Data Processing Agreement

Data Processing Agreement

Last updated: 31 May 2026

Auf Deutsch

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and ShiftPriority ("Processor") and satisfies the requirements of Art. 28 GDPR for processing personal data of EU data subjects on the Controller's behalf.

1. Definitions

  • Controller — the customer organisation using ShiftPriority.
  • Processor — ShiftPriority, the operator of the Service.
  • Personal Data — data relating to identified or identifiable natural persons entered into the Service, including employee names, contact details, roles, and schedules.
  • Processing — any operation performed on Personal Data, including storage, retrieval, use, and deletion.

2. Subject matter and duration

The Processor processes Personal Data on the Controller's behalf for the purpose of providing the ShiftPriority scheduling and tip-management service. Processing continues for the duration of the active subscription and ceases upon account deletion, after which data is purged within 30 days.

3. Categories of data processed

Category Examples
Identity data Employee name, role, employment type
Contact data Email address, phone number
Scheduling data Shift times, availability, time-off requests
Financial data Hourly rate, tip payouts, monthly hours
Authentication data Hashed password, session tokens

4. Obligations of the Processor

ShiftPriority agrees to:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure authorised persons are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (Art. 32 GDPR).
  • Assist the Controller in responding to data-subject rights requests.
  • Delete or return all Personal Data upon termination of services.
  • Notify the Controller within 72 hours of becoming aware of a personal data breach.
  • Provide all information necessary to demonstrate compliance with Art. 28 GDPR.

5. Sub-processors

The Controller authorises use of the following sub-processors. ShiftPriority will provide at least 14 days' notice of any intended changes.

Processor Purpose Location
Supabase, Inc. Database hosting, authentication, edge compute EU (Frankfurt, Germany)
Stripe, Inc. Payment processing and invoicing US (SCC — Art. 46 GDPR)
Resend, Inc. Transactional email delivery US (SCC — Art. 46 GDPR)

6. International data transfers

Where Personal Data is transferred outside the EEA, ShiftPriority ensures appropriate safeguards via Standard Contractual Clauses (SCC) approved under Art. 46(2)(c) GDPR.

7. Technical and organisational measures (TOMs)

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Row-level security on all database tables — each organisation's data is fully isolated.
  • JWT-based authentication and role-based access control.
  • Automated backups with point-in-time recovery.
  • 72-hour breach notification procedure.

8. Audits

The Controller may audit compliance with this DPA upon 14 days' written notice, no more than once per year. ShiftPriority will cooperate fully.

9. Entry into force

This DPA is automatically incorporated into the Terms of Service. For a countersigned copy, contact [email protected].