1. Who we are
Rotahr is a hospitality workforce management platform operated by Rotahr, Ireland. For the purposes of GDPR, Rotahr is the data controller for platform-level data (account data, subscription data, platform usage). Individual businesses using Rotahr act as data controllers for data they collect about their own customers and staff; Rotahr acts as a data processor on their behalf in relation to that data.
Contact: privacy@rotahr.com
2. What data we collect
- Account data: name, email address, hashed password (bcrypt, cost 12), role, business name.
- Employee HR data (collected by businesses on their staff): name, email, phone, home address, start date, contract type, hourly rate, PPS Number (masked in UI), IBAN and BIC (masked in UI), emergency contact name/phone/relationship, shift records, time-off requests, availability preferences, clock-in/out events (with optional GPS coordinates), certifications, documents uploaded by managers.
- Customer booking data: name, email, phone, party size, date/time, occasion notes, dietary/menu notes.
- Financial data: expense records, VAT amounts, supplier names and VAT numbers, receipt images (temporarily), supplier invoice data, stock item prices and purchase history, wastage records (item name, quantity, date, reason, estimated cost), recipe and ingredient data (names, quantities, unit costs, GP% calculations). This data is stored solely to provide cost management features and is not shared with third parties. You can delete any wastage record or recipe at any time from within the platform.
- Payment data: subscription status, plan type. Payment card processing is handled entirely by Lemon Squeezy — Rotahr does not store card numbers or full payment details.
- Usage data: authentication logs, session tokens, error logs.
3. Lawful basis for processing
- Account and subscription data — GDPR Art.6(1)(b) (contract performance) and Art.6(1)(f) (legitimate interest in operating the platform).
- Employee HR and payroll data (shifts, wages, time off, PPS Number, IBAN) — GDPR Art.6(1)(b) (performance of employment contract) and Art.6(1)(c) (legal obligation under Terms of Employment Act 1994, National Minimum Wage Act 2000, Payment of Wages Act 1991, and Revenue obligations under Taxes Consolidation Act 1997 s.886). Payroll records must be retained for a minimum of 6 years under Irish law.
- Emergency contact data — GDPR Art.6(1)(f) (legitimate interest — health and safety in the workplace under Safety, Health and Welfare at Work Act 2005).
- Customer booking data — GDPR Art.6(1)(f) (legitimate interest in managing reservations). PII is anonymised on deletion; financial booking record is retained.
- Clock-in/out location data — GDPR Art.6(1)(b) (contract performance; geofencing for attendance verification). Retained for 12 months, then purged.
- Financial/VAT records — GDPR Art.6(1)(c) (legal obligation). Irish Revenue requires retention for a minimum of 6 years (TCA 1997 s.886). These records are never permanently deleted.
4. Data retention
- Payroll and HR records (PPS, IBAN, shifts, wages): retained for minimum 6 years per TCA 1997 s.886 and Irish employment law. Cannot be deleted during this period.
- Financial/VAT records: retained permanently (minimum 6 years, no maximum under Irish Revenue rules).
- Receipt images: base64 preview purged after 30 days by automated cron; Vercel Blob copy subject to your Blob storage settings.
- Customer PII (bookings/CRM): anonymised on deletion — booking record (financial) retained. Full anonymisation available on request to comply with GDPR Art.17.
- Clock-in location data: purged after 12 months.
- Staff messages: retained for 12 months, then subject to deletion.
- Account data: retained for the duration of the business subscription. Deleted within 90 days of confirmed account closure, except where legal retention obligations apply.
5. Employee data — notice to staff
If you are an employee whose data has been entered into Rotahr by your employer, your employer (the business) is the data controller for your personal data. Your employer is responsible for informing you of what data is held and why. Rotahr processes this data on behalf of your employer as a data processor.
The following personal data may be stored: your name, contact details, home address, employment start date, contract type, hourly rate, PPS Number, IBAN/BIC (for payroll), emergency contact, shift and attendance records, time-off requests, and training/certification records.
Sensitive fields (PPS Number, IBAN) are masked in the platform and only accessible to authorised managers and administrators within your employer's account.
To request access to, correction of, or deletion of your data, contact your employer directly or email privacy@rotahr.com.
6. Your rights under GDPR
As a data subject, you have the right to:
- Access your personal data (Art.15)
- Rectification of inaccurate data (Art.16)
- Erasure ("right to be forgotten") where no legal obligation to retain (Art.17)
- Restrict processing (Art.18)
- Data portability (Art.20)
- Object to processing (Art.21)
Note: The right to erasure does not apply to records we are legally required to retain — including payroll records (6 years), VAT/financial records, and any data subject to Irish Revenue or employment law obligations.
To exercise your rights, email privacy@rotahr.com. You also have the right to lodge a complaint with the Data Protection Commission (DPC) at dataprotection.ie. UK residents may contact the ICO at ico.org.uk.
6a. Rights for US, Canadian and Australian users
Rotahr applies the same high privacy standard (based on GDPR) to all users worldwide, regardless of where you or your business are located. In addition, depending on where you're based, you have rights under your local privacy law:
- United States: If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete it (subject to the same legal retention exceptions described above), and the right to opt out of the sale or sharing of personal information — Rotahr does not sell personal data, so this right is already satisfied by default. Residents of other US states with similar privacy laws (e.g. Virginia, Colorado, Connecticut, Utah) have equivalent rights.
- Canada: Rotahr processes personal data in line with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to access, correct, and (subject to legal retention obligations) request deletion of your personal information. Complaints can be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
- Australia: Rotahr processes personal data in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You have the right to access and correct your personal information and to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
To exercise any of these rights, email privacy@rotahr.com. As with all users, rights to deletion do not override legal retention obligations that apply to financial, payroll, or tax-related records in your jurisdiction.
7. Data sharing and sub-processors
We do not sell personal data. Data is shared only with the following sub-processors to operate the platform:
- Neon (database hosting): PostgreSQL cloud — data processed in EU/US. Neon is GDPR-compliant and provides EU data residency options.
- Vercel (hosting + Blob storage): Platform hosting and receipt image storage. Vercel operates under EU-US Data Privacy Framework.
- OpenAI (optional AI features): Receipt content is sent to GPT-4o for data extraction only when AI reading is enabled. OpenAI does not use this data for model training (zero data retention policy via API).
- Resend (transactional email): Used for shift notifications, booking confirmations, and account emails. GDPR-compliant.
- Lemon Squeezy (payments): Subscription billing and payment processing. Lemon Squeezy is the Merchant of Record and handles all payment card data under PCI DSS. Rotahr does not store card details.
- Railway (email marketing infrastructure): Used to send opt-in marketing communications to prospective business customers. Not used for employee or end-customer data.
8. Security
Passwords are hashed using bcrypt (cost factor 12). All data in transit is encrypted via TLS 1.2+. Database access is restricted by role and business-scoped session. Sensitive fields (PPS Number, IBAN) are masked in the UI and only revealable by authorised users. Receipt images are stored in private Vercel Blob with access-controlled URLs.
9. Cookies
Rotahr uses only essential session cookies required for authentication. No advertising or tracking cookies are used. No third-party analytics scripts are loaded on the platform.
10. International transfers
Some sub-processors (Vercel, OpenAI, Lemon Squeezy) may process data outside the EEA. Where this occurs, transfers are protected by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
11. Changes to this policy
We may update this policy. Material changes will be communicated via the platform dashboard and/or email. The date at the top of this page indicates when it was last revised. Continued use after changes constitutes acceptance.