GDPR Compliance
Last updated: May 04, 2023
ProRota & the General Data Protection Regulation (GDPR)
How we comply with UK GDPR
What is the GDPR?
The General Data Protection Regulation (GDPR) is a data protection framework designed to strengthen the rights of individuals and unify data protection standards across Europe and the United Kingdom.
The regulation was adopted by the European Parliament in 2016 and came into effect on 25 May 2018. In the UK, GDPR continues to apply under the UK GDPR and the Data Protection Act 2018.
GDPR gives individuals greater control over their personal data and places clear obligations on organisations that collect, process, or store personal data. Organisations that fail to comply may face significant regulatory penalties.
Any organisation that processes personal data relating to UK or EU residents is required to comply with GDPR, regardless of where the organisation itself is located.
How GDPR applies to ProRota customers
ProRota is a cloud-based workforce management platform used by organisations to manage employees, shifts, attendance, and operational records.
In this context:
- ProRota (operated by Nexverse Ltd) acts as a Data Processor
- Our customers act as Data Controllers
- Employees and workers whose data is entered into ProRota are Data Subjects
As a result, both ProRota and our customers have responsibilities under GDPR.
Your responsibilities as a Data Controller
As a ProRota customer, you are responsible for ensuring that your organisation uses the platform in a GDPR-compliant manner.
While only a qualified legal professional can provide tailored legal advice, organisations typically need to:
- Maintain an inventory of personal data they control
- Ensure staff understand data protection obligations
- Assess whether a Data Protection Impact Assessment (DPIA) is required
- Understand and respond to data subject rights requests
- Ensure that all data processors they use (including ProRota) comply with GDPR
We support our customers in meeting these obligations by operating ProRota in a secure, transparent, and GDPR-aligned manner.
What we’ve done to be GDPR compliant
We take data protection and security seriously and have implemented both technical and organisational measures to protect personal data processed through ProRota.
Infrastructure & hosting
- ProRota is hosted on UK-based secure infrastructure
- Access to systems is restricted and monitored
- Secure firewall and network controls are in place
- HTTPS is enforced across the platform
Security measures
- Encrypted connections (SSL/TLS)
- Role-based access control
- Two-factor authentication (2FA)
- Secure backups and monitoring
- Controlled access to production systems
Organisational measures
We maintain internal policies and procedures, including:
- A data inventory covering personal data processed by the platform
- Documentation of data flows and sub-processors
- Access control and least-privilege principles
- A documented data breach response procedure
- Staff awareness of data protection responsibilities
Policies and transparency
We have reviewed and published key documents to ensure transparency and GDPR alignment, including:
- Privacy Policy
- Terms & Conditions
- Data Processing Agreement (DPA) (available on request)
These documents clearly define:
- Data protection roles
- Lawful bases for processing
- Security measures
- Data subject rights
- Processor obligations
Data Processing Agreement (DPA)
Where required, Nexverse Ltd enters into a UK GDPR-compliant Data Processing Agreement with business customers.
The DPA governs:
- How personal data is processed
- Security measures
- Sub-processors
- Breach notification procedures
- Data deletion or return upon termination
The DPA is available on request and provided during onboarding or due diligence.
Data subject rights
Individuals whose data is processed through ProRota have rights under GDPR, including the right to:
- Access their personal data
- Request correction or deletion
- Restrict or object to processing
- Request data portability
ProRota supports customers in fulfilling these obligations in accordance with GDPR.
Questions about GDPR and data protection
We welcome questions from current and prospective customers regarding data protection, GDPR compliance, or security practices.
Email: contact@prorota.app
Website: https://prorota.app