Privacy Policy
Effective date: 30 September 2026
This policy explains how ESSI Payroll Email, operated for the Employees Social Security Institution (ESSI), Khyber Pakhtunkhwa, accesses the department-controlled payroll mailbox for email delivery reconciliation.
Mailbox data accessed
The application uses the department-controlled Gmail account through encrypted IMAP in read-only mode. It may inspect recent Sent-message headers and relevant mail-delivery notices when required to correlate a payroll email attempt with delivery evidence. The application does not request Gmail API OAuth access and is not a general-purpose inbox reader.
How Google data is used
Mailbox data is used only to reconcile payroll salary-statement email delivery: to correlate a Sent item or authenticated delivery-status notice with an existing payroll email attempt and to record operational delivery evidence such as accepted, delayed, delivered, or failed status.
Storage and retention
The application does not retain raw Gmail message bodies or Gmail attachments. It retains only the payroll delivery audit information needed for departmental operations, such as delivery status, timestamps and sanitised diagnostic information. Retention of those audit records follows applicable ESSI official record and audit requirements.
Mailbox credentials are held only in protected server configuration and are not stored in public pages or application database records. The reconciliation process reuses the approved departmental mailbox credential and opens IMAP folders read-only.
Sharing and advertising
Mailbox data is not sold, used for advertising, or shared for unrelated purposes. Access is limited to authorised operation of the ESSI payroll email function and disclosures required by applicable law or official security/audit obligations.
Security and access control
Operational payroll functions require authentication. The departmental mailbox connection is protected by server access controls and encrypted SMTP/IMAP transport.
Disabling mailbox access
ESSI system administrators can disable mailbox reconciliation at any time and can rotate or remove the protected departmental mailbox credential when the integration is disabled or replaced.
Contact
Questions about this policy or the payroll email integration may be sent to financeessi80@gmail.com.