Data Processing Agreement

Last updated: 31 May 2026

Auf Deutsch

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and ShiftPriority ("Processor") and satisfies the requirements of Art. 28 GDPR for processing personal data of EU data subjects on the Controller's behalf.

1. Definitions

  • Controller - the customer organisation using ShiftPriority.
  • Processor - ShiftPriority, the operator of the Service.
  • Personal Data - data relating to identified or identifiable natural persons entered into the Service, including employee names, contact details, roles, and schedules.
  • Processing - any operation performed on Personal Data, including storage, retrieval, use, and deletion.

2. Subject matter and duration

The Processor processes Personal Data on the Controller's behalf for the purpose of providing the ShiftPriority scheduling and tip-management service. Processing continues for the duration of the active subscription and ceases upon account deletion, after which data is purged within 30 days.

3. Categories of data processed

CategoryExamples
Identity dataEmployee name, role, employment type
Contact dataEmail address, phone number
Scheduling dataShift times, availability, time-off requests
Financial dataHourly rate, tip payouts, monthly hours
Authentication dataHashed password, session tokens

4. Obligations of the Processor

ShiftPriority agrees to:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure authorised persons are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (Art. 32 GDPR).
  • Assist the Controller in responding to data-subject rights requests.
  • Delete or return all Personal Data upon termination of services.
  • Notify the Controller within 72 hours of becoming aware of a personal data breach.
  • Provide all information necessary to demonstrate compliance with Art. 28 GDPR.

5. Sub-processors

The Controller authorises use of the following sub-processors. ShiftPriority will provide at least 14 days' notice of any intended changes.

ProcessorPurposeLocation
Supabase, Inc.Database hosting, authentication, edge computeEU (Frankfurt, Germany)
Stripe, Inc.Payment processing and invoicingUS (SCC - Art. 46 GDPR)
Resend, Inc.Transactional email deliveryUS (SCC - Art. 46 GDPR)

6. International data transfers

Where Personal Data is transferred outside the EEA, ShiftPriority ensures appropriate safeguards via Standard Contractual Clauses (SCC) approved under Art. 46(2)(c) GDPR.

7. Technical and organisational measures (TOMs)

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Row-level security on all database tables - each organisation's data is fully isolated.
  • JWT-based authentication and role-based access control.
  • Automated backups with point-in-time recovery.
  • 72-hour breach notification procedure.

8. Audits

The Controller may audit compliance with this DPA upon 14 days' written notice, no more than once per year. ShiftPriority will cooperate fully.

9. Entry into force

This DPA is automatically incorporated into the Terms of Service. For a countersigned copy, contact [email protected].