This Data Processing Agreement (“DPA”) forms part of the agreement between Shift Terminal Inc. (“Processor,” “we,” “us”) and the Organization subscribing to the Shift Terminal service (“Controller,” “you,” “your”), collectively the “Parties.”
This DPA applies to the extent that Shift Terminal processes Personal Data on behalf of the Controller in the course of providing the Shift Terminal workforce management platform (the “Service”) as described in our Terms of Service.
This DPA is designed to meet the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and other applicable data protection legislation.
1. Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Service.
- “Processing” means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
- “Data Subject” means the individual whose Personal Data is processed, typically employees, managers, and other workforce members of the Controller.
- “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Scope and Purpose of Processing
The Processor processes Personal Data solely for the purpose of providing the Service to the Controller, which includes:
- Employee scheduling and shift management
- Time tracking, clock-in/clock-out, and attendance management
- Time-off request management
- Team communication (messaging and shift notes)
- Workforce reporting and analytics
- User account administration and access control
- Sending service-related notifications (email, push, in-app)
- Subscription billing and payment processing
The Processor shall not process Personal Data for any purpose other than as instructed by the Controller or as required by applicable law.
3. Categories of Personal Data
The following categories of Personal Data are processed through the Service:
3.1 Data Subjects
Employees, managers, supervisors, and administrators of the Controller’s organization.
3.2 Types of Personal Data
- Identity Data: First name, last name, employee ID
- Contact Data: Email address, phone number
- Employment Data: Role, position, department, employment type, start date, hourly wage, maximum hours per week
- Authentication Data: Hashed passwords, session tokens (not accessible in plaintext)
- Scheduling Data: Shift assignments, schedule preferences, availability
- Attendance Data: Clock-in/clock-out timestamps, break records, time-off requests and approvals
- Location Data: GPS coordinates at clock-in/clock-out (only when geofencing is enabled by the Controller)
- Communication Data: Team chat messages, shift notes
- Device Data: IP address, browser type, device type (collected automatically for security)
- Profile Data: Profile photos (when uploaded by the Data Subject)
3.3 Sensitive Data
The Service is not designed to process special categories of data (e.g., health data, biometric data, racial or ethnic origin). The Controller shall not submit sensitive personal data through the Service unless expressly agreed in writing.
4. Controller Obligations
The Controller shall:
- Ensure that it has a lawful basis for the processing of Personal Data and has provided appropriate notice to Data Subjects
- Ensure that instructions given to the Processor comply with applicable data protection laws
- Be responsible for the accuracy, quality, and legality of the Personal Data provided to the Processor
- Promptly notify the Processor of any data subject requests that require the Processor’s assistance
- Maintain appropriate internal privacy policies and practices
5. Processor Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law
- Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing
- Not engage a Sub-processor without prior written authorization from the Controller (see Section 8)
- Assist the Controller in responding to Data Subject requests (see Section 7)
- Assist the Controller in ensuring compliance with breach notification obligations (see Section 9)
- At the Controller’s choice, delete or return all Personal Data after the end of the provision of services (see Section 11)
- Make available to the Controller all information necessary to demonstrate compliance with this DPA
6. Security Measures
The Processor implements and maintains the following technical and organizational security measures:
- Encryption in Transit: All data transmitted between clients and servers uses TLS 1.2 or higher
- Encryption at Rest: All stored data is encrypted using AES-256 encryption
- Row-Level Security: Database-enforced policies ensure strict data isolation between organizations
- Role-Based Access Controls: Granular permission system (admin, manager, supervisor, employee) restricts data access
- Authentication Security: Passwords are hashed using bcrypt; session tokens are cryptographically signed JWTs with expiration
- Infrastructure: Hosted on SOC 2 Type II and ISO 27001 certified infrastructure providers
- Access Logging: Administrative actions are logged in audit trails with timestamps and actor identification
- Rate Limiting: API and email rate limiting to prevent abuse
- CAPTCHA Protection: Bot protection on authentication endpoints
The Processor shall regularly review and update security measures to maintain an appropriate level of protection. Security measures shall not be reduced below the level described above without prior notice to the Controller.
7. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests, including requests for:
- Access to their Personal Data
- Rectification of inaccurate Personal Data
- Erasure of Personal Data (“right to be forgotten”)
- Restriction of processing
- Data portability (export in machine-readable format)
- Objection to processing
- Withdrawal of consent
The Controller may use the Service’s built-in tools for many of these requests, including user profile management, data export, and account deactivation. For requests that cannot be fulfilled through the Service interface, the Controller may contact the Processor at privacy@shiftterminal.com.
The Processor shall respond to Controller requests for assistance within 5 business days and shall not independently respond to Data Subject requests unless authorized by the Controller or required by law.
8. Sub-processors
The Controller authorizes the Processor to engage the following Sub-processors. The Processor shall notify the Controller at least 30 days before adding or replacing a Sub-processor, giving the Controller the opportunity to object.
