# GDPR Compliance

Last updated: March 11, 2026

## 1. Our Commitment

ShiftPro is committed to compliance with the General Data Protection Regulation (GDPR). We process personal data lawfully, transparently, and only for specified purposes. This page outlines how we uphold your rights under GDPR.

## 2. Data Controller & Processor

When a company uses ShiftPro to manage its workforce, the **company is the Data Controller** and **ShiftPro acts as the Data Processor**. We process employee personal data only on behalf of and under the instructions of the company.

For data collected directly from individuals (e.g., account registration, contact form submissions), ShiftPro acts as the Data Controller.

## 3. Legal Basis for Processing

We process personal data under the following legal bases:

- **Contract performance:** Processing necessary to provide the Service (e.g., scheduling, time tracking, billing).
- **Legitimate interest:** Analytics and service improvement using aggregated data; fraud prevention; security monitoring.
- **Legal obligation:** Tax records, audit trails, and compliance with labor laws.
- **Consent:** Where applicable, such as optional marketing communications.

## 4. Your Rights Under GDPR

If you are in the European Economic Area (EEA), you have the following rights:

### Right of Access

Request a copy of the personal data we hold about you.

### Right to Rectification

Request correction of inaccurate or incomplete personal data.

### Right to Erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

### Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

### Right to Data Portability

Receive your data in a structured, machine-readable format and transfer it to another service.

### Right to Object

Object to processing based on legitimate interest, including profiling.

### Right to Withdraw Consent

Withdraw consent at any time where processing is consent-based, without affecting prior lawful processing.

## 5. How to Exercise Your Rights

To exercise any of these rights, contact us at [Contact@shiftpro.io](mailto:Contact@shiftpro.io) with the subject line "GDPR Request". We will respond within 30 days. We may need to verify your identity before processing your request.

If you are an employee whose data is managed through ShiftPro by your employer, please first contact your employer (the Data Controller) to exercise your rights.

## 6. Data Transfers

Your data may be processed in countries outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions, to protect your data in accordance with GDPR requirements.

## 7. Data Protection Measures

We implement technical and organizational measures to protect personal data, including:

- End-to-end encryption for data in transit (SSL/TLS).
- Encryption at rest for stored data.
- Row Level Security ensuring strict tenant isolation.
- Multi-factor authentication for administrative access.
- Regular security audits and vulnerability assessments.
- Comprehensive audit logging of data access.

## 8. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR.

## 9. Data Processing Agreements

ShiftPro enters into Data Processing Agreements (DPAs) with all customers who require them. To request a DPA, contact us at [Contact@shiftpro.io](mailto:Contact@shiftpro.io).

## 10. Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe your data is being processed in violation of GDPR.

## 11. Contact

For GDPR-related inquiries or to exercise your rights, contact our data protection team at [Contact@shiftpro.io](mailto:Contact@shiftpro.io) or visit our [Contact page](https://shiftpro.io/contact).
