Legal
Data Processing Agreement
Last updated: 2 October 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Controller") and Suparota Ltd, a company registered in England and Wales (company number 17449552) with its registered office at 18 Stoke Newington High St, London N16 7PL ("Suparota", "we", "us", the "Processor"), for the Suparota workforce management platform (the "Services"). It is incorporated into our Terms of Service.
It sets out how we process personal data on your behalf, as required by Article 28 of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
1. Definitions
Data Protection Law — the UK GDPR, the Data Protection Act 2018, and any successor legislation, as amended.
Personal Data, Processing, Controller, Processor, Data Subject — as defined in Data Protection Law.
Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data we process under this DPA.
Sub-processor — a third party we engage to process Personal Data on your behalf.
Authorised Users — the owners, managers and staff you invite to use the Services.
2. Roles
You are the Controller of the personal data of your staff and Authorised Users that is entered into or generated by the Services. You decide what data is entered, which features are switched on, and how the Services are used.
We are the Processor. We process that data only on your documented instructions and only to provide the Services. Your instructions are this DPA, the Terms of Service, and the settings and features you choose within the Services.
For data we collect about you as our customer (your account, billing and support contact), we are a controller, as described in our Privacy Policy.
3. Duration
We process Personal Data for as long as you use the Services, including any free trial, and afterwards only as set out in Section 14.
4. Nature and purpose of processing
We process Personal Data to provide the Services, including to:
- store and display staff records and rotas
- record clock-in and clock-out times, hours worked and attendance
- where you switch it on, check at clock-in whether a staff member is at the venue (Section 6.3)
- manage holiday, absence, sickness and availability
- calculate pay, holiday pay, sick pay and tronc figures, and produce payroll reports
- send notifications to staff by email, push notification and, where you switch it on, WhatsApp
- provide calendar feeds of shifts
- provide Supe AI, our built-in AI assistant, where Authorised Users choose to use it
- keep audit records of actions taken in the Services
5. Data subjects
- Your staff, including employees, workers and casual staff, some of whom may be under 18
- Your Authorised Users, including owners and managers
- Anyone else whose data you choose to enter
6. Types of Personal Data
6.1 Categories
- Identity and contact — name, display name, email address, WhatsApp number
- Employment — employee type, role, department, start date, employment status, contracted hours and days, venue
- Pay — hourly rate, salary, contracted hours, pay calculations, holiday pay and tronc allocations
- Attendance — clock-in and clock-out times, hours worked, breaks, shift confirmations
- Location check result — where switched on, whether a clock-in was on site or off site and the distance from the venue (Section 6.3)
- Leave and availability — holiday requests and balances, availability
- Sickness absence — sickness records, how sick shifts are treated for pay, and any notes entered (Section 6.2)
- Supe AI — questions asked and answers given
- Technical — user identifiers, notification settings and push subscriptions, calendar feed links
- Audit — records of who did what in the Services, and when
6.2 Special category data
Sickness absence records are health data, which is special category data under Article 9 of the UK GDPR. You are responsible for having a condition under Article 9 that permits you to process it. For most employers this is the employment-law condition in Article 9(2)(b), together with the related requirements of the Data Protection Act 2018. Only enter the health information you need. Avoid putting medical detail in free-text notes.
We do not ask you to enter any other special category data. If you choose to enter it into free-text fields, you are responsible for having a lawful basis to do so.
6.3 The location check
The location check is off unless you switch it on. When it is on, a staff member's device shares its location once, at clock-in. We compare it with your venue's location and keep only the result (on site, off site, or no location) and the distance. We do not store the coordinates, and we do not track location at any other time. If a staff member clocks in off site, your managers are notified.
7. Your obligations
As Controller, you will:
- have a lawful basis for processing your staff's personal data and for sharing it with us. For staff data this is not usually consent, which is rarely valid in an employment relationship.