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Supabase Inc. | Database hosting, authentication, real-time infrastructure, edge functions | Canada (AWS ca-central-1, Montréal) |
| Stripe Inc. | Payment processing and subscription management | United States |
| Resend Inc. | Transactional email delivery | United States |
| Vercel Inc. | Web application hosting and content delivery | Global CDN (primary: United States) |
| OpenWeather Ltd. | Weather data for scheduling features (no Personal Data shared) | United Kingdom |
The Processor shall impose on each Sub-processor data protection obligations no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-processor’s obligations.
If the Controller objects to a new Sub-processor within 30 days of notification, the Parties shall discuss the objection in good faith. If no resolution can be reached, the Controller may terminate the affected portion of the Service.
9. Data Breach Notification
In the event of a Data Breach affecting Personal Data processed on behalf of the Controller, the Processor shall:
- Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, providing:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects affected
- The name and contact details of the Processor’s contact point for further information
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including mitigation
- Cooperate with the Controller in investigating and remediating the breach
- Take immediate steps to contain and mitigate the effects of the breach
- Not notify any Data Subject or regulatory authority on behalf of the Controller unless instructed to do so
- Document all breaches, including facts, effects, and remedial actions taken
10. International Data Transfers
Shift Terminal is incorporated in Canada. The European Commission has recognized Canada as providing an adequate level of data protection under GDPR Article 45. Personal Data may also be processed in the United States through our Sub-processors listed in Section 8.
Where Personal Data is transferred to a country that has not received an adequacy decision, the Processor shall ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (Commission Decision 2021/914)
- The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, where applicable
- Supplementary measures where required by transfer impact assessments
Upon request, the Processor shall provide the Controller with copies of any relevant transfer mechanisms in place with Sub-processors.
11. Data Return and Deletion
Upon termination or expiration of the Service agreement, or upon the Controller’s written request, the Processor shall:
- Data Export: Provide the Controller with the ability to export all Personal Data in a structured, commonly used, machine-readable format (JSON) for a period of 30 days following termination
- Data Deletion: After the 30-day export period (or upon Controller instruction), securely delete all Personal Data from production systems, including all copies and backups, within 90 days
- Certification: Upon request, provide written confirmation that all Personal Data has been deleted
The Processor may retain Personal Data to the extent required by applicable law (e.g., tax records, employment law compliance). Any retained data shall continue to be protected in accordance with this DPA and shall be deleted when the legal retention obligation expires.
12. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller.
- Audits shall be conducted with reasonable notice (at least 30 days) and during normal business hours
- The Controller may conduct up to one audit per 12-month period, unless a Data Breach or regulatory investigation requires additional audits
- The Controller shall bear the costs of any audit unless the audit reveals material non-compliance by the Processor
- The Processor may satisfy audit requests by providing relevant certifications, audit reports (e.g., SOC 2), or other evidence of compliance
13. Liability
Each Party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, except that:
- Neither Party’s liability for breaches of data protection obligations shall be limited to the extent that such limitation would conflict with applicable data protection law
- The Processor shall be liable for damage caused by processing that violates the Controller’s documented instructions or this DPA
- Each Party shall indemnify the other for any fines, penalties, or damages arising from the indemnifying Party’s breach of this DPA or applicable data protection law
14. Term and Termination
This DPA shall remain in effect for the duration of the Processor’s processing of Personal Data on behalf of the Controller. It shall automatically terminate when the Processor no longer processes Personal Data on behalf of the Controller.
The obligations in Sections 6 (Security), 9 (Breach Notification), 11 (Data Return and Deletion), 12 (Audit Rights), and 13 (Liability) shall survive termination of this DPA.
15. PIPEDA-Specific Provisions
In addition to the obligations above, and to the extent that PIPEDA applies to the processing:
- The Processor acknowledges that the Controller is accountable for Personal Data transferred to the Processor under PIPEDA Principle 4.1.3
- The Processor shall use comparable means to protect Personal Data while it is being processed
- The Processor shall assist the Controller in responding to access requests from individuals under PIPEDA Principle 4.9
- The Processor shall retain Personal Data only as long as necessary for the purposes for which it was collected, in accordance with PIPEDA Principle 4.5
- The Processor shall protect Personal Data with security safeguards appropriate to the sensitivity of the information, in accordance with PIPEDA Principle 4.7
16. Amendments
This DPA may be amended to reflect changes in applicable data protection law or to the Service. The Processor shall notify the Controller of any material changes at least 30 days before they take effect. Continued use of the Service after notification constitutes acceptance of the amended DPA. If the Controller does not agree with a material change, it may terminate the Service in accordance with the Terms of Service.
17. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict of law principles. Any dispute arising under this DPA shall be subject to the exclusive jurisdiction of the courts of Ontario, Canada.
18. Contact
For questions about this DPA or to exercise any rights described herein, contact:
Shift Terminal Inc.
Privacy & Data Protection
Email: privacy@shiftterminal.com
Website: shiftterminal.com
This Data Processing Agreement is provided as a standard template for Shift Terminal customers. Enterprise customers requiring a countersigned DPA or custom data processing terms should contact us at privacy@shiftterminal.com.
