Data Protection
Last updated: 10 April 2026
Lune Valley Payroll is committed to handling personal data responsibly and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. As a payroll service provider, we process personal data on behalf of our clients as part of our core services, and we take this responsibility very seriously.
1. Data controller and data processor
Lune Valley Payroll acts in two capacities under UK GDPR. In relation to our own business operations and website, we are the data controller. When processing employee payroll data on behalf of our clients, we act as a data processor, carrying out processing activities under the instructions of our clients who remain the data controller for their employees’ personal data.
Email: [email protected]
Website: lunevalleypayroll.co.uk
2. What personal data we hold
As part of providing payroll services, we may process the following categories of personal data:
- Employee names, addresses, and contact details
- National Insurance numbers and tax codes
- Salary, wage, and payment information
- Bank account details for payroll payments
- Statutory payment records (SSP, SMP, SPP, etc.)
- Pension enrolment and contribution data
- Starter and leaver information including P45s and P60s
- CIS subcontractor verification and payment records where applicable
We also hold personal data relating to our business clients, including contact names, email addresses, phone numbers, and business details necessary to manage our working relationships.
3. Lawful basis for processing
We process personal data on the following lawful bases:
- Contract — to deliver payroll services as agreed with our clients
- Legal obligation — to meet HMRC reporting requirements, including Real Time Information (RTI) submissions, and other statutory obligations
- Legitimate interests — to manage our business relationships and respond to enquiries
- Consent — where applicable, for marketing communications
4. How we store and secure your data
All payroll data is processed and stored within our GDPR-secure, cloud-based platform hosted on Microsoft Azure, ensuring industry-leading security, performance, and availability. Access to personal data is strictly limited to authorised members of our team and is protected by robust security measures including encrypted data transmission and access controls.
We do not store payroll data on unsecured devices or systems, and our employee self-service portal allows employees to securely access their own payslips, P60s, and HR documents at any time.
5. How long we keep your data
We retain personal data in line with HMRC and statutory requirements. Payroll records are typically retained for a minimum of 6 years following the end of the tax year to which they relate, in line with HMRC guidance. Data held for business relationship management purposes is kept for up to 6 years after the end of the client relationship.
6. Sharing your data
We do not sell personal data. In carrying out our payroll services, we may share relevant data with the following parties where necessary:
- HMRC — for RTI submissions, CIS returns, and statutory reporting
- Modulr — our FCA-authorised payments technology partner, for processing employee and HMRC payments
- Pension providers — for auto-enrolment and contribution submissions
- Our clients — who remain the data controller for their employees’ data
All third parties we work with are required to handle personal data in accordance with UK GDPR.
7. Your rights
Under UK GDPR, individuals have the following rights in relation to their personal data:
- The right to access the personal data held about them
- The right to have inaccurate data corrected
- The right to have data deleted (where applicable)
- The right to restrict or object to processing
- The right to data portability
- The right to withdraw consent at any time
Employees wishing to exercise their rights in relation to payroll data should contact their employer in the first instance, as their employer is the data controller for that data. For any other data protection queries, please contact us directly and we will respond within one month.
8. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator.
ICO website: www.ico.org.uk | ICO helpline: 0303 123 1113
Contact us
For any data protection queries, please contact the Lune Valley Payroll team:
Email: [email protected]
Website: lunevalleypayroll.co.uk