Hospitech.

Legal Data Processing Agreement

Hospitech — Data Processing Agreement (DPA)

Controller: the Customer (the business holding the account). Processor: Hospitech Solutions Ltd, 14 Cronans Well Grove, Swords, Co. Dublin, K67 X5F1, CRO no. 817101.

1. Subject matter and roles

1.1 The Customer uses the Hospitech platform to manage its staff. Depending on the modules it subscribes to, that includes employee records and contracts, scheduling and attendance, holiday and absence management, food-safety records, and staff training. In doing so the Customer determines the purposes and means of processing its staff's personal data and is the controller; Hospitech processes that data only to provide the Service and is the processor. 1.2 Duration: the term of the Customer's account, plus the wind-down periods in clause 8. 1.3 The Service is modular. A Customer is only ever a controller for the data belonging to modules it actually uses; this Agreement covers the whole platform so that adding a module later does not require a new agreement.

2. Processing details (Art 28(3))

Categories of personal data, by module:

ModulePersonal data processed
HR (spine — always present)Identity (name, staff number, date of birth), contact details, emergency contact, PPS number, bank account details, right-to-work and identity documents, employment terms (job title, site, department, pay type and rate, start date), signed contracts and policy acknowledgements, leaver records and statements of service, audit log of who changed what
TimeAvailability, scheduled shifts, clock-in/out events, per-person clock-in PIN (stored hashed), derived worked hours and pay figures
Roster & HolidayLeave requests, approvals and balances, absence records including sick leave
HACCPFood-safety records signed by named staff, temperature and check submissions, corrective actions, photographs taken during checks, incident reports including staff illness / fitness-to-work and allergen incidents, manager daily sign-offs, supplier certificate contacts
TrainingCourse assignments, quiz attempts and scores, pass/fail outcomes, issued certificates and expiry dates, certificates issued by third-party providers where uploaded by the Customer

2A. Special-category data (Article 9)

2A.1 The Service does process special-category data, specifically data concerning health:

2A.2 Hospitech processes this data solely on the Customer's instructions as processor, and applies no automated decision-making to it.

2A.3 The Article 9(2) condition is the Controller's responsibility to establish and record. In an employment context the Customer will ordinarily rely on Art 9(2)(b) (obligations in the field of employment and social security law) together with section 46 of the Data Protection Act 2018, and on Art 9(2)(i) (public health) for food-safety illness reporting under Regulation (EC) 852/2004 Annex II Chapter VIII. Customers should confirm their own lawful basis and record it in their Article 30 record; Hospitech does not determine it and cannot do so on their behalf.

2A.4 Because health data is present, the Customer should consider whether a Data Protection Impact Assessment is required. Hospitech will assist under clause 3(f).

3. Processor obligations

Hospitech shall: (a) process personal data only on the Customer's documented instructions (the Service configuration and use constitute those instructions), unless required by EU/Irish law, in which case it will inform the Customer unless prohibited; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in the Annex; (d) respect the sub-processor conditions in clause 4; (e) taking into account the nature of the processing, assist the Customer with data-subject requests (access, rectification, erasure, portability) — largely self-service via the Service's own tools; (f) assist the Customer with Articles 32–36 (security, breach notification, DPIAs) as reasonably needed; (g) at the Customer's choice, delete or return all personal data at the end of the Service (clause 8); (h) make available information reasonably necessary to demonstrate compliance and allow audits, no more than annually and on 30 days' notice, at the Customer's cost.

4. Sub-processors

4.1 The Customer grants general authorisation for the sub-processors listed at hospitech.ie/dpa/, currently:

Sub-processorPurposeRegion
Supabase (on AWS)Database, authentication, file storage, hostingEU (Ireland, eu-west-1)
VercelApplication hostingEU/global edge
ResendTransactional email sent on the Customer's behalfEU/US
Google (Workspace / Sign-in)Optional single sign-on for the Customer's managersEU/US
StripeCard payments and subscription billingEU/US

Note on Stripe: it processes the account holder's billing details — name, email, company and card — and never receives staff personal data. Card details go to Stripe directly and are not held by Hospitech at any point. For that processing Stripe is an independent controller under its own terms as well as our sub-processor.

4.2 Hospitech will give at least 30 days' notice of intended additions or replacements; the Customer may object on reasonable data-protection grounds, in which case the Customer may terminate and export. 4.3 Hospitech remains fully liable for its sub-processors' performance.

5. International transfers

Primary data residency is the EU (Ireland). Where a sub-processor's group involves transfers outside the EEA (e.g. US-parented providers), transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable.

6. Personal-data breach

Hospitech will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data, with sufficient information to support the Customer's own notification duties, and will cooperate in remediation.

7. Data-subject requests

Requests received directly by Hospitech from the Customer's staff will be forwarded to the Customer without undue delay; Hospitech will not respond on the Customer's behalf except as instructed.

8. Return and deletion

On account closure the Customer's access is revoked but no personal data is deleted. It is retained unchanged for 90 days, during which the Customer may export it in full at any time, or reactivate the account. At the end of that window personal data is deleted from production systems, and from backups as those backups expire, except where retention is required by law.

Hospitech retains after deletion only: statutory billing records, and a record of the deletion itself comprising the Customer's company name and the relevant dates, which contains no personal data. The operational detail is published at Leaving Hospitech.

The Customer is reminded that several categories of this data must be retained by the employer and should be exported before closure:

Annex — Technical and organisational measures

← All documents · Questions: hello@hospitech.ie