Data Processing Agreement
Last updated: 31 July 2026
This agreement governs our handling of the personal data you put into ShiftPlate, or that we read from the systems you connect. It forms part of our Terms of Service and applies automatically for as long as we provide the platform to you — you do not need to ask for it or sign anything separate.
It is written to Article 28 of the UK and EU General Data Protection Regulation. If your own advisers would rather we signed their form of processor agreement instead, send it to us and we will.
1. The parties, and who is who
This agreement is between you — the business that uses ShiftPlate — and ShiftPlate Ltd, a company registered in England and Wales under company number 17372399, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
You are the controller of the personal data in your organisation: you decide whose data goes in, what it is used for, and how long it stays. We are your processor. We act on your instructions and do not decide what to do with your data ourselves.
Our Privacy Policy is a different document, covering the personal data we handle as a controller in our own right — website visitors, people who fill in the demo form, and people who email us. It does not apply to your staff's data.
2. What we process, and why
Subject matter and purpose: providing the ShiftPlate platform to you — sales analytics, rotas and time records, HR records and payroll figures, recipe costing, supplier invoices and expenses, inventory and waste, reports, and the Pepper assistant.
Duration: for as long as your agreement with us runs, plus the short period after it ends described in section 9.
Nature of the processing: collection, recording, storage, structuring, calculation, display, export, transmission to the sub-processors listed below, and deletion.
- Categories of data subject: your employees and former employees; the people who work at your suppliers, where their names appear on invoices or correspondence; and your own users of the platform.
- Types of personal data (staff): name, contact details, date of birth, national identity and social-security numbers, bank account details for payroll, salary and employer cost, job position, start and end dates, rota and clock-in records, holiday and absence records, performance reviews, goals, meetings and disciplinary notes, and documents you upload to a person's record.
- Types of personal data (other): names and contact details appearing on supplier invoices and in a connected invoice mailbox; the account details of your ShiftPlate users, including their email address, role and sign-in activity; and anything personal your users type into notes, expenses or the assistant.
- Special category data: ShiftPlate has no field designed for health, union membership or other special-category data. If you record it anyway — a sickness note in an absence record, for example — you remain responsible for having a lawful basis to do so.
3. We act only on your instructions
We process your personal data only on your documented instructions. Your instructions are: this agreement, our Terms of Service, the settings you choose in the platform, and anything else you tell us in writing.
We will tell you if we believe an instruction breaks data protection law. If we are required by UK or EU law to process your data for some other reason, we will tell you before doing so unless that law forbids it.
We do not sell your data, we do not use it to advertise to anyone, and we do not use it for our own purposes. We may produce aggregated or anonymised statistics to operate and improve the platform, provided they cannot reasonably be used to identify you, your staff or your customers.
4. Confidentiality and security
Everyone who has access to your personal data — our own people and our sub-processors — is bound by a duty of confidentiality.
We take appropriate technical and organisational measures to protect your data, taking account of what is at stake for the people it is about. In practice that means: access to your organisation's data is restricted by role and enforced on every request; data is encrypted in transit and at rest by our infrastructure providers; files are stored privately and served only to authenticated users; secrets and credentials are encrypted; and access to production systems is limited to those who need it.
Security measures change as threats do. We may change ours, but not in a way that materially reduces the protection your data gets.
5. Sub-processors
You give us general authorisation to use the sub-processors listed below to provide the platform. Each is bound by written terms that impose the same data protection obligations we owe you, and we remain responsible to you for what they do.
We will tell you at least 30 days before we add or replace a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may end your agreement and we will refund any fees you have paid covering the period after it ends.
6. The sub-processors we use
Every provider below processes personal data on our behalf to deliver part of the platform.
