Data Processing Agreement
Last updated: 31 May 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and ShiftPriority ("Processor") and satisfies the requirements of Art. 28 GDPR for processing personal data of EU data subjects on the Controller's behalf.
1. Definitions
- Controller — the customer organisation using ShiftPriority.
- Processor — ShiftPriority, the operator of the Service.
- Personal Data — data relating to identified or identifiable natural persons entered into the Service, including employee names, contact details, roles, and schedules.
- Processing — any operation performed on Personal Data, including storage, retrieval, use, and deletion.
2. Subject matter and duration
The Processor processes Personal Data on the Controller's behalf for the purpose of providing the ShiftPriority scheduling and tip-management service. Processing continues for the duration of the active subscription and ceases upon account deletion, after which data is purged within 30 days.
3. Categories of data processed
| Category | Examples |
|---|---|
| Identity data | Employee name, role, employment type |
| Contact data | Email address, phone number |
| Scheduling data | Shift times, availability, time-off requests |
| Financial data | Hourly rate, tip payouts, monthly hours |
| Authentication data | Hashed password, session tokens |
4. Obligations of the Processor
ShiftPriority agrees to:
- Process Personal Data only on documented instructions from the Controller.
- Ensure authorised persons are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures (Art. 32 GDPR).
- Assist the Controller in responding to data-subject rights requests.
- Delete or return all Personal Data upon termination of services.
- Notify the Controller within 72 hours of becoming aware of a personal data breach.
- Provide all information necessary to demonstrate compliance with Art. 28 GDPR.
5. Sub-processors
The Controller authorises use of the following sub-processors. ShiftPriority will provide at least 14 days' notice of any intended changes.
| Processor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication, edge compute | EU (Frankfurt, Germany) |
| Stripe, Inc. | Payment processing and invoicing | US (SCC — Art. 46 GDPR) |
| Resend, Inc. | Transactional email delivery | US (SCC — Art. 46 GDPR) |
6. International data transfers
Where Personal Data is transferred outside the EEA, ShiftPriority ensures appropriate safeguards via Standard Contractual Clauses (SCC) approved under Art. 46(2)(c) GDPR.
7. Technical and organisational measures (TOMs)
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Row-level security on all database tables — each organisation's data is fully isolated.
- JWT-based authentication and role-based access control.
- Automated backups with point-in-time recovery.
- 72-hour breach notification procedure.
8. Audits
The Controller may audit compliance with this DPA upon 14 days' written notice, no more than once per year. ShiftPriority will cooperate fully.
9. Entry into force
This DPA is automatically incorporated into the Terms of Service. For a countersigned copy, contact [email protected].