policy).
- Analytics data (subject to your consent).
Special category data
PaySentry is not designed to process special category data (UK GDPR Article 9 — e.g. health, or trade-union membership). However, a payslip that a customer uploads for audit may incidentally contain such data — for example a trade-union subscription deduction (which can reveal trade-union membership) or a Statutory Sick Pay / Statutory Maternity Pay line (which can reveal health or maternity information).
Where such data is incidentally present:
- we do not seek, target or profile on it;
- our lawful basis for any Article 9 data is the employment, social security and social protection condition (Article 9(2)(b)) and/or the substantial public interest condition, consistent with our role in umbrella-payroll compliance;
- we apply strict data minimisation — we extract only the fields needed for the compliance audit; and
- the data is encrypted at rest and access-controlled (see section 9).
We do not knowingly process personal data of children through the Service.
4. How we collect your personal data
We collect personal data:
- directly from you when you register, subscribe, upload documents, contact support, or fill in a form on our website;
- from our customers when they onboard workers or upload payroll data for audit;
- automatically when you use the website (cookies, logs, analytics); and
- from public and third-party sources — such as Companies House, HMRC's public APIs, and credit-reference agencies — for company due-diligence and verification.
5. Why we use your personal data, and our lawful basis
Under UK GDPR we must have a lawful basis for each processing purpose. Our bases are set out below.
- Create and manage your account; deliver the Service — to perform our contract with you. Lawful basis: Contract (Art 6(1)(b)).
- Take payment and manage your subscription — to perform our contract and keep financial records. Lawful basis: Contract (Art 6(1)(b)); Legal obligation (Art 6(1)(c)) for tax/accounting.
- Run compliance audits, scoring, watchlist screening and due-diligence — to provide the core Service and detect payroll non-compliance and fraud risk in the labour supply chain. Lawful basis: Contract (Art 6(1)(b)); Legitimate interests (Art 6(1)(f)) — see below.
- Keep the Service secure, prevent fraud and abuse, and maintain audit logs — to protect our platform, customers and workers. Lawful basis: Legitimate interests (Art 6(1)(f)).
- Provide support and respond to your queries — to help you and honour our contract. Lawful basis: Contract (Art 6(1)(b)); Legitimate interests (Art 6(1)(f)).
- Comply with legal, tax, accounting and regulatory obligations — because the law requires it. Lawful basis: Legal obligation (Art 6(1)(c)).
- Send service/administrative messages — to run the Service you've asked for. Lawful basis: Contract (Art 6(1)(b)); Legitimate interests (Art 6(1)(f)).
- Send marketing about our products — you can opt out at any time. Lawful basis: Consent (Art 6(1)(a)) where required, otherwise Legitimate interests (Art 6(1)(f)).
- Analytics and website improvement — to understand and improve the Service. Lawful basis: Consent (Art 6(1)(a)) via our cookie banner.
Our "legitimate interests". Where we rely on legitimate interests, our interest is in operating a compliance-and-fraud-detection service that protects umbrella workers, recruitment agencies and the wider labour supply chain from payroll non-compliance and tax-avoidance risk, and in keeping our platform secure. We have assessed that this interest is not overridden by your rights and freedoms, and we apply safeguards (minimisation, encryption, access control, and your right to object). You can ask us for details of this assessment at privacy@paysentry.uk.
We will always tell you before using your personal data for a new purpose that is not compatible with the purposes above.
Do you have to provide your personal data? Where we process your data to perform our contract with you (for example your account and billing data), providing that data is a requirement of using the Service — if you don't provide it, we won't be able to give you an account or deliver the Service. Where we rely on consent (for example analytics or marketing), providing your data is entirely optional and you can decline or withdraw at any time without affecting your use of the core Service. For worker/payroll data that a customer uploads, whether it must be provided is a matter for that customer (the controller) and their employment/engagement terms.
Withdrawing consent. Where we rely on your consent, you have the right to withdraw it at any time — for example by changing your cookie choices, using the unsubscribe link in a marketing email, or emailing privacy@paysentry.uk. Withdrawing consent does not affect processing we already carried out lawfully before you withdrew it.
6. Automated processing and AI
PaySentry uses automated processing, including artificial intelligence, to help assess payroll compliance and supply-chain risk — for example:
- deterministic re-computation of payslip figures against HMRC/employment-law rules;
- a compliance score and risk indicators; and
- AI-assisted interpretation and due-diligence research.
Important safeguards:
- The compliance score and any certification are limited-assurance indicators shown alongside the evidence — they are not a guarantee of compliance, an official approval, or a substitute for your own due diligence.
- These outputs are not used to make legal or similarly significant decisions about an individual worker within the meaning of UK GDPR Article 22. They are decision-support tools for our business customers.
