We're in beta and it's completely free. Your feedback shapes what we build — feedback@rotaleave.co.uk

Data processing summary

Last updated: 3 July 2026

When your organisation uses Rotaleave, you are the data controller for your staff's records and we are your data processor. This page summarises our Article 28 commitments; a signed DPA is available on request via hello@rotaleave.co.uk.

What we process

Staff names, email addresses, department membership, working patterns, and leave/absence records — entered by your organisation, processed solely to provide the service.

Our commitments

We process staff data only on your instructions; ensure staff handling data are bound by confidentiality; apply the security measures described on our security page; help you respond to data-subject requests; notify you without undue delay of any personal-data breach; and delete or return your data when the account closes.

Sub-processors

Hetzner Online GmbH (infrastructure, Falkenstein, Germany — EEA), Stripe (billing), and Resend (transactional email). We'll give notice before adding or changing sub-processors.

International transfers

Your organisation's staff data is hosted on infrastructure in the EEA (Germany). Limited data is processed by sub-processors in the United States (Stripe for billing; Resend for transactional email) under UK-approved safeguards — Standard Contractual Clauses with the UK International Data Transfer Addendum, and, where applicable, the UK extension to the EU–US Data Privacy Framework.