Data Processing Addendum (DPA)
1. Parties
Processor: the operator of ShiftQ — a private individual based in Ukraine (full sole-proprietor (FOP) registration details will be published before paid plans launch).
Controller: the organization that registered an account with ShiftQ and enters its employees' data ("Customer").
2. Definitions
- Personal Data — any information relating to an identified or identifiable natural person (in particular, the Customer's employees' data).
- Data Subject — the natural person whose personal data is processed (the Customer's employee).
- Processing — any operation performed on personal data: collection, storage, alteration, deletion, etc.
- Sub-processor — a third party engaged by the Processor to process personal data in the course of providing the Service.
3. Subject matter and duration of processing
The Processor processes Data Subjects' personal data solely to provide the Customer with the Service's functionality (shift scheduling, staff management, notifications) for the duration of the Customer's account, and additionally for the period necessary to meet legal obligations after termination (e.g., backups until rotated out).
4. Nature and purpose of processing
Processing includes: storing data in the database, displaying it in the Service's interface, sending notifications (including push notifications), automated deletion of aged notifications, and backups for resilience.
5. Categories of data subjects
The Customer's employees, whose access to the Service is created by the Customer (managers, supervisors, regular staff).
6. Categories of personal data
Name, email address, phone number, position/role, photo (at the Customer's discretion), and work-schedule data (shifts, swaps, time off/leave).
7. Processor's obligations
- process personal data only on the Controller's documented instructions (given through the Service's own functionality) and not use it for any purpose of its own unrelated to providing the Service;
- maintain confidentiality — only personnel who need access to support the Service may access the data;
- implement technical and organizational security measures, including per-organization data isolation at the database level (Row Level Security) and rate limiting of sensitive requests;
- notify the Controller without undue delay upon becoming aware of a security incident affecting the Controller's personal data;
- assist the Controller in responding to data subject requests (access, correction, erasure) — implemented in practice through the Service's own features (staff management, organization account deletion, data export);
- delete or return all personal data to the Controller after the Service relationship ends, at the Controller's choice, unless applicable law requires further retention;
- not engage a new sub-processor without prior notice to the Controller, giving a reasonable opportunity to object.
8. List of sub-processors
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | European Union (Ireland) |
| Vercel | Application hosting | Global edge network |
| Sentry | Error monitoring | European Union (Germany) |
| PostHog | De-identified usage analytics | European Union |
| OneSignal | Push notification delivery | United States |
| Resend | Transactional email | United States |
| — | Subscription payment processing (no access to employee personal data; not used during the free beta) | — |
9. International data transfers
Transfers of personal data to sub-processors outside the European Union (in particular, to the United States) rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism in effect at the time of transfer.
10. Audit
The Controller may request, once per year, information demonstrating the Processor's compliance with this Addendum (including the sub-processor list and security measures in place); a full technical infrastructure audit may be arranged separately by agreement.
11. Liability
The Processor's liability for breach of this Addendum is governed by the "Limitation of Liability" section of ShiftQ's Terms of Service.
12. Contact
For questions about this Addendum, contact: shiftqsupport@gmail.com.
ShiftQ