- Where a human-impacting decision is involved, a human reviews it.
If you believe an automated output about you is wrong, contact us at privacy@paysentry.uk and we will review it.
7. Who we share your personal data with
We do not sell your personal data. We share it only as needed to run the Service and comply with the law:
- Our sub-processors — trusted service providers who process personal data on our behalf under contract (for example: our AI provider, our credit-reference provider, our hosting and email providers, our analytics and payment providers). A current list is in our Sub-processor list (see section 12), and each is bound by UK GDPR Article 28 terms.
- Between customers in the supply chain — where an umbrella company and a recruitment agency are linked through the Service, limited, filtered compliance information (for example a compliance indicator) may be visible to the linked party; sensitive figures and worker personal data are not exposed cross- organisation.
- Public and regulatory bodies — such as HMRC and the ICO — where we are legally required to, or to protect our rights.
- Professional advisers, auditors, and insurers — where necessary and under duties of confidentiality.
- A buyer or successor — if we sell or reorganise our business, subject to this policy.
8. Payments
Payments are processed by our third-party payment provider. When you pay, your card details are collected and processed directly by that provider under their own security standards (PCI-DSS). We do not receive or store your full card number. We keep only records of the transaction (amount, date, plan, and a payment reference).
9. How we keep your personal data secure
Security is central to how PaySentry is built. Our measures include:
- Encryption at rest of personal and payroll data using AES-256-GCM, with strict tenant isolation enforced throughout the platform so each customer's data is kept separate.
- Encryption in transit (TLS/HTTPS) for all connections.
- Access controls — role-based permissions, strict tenant isolation, and least-privilege access for our staff.
- Multi-factor authentication support, and secure password hashing.
- Audit logging of significant actions.
- Data minimisation — we extract and retain only what the compliance task needs.
- Regular security review and hardening of our platform.
No system can be guaranteed 100% secure, but we work hard to protect your data and we will notify you and the ICO of a personal-data breach where the law requires.
10. International transfers
We aim to process personal data in the UK. However, some of our sub-processors process data outside the UK — in particular our AI provider (Google/Gemini), our analytics providers (Google Analytics and Microsoft Clarity, used only with your consent), and our payment provider (Stripe), which are based in or transfer data to the US and other countries. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as:
- transfer to a country with UK "adequacy" status; or
- the ICO's International Data Transfer Agreement (IDTA) / the EU Standard Contractual Clauses with the UK Addendum; together with additional technical measures such as encryption.
You can ask us for details of the safeguards for a specific transfer at privacy@paysentry.uk.
11. How long we keep your personal data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. In general:
- Account data — for the life of your account, then up to 12 months after closure (unless you ask us to delete it sooner and there is no legal reason to keep it).
- Payroll / audit documents and results — for the period agreed with the customer (controller); by default while the account is active, then deleted or returned on the customer's instruction.
- Billing and tax records — up to 6 years (to meet UK tax/accounting law).
- Security and audit logs — typically 12 months, longer where needed to investigate an incident.
- Website analytics — per the retention set in our analytics tools and your cookie choices.
Where we act as processor, retention of worker/payroll data is ultimately directed by our customer (the controller).
12. Related documents
- Cookie Policy — the cookies and similar technologies we use.
- Data Processing Agreement (DPA) — our UK GDPR Article 28 terms for customers (where we act as processor of worker/payroll data).
- Sub-processor list — the third parties that process personal data on our behalf.
13. Your rights
Under UK GDPR you have the right to:
- Be informed — as set out in this policy.
- Access your personal data (a "subject access request").
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data ("right to be forgotten"), where applicable.
- Restrict processing in certain circumstances.
- Data portability — receive your data in a portable format.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Rights relating to automated decision-making and profiling (see section 6).
To exercise any right, email privacy@paysentry.uk. We will respond within one month (extendable by up to two further months for complex requests, in which case we'll tell you). We do not charge a fee for a genuine request. We may need to verify your identity first.
If your request concerns worker/payroll data that a customer uploaded (where we are processor), we will pass your request to the relevant customer (the controller), or act on their instructions.
14. Cookies
We use cookies and similar technologies. Strictly-necessary cookies keep you logged in and keep the Service secure; analytics and other non-essential cookies are used only with your consent, managed through our cookie banner (Google Consent Mode). Full details are in our Cookie Policy.
15. Changes to this policy
We may update this policy from time to time. We'll change the "Last updated" date above and, where changes are significant, we'll tell you (for example by email or an in-Service notice). Please check back periodically.
16. How to contact us or complain
- Data-protection contact: privacy@paysentry.uk
- Post: Nexus Sentry Ltd, 124 City Road, London, England, EC1V 2NX
If you're unhappy with how we've handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK regulator:
Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 · https://ico.org.uk