top of page

Try all premium features free for 14 days, no credit card required. Start your trial →

Rosterloop logo in purple and mint green

Weekly Shifts Made Easy

Data Processing Addendum

DATA PROCESSING ADDENDUM

Governing how RosterLoop processes personal data on behalf of its customers.

Last updated: July 6, 2026

1. SCOPE AND ROLES

This Data Processing Addendum (“DPA” or “Addendum”) forms part of, and is subject to, the RosterLoop Terms of Use between RosterLoop LLC (“RosterLoop”) and the Customer. It applies whenever RosterLoop processes Personal Data on behalf of the Customer through the RosterLoop platform (the “Service”).

For the purposes of this Addendum, the Customer acts as the Controller of the Personal Data it uploads about its employees, drivers, and staff, and RosterLoop acts as the Processor of that data. RosterLoop processes Personal Data only to provide, maintain, and support the Service, and in accordance with the Customer’s documented instructions as reflected in the Terms of Use, the Privacy Policy, and this Addendum.

2. DEFINITIONS

Term

Definition

Customer

The organization that has subscribed to the Service and uploads personal data about its workforce.

Controller

The party that determines the purposes and means of processing personal data. The Customer is the Controller.

Processor

The party that processes personal data on behalf of the Controller. RosterLoop is the Processor.

Personal Data

Any information relating to an identified or identifiable individual that Customer uploads to or generates within the Service (e.g., employee and driver names, schedules, contact details).

Sub-processor

A third-party engaged by RosterLoop to process Personal Data in connection with the Service.

Applicable Law

All data protection and privacy laws applicable to the processing of Personal Data under this Addendum.

 

3. CUSTOMER OBLIGATIONS

The Customer represents and warrants that it has all necessary rights, permissions, and a valid legal basis to provide the Personal Data to RosterLoop and to have it processed through the Service. The Customer is responsible for the accuracy of the Personal Data it uploads and for ensuring that its collection and use of that data complies with Applicable Law, including any obligations to inform or obtain consent from its own employees and staff.

The Customer is responsible for managing user roles and access within its organization and for promptly updating or removing access as personnel changes occur.

4. ROSTERLOOP OBLIGATIONS

RosterLoop will:

  • Process Personal Data only on behalf of and in accordance with the Customer’s instructions, unless required to act otherwise by Applicable Law;

  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations;

  • Implement appropriate technical and organizational security measures as described in the RosterLoop Security Policy, including encryption in transit and at rest, role-based access control, and access logging;

  • Assist the Customer, taking into account the nature of the processing, in responding to requests from individuals exercising their rights under Applicable Law;

  • Make available information reasonably necessary to demonstrate compliance with this Addendum.

5. SUB-PROCESSORS

The Customer authorizes RosterLoop to engage the Sub-processors listed below to process Personal Data in connection with the Service. RosterLoop remains responsible for the performance of its Sub-processors’ obligations and will impose data protection terms on each Sub-processor that are no less protective than those in this Addendum.

Sub-processor

Purpose

Hostinger

Cloud hosting of the RosterLoop application and database

Cloudflare, Inc.

DNS management and network security

Stripe, Inc.

Subscription and payment processing

Resend, Inc.

Transactional and notification email delivery

Wix.com Ltd.

Hosting of the marketing and landing page

Firebase Cloud Messaging (Google LLC)

Delivery of push notifications to the mobile app

Google Analytics

Anonymized, aggregated usage analytics

 

RosterLoop may update this list as the Service evolves and will make the current list available to Customers. Where required by Applicable Law, RosterLoop will provide a mechanism for Customers to be informed of changes to its Sub-processors.

6. INTERNATIONAL DATA TRANSFERS

Personal Data may be processed and stored in the United States and in other countries where RosterLoop or its Sub-processors operate. Where Personal Data is transferred across borders, RosterLoop will take steps to ensure the data remains protected in accordance with this Addendum and Applicable Law.

7. SECURITY

RosterLoop maintains a documented information security program with technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction. These measures are described in the RosterLoop Security Policy, which is incorporated into this Addendum by reference. Specific measures may be updated over time provided the overall level of protection is not materially reduced.

8. DATA BREACH NOTIFICATION

If RosterLoop becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data, RosterLoop will notify the affected Customer without undue delay, and in any case within 72 hours of confirming the breach. The notification will describe, to the extent known, the nature of the incident, the categories of data affected, and the measures taken or proposed in response. The Customer is responsible for any further notifications it is required to make to individuals or authorities under Applicable Law.

9. DATA RETENTION AND DELETION

RosterLoop retains and deletes Personal Data in accordance with the retention schedules set out in the Data Retention section of the RosterLoop Privacy Policy. Upon termination of the Customer’s subscription, Personal Data is deleted following the applicable retention window described in that policy. Deletion is cascading: when a company account is deleted, all data linked to that account is removed.

10. DATA SUBJECT RIGHTS

Taking into account the nature of the processing, RosterLoop will provide reasonable assistance to enable the Customer to respond to requests from individuals seeking to exercise their rights under Applicable Law, including rights of access, correction, deletion, and data export. Because the Customer controls the Personal Data within its account, the Customer is primarily responsible for responding to such requests from its own workforce.

11. AUDIT AND COMPLIANCE

Upon reasonable written request, and no more than once per year unless required by a supervisory authority or following a security incident, RosterLoop will make available to the Customer information reasonably necessary to demonstrate compliance with this Addendum. RosterLoop is working toward formal third-party certifications (such as SOC 2 Type II) and will make relevant reports available to Customers as they are obtained.

12. TERM AND TERMINATION

This Addendum remains in effect for as long as RosterLoop processes Personal Data on behalf of the Customer under the Terms of Use. Upon termination of the Service, RosterLoop’s obligations to delete Personal Data are governed by Section 9 of this Addendum.

13. GENERAL

In the event of a conflict between this Addendum and the Terms of Use with respect to the processing of Personal Data, this Addendum controls. All other terms of the Terms of Use remain in full force and effect. This Addendum is governed by the laws of the State of Florida, United States, consistent with the RosterLoop Terms of Use.

14. CONTACT

For questions relating to this Addendum or the processing of Personal Data, contact RosterLoop at info@rosterloop.com.

bottom of page