MS Payroll

Legal

Privacy Policy

Last updated: 4 August 2026. This policy explains how we handle personal data as a UK payroll provider.

Milman Services Ltd (“MS Payroll”, “we”, “us”, or “our”) takes the protection of personal data seriously. Payroll data is sensitive by nature: it includes identifiers, earnings, tax codes, bank details for pay processing, and often special-category information connected to statutory payments. This Privacy Policy explains what we collect, why we process it, who we share it with, how long we keep it, and what rights you have under UK data protection law.

This policy covers our website, enquiry forms, and the processing we carry out when delivering payroll, CIS, auto-enrolment, and related services. Where we process employee or worker data on behalf of a client employer or agency, we typically act as a data processor. Where we process data for our own business (for example website analytics, marketing, or our own staff), we act as a data controller.

1. Who we are

Data controller / provider: Milman Services Ltd
Company number: 17262522
Incorporated: 4 June 2026
Registered / trading address: 26 Milman Road, Liverpool, England, L4 5SH
Privacy contact: privacy@milman.services
Telephone: 0161 835 4141

If you are an employee or worker paid through a client of ours, your employer or engaging agency is usually the data controller for your employment/payroll data. We process that data under their instructions and a data processing agreement.

2. Whose data we process

  • Employers, directors, agency contacts, and other business clients
  • Employees, workers, CIS subcontractors, and contractors whose pay we process
  • Website visitors and people who submit contact or callback forms
  • Accountants, bookkeepers, HR contacts, and other professional advisers acting for clients
  • Our own staff, applicants, and suppliers (covered under separate internal policies where applicable)

3. Categories of personal data

Depending on your relationship with us, we may process:

  • Identity and contact data: name, title, address, email, telephone number, date of birth, National Insurance number, employee/payroll reference
  • Employment and engagement data: job title, department, start/leave dates, contract type, hours, rotas, venue or site, SIA licence details where relevant, and status (employee, worker, CIS, director)
  • Pay and tax data: tax codes, student loan indicators, PAYE references, Accounts Office references, gross/net pay, NIC, statutory payments (SMP, SPP, SSP, SAP), attachments of earnings, court orders, bonuses, allowances, tips/tronc, mileage, and overtime
  • Pension data: auto-enrolment assessment outcomes, contribution rates, scheme membership, opt-in/opt-out status, and provider identifiers
  • CIS and construction data: UTR, verification status, deduction rates (20%/30%/0%), and monthly CIS statement information
  • Banking data for payroll: sort code and account number (or equivalent) used to generate BACS/payment files - we do not store payment card details for website fees
  • Special category / sensitive data may arise incidentally through statutory leave, health-related SSP information, or equality monitoring supplied by a client. We process this only where necessary and lawful (typically under employment/social security obligations or with appropriate safeguards)
  • Technical and usage data: IP address, browser/device type, pages viewed, referral source, and cookie identifiers (see our Cookie Policy)
  • Communications: enquiry messages, call notes, approval emails, and support tickets

4. How we collect data

  • Directly from you via our website forms, email, phone, or onboarding packs
  • From client employers/agencies who instruct us to run payroll
  • From previous payroll providers during mid-year takeovers (YTD figures, starter/leaver history)
  • From HMRC systems in the course of RTI, tax code notices, and CIS verification
  • From pension providers in connection with contribution files and membership status
  • Automatically via cookies and similar technologies when you use our website

5. Purposes and lawful bases

Under UK GDPR we only process personal data where we have a lawful basis. Typical purposes include:

  • Delivering contracted payroll services (calculations, payslips, RTI, CIS, pensions, journals, year-end) - contractual necessity and/or processing on behalf of a controller under Article 28
  • Meeting legal and regulatory obligations to HMRC, The Pensions Regulator, and other authorities - legal obligation
  • Responding to worker and employer enquiries (including payslip, missing payment, and emergency payment queries) - legitimate interests or contractual necessity
  • Securing our systems and preventing fraud/misuse - legitimate interests / legal obligation
  • Improving our website and services using aggregated analytics - consent (non-essential cookies) or legitimate interests where appropriate
  • Marketing to business contacts - consent and/or soft opt-in rules under UK PECR where applicable; you can opt out at any time

Where we rely on legitimate interests, we balance those interests against your rights and expectancies, particularly for workers whose data is processed primarily for pay compliance.

