Privacy Statement

1. Who we are

The Salary Matrix platform at https://www.salarymatrix.idhtrade.org (the "Platform") is operated by IDH Solutions B.V., registered with the Dutch Chamber of Commerce (KvK) under number 88809390, with registered office at Arthur van Schendelstraat 500, 3511 MH, Utrecht, the Netherlands ("IDH Solutions", "we", "us"). IDH Solutions is part of the group of Stichting IDH.

For all data protection questions, or to exercise any of your rights, contact us at dpo@idhtrade.org. Capitalised terms not defined here have the meaning given in our Terms of Use at https://salarymatrix.idhtrade.org/terms-of-use and, for worker data, our Data Processing Agreement at https://salarymatrix.idhtrade.org/data-protection-agreement.

2. What this statement covers — and our two different roles

We handle personal data in two fundamentally different roles, and it matters which one applies to you:

  • Where we are the controller (this statement applies in full). We decide how and why we process personal data relating to: visitors of the Website; the individuals who register and use Accounts (producers, buyers, intermediaries and their authorised users); contact persons of our customers and partners; and people who contact our support or attend our trainings and events. We are also the controller for the creation and use of fully anonymised, aggregated statistics (Section 6).
  • Where we are a processor (this statement applies only indirectly). The payroll and workforce data that a producer uploads about its workers — remuneration, benefits, job category, gender, worker IDs — is controlled by that producer (or its employing entity). We process it exclusively on the producer’s documented instructions under our Data Processing Agreement at https://salarymatrix.idhtrade.org/data-protection-agreement, and we never disclose it to a buyer or intermediary unless the producer has accepted a data-sharing Connection in the Platform. Section 5 explains what this means if you are a worker.

Our Terms of Use (Section 7.2) set out this role allocation contractually. If anything in older documents suggested that IDH is the controller of all data on the Platform, this statement and the Terms of Use replace that description.

3. Personal data we collect as controller

Account and profile data Name, (business) email address, organisation, role, country, language preference, password (hashed), account settings, and acceptance records of the Terms of Use (version and timestamp).
Organisation and connection metadata Facility names and system-generated Facility IDs, system-generated Matrix/ Calculation IDs, the existence and settings of Connections (who is connected to whom, at what visibility level, for what duration), and invitation and revocation events.
Usage and log data Log-ins, IP address, browser and device information, pages and features used, timestamps, error logs, and security events (such as failed log-in attempts).
Support and communications data The content of your messages to our support, training and event registrations and attendance, feedback and survey responses, and records of correspondence.
Billing and transaction data For paid Accounts: billing contact, organisation billing details, VAT/tax identifiers, plan and add-ons, invoices and payment status. We do not store full card numbers; card payments, if any, are handled by our payment provider.

We collect this data directly from you when you register, use or configure the Platform, contact us or attend our events; automatically when you use the Website and Platform; and occasionally from the colleague or organisation that invited you to an Account.

4. Why we process it, and our legal bases (as controller)

We process the personal data described in Section 3 for the following purposes, on the legal bases indicated (all references are to Article 6(1) GDPR):

Providing the Platform Creating and managing Accounts, authenticating users, enabling Connections and the Buyer Dashboard, and delivering the functionality you request. Basis: performance of a contract (b), or our legitimate interest in serving the organisation that invited you (f).
Security and integrity Protecting the Platform and its users against unauthorised access, fraud and abuse, including logging, monitoring described in Section 10.2 of the Terms, and enforcing usage limits. Basis: legitimate interests (f) and legal obligation (c).
Support and service communications Responding to your requests, sending service and administrative messages, and providing training. Basis: contract (b) and legitimate interests (f).
Billing and administration Invoicing, collecting fees, tax and accounting compliance. Basis: contract (b) and legal obligation (c).
Improving the Platform Understanding how the Platform is used, diagnosing problems and developing new features, wherever possible using aggregated or pseudonymised data. Basis: legitimate interests (f).
Marketing (limited) Sending occasional information about the Platform to business contacts, from which you can opt out at any time. Basis: legitimate interests (f) or, where required, consent (a).
Legal compliance and defence Complying with legal obligations and establishing, exercising or defending legal claims. Basis: legal obligation (c) and legitimate interests (f).