| Provider | What it does for us | Where data is processed | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. (United States) | Hosting: the servers that run the platform, the private file storage holding invoice images and receipts, and the AI Gateway that our AI calls pass through. | The servers that handle your requests run in Frankfurt. File storage and platform-level services may be processed elsewhere, including the United States. | EU Standard Contractual Clauses and the UK Addendum. |
| Neon, LLC (a Databricks company) | The main database — everything you and your staff enter into ShiftPlate, and everything we read from your point-of-sale system. | Frankfurt, in the European Union. | No transfer out of the EU for the database itself. EU Standard Contractual Clauses and the UK Addendum cover support and telemetry. |
| Clerk, Inc. (United States) | Sign-in, accounts and sessions: email addresses, names, sign-in method, and session and device information. | United States. Clerk offers no EU region. | EU-US Data Privacy Framework, including its UK extension, with Standard Contractual Clauses and the UK Addendum as the fallback. |
| Inngest, Inc. (United States) | Runs our background jobs — reading supplier invoices, syncing point-of-sale data — and holds each job's inputs and results while it runs. | United States. | Under Inngest's data processing agreement. Inngest publishes no standard transfer terms; we agree them directly. |
| Anthropic, PBC (United States) | The AI models behind Pepper, the automatic reading of invoices and receipts, and the written reports — reached through the Vercel AI Gateway rather than directly. They are not permitted to train on your content. | United States. | Covered by Vercel's Standard Contractual Clauses and UK Addendum, as part of the AI Gateway. |
| Plus Five Five, Inc., trading as Resend (United States) | Sends the email the platform generates: reports, alerts and notifications, and the addresses they go to. | United States. | EU Standard Contractual Clauses, the UK Addendum, and the EU-US Data Privacy Framework. |
| Raintank Inc., trading as Grafana Labs (United States) | Stores our server logs, which record which account made which request, and when. | United Kingdom. | The European Commission's adequacy decision for the UK. EU Standard Contractual Clauses and the UK Addendum cover support access from the United States. |
| Hosts the mailbox that receives supplier invoices, where you have asked us to collect them by email. | European Union or United States, depending on the mailbox's region setting. | EU-US Data Privacy Framework, including its UK extension, and Standard Contractual Clauses. | |
| Your browser's push service (Google, Apple or Mozilla) | Delivers push notifications to a device someone has enrolled. The content of each notification is encrypted before it leaves us, so the push service cannot read it. | Operated by the browser vendor. | No readable personal data reaches the push service — only an encrypted payload and the device's own subscription address. |
Each of these providers engages its own sub-processors, named in its own agreement. We review this list whenever we change how the platform is built; ask us and we will tell you when it last changed.
7. International transfers
Your database is hosted in the European Union, in Frankfurt, and the servers that handle your requests run there too.
We are established in the United Kingdom, and some of the providers above process data outside the EEA. Where personal data leaves the EEA, the transfer is covered by an appropriate safeguard — the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK is involved), or an adequacy decision, as set out in the table. The European Commission has recognised the United Kingdom as providing adequate protection.
8. Helping you meet your own obligations
Requests from your staff: the platform lets you find, correct, export and delete a person's record yourself. If someone exercises a right and you need more than the platform gives you, ask us and we will help. If a request reaches us directly, we will not answer it — we will pass it to you, because it is your decision to make.
Personal data breaches: if there is a breach affecting your personal data, we will tell you without undue delay after we become aware of it, and in time for you to meet your own 72-hour obligation to your supervisory authority. We will tell you what we know, what we are doing about it, and what we recommend you do.
Impact assessments: if you carry out a data protection impact assessment or have to consult your supervisory authority about the platform, we will give you the information you reasonably need.
9. Deletion and return
When your agreement ends you choose: we delete your personal data, or we return a copy of it and then delete our own. Tell us which. If you have not told us within 30 days of the end, we will ask before doing anything.
You can export your records from within the platform for as long as you have access. Anything the built-in exports do not cover, we will put together for you on request.
We may keep data where UK or EU law requires it. Backups are deleted on their normal cycle rather than individually, and remain protected by this agreement until they are.
10. Showing that we comply
We will give you the information you reasonably need to show that we meet this agreement.
If that is not enough, you may audit us — or have an auditor you appoint do it — once in any 12-month period, on 30 days' notice, during business hours, at your cost, subject to confidentiality, and without disrupting the service. If a supervisory authority requires an audit sooner, we will accommodate it.
11. How this fits with the rest
This agreement forms part of our Terms of Service. Where it and the terms disagree about personal data, this agreement wins; on everything else, the terms apply.
We may update this agreement as the platform or the law changes. Where a change materially affects you we will tell you at least 30 days before it takes effect, in the same way as a change to the terms.
12. Contact
Anything about this agreement, a data subject request, an audit or a breach: hello@shiftplate.app, or ShiftPlate Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.