Privacy Notice
Last updated: 19 September 2026
1. Who we are
SHIFT MATRIX is operated by Round Da Clock Doc, based in Ireland. For account, billing and service data we act as the data controller. For the staff scheduling data an organisation enters into the Service, we act as a data processor on that organisation's instructions.
2. Personal data we collect
- Account data — name, work email address, phone number, organisation and role.
- Login credentials — authentication identifiers and password hashes handled by our authentication provider; we never see your password.
- Scheduling data — shifts, assignments, availability, leave requests and swap requests.
- Billing data — organisation legal name, address, VAT number and billing email. Card details are never received or stored by us.
- Support messages — the content of emails or requests you send us.
- Usage and technical data — log entries, audit records of actions in the app, device information and IP address.
3. Why we use it, and our legal basis
- Providing the Service (account creation, rota scheduling, notifications) — performance of a contract.
- Billing and invoicing — performance of a contract and legal obligation.
- Security, audit logging and fraud prevention — legitimate interests in keeping the Service and tenant data safe.
- Support and service communications — performance of a contract and legitimate interests.
- Product improvement — legitimate interests, using aggregated or minimal data.
- Marketing emails, where sent — consent, which you can withdraw at any time.
4. Who we share data with
- Service providers — hosting, database, and email delivery providers acting as our processors.
- Merchant of Record — Paddle.com, for the sale of the product, subscription management, payments, tax compliance and invoicing.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where required by law.
We do not sell personal data.
5. International transfers
Data is primarily hosted within the EEA. Where a provider processes data outside the EEA or UK, we rely on adequacy decisions or Standard Contractual Clauses together with appropriate technical safeguards.
6. Retention
Account and scheduling data is retained for as long as the organisation's subscription is active, and for up to 30 days after termination to allow export, after which it is deleted or anonymised. Billing records are kept for as long as tax and accounting law requires (typically six years). Security and audit logs are kept for up to 24 months.
7. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. We respond within one month. You also have the right to complain to a supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie). If your data was entered by your employer, please contact your organisation's administrator first, and we will support them in responding.
8. Security
We apply appropriate technical and organisational measures, including encryption in transit, database-level access rules that isolate each organisation's data, role-based permissions, audit logging, and restricted administrative access.
9. Cookies
We use only essential cookies and local storage needed to keep you signed in, remember your display preference, and secure the Service. We do not use advertising cookies. You can clear or block cookies in your browser, but sign-in will not work without the essential ones.
10. Contact
For any privacy question or request, contact Round Da Clock Doc at privacy@shiftmatrix.ie.