 

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may ask us for information about that balancing, and you may object as described in Section 11. Where we rely on consent (for example, certain cookies or marketing), you may withdraw it at any time without affecting processing that already took place.

5. If you are a worker (we are a processor, not the controller)

If you work for an producer employer that uses the Salary Matrix, that producer employer may upload data about your remuneration and job to calculate the gap between what workers are paid and a living wage. For that worker data, your employer — the producer, or the entity that employs you — is the controller. It decides what to upload and why. We only host and process that data on the producer’s employer’s instructions, as its processor under our Data Processing Agreement.

What this means for you in practice:

  • Your employer should have informed you about this processing and given you its own privacy notice. Questions about why your data is processed, and requests to access, correct or delete it, should be directed to your employer as the controller.
  • The Platform is designed to identify workers by job category groups or pseudonymous worker IDs rather than by name. Producers are contractually instructed not to upload names or other direct identifiers unless strictly necessary, and not to upload special-category data (such as health or trade-union membership) unless strictly necessary and lawful.
  • Your data is not visible to any buyer or intermediary unless your employer has actively accepted a Connection in the Platform. Even then, sharing is limited to the agreed visibility level and can be revoked for the future by your employer.
  • If you contact us directly about worker data, we cannot act on it ourselves — but we will, without undue delay, forward your request to the relevant producer employer account and assist that producer employer in responding, as our DPA requires. If you are unable to identify or reach your employer, contact us at livingwagematrix@idhtrade.org and we will help you find the right route.

You retain all rights the GDPR gives you against the controller, and you may always lodge a complaint with a supervisory authority (Section 14).

6. Anonymised and aggregated data

We create statistics and insights about living wage gaps across sectors, countries and supply chains. Before any such data is used for our own analysis, benchmarking, publication or commercial purposes, it is aggregated and anonymised so that no individual, facility or organisation can be identified, whether directly or indirectly, by us or by anyone else — taking into account the risks of singling out, linkability and inference. This anonymisation standard is the one set out in Section 8 of the Terms. Once data meets this standard it is no longer personal data and falls outside the GDPR. For the operation of creating this data, and for the resulting datasets, we act as controller in our own right (Section 7.2 of the Terms and Clause 11 of the DPA).

We do not sell personal data. We only ever commercialise data in this fully anonymised, aggregated form. 

7. Who we share data with

We share personal data only as necessary and only with:

  • Service providers (processors) who host and support the Platform on our behalf, under contracts that meet Article 28 GDPR. Our current sub-processors — (including Heroku and Amazon Web Services as core hosting providers, hosting region: Europe) is listed at https://salarymatrix.idhtrade.org/sub-processors.
  • Other users, to the extent the Platform is designed to make information visible — for example, the fact and settings of a Connection are visible to the connected parties. Worker data is shared with a buyer or intermediary only through a Connection accepted by the producer, as described in Section 5 and Section 7.4 of the Terms; the recipient then acts as an independent controller of the data it receives.
  • Professional advisers, auditors, payment and tax service providers, where necessary and under confidentiality.
  • Authorities and third parties where required by law, to enforce our Terms, or to protect the rights, safety and security of IDH Solutions, our users or the public.
  • A successor entity in the context of a merger, acquisition or reorganisation, subject to this statement and applicable law.

We do not share personal data with third parties for their own marketing.

8. International transfers

The Platform is hosted on Heroku in Europe. Some of our service providers may process personal data outside the European Economic Area (EEA). Where that happens, we rely on a recognised transfer mechanism under Chapter V GDPR — an adequacy decision of the European Commission, EU-US Data Privacy Framework registration, or the Commission’s Standard Contractual Clauses supplemented by additional safeguards where necessary. You may request a copy of the relevant safeguards, or information about the countries involved, at dpo@idhtrade.org.

