Data Processing Agreement
Last updated 2 August 2026
This DPA forms part of the agreement between your organisation (the “Controller”) and Rotasmith (the “Processor”) and governs processing of personal data under UK GDPR.
Roles & scope
Rotasmith processes personal data only to provide the rota, attendance and leave service, and only on the Controller's documented instructions (including via the application's settings).
Nature of processing
- Data subjects: the Controller's employees and invited staff.
- Categories: identity/contact, employment details, leave records, and — where used — sickness absence (health data), restricted to HR-role users.
- Attendance: scheduled shifts, clock-in and clock-out times, hours worked and overtime. Where a shared clocking-in device is used, a four-digit PIN per person, held only as a salted hash. No biometrics, no location data, no images.
- Purpose: building and publishing rotas, recording working time, calculating hours and overtime for payroll, and recording, approving and reporting on leave.
- Duration: for as long as the Controller's account is active, plus any retention period they set.
Security measures
- Encryption in transit (TLS) and at rest at the infrastructure layer.
- Strict per-organisation data isolation enforced on every query.
- Role-based access; special-category (sickness) data limited to HR.
- Least-privilege access to production and audit logging of changes.
Sub-processors
The complete list of sub-processors, and where each one processes data:
- Vercel — application hosting. Processed in London (lhr1).
- Neon — database hosting. Processed in London (eu-west-2).
- Resend — transactional email (sign-in links, approval notices). Processed in the EU (Ireland).
- Stripe — payment processing. Billing contact and payment data only; no staff records are shared with Stripe.
We will give the Controller notice before adding or changing a sub-processor, so they have the opportunity to object.
International transfers
Data is stored in the UK/EU. Where any transfer outside the UK occurs, it is covered by an adequacy decision or the UK International Data Transfer Agreement / SCCs.
Data subject rights & assistance
We provide tools for export and erasure and will assist the Controller in responding to data subject requests and to the ICO where required.
Breach notification
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting their data.
Deletion & return
On termination, and at the Controller's choice, we return or delete personal data, subject to any legal retention requirement.
Contact
Email mehceh3690@gmail.com.