- give your staff a privacy notice explaining how their data is handled using the Services, including the location check if you switch it on
- have an Article 9 condition for any sickness or other special category data you enter
- keep the data you enter accurate and up to date
- give Authorised Users access appropriate to their role
8. Our obligations
As Processor, we will:
- process Personal Data only on your documented instructions, unless the law requires otherwise, in which case we will tell you first unless the law prevents it
- tell you promptly if we believe an instruction breaks Data Protection Law
- ensure anyone authorised to process Personal Data is bound by confidentiality
- maintain the security measures in Section 11
- use Sub-processors only as set out in Section 9
- help you respond to requests from your staff exercising their rights (Section 10)
- help you meet your obligations on security, breach notification, data protection impact assessments and consultation with the Information Commissioner's Office, taking into account the nature of the processing and the information available to us
- delete or return Personal Data at the end of the Services as set out in Section 14
- give you the information reasonably needed to show we meet this DPA (Section 15)
8.1 Anonymised statistics
You authorise us to create anonymised, aggregated statistics from use of the Services, to operate and improve the Services and produce industry benchmarks. Anonymised statistics cannot identify any individual or any business, and once anonymised they are not Personal Data.
9. Sub-processors
You give us general authorisation to engage Sub-processors. The current list, with what each does and where, is at suparota.com/sub-processors.
We will give you at least 14 days' notice by email before adding or replacing a Sub-processor. If you object on reasonable data protection grounds within that period, we will work with you to find a solution. If we cannot, you may end your Subscription before the change takes effect.
Each Sub-processor is bound by a written contract with data protection obligations materially equivalent to this DPA. We remain liable to you for our Sub-processors' performance of those obligations.
10. Your staff's rights
If one of your staff contacts us directly to exercise their data protection rights, we will refer them to you and let you know promptly.
You can view and correct staff data within the Services. Where you cannot do something yourself through the Services, such as exporting all of a person's data, we will do it for you on request, within a reasonable time.
11. Security measures
We maintain appropriate technical and organisational measures, including:
- database-level access controls (row-level security) separating each business's data from every other business
- encryption in transit (TLS) and at rest
- secure sign-in through Clerk, with optional two-step verification
- role- and permission-based access within the Services, with sensitive actions such as confirming payroll limited to specific permissions
- short-lived sign-in tokens
- audit records of significant actions
- restricting access to production systems to authorised personnel
- assessing Sub-processors' security before engaging them
- an incident response process
12. Data Breach notification
If we become aware of a Data Breach affecting Personal Data we process for you, we will notify you without undue delay, and where feasible within 48 hours. We will give you the information you reasonably need to meet your own obligations, including what happened, the categories and approximate numbers of people and records affected, the likely consequences, and what we have done or propose to do. We will keep you updated as we learn more, cooperate with your investigation, and not notify anyone else about the breach without your agreement, unless the law requires us to.
13. International transfers
Some Sub-processors process Personal Data outside the UK, or are US companies that may access data stored in the EU. For each such transfer we rely on a mechanism recognised by UK Data Protection Law: the UK Extension to the EU–US Data Privacy Framework where the Sub-processor is certified, or otherwise the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Details for each Sub-processor are available on request.
14. End of the Services: return and deletion
When your Subscription or free trial ends without being renewed, including after any grace period:
- your account is locked and your data is kept for 30 days
- during those 30 days you can ask us for an export of your data in a standard machine-readable format, or reactivate your Subscription with your data intact
- we will email you before your data is deleted
- after 30 days we will permanently delete your Personal Data from our live systems. Any copies in our backups are deleted as those backups expire, within a further 30 days
- we will confirm deletion in writing on request
Statutory record-keeping duties, such as keeping pay records for minimum wage purposes, are yours as the employer. If you need those records after leaving, export them during the 30 days. We keep our own billing records about you as required by law; these are covered by our Privacy Policy, not this DPA.
15. Audits
You may request, no more than once a year and with at least 30 days' written notice, information reasonably needed to confirm we comply with this DPA. We will provide relevant security documentation, summaries of available third-party assurance for us or our Sub-processors, and answers to a reasonable data protection questionnaire. If that is not enough to demonstrate compliance, we will agree a reasonable further review with you.
16. Liability
Liability under this DPA is subject to the limitations in our Terms of Service, except where Data Protection Law does not allow liability to be limited.
17. Governing law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
18. Contact
For data protection questions, requests or breach notifications:
Email: support@suparota.com Address: Suparota Ltd, 18 Stoke Newington High St, London N16 7PL