Draft for launch readiness — have counsel review before relying on this text in production.
EmerRoster ("we", "us") provides workforce rostering software. For personal data processed to operate the service for a customer organization, that organization is typically the controller and EmerRoster acts as a processor under GDPR. See our Data Processing Agreement.
Depending on how the product is used, we may process:
We process data to provide the rostering service, authenticate users, secure the platform, comply with law, and respond to data-subject requests. Where we are controller (e.g. account administration for the platform), bases may include contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), and legal obligation (Art. 6(1)(c)). Where we are processor, processing follows the customer's instructions as described in the DPA.
We use Google Firebase (Authentication, Cloud Firestore, Cloud Functions, App Hosting) to host and run the service. Processing regions are configured for EU where available (e.g. Firestore/Functions in europe-west1). Review Google's terms and DPA for subprocessors.
Active organization data is retained while the organization uses the service. When an organization is cancelled, we retain its data for 90 days and then permanently delete it, unless the owner places a retention hold (for example after a lawful request to preserve data). Soft-deleted member records may remain visible in historical roster assignments until organization purge.
Subject to GDPR, you may request access, rectification, erasure, restriction, portability, and objection. In the product you can use Export my data (My area) for a machine-readable export of your personal data. Organization owners can cancel (delete) their organization from Settings. Contact privacy@emerroster.app for other requests. You may lodge a complaint with your supervisory authority.
Access is protected with Firebase Authentication. Firestore security rules isolate organization data to members of that organization. Administrative actions are recorded in audit logs.
Privacy inquiries: privacy@emerroster.app. Replace this address with your production contact before launch.