1. Parties and scope
This Data Processing Agreement ("DPA") is between the Customer ("Controller") and Rodez Digital LLC ("Processor"), and forms part of the Terms of Service. It governs our processing of personal data on your behalf under Article 28 GDPR, the UK GDPR, and the Swiss FADP.
Where this DPA conflicts with the Terms, this DPA prevails for matters of personal data. Terms defined in the GDPR — controller, processor, personal data, processing, data subject, supervisory authority — carry their GDPR meanings here.
This DPA does not cover data for which we are the controller: your account details, your billing information, and your usage of the product. That is the Privacy Policy.
2. Roles
You are the controller of the personal data you enter about your staff. You determine why it is collected and what happens to it, and you warrant that you have a lawful basis for it and have given your staff the information they are owed under Articles 13 and 14.
We are the processor. We process that data only on your documented instructions — the instructions being your use of the product's features, this DPA, and the Terms. If we believe an instruction breaches data protection law, we will tell you and may decline it.
3. Subject matter of the processing
The particulars required by Article 28(3), which in a standard DPA sit in an annex nobody opens:
- Subject matter — providing workforce scheduling software.
- Duration — the term of your subscription, plus the deletion window in §9.
- Nature and purpose — storing, organizing, retrieving, displaying, and transmitting staff records so you can plan, publish, and communicate schedules; generating AI proposals when you invoke them.
- Categories of data subject — your employees, contractors, and the managers who use the product.
- Categories of personal data — name, email, phone where you provide it, role and position, employment identifiers, skills and qualifications, availability, shifts worked and scheduled, time-off requests and any reasons you record, swap requests, manager notes, and in-app activity.
- Special categories — none are requested by the product. Free-text fields such as notes and time-off reasons can hold them if you type them there; you should not, and if you do, that processing is yours to justify.
4. Our obligations
- Process only on your documented instructions, including transfers.
- Ensure everyone authorized to access the data is bound by confidentiality.
- Implement the security measures in §10.
- Respect the conditions in §5 for engaging subprocessors.
- Assist you with data subject requests (§6).
- Assist you with security, breach notification, impact assessments, and prior consultation, taking into account what we know and you do not.
- Delete or return the data at the end (§9).
- Make available the information needed to demonstrate compliance, and allow audits (§11).
5. Subprocessors
You give general written authorization for us to engage subprocessors. The current list is on the subprocessors page and is reproduced below as of the effective date. Each is bound by data protection obligations no less protective than this DPA, and we remain fully liable to you for their performance.
We will give at least 30 days' notice before a new subprocessor starts processing your data — subscribe on that page to be emailed. If you reasonably object on data protection grounds within those 30 days, tell us and we will work to find an alternative; if we cannot, you may terminate the affected part of the service and receive a refund of the unused prepaid term. That is a real remedy, not a formality: the alternative is a notice period during which you can do nothing.
| Subprocessor | Purpose | Data shared | Processing location |
|---|---|---|---|
| Supabase | Primary infrastructure: the Postgres database, authentication, realtime, and file storage. | All customer data at rest, including employee records, schedules, notes, and account credentials. | United States (AWS us-east-2) |
| Vercel | Application hosting and content delivery for the web app. | Data in transit as requests are served, plus request logs. No customer data is stored at rest. | United States |
| Stripe | Subscription billing and payment processing. | Billing contact email, company name, plan, and location count. Card details go directly to Stripe and never reach our servers. | United States |
| Anthropic | The Claude API, which powers the AI scheduling features. | Only when an AI feature is invoked: the org context that request needs — employee names, availability, shifts, notes — and the prompt. Anthropic does not train its models on this data. | United States |
| Resend | Transactional email: invitations, notifications, and password resets. | Recipient name and email address, and the content of that message — which may name a shift or a schedule. | United States |
| PostHog | Product analytics: which features are used and where people get stuck. | User id, email, organization id, and which actions were taken. Never the content of schedules, notes, or anything typed to the AI. | United States |
| Sentry | Error monitoring and performance diagnostics. | Technical diagnostics when something breaks: stack traces, browser, and the URL with tokens and access codes stripped out. | United States |
6. Data subject requests
The product is built so you can answer most requests yourself: search, export, correct, and delete a member's record from the dashboard, without asking us and without waiting.
