Privacy Policy

← Back to policies

This policy details how Shift Craft | ATLAS processes personal data within regulated and safety-critical environments.

Data Controller

Shift Craft | ATLAS acts as the Data Controller defined under the GDPR for account management purposes and as the Data Processor for operational roster data.

Data We Process

  • Identity data (names and staff IDs)
  • Contact data (email addresses and phone numbers)
  • Operational data (shift patterns, roles and location assignments)
  • Audit data (login history and modification logs)

Use of Data

We use this data solely to provide roster compliance validation, fatigue management and operational scheduling services. We do not share operational data with third parties for marketing purposes.

Data Retention

Operational data is retained for the duration of the organisation's active subscription. Audit logs are tamper-evident (each entry is cryptographically chained to the one before it) and are retained for the duration of the contract plus any applicable statutory period. We do not currently offer self-service configuration of retention periods; where an organisation needs a different retention arrangement, this can be agreed directly with us.

Third Parties and Sub-processors

We use a small number of third parties to help provide the service, each processing only what is necessary for their function:

  • Supabase: hosts our database and provides authentication infrastructure.
  • Stripe: processes subscription billing and payment data for licensed accounts.
  • Have I Been Pwned (HIBP): used to check new passwords against known data breaches. Only a partial, irreversible hash prefix of the password is ever sent; the password itself never leaves our servers.

A current list of sub-processors, including any changes, is available on request. See also our Data Processing Agreement.

Your Rights

You have the right to request access to your personal data, correction of inaccurate data and deletion of data where no legal override exists.

For data protection enquiries, please refer to your organisation's internal data protection officer in the first instance.