9. How long we keep data (as controller

We keep personal data only as long as necessary for the purposes in Section 4, and then delete or anonymise it. Our main retention periods are:

Account and profile data For the life of the Account, and then deleted or anonymised within a reasonable period after the Account is closed, subject to the export window and backup purge below.
Post-termination export On account closure, worker data controlled by a producer is available for export for 90 days (Section 7.7 of the Terms and Clause 14 of the DPA), after which it is deleted from active systems.
Backups Residual copies in backups are overwritten on our routine backup cycle, within a maximum of 35 days after deletion from active systems.
Usage and log data Generally up to 12–24 months, and shorter where possible; security logs may be kept longer where needed to investigate incidents.
Billing and tax records Retained for the statutory period under Dutch law (currently 7 years for tax purposes).
Support and communications For as long as needed to handle your request and for a reasonable period afterwards for quality and reference.
Acceptance records Records of Terms acceptance (version and timestamp) are kept for the life of the Account and a reasonable period afterwards, to evidence the agreement.

 

Where we are required to keep certain data by law, or need it to establish, exercise or defend legal claims, we retain it for as long as that obligation or need lasts. Anonymised aggregated data (Section 6) is not subject to these periods, because it is no longer personal data.

11. Your rights

Where we are the controller, you have the following rights under the GDPR, which you can exercise by contacting us at dpo@idhtrade.org:

  • Access — to obtain confirmation of, and a copy of, the personal data we hold about you.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted in the circumstances the GDPR provides.
  • Restriction — to limit our processing in certain circumstances.
  • Objection — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Portability — to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Withdraw consent — where we rely on consent, to withdraw it at any time without affecting prior processing.

We will respond within the time the GDPR allows (normally one month). We may need to verify your identity, and in some cases a right may be limited or not apply — we will explain why if so. Exercising your rights is free unless a request is manifestly unfounded or excessive. If you are a worker whose data was uploaded by an employer producer, please address these rights to that producer employer as controller; Section 5 explains how we assist.

12. How we protect data

We apply appropriate technical and organisational measures under Article 32 GDPR, including encryption of data in transit (TLS) and at rest, role-based access controls and least-privilege access, logging and monitoring, the anti-enumeration design of the Connection invitation flow, secure development practices, and regular assessments. The specific measures we commit to for worker data are set out in Annex 2 of the DPA. No system is perfectly secure, but we work continuously to protect your data and to respond quickly to any incident.

13. Personal data breaches

If a personal data breach occurs, we act promptly to contain and assess it. Where we are the controller and the breach is likely to result in a risk to individuals, we notify the competent supervisory authority as required by law and, where the risk is high, affected individuals. Where we are a processor for worker data, we notify the relevant producer (the controller) without undue delay, as set out in Clause 9 of the DPA, so that it can meet its own obligations.

14. Complaints and supervisory authority

We hope to resolve any concern directly — please contact us first at [PRIVACY EMAIL]. You also have the right to lodge a complaint with a data protection supervisory authority. Our lead authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, the Netherlands, https://autoriteitpersoonsgegevens.nl. You may also complain to the authority in your country of residence or work.

15. Children

The Platform is a business tool intended for use by organisations and their authorised personnel. It is not directed at children, and we do not knowingly collect personal data from children through the Platform.

16. Changes to this statement

We may update this statement from time to time to reflect changes in the Platform, our practices or the law. When we make material changes, we will update the version number and effective date above and, where appropriate, notify Account holders through the Platform or by email. The version in force is the one published at the URL above on the date you access it.

How to contact us

Controller: IDH Solutions B.V., KvK 88809390, Arthur van Schendelstraat 500, 3511 MH, Utrecht, the Netherlands.

Data Protection Officer: dpo@idhtrade.org

General support: livingwagematrix@idhtrade.org Helpdesk email address