Legal
Data Processing Agreement
Last updated: August 2026
This Data Processing Agreement ("DPA") is required under UK GDPR Article 28 and applies whenever a business shares employee personal data with RotaHQ. It forms part of the agreement between:
The Restaurant — the Data Controller
RotaHQ / Htet Min Aung — the Data Processor
1. Purpose
RotaHQ processes employee personal data on behalf of the restaurant solely to provide the RotaHQ service.
2. Data processed
Categories of data:
- Employee names and contact details
- Phone numbers
- Work schedules and shift times
- Clock in/out timestamps
- Wage rates and payslip information
- Leave requests
Data subjects:
- Restaurant employees and managers
3. Processor obligations
RotaHQ agrees to:
- Only process data on the restaurant's documented instructions
- Ensure staff handling data are bound by confidentiality
- Implement appropriate security measures
- Not engage sub-processors without the restaurant's general authorisation (sub-processors are listed in our Privacy Policy)
- Help the restaurant respond to data subject rights requests
- Delete or return all data on termination
- Provide information to demonstrate compliance with this agreement
4. Security measures
Technical measures:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest in the database
- Password hashing (bcrypt)
- JWT-based authentication
- Role-based access control
- Tenant data isolation
Organisational measures:
- Access limited to necessary personnel only
- Regular security reviews
- Incident response process
5. Data breach
In the event of a personal data breach:
- We will notify the restaurant within 72 hours of becoming aware.
- The notification will include the nature of the breach, categories affected, likely consequences and the measures taken.
6. Sub-processors
Authorised sub-processors:
- Twilio Inc (WhatsApp/SMS)
- MongoDB Inc (database)
- Stripe Inc (payments)
- Emergent (hosting)
7. Termination
On termination of the RotaHQ subscription:
- Restaurant data remains available for export for 30 days.
- After 30 days, data is permanently deleted.
- Deletion is confirmed on request.
8. Governing law
This agreement is governed by the laws of England and Wales.