Data processing agreement

For businesses using StaffOPs to roster their staff. It covers what we may do with your people’s personal information.

Draft — not yet in force

This agreement is with our lawyer for review. The facts in it — where data is processed and what protects it — are accurate today and are set out in full on our security page. The contractual wording is not final.

1. Roles

You are the agency or controller of your staff's personal information; we process it on your instructions to run StaffOPs for you. In New Zealand terms, the information is held by you and we hold it as your agent.

2. What we process, and why

Names, email addresses, job titles, department membership, rosters and answers to shift requests, clock-in and clock-out times and the hours they produce, pay rates where you set them, leave you record, and messages sent to the in-app assistant. We process them to provide the service and for nothing else — no profiling, no advertising, no sale.

3. Our obligations

To be drafted — Confidentiality, staff access on a need-to-know basis, assistance with your privacy obligations, and the security measures we commit to maintaining.

4. Breach notification

To be drafted — Our notification window and what we will tell you, and the allocation of who decides whether a breach is notified to a regulator and to affected people.

5. Sub-processors

We use a small number of other companies to run StaffOPs. Each is named, with what it receives and where it processes, on our security page, and that list forms a schedule to this agreement.

To be drafted — Your right to notice before a new sub-processor starts, and what you may do if you object.

6. Where the data is

Stored and processed in Sydney, Australia, with the application running in the same region and backups held there. Three sub-processors — email delivery, the assistant, and address lookup for workplace addresses — process a limited data set in the United States.

7. Retention and return

Assistant messages are purged after 12 months and records of who was asked to work a shift after 24 months. Timesheets are kept while the account exists, because they are wage records you are required to keep. You can export the whole account at any time, and closing it erases everything 30 days later.

8. Audit and assistance

To be drafted — How we support your own due diligence, and what we will provide on request.

Schedule — security measures

Row-level security enforced by the database itself; department-scoped visibility of pay rates; frozen pay periods and an unalterable edit trail on wage records; TLS in transit and encryption at rest; a Content Security Policy with no third-party keys in the browser; least privilege for automated processes; automated daily backups retained seven days in the same region; and automatic retention purges. The current gaps — no multi-factor authentication yet, no point-in-time recovery, no third-party certification — are listed alongside them on the security page rather than left out.

Questions about any of this: hello@joytech.nz