6. Who we share data with

We do not sell personal data. We share it only where necessary for service delivery or legal compliance, including with:

  • HM Revenue & Customs (RTI FPS/EPS, CIS300, tax code notices, and related filings)
  • Workplace pension providers (e.g. NEST, The People’s Pension, Smart Pension, Aviva, Equity Pension Scheme where applicable)
  • Client-nominated accountants, bookkeepers, HR teams, and auditors
  • Payroll software platforms used to deliver the service (such as BrightPay, Xero Payroll, Sage, or equivalents)
  • Secure hosting, email, document, and IT support providers operating under processor terms
  • Payment processors for our own fee collection (card data handled by the processor, not stored by us)
  • Professional advisers (legal, insurance) under confidentiality
  • Regulators, courts, or law enforcement where required by law

Client employers remain responsible for telling their workforce how payroll data is shared with us, typically via their own privacy notice and employment documentation.

7. International transfers

We aim to keep payroll data within the United Kingdom. If a supplier processes data outside the UK, we implement appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another transfer mechanism recognised under UK GDPR, together with transfer risk assessments where required.

8. Retention

We retain records for as long as needed for the purpose collected, then delete or irreversibly anonymise them, subject to legal minimums:

  • Payroll, RTI, CIS, and related statutory records: typically 6 years plus the current tax year (aligned with HMRC expectations and limitation periods)
  • Pension contribution and auto-enrolment evidence: retained in line with Pensions Regulator and scheme requirements
  • Website enquiry and marketing records: retained while the enquiry is active, then for a limited period for follow-up, or until consent is withdrawn for marketing
  • System logs and security records: retained for a shorter operational period unless needed for an investigation

When a client engagement ends, we return or securely destroy client payroll data in accordance with the service agreement, retaining only what we must keep for legal, regulatory, or insurance purposes.

9. Security measures

We apply technical and organisational measures appropriate to the risk of processing payroll data, including:

  • Encryption in transit for data exchange and encrypted storage where supported by our platforms
  • Role-based access controls and least-privilege principles for staff
  • UK-preferenced hosting and documented processor due diligence
  • Staff confidentiality obligations and awareness of payroll data sensitivity
  • Secure methods for receiving timesheets, starter/leaver packs, and approval of pre-run summaries
  • Incident detection, escalation, and breach assessment processes

No method of transmission or storage is perfectly secure. Clients must also protect credentials, approve pay runs carefully, and send data through agreed channels.

10. Your rights

Under UK GDPR you may have the right to:

  • Access your personal data (subject access)
  • Rectify inaccurate or incomplete data
  • Erase data in certain circumstances (not where we must retain it for HMRC or other legal duties)
  • Restrict or object to certain processing
  • Data portability for data you provided to us as a controller
  • Withdraw consent where processing is consent-based
  • Complain to the Information Commissioner’s Office

If we process your data only as a processor for your employer, we may need to refer your request to that employer as controller. To exercise rights where we are controller, contact privacy@milman.services. We may need to verify your identity before responding.

11. Automated decision-making

We do not use solely automated decision-making that produces legal or similarly significant effects about individuals without human involvement. Payroll calculations follow statutory rules and client-approved inputs; material outputs (including pay runs) are subject to agreed approval workflows.

12. Children

Our services and website are directed at businesses and working-age individuals in employment or engagement contexts. We do not knowingly market to children. Where a client employs young workers lawfully, relevant payroll data is processed only as instructed for that employment relationship.

13. Cookies

We use cookies and similar technologies as described in our Cookie Policy. Non-essential cookies are used only with consent under UK PECR.

14. Changes to this policy

We may update this Privacy Policy from time to time - for example when regulations, systems, or services change. The “Last updated” date at the top of this page will change when we do. Material updates may also be notified to clients through our usual communication channels.

15. Complaints and contact

Please contact us first so we can try to resolve your concern: privacy@milman.services.

You also have the right to complain to the Information Commissioner's Office (ICO):
Helpline: 0303 123 1113
Website: https://ico.org.uk/

Postal enquiries: 26 Milman Road, Liverpool, England, L4 5SH