FairGrade

LEGAL

Privacy Policy

This policy explains what personal data FairGrade handles, why, where it is stored, and what rights you have over it.

Version 1.0 · July 2026

1. Who we are

FairGrade ("we", "us") provides a software platform that helps employers evaluate roles, build pay structures and meet their obligations under Directive (EU) 2023/970.

For questions about this policy or about your personal data, contact us at privacy@fairgrade.eu.

2. Two different roles we play

We are the data controller for the personal data of people who create a FairGrade account and use our website — their name, email address, and how they use the service.

We are a data processor for the employee data that a customer company enters into the platform: staff names, roles, gender, hire dates, pay figures and consent records. That data belongs to the customer, who decides why and how it is processed. We act only on their documented instructions, under a data processing agreement.

If you are an employee whose data appears in FairGrade and you want it corrected or removed, contact your employer — they control it. We will support them in responding to you.

3. What we collect

Account data: full name, email address, password (stored only as a cryptographic hash), preferred language, and the organisation you belong to with your role in it.

Company data: company name, country, industry and headcount.

Role data: job titles, functions, levels, and the role descriptions you write.

Employee data entered by our customers: full name, the role a person holds, gender where provided, hire date, and pay components — base salary, total cash and allowances — with their effective dates.

Transparency records: whether an employee has reviewed how their pay is determined, the date they confirmed it, information requests they submit, and the employer's answers.

Technical data: authentication session cookies, and server logs containing IP address, request time and error information.

4. Why we process it, and on what legal basis

To provide the service you signed up for — creating your account, running the platform, generating your reports. Legal basis: performance of a contract.

To keep the service secure and diagnose faults, including retaining server logs. Legal basis: our legitimate interest in operating a secure and reliable platform.

To meet our own legal and accounting obligations, such as issuing invoices. Legal basis: compliance with a legal obligation.

Employee data is processed on behalf of the customer, who determines its legal basis — typically compliance with their obligations under the pay transparency directive and national employment law.

5. Special category data

Gender is recorded so that a gender pay gap can be calculated, which the directive requires employers to do. Providing it is optional in the platform, and the field can be left blank.

Pay figures are not special category data under the GDPR, but we treat them as highly sensitive: they are visible only to authorised members of the employing company, and to the individual employee for their own record.

6. Where your data is stored

All personal data is stored within the European Union, on infrastructure located in Frankfurt, Germany (AWS eu-central-1), operated through Supabase.

Our application is served by Vercel. Static assets and requests may be routed through its global edge network, but personal data at rest remains in the EU.

We do not transfer personal data outside the European Economic Area. If that ever changes, we will update this policy and put an appropriate transfer mechanism in place first.

7. Who else can see it

Within a customer company, access is controlled by role. Owners and administrators see the full workspace; editors can change data; viewers can only read it. Data belonging to one company is never visible to another.

Employees access their own record through a private link containing a secret token. That link shows only their own role, pay breakdown and consent status.

We use a small number of service providers who process data on our behalf: Supabase (database, authentication), Vercel (hosting), and payment providers when a subscription is taken out. Each is bound by a data processing agreement.

We do not sell personal data, and we do not use it for advertising.

8. How long we keep it

Account and company data is kept while your account is active. If you close your account, we delete or irreversibly anonymise it within 30 days, except where we must retain records for legal or accounting purposes.

Employee data is kept for as long as the customer keeps it in their workspace. Because evaluation records and consent evidence may need to be produced in an inspection or a dispute, customers often retain them for several years; that decision is theirs.

Server logs are retained for a short period for security and troubleshooting.

9. Your rights

You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent where processing relies on it.

To exercise these rights over your account data, contact privacy@fairgrade.eu. We respond within one month.

If you are unhappy with how we handle your data, you may complain to your national data protection authority — in Poland, the President of the Personal Data Protection Office (UODO).

10. Security

Data is encrypted in transit and at rest. Access to each company's data is enforced at the database level, not only in the application, so a request for data outside your organisation cannot succeed.

Employee portal links use long, randomly generated tokens that cannot be guessed. Treat such a link as confidential and share it only with the employee it belongs to.

Access to production systems is limited to those who need it, and protected by strong authentication.

11. Cookies

We use cookies that are strictly necessary to keep you signed in and to keep your session secure. They cannot be switched off without breaking the service.

We do not currently use advertising or third-party tracking cookies. If we introduce analytics, we will ask for your consent first and update this policy.

12. Automated decision-making

FairGrade proposes role scores to help you evaluate work, but no grade is ever finalised automatically. A named person reviews and approves every evaluation, and that approval is recorded. There is no automated decision-making producing legal effects within the meaning of Article 22 GDPR.

13. Changes to this policy

If we make a material change, we will notify account holders by email before it takes effect. The date below shows when this version was published.

DRAFT — PENDING LEGAL REVIEW

This text is a working draft prepared from how the platform actually operates. It must be reviewed and signed off by a qualified data protection lawyer before FairGrade accepts real customer data.