Data Processing Agreement
Last updated July 2026
This DPA forms part of the agreement between your organisation (the “Controller”) and Rotasmith (the “Processor”) and governs processing of personal data under UK GDPR.
Roles & scope
Rotasmith processes personal data only to provide the leave-management service and only on the Controller's documented instructions (including via the application's settings).
Nature of processing
- Data subjects: the Controller's employees and invited staff.
- Categories: identity/contact, employment details, leave records, and — where used — sickness absence (health data), restricted to HR-role users.
- Purpose: recording, approving and reporting on staff leave.
Security measures
- Encryption in transit (TLS) and at rest at the infrastructure layer.
- Strict per-organisation data isolation enforced on every query.
- Role-based access; special-category (sickness) data limited to HR.
- Least-privilege access to production and audit logging of changes.
Sub-processors
We use vetted sub-processors for hosting, database and transactional email, located in the UK/EU. We maintain a current list and will give notice of changes so the Controller can object.
International transfers
Data is stored in the UK/EU. Where any transfer outside the UK occurs, it is covered by an adequacy decision or the UK International Data Transfer Agreement / SCCs.
Data subject rights & assistance
We provide tools for export and erasure and will assist the Controller in responding to data subject requests and to the ICO where required.
Breach notification
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting their data.
Deletion & return
On termination, and at the Controller's choice, we return or delete personal data, subject to any legal retention requirement.
Contact
Email: privacy@rotasmith.example — replace with your real contact address.