← Back

This page is maintained by RotaOS to answer common privacy questions about the Service.

RotaOS — Privacy Policy

Last updated: 11 July 2026

1. Controller

RotaOS, Ireland. Contact: hello@rotaos.app.

2. What we collect

3. Why we process it (legal bases, GDPR Art. 6)

A note on leave data: leave type entries (such as sick leave) about your colleagues may constitute personal data, and in some cases special-category data, of those colleagues. Where you enter data about other people, you confirm you are authorised to do so for workforce-scheduling purposes. Consider using generic leave labels where detail isn't needed.

4. Where your data lives

Data is hosted with our infrastructure providers in the EU. If any transfer outside the EEA occurs, it is protected by EU Standard Contractual Clauses or an adequacy decision.

5. Sharing

We share data only with processors needed to run the Service (hosting, payment, email delivery), under data-processing agreements. We do not sell personal data. View-only rota links are visible to anyone holding the link.

6. Retention

Account and rota data are kept while your account is active, exported on request, and deleted within 30 days of account deletion, subject to legal retention duties (e.g. billing records).

7. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to certain processing. Contact hello@rotaos.app. You may lodge a complaint with the Data Protection Commission (dataprotection.ie).

8. Security

Access controls, encryption in transit, row-level security on stored data, and least-privilege access. No system is perfectly secure; notify us immediately of any suspected breach of your account.

9. Cookies

We use only cookies strictly necessary to keep you logged in and run the Service. If we ever add analytics cookies, we will ask consent first.

10. Changes

We'll post changes here and notify you of material ones. Continued use after notice constitutes acceptance.