Privacy Policy

Last updated: 24 July 2026

This Privacy Policy explains how [COMPANY LEGAL NAME](“RotaApp”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use rotaapp.uk and the RotaApp shift-scheduling application (together, the “Service”).

We are the data controller for the personal data described in this policy and we are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

  • Data controller: [COMPANY LEGAL NAME], registered in England and Wales under company number [COMPANY NUMBER]
  • Registered office: [REGISTERED ADDRESS]
  • ICO registration number: [ICO REGISTRATION NUMBER]
  • Contact: privacy@rotaapp.uk

If you have a question about this policy or how we handle your data, please contact us using the details above before contacting the Information Commissioner's Office (ICO).

2. What personal data we collect

We collect personal data in the following categories, depending on how you use the Service:

  • Account data: name, email address, password (stored as a salted hash), phone number, and account role (owner, manager, or employee).
  • Organisation and employment data: employer/organisation name, employee job titles, departments, locations, working patterns, availability preferences, and qualifications or certifications you choose to record.
  • Scheduling data: shifts, shift swap requests, time-off requests, time and attendance clock-in/clock-out records, and rota publication history.
  • Billing data: billing name, billing address, and subscription/seat details. Card payment details are collected and processed directly by our payment processor, Stripe — we do not store full card numbers on our servers.
  • Communications data: messages you send us for support, and content of notifications we send about rota changes, shift swaps, or account activity.
  • Technical data: IP address, browser type, device information, and log data generated when you use the Service.
  • AI assistant data: if you use the rota AI assistant, the natural-language prompts you enter and the scheduling data needed to generate a response are sent to our AI processing provider to generate a reply.

We do not knowingly collect special category data (such as health information) except where an employer chooses to record sickness-related time-off in the ordinary course of managing staff absence; this is controlled by the employer organisation using the Service, acting as data controller for its own staff records, with RotaApp acting as a data processor on the employer's behalf in that context.

3. How we use your personal data and our lawful basis

PurposeLawful basis (UK GDPR Article 6)
Creating and administering your accountPerformance of a contract
Providing shift scheduling, swaps, time-off, and time-tracking featuresPerformance of a contract
Processing subscription paymentsPerformance of a contract; legal obligation (tax/accounting records)
Sending service notifications (rota published, shift reminders, invites)Performance of a contract
Sending optional marketing communicationsConsent (you can withdraw this at any time)
Maintaining audit logs for security and complianceLegitimate interests (protecting the security and integrity of the Service)
Responding to support requestsLegitimate interests; performance of a contract
Detecting and preventing fraud or misuseLegitimate interests; legal obligation

4. Who we share your data with

We do not sell personal data. We share personal data only with the following categories of recipients, each acting under a data processing agreement where they process data on our behalf:

  • Hosting and database infrastructure providers, to store and run the Service.
  • Stripe, to process subscription payments.
  • Amazon Web Services (AWS SES), to deliver transactional and notification emails.
  • OpenRouter and the underlying AI model providers it routes to, to power the optional rota AI assistant feature.
  • Other members of your organisation (e.g. managers and owners) who require access to rota, availability, and time-off data to run the scheduling features you use.
  • Regulators, law enforcement, or professional advisers, where we are required to do so by law or to establish, exercise, or defend legal claims.
  • A buyer or successor, if we sell, merge, or transfer all or part of our business, subject to the same protections described in this policy.

5. International data transfers

Some of our service providers (including AI processing and email delivery providers) may process data outside the UK, including in the United States. Where this happens, we rely on the UK International Data Transfer Agreement (IDTA), an EU Commission adequacy decision extended to the UK, or the UK Addendum to the EU Standard Contractual Clauses, to ensure your data receives an equivalent level of protection.

6. How long we keep your data

  • Account and scheduling data: retained for as long as your organisation has an active account, and for up to 7 years afterwards to meet UK employment record and tax record-keeping obligations (for example, working time and payroll-adjacent records under the Working Time Regulations 1998 and HMRC requirements).
  • Billing records: retained for 6 years after the end of the tax year they relate to, in line with HMRC requirements.
  • Audit logs: retained for up to 2 years for security and compliance purposes.
  • Marketing consent records: retained until you withdraw consent, plus a short period to evidence compliance.

When an organisation closes its account, we delete or anonymise personal data once these retention periods have passed, unless we are required to keep it for longer by law.

7. Your rights under UK GDPR

You have the right to:

  • be informed about how your data is used (this policy);
  • access a copy of the personal data we hold about you;
  • have inaccurate personal data corrected;
  • request erasure of your personal data, where applicable;
  • restrict or object to certain processing of your data;
  • data portability, for data you provided to us that we process by automated means under contract or consent;
  • withdraw consent at any time, where we rely on consent (e.g. marketing emails);
  • not be subject to solely automated decision-making that has a legal or similarly significant effect on you; and
  • lodge a complaint with the Information Commissioner's Office (ICO).

Where your employer organisation is the data controller for your employment records (see Section 2), some of these rights should be exercised against your employer directly, as they control how that data is used. We will support employers in fulfilling these requests where we act as their data processor.

To exercise any of these rights, email privacy@rotaapp.uk. We will respond within one month, as required by UK GDPR.

You can contact the ICO at ico.org.uk or on 0303 123 1113 if you believe your data protection rights have not been respected.

8. Cookies

RotaApp only uses strictly necessary cookies required to keep you signed in, remember your session, and maintain security (for example, an authentication session cookie and a locale/theme preference cookie). We do not currently use analytics, advertising, or tracking cookies, so no cookie consent banner is shown. If this changes in the future, we will update this policy and, where required, request your consent in line with the Privacy and Electronic Communications Regulations (PECR).

9. Data security

We use technical and organisational measures to protect personal data, including encryption of data in transit, database-level row-level security so organisations can only access their own data, hashed password storage, and restricted access to production systems. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.

10. Children

The Service is intended for business use by employers and their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under the minimum working age applicable in their jurisdiction outside of the ordinary employment context an employer manages through the Service.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated version on this page with a revised “Last updated” date, and where changes are material, we will notify account owners by email.

12. Contact us

If you have any questions about this Privacy Policy or our data practices, contact us at privacy@rotaapp.uk.