Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how [COMPANY LEGAL NAME](“RotaApp”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use rotaapp.uk and the RotaApp shift-scheduling application (together, the “Service”).
We are the data controller for the personal data described in this policy and we are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
- Data controller: [COMPANY LEGAL NAME], registered in England and Wales under company number [COMPANY NUMBER]
- Registered office: [REGISTERED ADDRESS]
- ICO registration number: [ICO REGISTRATION NUMBER]
- Contact: privacy@rotaapp.uk
If you have a question about this policy or how we handle your data, please contact us using the details above before contacting the Information Commissioner's Office (ICO).
2. What personal data we collect
We collect personal data in the following categories, depending on how you use the Service:
- Account data: name, email address, password (stored as a salted hash), phone number, and account role (owner, manager, or employee).
- Organisation and employment data: employer/organisation name, employee job titles, departments, locations, working patterns, availability preferences, and qualifications or certifications you choose to record.
- Scheduling data: shifts, shift swap requests, time-off requests, time and attendance clock-in/clock-out records, and rota publication history.
- Billing data: billing name, billing address, and subscription/seat details. Card payment details are collected and processed directly by our payment processor, Stripe — we do not store full card numbers on our servers.
- Communications data: messages you send us for support, and content of notifications we send about rota changes, shift swaps, or account activity.
- Technical data: IP address, browser type, device information, and log data generated when you use the Service.
- AI assistant data: if you use the rota AI assistant, the natural-language prompts you enter and the scheduling data needed to generate a response are sent to our AI processing provider to generate a reply.
We do not knowingly collect special category data (such as health information) except where an employer chooses to record sickness-related time-off in the ordinary course of managing staff absence; this is controlled by the employer organisation using the Service, acting as data controller for its own staff records, with RotaApp acting as a data processor on the employer's behalf in that context.
3. How we use your personal data and our lawful basis
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Creating and administering your account | Performance of a contract |
| Providing shift scheduling, swaps, time-off, and time-tracking features | Performance of a contract |
| Processing subscription payments | Performance of a contract; legal obligation (tax/accounting records) |
| Sending service notifications (rota published, shift reminders, invites) | Performance of a contract |
| Sending optional marketing communications | Consent (you can withdraw this at any time) |
| Maintaining audit logs for security and compliance | Legitimate interests (protecting the security and integrity of the Service) |
| Responding to support requests | Legitimate interests; performance of a contract |
| Detecting and preventing fraud or misuse | Legitimate interests; legal obligation |
4. Who we share your data with
We do not sell personal data. We share personal data only with the following categories of recipients, each acting under a data processing agreement where they process data on our behalf:
- Hosting and database infrastructure providers, to store and run the Service.
- Stripe, to process subscription payments.
- Amazon Web Services (AWS SES), to deliver transactional and notification emails.
- OpenRouter and the underlying AI model providers it routes to, to power the optional rota AI assistant feature.
- Other members of your organisation (e.g. managers and owners) who require access to rota, availability, and time-off data to run the scheduling features you use.
- Regulators, law enforcement, or professional advisers, where we are required to do so by law or to establish, exercise, or defend legal claims.
- A buyer or successor, if we sell, merge, or transfer all or part of our business, subject to the same protections described in this policy.
5. International data transfers
Some of our service providers (including AI processing and email delivery providers) may process data outside the UK, including in the United States. Where this happens, we rely on the UK International Data Transfer Agreement (IDTA), an EU Commission adequacy decision extended to the UK, or the UK Addendum to the EU Standard Contractual Clauses, to ensure your data receives an equivalent level of protection.
6. How long we keep your data
- Account and scheduling data: retained for as long as your organisation has an active account, and for up to 7 years afterwards to meet UK employment record and tax record-keeping obligations (for example, working time and payroll-adjacent records under the Working Time Regulations 1998 and HMRC requirements).
- Billing records: retained for 6 years after the end of the tax year they relate to, in line with HMRC requirements.
- Audit logs: retained for up to 2 years for security and compliance purposes.
- Marketing consent records: retained until you withdraw consent, plus a short period to evidence compliance.
When an organisation closes its account, we delete or anonymise personal data once these retention periods have passed, unless we are required to keep it for longer by law.
7. Your rights under UK GDPR
You have the right to:
- be informed about how your data is used (this policy);
- access a copy of the personal data we hold about you;
- have inaccurate personal data corrected;
- request erasure of your personal data, where applicable;
- restrict or object to certain processing of your data;
- data portability, for data you provided to us that we process by automated means under contract or consent;
- withdraw consent at any time, where we rely on consent (e.g. marketing emails);
- not be subject to solely automated decision-making that has a legal or similarly significant effect on you; and
- lodge a complaint with the Information Commissioner's Office (ICO).
Where your employer organisation is the data controller for your employment records (see Section 2), some of these rights should be exercised against your employer directly, as they control how that data is used. We will support employers in fulfilling these requests where we act as their data processor.
To exercise any of these rights, email privacy@rotaapp.uk. We will respond within one month, as required by UK GDPR.
You can contact the ICO at ico.org.uk or on 0303 123 1113 if you believe your data protection rights have not been respected.
8. Cookies
RotaApp only uses strictly necessary cookies required to keep you signed in, remember your session, and maintain security (for example, an authentication session cookie and a locale/theme preference cookie). We do not currently use analytics, advertising, or tracking cookies, so no cookie consent banner is shown. If this changes in the future, we will update this policy and, where required, request your consent in line with the Privacy and Electronic Communications Regulations (PECR).
9. Data security
We use technical and organisational measures to protect personal data, including encryption of data in transit, database-level row-level security so organisations can only access their own data, hashed password storage, and restricted access to production systems. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.
10. Children
The Service is intended for business use by employers and their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under the minimum working age applicable in their jurisdiction outside of the ordinary employment context an employer manages through the Service.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated version on this page with a revised “Last updated” date, and where changes are material, we will notify account owners by email.
12. Contact us
If you have any questions about this Privacy Policy or our data practices, contact us at privacy@rotaapp.uk.