Legal Data Processing Agreement
Hospitech — Data Processing Agreement (DPA)
Controller: the Customer (the business holding the account). Processor: Hospitech Solutions Ltd, 14 Cronans Well Grove, Swords, Co. Dublin, K67 X5F1, CRO no. 817101.
1. Subject matter and roles
1.1 The Customer uses the Hospitech platform to manage its staff. Depending on the modules it subscribes to, that includes employee records and contracts, scheduling and attendance, holiday and absence management, food-safety records, and staff training. In doing so the Customer determines the purposes and means of processing its staff's personal data and is the controller; Hospitech processes that data only to provide the Service and is the processor. 1.2 Duration: the term of the Customer's account, plus the wind-down periods in clause 8. 1.3 The Service is modular. A Customer is only ever a controller for the data belonging to modules it actually uses; this Agreement covers the whole platform so that adding a module later does not require a new agreement.
2. Processing details (Art 28(3))
- Data subjects: the Customer's employees, workers and job applicants; in limited cases the Customer's suppliers' contact staff (HACCP supplier certificates).
- Nature and purpose: hosting, storage, display to authorised users of the Customer, computation (rosters, worked time, pay estimates, compliance scoring, quiz marking), document generation (contracts, certificates, inspection packs), transactional email on the Customer's behalf, and export at the Customer's direction.
Categories of personal data, by module:
| Module | Personal data processed |
|---|---|
| HR (spine — always present) | Identity (name, staff number, date of birth), contact details, emergency contact, PPS number, bank account details, right-to-work and identity documents, employment terms (job title, site, department, pay type and rate, start date), signed contracts and policy acknowledgements, leaver records and statements of service, audit log of who changed what |
| Time | Availability, scheduled shifts, clock-in/out events, per-person clock-in PIN (stored hashed), derived worked hours and pay figures |
| Roster & Holiday | Leave requests, approvals and balances, absence records including sick leave |
| HACCP | Food-safety records signed by named staff, temperature and check submissions, corrective actions, photographs taken during checks, incident reports including staff illness / fitness-to-work and allergen incidents, manager daily sign-offs, supplier certificate contacts |
| Training | Course assignments, quiz attempts and scores, pass/fail outcomes, issued certificates and expiry dates, certificates issued by third-party providers where uploaded by the Customer |
2A. Special-category data (Article 9)
2A.1 The Service does process special-category data, specifically data concerning health:
- Certified and uncertified sick leave recorded in the Roster & Holiday module, including where a medical certificate is uploaded and whether statutory sick pay was applied;
- Staff illness and fitness-to-work reporting in the HACCP module, which food-safety law requires a food business operator to record;
- Allergen incident reports, which may disclose an individual's allergy;
- Related maternity, paternity, parental, carer's and force-majeure leave records, which may disclose family circumstances or health.
2A.2 Hospitech processes this data solely on the Customer's instructions as processor, and applies no automated decision-making to it.
2A.3 The Article 9(2) condition is the Controller's responsibility to establish and record. In an employment context the Customer will ordinarily rely on Art 9(2)(b) (obligations in the field of employment and social security law) together with section 46 of the Data Protection Act 2018, and on Art 9(2)(i) (public health) for food-safety illness reporting under Regulation (EC) 852/2004 Annex II Chapter VIII. Customers should confirm their own lawful basis and record it in their Article 30 record; Hospitech does not determine it and cannot do so on their behalf.
2A.4 Because health data is present, the Customer should consider whether a Data Protection Impact Assessment is required. Hospitech will assist under clause 3(f).
3. Processor obligations
Hospitech shall: (a) process personal data only on the Customer's documented instructions (the Service configuration and use constitute those instructions), unless required by EU/Irish law, in which case it will inform the Customer unless prohibited; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in the Annex; (d) respect the sub-processor conditions in clause 4; (e) taking into account the nature of the processing, assist the Customer with data-subject requests (access, rectification, erasure, portability) — largely self-service via the Service's own tools; (f) assist the Customer with Articles 32–36 (security, breach notification, DPIAs) as reasonably needed; (g) at the Customer's choice, delete or return all personal data at the end of the Service (clause 8); (h) make available information reasonably necessary to demonstrate compliance and allow audits, no more than annually and on 30 days' notice, at the Customer's cost.
4. Sub-processors
4.1 The Customer grants general authorisation for the sub-processors listed at hospitech.ie/dpa/, currently:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage, hosting | EU (Ireland, eu-west-1) |
| Vercel | Application hosting | EU/global edge |
| Resend | Transactional email sent on the Customer's behalf | EU/US |
| Google (Workspace / Sign-in) | Optional single sign-on for the Customer's managers | EU/US |
| Stripe | Card payments and subscription billing | EU/US |
Note on Stripe: it processes the account holder's billing details — name, email, company and card — and never receives staff personal data. Card details go to Stripe directly and are not held by Hospitech at any point. For that processing Stripe is an independent controller under its own terms as well as our sub-processor.
4.2 Hospitech will give at least 30 days' notice of intended additions or replacements; the Customer may object on reasonable data-protection grounds, in which case the Customer may terminate and export. 4.3 Hospitech remains fully liable for its sub-processors' performance.
5. International transfers
Primary data residency is the EU (Ireland). Where a sub-processor's group involves transfers outside the EEA (e.g. US-parented providers), transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable.
6. Personal-data breach
Hospitech will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data, with sufficient information to support the Customer's own notification duties, and will cooperate in remediation.
7. Data-subject requests
Requests received directly by Hospitech from the Customer's staff will be forwarded to the Customer without undue delay; Hospitech will not respond on the Customer's behalf except as instructed.
8. Return and deletion
On account closure the Customer's access is revoked but no personal data is deleted. It is retained unchanged for 90 days, during which the Customer may export it in full at any time, or reactivate the account. At the end of that window personal data is deleted from production systems, and from backups as those backups expire, except where retention is required by law.
Hospitech retains after deletion only: statutory billing records, and a record of the deletion itself comprising the Customer's company name and the relevant dates, which contains no personal data. The operational detail is published at Leaving Hospitech.
The Customer is reminded that several categories of this data must be retained by the employer and should be exported before closure:
- Working-time records — Organisation of Working Time Act 1997 (3 years);
- Employment records and contracts — Terms of Employment (Information) Acts;
- Food-safety records — Regulation (EC) 852/2004, retained for the period appropriate to the product and typically required to be produced on an EHO inspection;
- Training records and certificates — needed to evidence the training obligation under Regulation (EC) 852/2004 Annex II Chapter XII and the Safety, Health and Welfare at Work Act 2005.
Annex — Technical and organisational measures
- EU hosting (Ireland region); encryption in transit (TLS) and at rest.
- Tenant isolation enforced in the database itself via row-level security on every table, scoped by customer account; deny-by-default policies. One customer's account cannot read another's records even in the event of an application-layer fault.
- Modules are separated by database schema; a module may reference the shared employee record but never another module's tables.
- Sensitive HR fields (PPS number, bank details) are stored encrypted at the application layer in addition to encryption at rest.
- Role-based access (owner / manager / supervisor / staff) enforced by database policy, not only by the interface; staff clock-in via per-person PINs (stored hashed, system-assigned, unique per account).
- Files (signed contracts, certificates, check photographs) held in private storage buckets with per-tenant access policies; no public URLs.
- Audit trail of authentication events via the hosting provider, and an in-application audit log of record changes.
← All documents · Questions: hello@hospitech.ie