Security & Privacy
Your payroll data in safe Swiss hands.
Payroll means working with a company's most sensitive data. That is why, for us, security is not an add-on feature, it is the foundation of everything we do. Find out how we protect your data here.
Data sovereignty
Swiss software, Swiss operations.
Paymira is Swiss Made Software: developed and operated in Switzerland. Your payroll and personnel data never leave the Swiss legal jurisdiction.
Swiss Made Software
Developed and operated entirely in Switzerland. No data is transferred abroad.
Data Protection Act and GDPR
We comply with the revised Swiss Data Protection Act and the European General Data Protection Regulation.
ISO 27001 certified
Documented processes, regular audits, and ongoing risk management, independently verified.
Our protection goals
Every measure we take contributes to one of three protection goals. They form the foundation of our information security management system.
Artificial Intelligence
AI-first, but responsible.
Your data does not train any models. We use AI to make payroll administration more efficient, but never at the expense of your data. We follow two clear principles when it comes to using AI.
No training with your data
Your payroll and personnel data will never be used to train AI models.
Zero Data Retention
Data used for AI processing is neither stored nor retained by the provider.
Found something? Let us know.
Report actual or suspected security incidents to our security team at any time. You will not face any negative consequences for reporting security concerns in good faith. Responsible reporting is explicitly encouraged and is a core part of our security culture.
General Information Security Policy
This policy outlines the principles by which Paymira protects the company's information and IT assets. It is mandatory for all employees.
Protecting our values
We protect the company's information and IT assets (including, but not limited to, all computers, mobile devices, network components, software, and sensitive data) from all internal, external, intentional, or accidental threats and mitigate the risks of theft, loss, misuse, damage, or unauthorized use of these systems.
Controlled access
Information is protected against unauthorized access. Users are granted access only to the resources for which they are explicitly authorized. The assignment of permissions is strictly controlled and regularly reviewed.
Confidentiality of Information
Information is protected against unauthorized access. Users are granted access only to the resources for which they are explicitly authorized. The assignment of permissions is strictly controlled and regularly reviewed.
Data Integrity
We ensure the integrity of information. This means protecting information from being altered by unauthorized parties.
Availability of information
We ensure the availability of information for business processes. This means guaranteeing that authorized parties can access information whenever they need it.
Compliance
We meet national legal and regulatory requirements, standards, and best practices, and exceed them wherever possible.
Continuous Improvement
We continuously improve our information security management system through corrective actions that enhance its effectiveness.
Business Continuity
We develop, maintain, and test emergency and continuity plans to ensure we stay on track, no matter what obstacles arise. True to the motto: keep calm and carry on.
Awareness & Training
We promote information security awareness and provide all employees with relevant training. We conduct regular awareness campaigns and targeted training sessions, integrate security responsibilities into job descriptions, and ensure that compliance with security requirements is an integral part of our company culture.
Whistleblower Protection
No action will be taken against employees who report a security concern, whether through an official channel or by contacting the Information Security Management team directly, unless the disclosure clearly indicates illegal activity, gross negligence, or repeated, intentional disregard for regulations or procedures.
Incident Reporting
All actual or suspected information security breaches must be reported to security@paymira.com.





