Data Processing (GDPR)
Last updated: 28 May 2026
When you (the customer) enter personal data about your employees into MyRota, you are the Data Controller and MyRota is the Data Processor under Article 28 of the GDPR.
This page summarises how we process that data. A full executable Data Processing Agreement (DPA) is available on request — email hello@myrota.ie.
1. Subject matter and duration
Subject matter: provision of the MyRota staff scheduling, leave management, compliance and payroll-export service.
Duration: for as long as you have an active subscription, plus a 30-day read-only export window after cancellation.
2. Nature, purpose and categories of data
Nature: storage, organisation, retrieval, display and export of employee scheduling and HR data.
Purpose: to enable you to build rotas, track leave and sickness, run Irish-employment-law compliance checks, and generate payroll exports.
Categories of personal data: names, contact details, employment details (start date, role, contracted hours, pay rate), shift records, leave and sickness records, uploaded documents (contracts, certificates), training records, HR notes, photos.
Categories of data subjects: your employees and any other staff records you enter.
3. Subprocessors
We use the following subprocessors. All store and process data within the European Union:
- Supabase Inc. — Postgres database and file storage. EU region (Frankfurt / eu-west-1).
- Vercel Inc. — application hosting and serverless compute. EU region (Frankfurt).
- Stripe Payments Europe Ltd — payment processing. Dublin, Ireland.
- Resend Inc. — transactional email delivery. Dublin, Ireland.
We will give you reasonable advance notice (by email) before adding or replacing a subprocessor. You may object on legitimate grounds.
4. Security measures (Article 32)
We implement appropriate technical and organisational measures, including:
- TLS 1.2+ for all data in transit.
- Encryption at rest for the database and file storage.
- Password hashing using industry-standard algorithms.
- Short-lived signed URLs for document and certificate downloads; files are never publicly accessible.
- Role-based access controls within the application and at the database layer.
- Audit logging of changes to employee records.
- Regular backups with a documented restore process.
- Principle of least privilege for our own staff accessing production systems.
5. International transfers
We do not transfer personal data outside the European Economic Area.
6. Assistance to the Controller
We will assist you, where reasonably practical, in: responding to data-subject requests; carrying out data-protection impact assessments; reporting personal-data breaches; and demonstrating compliance.
We will notify you without undue delay (and in any event within 72 hours) after becoming aware of a personal-data breach affecting your data.
7. Deletion and return of data
On termination of your subscription, your data is retained in read-only mode for 30 days so you can export it. After that period it is permanently deleted from production and from backups within a further 30 days, unless we are required by law to keep it (e.g. billing records held for 6 years for Revenue purposes).
You can also request earlier deletion at any time from Settings → Danger zone.
8. Audit rights
Once per calendar year, on at least 30 days' written notice, you may request and we will provide reasonable information needed to demonstrate compliance with our obligations as Processor.
9. Signed DPA
If you require a counter-signed Data Processing Agreement, email hello@myrota.ie with your legal-entity name and we will send one for execution.
10. Related policies
See also our Privacy Policy, Terms & Conditions, and Cookie Policy.