Skip to content

Legal

Privacy policy

Last updated: 5 October 2026. This policy explains what personal data Mediacent Interactive Ltd, trading as PayrollMaster Africa, collects, why, who we share it with, and what rights you have over it. It covers this website and the PayrollMaster Africa platform, including its integrations.

What data we collect

  • Enquiries and demos. When you contact us or request a demo, we collect your name, work email address, phone number if you give it, company size and the country you pay employees in.
  • Platform accounts. For each user of the platform: name, work email address, role, sign-in details and activity records such as audit logs.
  • Payroll data. The payroll and employee data your organisation uploads or imports — including names, contact details, bank details, salary, statutory identifiers and leave records.
  • Billing data. Payments are processed by our payment providers; we do not receive or store full card numbers. We keep payment references and amounts, and — only if you choose automatic renewal — a reusable payment token issued by the provider.
  • Technical data. IP address, browser and device type, and pages viewed, used for security, troubleshooting and the analytics described below.
  • Data from integrations you connect, described in the next section.

Data from QuickBooks and other integrations

Integrations are optional and are switched on by an administrator in your organisation.

  • QuickBooks Online. We read your company’s name, country, home currency and currency settings, and its chart of accounts, so you can choose which account each payroll item posts to. When one of your users posts a payroll run, we create a summarised journal entry in your company — totals by account, never one line per employee — and replace or remove it when your users ask us to. We do not read or change any other QuickBooks data.
  • Zoho People and Zoho Books. We read the employee, attendance and leave records, or the chart of accounts, needed for the features you turn on, and write payslips or journal entries back when your users ask us to.
  • Google Sheets (where available). We ask Google only for permission to see the email address of the Google account you connect and to work with the spreadsheets that PayrollMaster Africa creates or that you choose to use with it — not the rest of your Google Drive. We use that access only to write the reports and exports your users ask for.

We use data from integrations only to provide those features to your organisation. We do not sell it, use it for advertising, or share it with anyone else. The access tokens that let us reach a connected account are encrypted at rest (AES-256) and never shown in the platform or written to our logs. When you disconnect an integration — in PayrollMaster Africa or from the third-party service — we revoke and delete those tokens; we keep the record of what was posted, such as journal numbers and totals, as part of your audit history.

Google user data

PayrollMaster Africa’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • we use Google user data only to provide the Google Sheets features your users ask for in PayrollMaster Africa, and not for advertising, profiling or any unrelated purpose;
  • we do not sell Google user data, and we transfer it to others only as needed to provide those features, to comply with the law, or as part of a merger or acquisition with notice to you;
  • our staff do not read Google user data unless you ask us to for support, it is needed for security or to investigate abuse, or the law requires it;
  • we do not use Google user data to develop, improve or train generalised artificial intelligence or machine-learning models.

Google access tokens are encrypted at rest like other integration tokens. You can remove our access at any time by disconnecting Google Sheets in PayrollMaster Africa or at myaccount.google.com/permissions; we then delete the tokens and any Google data we hold, and you can ask us to confirm deletion by emailing [email protected].

How we use data

To provide, secure and support the service; to calculate payroll and produce the filings and payments you ask for; to bill you; to send service emails such as payslips, invitations and account notices; to improve the product; and to reply to enquiries and send product news to people who asked for it, which you can unsubscribe from at any time. We also process data where the law requires us to.

Who controls payroll data

Your organisation is the data controller for employee payroll data. PayrollMaster Africa is a processor: we process that data on your instructions, for the purpose of running payroll and producing statutory filings, and for nothing else.

Cookies and analytics

This website uses Google Analytics to measure visits, which is on by default. Advertising and remarketing pixels — Meta Pixel and LinkedIn Insight — load only if you opt in. Zoho SalesIQ provides the chat widget on some pages. The platform uses Google Tag Manager, with consent controls, and Site24x7 to monitor performance and errors. You can block or delete cookies in your browser settings; doing so does not stop the platform from working.

Who we share data with

We do not sell personal data. We share it only with service providers that process it for us under contract, with the third-party services you connect, and with authorities where the law requires. Our main service providers are:

  • DigitalOcean — hosting and databases;
  • Zoho — transactional email (ZeptoMail), customer relationship records (Zoho CRM), website chat (SalesIQ) and performance monitoring (Site24x7);
  • Paystack and DPO Pay — payment processing;
  • Google, Meta and LinkedIn — website analytics and, only with your consent, advertising;
  • Intuit, Zoho and Google — only when your organisation connects QuickBooks Online, Zoho apps or Google Sheets.

Where data is stored

Platform data is stored with DigitalOcean in data centres in India. Where data leaves the country it was collected in, we rely on contracts and the safeguards our providers offer, as the applicable data-protection law requires.

How we protect data

Data is encrypted in transit (TLS). Integration tokens are encrypted at rest. Access inside the platform is controlled by roles your organisation assigns, sensitive actions are recorded in audit logs, and our staff access customer data only to provide support or when the law requires it.

How long we keep it

Payroll records are retained for the period the relevant tax authority requires, which differs by country. When your organisation leaves, we return its data on request and then delete or anonymise it, except records we must keep by law. Integration tokens are deleted when you disconnect. Marketing contact data is deleted on request.

Your rights

You can request access to, correction of, or deletion of your personal data, or object to how we use it, by emailing [email protected]. Employees whose payroll we process should contact their employer, who is the controller of that data. If you are not satisfied with our response you can complain to the data-protection authority where you live — in Kenya, the Office of the Data Protection Commissioner.

Changes to this policy

We will update this policy when our practices change; the date at the top shows the latest version. We will tell platform customers about material changes by email or in the platform.

Contact

Mediacent Interactive Ltd, trading as PayrollMaster Africa, The Apiary, 4th Floor, ABC Place, Waiyaki Way, Nairobi, Kenya. [email protected]