Cintra People
Our service provides HR and Payroll software and services to clients across multiple industries in all sectors. Our cloud-based solution supports the in-house processing of HR and Payroll Management including but not limited to performance management, onboarding, analytics with full integration capability. We also offer an outsourced payroll service.
Features
- Employee Self Service
- Cloud Platform
- Single Solution - integrated HR and Payroll
- Automate processes - workflows, RTI
- Reporting - report packs
- Fully compliant - automatic updates
- Date Driven - Auto-calculations
- Seamless onboarding - dedicated project team
- Configurable solution
Benefits
- Safe, secure, minimises workload, reduces paperwork, tailored , responsive interface
- Access to payroll data, dashboard tiles, manager access, devolve responsibility
- Streamline tasks, improve efficiencies, reduce risk
- Simplify processes, save time, reduce human intervention
- Time reduction, easy report creation,
- Total compliance always, reduced risk
- Removes need for manual calculations
- Online email support, messaging and phone support
- Adaptable, time saving, better process management, reduce errors
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 3 9 2 8 0 3 5 4 3 6 2 8 8 9
Contact
CINTRA HR & PAYROLL SERVICES LTD
Aimee Charlotte Skelton
Telephone: +441914787000
Email: sales@cintra.co.uk
About the service
- Service categories
-
Applications
Enterprise resource management
- Payroll management
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
NA - no hardware constraints
Maintenance arrangements are also minimal - System requirements
- MFA
User support
- Email or online ticketing support
- Yes
- Support response times
- Questions are triaged. In general questions are responded to within one workind day unless they are determined to be urgent in which case they will be responded to within 30mins/1 hour
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer a single level of support for all clients.
We have a dedicated support team who can deal with all technical queries and issues. You will have a named account manager that will be able to assist with on-going contract management and work with you on a consultancy level . - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- From the outset, we provide guided implementation project support which ensures that the system is configured for your requirements. We provide User training as part of the implementation process and on an ongoing basis as required. We have an extensive online library of guidance, information, fact sheets and how-tos. We also have a dedicated support team who can respond to queries as well as the use of our Cloud messaging service which is a means of communicating directly with our outsource team if you are using our payroll team for processing.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Data can be extracted from the system
This can be provided to the client within a CSV format - End-of-contract process
-
Our Exit Strategy details the process for contract migration or handover.
Data which is returned to the Data Controller will be executed in line with the Information Transfer Policy which can be summarised as follows:
-Formal agreements and arrangements for the transfer of data must be set up prior to data transfer.
-Transfer of data should not contradict the PSSG Data Protection Policy, PSSG Data Retention Policy, or contravene any data protection legislation.
-Personal data will not be transferred outside of the European Economic Area without prior written consent of the data subjects and proper legal justification.
-Transfer volume and frequency should not unduly affect normal operations. If excessive or unfounded requests for data transfer are received, PSSG reserve the right to charge an appropriate admin fee, which will be agreed in advance by both parties.
-Both parties must take appropriate steps to ensure confidentiality, integrity, and availability of data is preserved during transfer. Key contacts for data transfer should be agreed in advance of the event - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Online
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
No difference
Employee Manager access to self service has been designed with mobile phones in mind enabling users to download payslips, book absences, access P60s, P11d - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Cintra’s service interface enables secure, automated data exchange between your HR/payroll system and third-party applications. Interfaces can be inbound or outbound, using encrypted file transfers via SFTP and PGP. Custom business rules, scheduling options, and full transaction logging ensure accuracy and compliance. Development includes requirements gathering, build, and rigorous testing before client UAT. Once approved, interfaces go live under agreed criteria for frequency, data types, and governance. Post-launch changes follow a formal change control process. This structured approach ensures seamless integration, robust security, and flexibility to meet your organisation’s operational needs.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Cintra’s service is designed for accessibility and inclusivity. Users can access the platform via any modern web browser without additional software, ensuring compatibility with assistive technologies like screen readers. Administrators can configure user roles, granting permissions for tasks like data entry, reporting, and approvals
- Accessibility testing
- We use CircleCI as our testing software in order to deploy our software. When we add new functionality , as part of testing before deployment we build into our testing routines. The software steps through each process automatically.
