Data processing
Data processing agreement
Last updated 21 July 2026
This agreement covers the staff personal data we process on your behalf. It is incorporated into the terms of service and applies automatically to every account - there is nothing to sign. It is written to meet Article 28 of the UK GDPR. You are the controller; Wavro Technologies Ltd is the processor.
1. Scope of the processing
- Subject matter - providing the Wavro rota, clock-in and timesheet service.
- Duration - for as long as your account is open, plus the retention window in the privacy notice.
- Nature and purpose - storing, organising, displaying, calculating on and deleting staff data so you can plan shifts, record attendance and approve hours.
- Types of personal data - name, contact details, date of birth, start date, pay rate or salary, contract type, shifts, availability and absence, clock-in and clock-out times and breaks, timesheets, holiday balances, and clock-in location where you have enabled the geofence.
- Categories of data subject - your employees, workers and contractors, and the managers who use the account.
Wavro is not designed to hold special category data. Please do not put health records, biometric identifiers or similar into free-text fields.
2. Our obligations
- We process staff data only on your documented instructions. Using the product is an instruction; anything else comes to us in writing. If the law forces us to process it otherwise, we will tell you unless we are barred from doing so.
- Everyone with access is bound by confidentiality.
- We apply appropriate technical and organisational measures - encryption in transit and at rest, hashed passwords, per-company query scoping, and least-privilege access to production.
- We assist you, as far as we reasonably can, with data subject requests, impact assessments and consultations with the ICO.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.
- On termination we delete your data after the retention window, or return it earlier if you ask, unless the law requires us to keep it.
3. Your obligations
- You confirm you have a lawful basis for the staff data you put into Wavro and that you have told your staff how it is used.
- You keep the data accurate and decide when a leaver record is purged.
- If you enable clock-in location checks, you are responsible for telling staff and for judging whether it is proportionate for your business.
- You manage who has manager access in your account.
4. Sub-processors
You give us general authorisation to use the sub-processors listed below. Each is bound by data protection terms no weaker than these, and we stay liable to you for what they do.
| Supplier | What they do | Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting, CDN, file storage (profile photos), and privacy-friendly analytics | All application data in transit; profile photos at rest; request metadata | United States and European Union |
| Neon Inc. | Managed PostgreSQL database - the primary store for accounts, staff records, rotas, clock events and timesheets | All application data at rest | United States (us-east-1) |
| Stripe Payments Europe, Ltd. | Subscription billing and payment processing | Billing contact, company name, subscription and seat counts. Card details go straight to Stripe - they never reach our servers | European Union and United States |
| Resend (Plus Five Five, Inc.) | Transactional email - invites, password resets, welcome and release notices | Recipient name and email address, message content | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Technical error reports, which may include the acting user id and the page in use | United States |
| Google LLC | Optional "Sign in with Google" authentication | Name and email address of users who choose that sign-in method | United States |
| Apple, Google and Mozilla push services | Delivery of push notifications to a device that opted in | The device push endpoint and the notification content | United States and European Union |
We will update this list at least 30 days before adding or replacing one. If you reasonably object on data protection grounds, email hello@wavroapp.com within those 30 days and we will look for an alternative; if there isn’t one, you may cancel without penalty for the unused part of your term.
5. International transfers
Where a sub-processor is outside the UK or EEA, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by another lawful mechanism. The location of each one is in the table above.
6. Audit
On reasonable written notice, and no more than once a year unless a breach or the ICO says otherwise, we will provide the information you need to show compliance with this agreement. Given the size of the service, we would normally answer with documentation and a written security questionnaire rather than an on-site inspection.
7. Contact
Data protection questions and requests under this agreement go to hello@wavroapp.com.