GRADO Tech
Contact us Italiano
HR for SMEs

Attendance, leave and payslips
in one platform

GRADO HR digitises people management: clock-ins, leave, encrypted payslips visible only to authorised people, performance reviews, and sign-in with Google or MFA — integrated with GRADO Security.

No setup fee · Live in 24h Privacy policy
What's included
Time clock
Mobile, badge and web.
Leave & time off
Digital requests and approvals.
Encrypted payslips
Only authorised people.
Google sign-in & MFA
Two-step verification.
Security integration
One employee record.
Security integration
Training and safety where needed.
Smart clock-ins
Clock in from the mobile app with optional GPS, NFC badge or any browser. History always available.
Leave & time off
Employees request leave from the app. Managers approve in one click. Counters update in real time.
Encrypted payslips
PDFs and net amounts are encrypted at rest. Employees see only their own payslips; HR staff only with an explicit permission. Nothing sent in the clear by email.
Protected access
Sign in with identifier and password, “Sign in with Google” only if the account is already linked, and optional two-step verification (MFA) for every user.

What's included

Clock-in from mobile, NFC badge and web
Leave, time off, ROL and travel
Encrypted payslips, visible only to authorised people
Employee records and contracts
Goals and performance reviews (OKR)
Contract expiry and renewal alerts
Native integration with GRADO Security
Google sign-in, MFA and technical session cookies

Deep dive

Employees clock in and out from the mobile app (optional GPS), NFC badge or any browser. Managers see who is present, late or absent in real time. Hours, overtime and anomalies are calculated automatically.

Employees send requests from the app: holiday, leave, ROL, sickness or travel. Managers approve or reject in one click. Counters update automatically and team calendars stay in sync.

Payslip PDFs and net amounts are encrypted at rest. They are decrypted only when an authenticated, authorised user requests them. Employees see only their own published payslips; HR staff only with explicit permissions. Net amounts stay hidden in lists until unlocked, and every reveal is logged.

People sign in with an identifier (tax code for employees) and password, or with Google if the account was linked from the profile: an unlinked Google account cannot sign in and does not create a new user. Two-step verification uses an authenticator app (Google Authenticator, Authy or similar) and recovery codes. The session uses technical cookies; if you choose to remember the device, an MFA cookie skips the code for the period you set.
How it works

From clock-in to payslip, with protected access

A flow designed for HR managers in SMEs, with payroll data encrypted at rest.

Workflow

1
Import staff
Load records or sync from GRADO Security. Each person gets credentials; from the profile they can link Google and enable MFA.
2
Turn on clock-ins
Employees clock in from mobile, badge or browser. Attendance is recorded in real time with automatic hour calculation.
3
Manage leave
Employees send requests from the app. You approve or reject in one click, with calendars updating automatically.
4
Publish encrypted payslips
You upload the PDFs: they are encrypted in storage. Each employee finds only their own payslips. Unauthorised people cannot see them.
5
Monitor performance and deadlines
The HR dashboard shows contract deadlines, goals, reviews and attendance alerts.
A mobile app for every employee
Clock-ins, leave, payslips and documents on the phone. iOS and Android.
Google and two-step verification
“Sign in with Google” only for already linked accounts. MFA with an authenticator app, recovery codes and an optional remember-device cookie.
Payslips encrypted at rest
PDFs and net amounts are encrypted. The app decrypts them only for people with permission; amounts stay hidden until unlocked.
Integrated with GRADO Security
Shared records: hires and leavers stay in sync. Mandatory safety training is also tracked in the HR profile.
Access and data protection

Who gets in, how they get in, what they can see

GRADO HR is not a shared folder. Access is named, two-step verification is optional, and payslips stay encrypted and visible only to people the workspace has authorised.

1
Workspace credentials

Sign-in with identifier and password (irreversible hash). Employees typically use their tax code. Compromised passwords can be checked with k-anonymity, without sending the password in the clear.

2
Sign in with Google, only if linked

From the profile you link a Google account. After that, “Sign in with Google” opens that same user. An unlinked Google account cannot sign in and does not register a new user.

3
Two-step verification (MFA)

Scan a QR with Google Authenticator, Authy or a TOTP app. The secret is encrypted. Alternatively: 8 recovery codes. You can require the code at every sign-in or remember the device for 1, 7, 30 or 90 days.

4
Technical cookies, no profiling

Session, CSRF token and, if you choose, MFA or “remember me” cookies. No marketing cookies on the platform. Google sets its own cookies only if you use Google sign-in, on Google’s domain.

An unlinked Google account cannot sign in: no accounts created automatically
MFA with TOTP, encrypted secret and an optional “remember this device” cookie
Payslip PDFs and net amounts encrypted at rest; decrypted only on an authorised request
GRADO Tech does not browse workspace content unless explicitly authorised or required by law

Frequently asked questions

With identifier and password, or with Google if the account is already linked from the profile. If MFA is on, after the password (or Google) you enter the 6-digit authenticator code, or a recovery code.

Only people who are expressly authorised. Employees see only their own published payslips. HR staff access other people’s payslips only with workspace permissions. Files and net amounts are encrypted at rest: the application decrypts them at that moment. GRADO Tech does not access the content except in the cases set out in the privacy notice (support on request, legal obligations).

Technical cookies only: session (grado_hr_session), CSRF protection (XSRF-TOKEN), optional mfa_remember if you choose not to repeat the MFA code, and the “Remember me” cookie if you tick it at sign-in. We do not use profiling or marketing cookies. Google cookies appear only if you use “Sign in with Google”, on Google’s domain.

No. PDFs are encrypted in storage. In lists, net amounts stay hidden until an authorised user unlocks them; that reveal is logged. Traffic to the platform is protected with TLS.

Yes, if the controller enables it. Service photo check sends a resized image to an EU-hosted AI model (OpenAI, Gemini/Vertex or AWS Bedrock) to see whether the shot is usable: subject visible, lighting, focus. Any special category data (Art. 9 GDPR) is anonymised before it is sent. The result supports the operator; it is not an automated decision on pay, discipline or ranking. Admins can also optionally send sample payslip PDF text to the same stack to help configure import rules. Details are in the GRADO HR privacy notice.

Digitise human resources

Clock-ins, leave, encrypted payslips and protected access in one platform. Live in 24 hours.

GRADO Tech
Hi! How can I help you? Choose a question.