If a data subject contacts us directly, we will not respond substantively — we will refer them to you, and tell you, because you are their controller. Where you need help that the product does not give you, we will provide reasonable assistance at no charge.
7. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data — comfortably inside the 72 hours you then have to notify your supervisory authority, because a processor that uses the full 72 leaves its controller with none.
The notice will describe what happened, the categories and approximate number of records affected, the likely consequences, and the measures taken. We will keep you updated as facts develop, and we will not delay an initial notice to make it complete.
8. International transfers
We process your data in the United States. For transfers from the EEA, the parties adopt the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), or Module Three where you act as a processor for your own controller. They are incorporated into this DPA by reference and completed as follows: the docking clause applies; the governing law is Ireland; the forum is the courts of Ireland; Annex I is §3 and §12 of this DPA; Annex II is §10; Annex III is the subprocessor list. Option 2 of Clause 9(a) applies with the 30-day notice period in §5.
For UK transfers, the ICO's International Data Transfer Addendum (version B1.0) applies to those Clauses. For Switzerland, references to the GDPR are read as references to the FADP and the FDPIC is the competent authority.
We will tell you if we receive a legally binding request from a public authority for your data, unless legally prohibited, and we will challenge requests that appear unlawful.
9. Deletion and return
You can export your data at any time, in a machine-readable format, from the dashboard.
On termination we delete your data from live systems after a 30-day recovery window, and encrypted backups age out within a further 30 days. You can trigger deletion immediately from the dashboard instead of waiting. We keep only what law requires us to keep, and it stays subject to this DPA for as long as we hold it.
10. Security measures
The measures we maintain under Article 32 — this is Annex II of the Clauses:
- Encryption — TLS in transit; encryption at rest for the database, backups, and file storage.
- Access control — every operation carries a permission check scoped to one organization, with row-level security enabled deny-by-default in the database underneath, so an application bug is contained by the data layer rather than exposed by it.
- Credential handling — server-only secrets that never reach the browser bundle; passwords stored only as hashes by our authentication provider.
- Accountability — an append-only audit log of every mutation, recording actor, action, and time.
- Resilience — managed Postgres with automated point-in-time backups; infrastructure reprovisionable from version-controlled configuration.
- Development practice — least-privilege credentials, a typed data-access layer that makes cross-tenant queries hard to write, dependency and secret scanning, and an automated gate that blocks deployment on misconfigured production environments.
- Personnel — access limited to those who need it and bound by confidentiality.
We do not hold ISO 27001 or SOC 2 certification today, and will not imply otherwise. If you need one to buy, tell us — it is a roadmap question, and knowing it blocks a deal is how it gets prioritized.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to security questionnaires. You may audit once per year, or after a breach affecting your data, on 30 days' notice, during business hours, without disrupting our operations, and subject to confidentiality. Where we can answer with documentation instead of an on-site visit, we will offer that first.
12. Technical details of the processing
Completing Annex I: the frequency of processing is continuous for the duration of the subscription. Data is retained per §9. Transfers to subprocessors are for the purposes and to the locations set out on the subprocessors page. The competent supervisory authority is determined by your establishment or, where you are not established in the EEA, by the Member State where your data subjects are.
13. Liability and precedence
Liability under this DPA is subject to the limitations in Terms §16, except where data protection law does not permit that limitation. Nothing here restricts a data subject's rights against either party under the Clauses.
If the Clauses conflict with this DPA, the Clauses prevail. This DPA remains in force for as long as we process personal data on your behalf.
14. Contact
For anything under this DPA, including a countersigned copy or a completed security questionnaire: privacy@weekwright.com.