- API
- Yes
- What users can and can't do using the API
-
An integration key will be provided on request allowing for a third-party system to make API requests into our payroll system. All changes would be made through this method.
Our main API documentation can be accessed at - https://api.cintra.cloud/documentation/index.html. We also have the ability to create a specific Integration API for the purposes of a deeper integration. To use this, we would share a postman collection with the client of all the endpoints we have available. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Core HR modules - including absence management, performance reviews, onboarding workflows, and engagement tools -can be tailored to match your processes. Data fields, HR checklists, and policy templates are fully configurable, ensuring compliance with internal standards. Organisational structures are adaptable, supporting departments, teams, and complex approval flows, including multi-academy trust configurations.
Payroll services provide choice and scalability, with options for fully outsourced, co-managed, or hybrid models. Advanced reporting tools, such as Cintra Groups, enable consolidated insights across entities. Integrations with third-party systems; finance, recruitment, and learning management, can be implemented during onboarding for seamless connectivity.
A comprehensive policy library with over 100 editable templates allows branding and customisation to reflect your organisation’s identity. Reporting and analytics capabilities include configurable dashboards, KPIs, and bespoke reports for trust-wide or departmental visibility, empowering data-driven decision-making.
Scaling
- Independence of resources
- Databases are single-tenant which limits the effect on service users. The service is scalable and continually monitored.
Analytics
- Service usage metrics
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users have the ability to run standard and custom reports through the software. Data can be exported in CSV, xls, PDF , Word.
In Cintra Cloud, users can select data and export with a click of a button. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Xls
- Word
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We don't have an SLA for availability
- Approach to resilience
- Available on request
- Outage reporting
- Email alerts and status page are used to report outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Regarding support channels we follow user identification, to ensure that you are a user of the system.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus and ISAE3402
- Information security policies and processes
-
We have numerous policies in place and operate in line with ISO 27001.
Cintra follow the principles of the Data Protection Act 2018, United Kingdom General Data Protection Regulation (UK GDPR) and the European Union General Data Protection Regulation (EU GDPR). - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Compliance FAQs
Software development cycle compliance
IT infrastructure and cloud change management - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We have an IT team that follow security blogs and information portals to identify any new common threats.
We perform regular penetration testing to ensure that we analyse potential vulnerabilities.
Any vulnerabilities that are classed as either High or Critical have an SLA of 24 hours from being identified to when they are fixed, deployed and in production
Whenever a vulnerability or threat is identified, we convene a group of our most senior IT and infrastructure engineers to work out what needs to be done and plan a course of action within 4 hours of the threat being identified - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We have tools to monitor for potential compromises. Primarily we install anti-virus software on our machines. Compromises are alerted through email/live chat systems to our IT team.
An individual is responsible for triaging potential alerts in 5 mins. In the event of a large threat, they initiate a group call with relevant members of our IT/Development teams.
Our experienced professionals do no other work until the threat is identified and entirely eliminated.
Our maximum SLA is 24 hours to resolution but we expect this to be under 1 hour.
We use Dark Trace to eliminate and isolate network-related threats automatically. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Incidents are either reported manually by customers to our support team, or we have active monitoring of all servers and services and any incidents are quickly identified.
A designated individual for each area of our system is responsible for triaging potential issues and prioritising this. If they identify that the issue is a P1 issue (major customer impacting incident that prevents significant parts of our system from operating correctly) they convene a group of our experienced IT and Development professionals who work together until the incident is resolved.
Our SLA for P1 Incident resolution is 1 hour. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Cintra People HR is available which gives full access to our HR software
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- LRQA Limited -
- ISO/IEC 27001 accreditation date
- Wednesday 22 October 2025
- What the ISO/IEC 27001 doesn’t cover
- All business activities are in scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- LRQA Limited
- ISO 9001 accreditation date
- Wednesday 22 October 2025
- What the ISO 9001 doesn’t cover
- All business activities are in scope
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- F890cb81-0fdd-4f3f-a36b-fd2c95c5721e
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Beef8d78-d10a-44f6-b985-5ecce3ff0b1e
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce