Legal

Data Processing Agreement

Itembay Limited (trading as RotaCubed). Company Number 12027952. Registered Office 235 Foxhall Road, Ipswich, IP3 8LF. Last updated: 10 August 2026.

1. Background

1.1 This Data Processing Agreement ("DPA") supplements the Terms and Conditions between the Controller and Itembay Limited, trading as RotaCubed (the "Agreement"), and applies where Itembay Limited processes personal data on behalf of the Controller in connection with the RotaCubed Service.

1.2 This DPA reflects the parties' agreement with respect to the processing of Customer Personal Data, as defined below, in accordance with the requirements of the Data Protection Legislation.

1.3 If there is any conflict between this DPA and the Agreement in relation to the processing of Customer Personal Data, this DPA will prevail to the extent of that conflict.

2. Definitions

"Agreement" means the Terms and Conditions between the Controller and the Processor, as updated from time to time.

"Controller", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given in the Data Protection Legislation.

"Controller" means the Customer, as defined in the Agreement.

"Customer Personal Data" means any personal data processed by the Processor on behalf of the Controller in connection with the Service, as more particularly described in Schedule 1.

"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data in force in the United Kingdom from time to time, each as amended, replaced or superseded.

"Processor" means Itembay Limited, trading as RotaCubed.

"Sub processor" means any third party engaged by the Processor to process Customer Personal Data on behalf of the Controller, as listed in Schedule 2.

"UK GDPR" has the meaning given in section 3(10) of the Data Protection Act 2018.

3. Roles of the Parties

3.1 The parties agree that, in relation to Customer Personal Data, the Controller is the data controller and the Processor is the data processor, in each case for the purposes of the Data Protection Legislation.

3.2 Schedule 1 sets out the subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects.

4. Processor Obligations

4.1 The Processor shall:

(a) process Customer Personal Data only on the documented instructions of the Controller, including in relation to international transfers, unless required to do otherwise by law, in which case the Processor will inform the Controller of that legal requirement before processing, unless the law prohibits this;

(b) ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality;

(c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Schedule 3;

(d) not engage any Sub processor without the Controller's prior general authorisation, as set out in clause 5;

(e) taking into account the nature of the processing, provide reasonable assistance to the Controller, at the Controller's cost where the assistance requires material additional resource, to enable the Controller to respond to requests from Data Subjects exercising their rights under the Data Protection Legislation;

(f) provide reasonable assistance to the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR, including in relation to the security of processing, notification of Personal Data Breaches, and data protection impact assessments, taking into account the information available to the Processor;

(g) at the Controller's election, delete or return all Customer Personal Data at the end of the provision of the Service, save that the Processor may retain Customer Personal Data for the retention period described in clause 11 of the Agreement, or for as long as required by law, after which it will be permanently deleted;

(h) make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, in accordance with clause 7.

5. Sub Processors

5.1 The Controller provides the Processor with a general authorisation to engage the Sub processors listed in Schedule 2 for the processing of Customer Personal Data.

5.2 The Processor will give the Controller at least 30 days' prior notice of any intended addition or replacement of a Sub processor, giving the Controller the opportunity to object on reasonable data protection grounds. If the parties cannot resolve an objection, the Controller may terminate the Agreement in respect of the affected part of the Service, without penalty.

5.3 The Processor will impose data protection terms on any Sub processor that are no less protective of Customer Personal Data than those set out in this DPA, and will remain liable to the Controller for the performance of that Sub processor's obligations.

6. International Transfers

6.1 Customer Personal Data processed under this DPA is hosted and processed within the United Kingdom and the European Economic Area (EEA).

6.2 The Processor will not transfer Customer Personal Data outside the UK and EEA without the Controller's prior written consent, save where required to do so by law, and will in any such case ensure that appropriate safeguards under the Data Protection Legislation are in place.

7. Audits

7.1 The Processor will make available to the Controller, on reasonable written request, information reasonably necessary to demonstrate compliance with this DPA.

7.2 The Controller may conduct an audit of the Processor's compliance with this DPA, including on site inspection, no more than once in any 12 month period, on at least 30 days' written notice, during normal business hours, and subject to reasonable confidentiality obligations, except where a shorter period is required by a supervisory authority or following a Personal Data Breach.

7.3 The Controller will bear its own costs of any audit, and will reimburse the Processor's reasonable costs of supporting an audit beyond the information the Processor ordinarily makes available.

8. Personal Data Breach

8.1 The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 That notification will include, to the extent known at the time, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.

8.3 The Processor will provide reasonable further information and assistance to the Controller as is necessary for the Controller to meet any obligations to report the Personal Data Breach under the Data Protection Legislation.

9. Special Category Data

9.1 The Controller must not submit special category personal data, or personal data relating to criminal convictions or offences, to the Service unless it is strictly necessary and the Controller has an appropriate lawful basis for doing so under the Data Protection Legislation.

9.2 If the Controller does submit such data, it remains solely responsible for ensuring it has the appropriate lawful basis, and for notifying the Processor in advance so that appropriate additional safeguards can be considered.

10. Liability

10.1 Each party's liability arising out of or in connection with this DPA, whether in contract, tort, including negligence, or otherwise, is subject to the limitations and exclusions of liability set out in clause 15 of the Agreement, which apply to this DPA as if set out in full.

11. Term

11.1 This DPA takes effect on the Effective Date and will continue in force for as long as the Processor processes Customer Personal Data on behalf of the Controller in connection with the Service, notwithstanding the expiry or termination of the Agreement.

12. Effective Date and Incorporation

12.1 This DPA applies automatically, and forms part of the Agreement, from the date the Controller accepts the Agreement or first submits Customer Personal Data to the Service, whichever is earlier ("Effective Date"), without requiring a separate signature. This DPA is incorporated into, and legally binding as part of, the Agreement.

13. General

13.1 This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, consistent with clause 21 of the Agreement.

13.2 Except as amended by this DPA, the Agreement remains in full force and effect.

Schedule 1: Details of Processing

Subject matter: The provision of the RotaCubed workforce scheduling and rota management Service by the Processor to the Controller.

Duration: For the duration of the Agreement, and thereafter for the retention period described in clause 11 of the Agreement, currently 1 year following cancellation or termination.

Nature and purpose of processing: Processing personal data as necessary to provide workforce scheduling, rota management, leave management, and related features of the Service, including, where the Controller enables the relevant features, staffing cost and pay related data.

Types of Customer Personal Data: Names, contact details, such as email and phone number, job title or role, employment start date, shift and rota data, availability, leave records, and, where the Controller enables relevant features, pay rate and staffing cost data.

Categories of Data Subjects: Employees, workers, contractors, and other personnel of the Controller who are scheduled or managed using the Service.

Schedule 2: Sub Processors

AWS (Amazon Web Services): cloud hosting infrastructure. Location: UK and EEA.

Supabase: database and backend infrastructure. Location: UK and EEA.

Cloudflare: content delivery and security infrastructure. Location: UK and EEA.

PostHog: in application product analytics. Location: UK and EEA.

The Processor will update this Schedule, and notify the Controller in accordance with clause 5.2, if this list changes.

Schedule 3: Security Measures

The Processor maintains the following technical and organisational measures, and may update them from time to time provided they do not materially reduce the overall level of security.

(a) Encryption of Customer Personal Data in transit, using TLS, and at rest.

(b) Access controls based on the principle of least privilege, with unique user logins and role based permissions.

(c) Regular automated backups of Customer Personal Data.

(d) Logical separation of each Controller's data within the Service.

(e) Monitoring and logging of access to production systems and infrastructure.

(f) Confidentiality undertakings from personnel with access to production data, and restriction of that access to those who need it.

(g) Selection of infrastructure providers that host data within the UK and EEA and maintain appropriate security standards.

(h) An incident response process for identifying, containing and remediating security incidents, and notifying affected Controllers in accordance with clause 8.

Contact Us

Itembay Limited (trading as RotaCubed). Company Number 12027952. Registered Office 235 Foxhall Road, Ipswich, IP3 8LF. Email: support@rotacubed.com