RRosterly
Privacy policy
Version 1.0 · Last updated [DATE] · Applies to the Rosterly scheduling service
Draft for review. This policy describes what Rosterly does with personal data today, in plain language. It must be reviewed by a Dutch legal professional before the service goes live to paying customers.
1. Who we are
Rosterly is a staff-scheduling service for hospitality and retail businesses, operated by [COMPANY NAME], registered at [ADDRESS], the Netherlands, registered with the Chamber of Commerce under number [KVK], VAT [BTW]. Contact for privacy matters: privacy@roosterly.pro.
2. Our two roles
This distinction matters and we keep it honest:
| Role | When | What it means |
| Processor (we act for your employer-customer) |
Rosterly handles working data of employees on behalf of the company that uses the service. |
The company decides what data goes in and why. We only process it to run the service, under a processor agreement. |
| Controller (we act for ourselves) |
Account data of the people who sign up (owner, planners) and our own billing/administration. |
We decide how the account works, and we invoice for it. |
3. What data we process
Data of the people who use the account (controller role)
- Name, email address, role, login credentials (password stored hashed, never in readable form)
- Company details: name, sector, locations, departments, shift types
- Billing: company name, address, VAT number, payment references from the payment provider. We never store card or bank details ourselves.
- Technical logs: sign-in events, IP address, actions in the system (audit trail)
Employee working data (processor role, on behalf of the employer)
- Name, email address, department(s), location(s), contract hours
- Availability, shift assignments, swaps, leave and sick-call records
- Clock-in and clock-out moments (actual times), hours actually worked
- Date of birth where it is required to apply the legal rules for employees under 18
We do not ask for, and do not want, data about health, ethnicity, religion, or trade-union membership. Notes fields in the product are for scheduling information only.
4. Why we process it (purposes and legal bases)
- To run the service — building rosters, checking Dutch working-hours rules, calculating costs of the schedule. Legal basis: performance of our contract with the company.
- To invoice — administration of subscriptions. Legal basis: contract and our legal accounting duty.
- To secure the service — audit trail, access control, abuse prevention. Legal basis: legitimate interest.
- To support you when you contact us — reading the account's data to answer the question. Legal basis: legitimate interest and contract.
5. Surcharge and cost calculations
Rosterly calculates what a shift costs based on the rules and rates configured by the company. These calculations are administrative estimates for planning purposes. They are not payroll and they do not determine anyone's pay — final pay is set by the employer and its payroll administration.
6. Who else touches the data (sub-processors)
| Sub-processor | Purpose | Location |
| Hosting provider [PROVIDER], [DATACENTER LOCATION] | Running the application and storing the database | EU |
| Mollie B.V. | Subscription payments and invoicing | Netherlands / EU |
| Brevo (Sendinblue SAS) | Sending notification emails | France / EU |
We do not sell data, and we do not use it for advertising. There are no advertising trackers in the product.
7. How long we keep it
- Working data: for as long as the company's account exists. When a company leaves, we export their data if they ask, and delete it from the live system.
- Administrative and accounting records: as long as Dutch tax law requires.
- Backups: rotated and deleted on a short cycle; a deleted record disappears from the live system immediately and from backups as they rotate out.
8. Security
- Encrypted connections (HTTPS) for everything; passwords stored only as hashes
- Data separated per company workspace — one company can never see another's data
- Role-based access: planners see their company only; employees see their own data and what the company allows
- Daily automated backups, with the ability to restore
- An audit trail of administrative actions
9. Your rights
Employees and account users can ask to see, correct, or delete their data, and can ask for a copy in a usable format (the product has a one-click export for this). The fastest route for employee data is through the employer, because they are the one who decides about it — but you may also contact us and we will help you get to the right place. If you believe we handle data wrongly, you can complain to the Dutch data-protection authority (Autoriteit Persoonsgegevens).
10. Changes
If this policy changes in a way that matters, we will notify account owners by email before the change takes effect.
Terms of service · Back to Rosterly