About PAROGO

Data protection in HR.

Secure data, strong partnerships: handling sensitive personnel data is the foundation of our work – protected on several levels, under the EU GDPR.

Anyone processing personnel data must be able to account for it.

Master and transaction data, absences, certificates: payroll accounting and HR administration are where a company's most sensitive data comes together. We process it under the requirements of the EU GDPR. On our platform edlohn it is held exclusively in Germany and is therefore subject to German law and German data protection.

This page is where we set that out: the rules our specialists work to, the location and equipment of the data centre – and the question of what applies when we work in someone else's system.

Four levels

Four levels between your data and an incident.

Security does not come from one place but from four levels working together: with the people who handle the data, in the infrastructure, in the legal basis and in the rules that apply in day-to-day operation. If one level fails, the others carry.

  1. Security across the companyAll new employees are trained in security, data protection and compliance from their first day – by an independent third party. Data entry always runs under dual control, the software always in a segregated client system.
  2. Security infrastructureOn edlohn your data is held in a German data centre under the EU GDPR: multiple security mechanisms for resilience and protection against attack. Where we work in another system, we make sure the security infrastructure there is equivalent.
  3. Data protectionOn edlohn your data is held exclusively in Germany and is therefore subject to German law and German data protection. Processing follows the requirements of the EU GDPR in every case – including where the system is not operated by us.
  4. ComplianceWith threats growing more complex, we protect client data, employee data and copyright-protected material through clear rules and a corporate compliance that is actually practised.

Infrastructure

A safe home for your data.

Our own software and the third-party software processing personal data that we use – from our software partner Eurodata, for example – run in German data centres. Their security infrastructure provides resilience and protection against attacks of any kind, through multiple security mechanisms:

  • Video surveillance of the server facilities
  • Access controls
  • Redundant power supply
  • Modern firewall and intrusion prevention technology
  • Proactive monitoring by security experts
Security infrastructure

Hosting scenarios

Data security in every hosting scenario.

We work on edlohn or system-agnostically in another system. The standard for security is the same everywhere – who is technically responsible for it differs by scenario. That is why it is set out separately here.

With our software partner Eurodata
your data is held in a German data centre – certified to ISO 27001 and ISO 22301, located in Saarbrücken. The certifications are those of the data centre.
In another system
we make sure the security infrastructure is equivalent. Where we do not operate the system ourselves, the EU GDPR still applies – and we tell you what the operator commits to.
In our own software and our own processes
the same security standards apply: training from the first day, data entry under dual control, operation in a segregated client system.

Security & data protection

Your data – securely hosted in Germany.

We rely exclusively on certified partners and operate the cloud in German data centres – following BSI-Grundschutz and ISO 27001.

  • ISO 27001certified data centre
  • BSI-Grundschutzsecurity standard
  • Data centre in Germanylocated in Saarbrücken
  • GDPR-compliantencrypted in transit

People and rules

Technology protects data. Training and dual control protect against mistakes.

All employees are trained in security, data protection and compliance from their first day – by an independent third party. Data entry always runs under dual control, the software always in a segregated client system.

Our promise

Software supports. People take responsibility.

Let us talk about your payroll – no strings attached, specific, and with a dedicated contact from day one.

Set up fail-safetrue to detail, e.g. shadow payroll
Four-eyes reviewbefore every approval
Hosted in GermanyISO 27001 · GDPR

Frequent questions

What decision-makers want to know about data security.

Where exactly is our personnel data held?
That depends on the system. On edlohn exclusively in Germany – in the certified data centre in Saarbrücken – to ISO 27001 and ISO 22301. Your data is therefore subject to German law and German data protection. If we run payroll system-agnostically in another system, it is held wherever that system is operated; we make sure the security infrastructure there is equivalent. Processing follows the EU GDPR in every case.
Who works with our data – and under what controls?
Trained HR specialists: all employees are trained in security, data protection and compliance from their first day by an independent third party. Data entry runs under dual control, the software always in a segregated client system.
What happens if there is an incident at the data centre?
That is what the ISO 22301 certification covers, the standard for business continuity management: it protects against incidents, reduces their likelihood and secures recovery – supported by redundant power supply and proactive monitoring by security experts.
Are the certifications independently audited?
Yes – ISO 27001 and ISO 22301 are standards-based, audited certifications of the data centre, not self-declarations. They are audited by third parties, not by us.