Security

Your payroll data is safe with us.

Payroll is one of the most sensitive operations a business runs. Here is exactly how we protect your data and your employees' information.

Encrypted in transit and at rest

TLS 1.2+ for all connections. AES-256 encryption at rest on every database row.

Tenant isolation

Each business's data is isolated at the database level. No cross-tenant data access is possible.

Isolated per business

Row-level security keeps every business's records separate. No shared hosting, no infrastructure we do not control.

1. How your data is stored

All WadataHR data - business profiles, worker records, payroll history, contracts, and payslips - is held in a managed, access-controlled database with encryption at rest and automated backups.

We do not store data on shared hosting or on any infrastructure we do not control. If you need our current hosting region and provider in writing, for a procurement or due-diligence review, email hello@wadatahr.com and we will confirm them.

2. Encryption

In transit: Every connection between your browser and WadataHR uses TLS 1.2 or higher. All connections are HTTPS-only. We enforce HSTS (HTTP Strict Transport Security) so browsers never connect over plain HTTP.

At rest: All data stored on disk - database rows, backups, file attachments - is encrypted using AES-256. This means even if a physical drive were ever removed from a data centre, its contents would be unreadable without the decryption keys, which are stored separately.

Sensitive fields: Fields containing particularly sensitive employee data - National Identification Numbers (NIN), Bank Verification Numbers (BVN), and bank account details - are treated with additional controls beyond standard database encryption.

3. Tenant isolation

Every WadataHR account is a separate tenant. Your workers, payroll records, and business settings are isolated from every other business on the platform using Postgres Row-Level Security (RLS) - a database-enforced access policy, not just an application-level check.

This means even if there were a bug in our application code, the database itself would block any query that tried to read another business's data. One business cannot see, access, or modify another business's records under any circumstances.

4. Access control

Within your account, access is role-based:

Every action that changes data - running payroll, adding a worker, confirming a contract - is tied to the user who performed it. You can see who did what and when from your settings page.

Multi-factor authentication (MFA/TOTP) for account owners is on our near-term roadmap and will be available soon.

5. Authentication

Authentication uses industry-standard JWT (JSON Web Tokens) with short expiry windows and secure refresh token rotation. Passwords are hashed using bcrypt - we never store or have access to your plaintext password.

Session tokens are stored in secure, HttpOnly cookies that cannot be accessed by JavaScript running on the page, which protects against cross-site scripting (XSS) attacks.

6. Third-party services

We use a small, vetted set of third-party services. Each one is chosen for their security posture:

We do not use advertising networks, third-party analytics that track users across sites, or any service that sells user data. We previously used PostHog and Sentry - both have been removed.

7. Error monitoring and logging

Application errors are logged to our own internal error table - not to any third-party service. Logs are automatically scrubbed of sensitive fields before storage: passwords, tokens, API keys, salary figures, bank account numbers, BVN, and NIN are redacted and never appear in error logs.

Error logs are accessible only to WadataHR engineers and are retained for 90 days.

8. Data retention and deletion

You own your data. Before cancelling, you can export all payroll records, worker profiles, contracts, and payslips in Excel and PDF format at any time from your dashboard.

After account cancellation:

Payroll and compliance records you export are your responsibility to retain for the periods required under Nigerian law (FIRS recommends 6 years for tax records).

9. Incident response

If we ever detect a security incident that affects your data, we will notify you by email within 72 hours of becoming aware of it, in line with GDPR notification requirements. The notification will tell you what happened, what data was affected, what we are doing about it, and what you should do.

We maintain an internal incident response runbook that is reviewed and updated quarterly.

10. Data protection posture

WadataHR operates in compliance with Nigeria's Nigeria Data Protection Act 2023 (NDPA), administered by the Nigeria Data Protection Commission (NDPC). Where personal data is processed outside Nigeria, we apply GDPR-level safeguards to that transfer: data minimisation, purpose limitation, and prompt breach notification.

We act as a data processor on behalf of your business (the data controller) for your employees' personal data. Our Privacy Policy and Terms of Service set out the data processing agreement terms.

NDPA 2023 GDPR-level safeguards AES-256 at rest TLS 1.2+ Row-level isolation

Have a security question?

If you are evaluating WadataHR for your business and need more detail for your due diligence, we are happy to answer. Responsible disclosure reports are also welcome.

Email security@wadatahr.com