Privacy at RotaLoom

Privacy policy.

This policy explains what personal data RotaLoom handles, why it is used, who may receive it, and the choices and rights available to you.

Controller contact: rotaloom@geoffslab.com

1. Scope and privacy roles

This policy applies to the RotaLoom website, accounts, and workforce-management service. It does not govern a third party's own website or service, even where RotaLoom links to it.

RotaLoom is the controller for public enquiries, account administration, service security, billing administration, and communications it determines for itself.

For workforce data entered or managed by a subscribing organization, that organization normally decides why and how the data is used and is the controller. RotaLoom acts as its processor and follows its documented instructions. Employees should usually direct workplace-data requests to their employer first.

2. Personal data we handle

The data involved depends on how you use RotaLoom:

  • Public enquiries: name, work email, business name, workforce-size range, optional telephone number, message, source page, and anti-abuse request information.
  • Accounts and security: name, email, locale, time zone, password hash, verification and recovery state, passkey public credentials, authenticator configuration, sessions, device/browser information, notification preferences, and security events.
  • Organization and workforce records: organization structure, employee identity and contact details, employment terms, contract role, pay rates, schedules, availability, leave, sickness reports, public-holiday context, attendance, breaks, corrections, timesheets, overtime, payroll-preparation data, and audit history.
  • Location evidence: when an organization enables a workplace geofence, the browser may provide precise coordinates, reported accuracy, and related workplace-distance evidence when a person tests location or initiates clock-in or clock-out. RotaLoom does not continuously track location.
  • Billing: billing ownership, organization and active-employee counts, price snapshots, PayPal subscription identifiers and status, transaction evidence, and verified provider events. RotaLoom does not store payment-card details.
  • Technical information: IP address, timestamps, requested pages, user agent, error and security logs, essential cookie identifiers, and push-subscription endpoint and key information when browser notifications are enabled.

Some workforce records, including sickness information and certain statutory payroll fields, may be sensitive or special-category data. The subscribing organization is responsible for establishing the applicable employment-law and data-protection basis for that processing.

Where data comes from

Data may come directly from you, from your employer or another authorized organization user, from your browser or device when you use a feature, or from service providers such as PayPal when they report a transaction or subscription event.

3. Why we use data and our legal bases

  • Provide and administer the service: to create accounts, operate organization workspaces, deliver requested workforce functions, provide support, and administer subscriptions. The basis is normally performance of a contract or steps requested before entering one.
  • Protect RotaLoom and its users: to authenticate users, enforce permissions and tenant boundaries, prevent abuse, diagnose faults, preserve audit evidence, and defend legal claims. The basis is our legitimate interests in a secure and accountable service and, where applicable, legal obligations.
  • Respond to enquiries: to validate, deliver, and answer a message you submit. The basis is your requested pre-contractual step and our legitimate interest in responding to genuine business enquiries.
  • Billing and records: to calculate charges, connect to PayPal, reconcile subscriptions, retain payment evidence, and meet accounting or other legal duties. The basis is contract and applicable legal obligations.
  • Optional device features: to perform a requested workplace-location check or send browser notifications after the relevant browser permission and user action. Permission can be withdrawn in browser or operating-system settings, although previously created lawful records may still need to be retained.
  • Customer-directed workforce processing: when RotaLoom acts as processor, the customer determines the purposes and lawful bases, including any Article 9 condition needed for health or other special-category data.

RotaLoom does not sell personal data and does not use it for third-party behavioural advertising. It does not make solely automated decisions that produce legal or similarly significant effects. Automated validation, rate limiting, spam filtering, billing calculations, and permission checks support service operation but do not replace an employer's workforce decisions.

4. Who receives data

Personal data is disclosed only where needed for the purposes above, including to:

  • authorized users within the relevant subscribing organization, according to their server-enforced permissions;
  • hosting, database, cache, queue, backup, monitoring, and technical-support providers used to operate the service;
  • email-delivery infrastructure, including configured Microsoft 365 services, for account, workforce, and enquiry messages;
  • PayPal for subscription approval, payment administration, and verified billing events;
  • browser push services when a user chooses to enable Web Push;
  • OpenStreetMap tile infrastructure when an authorized employer opens the workplace map—employee clocking does not load that map; and
  • professional advisers, courts, regulators, law enforcement, or another party where disclosure is legally required or necessary to establish, exercise, or defend legal claims.

International transfers

Some providers may process data outside Malta or the European Economic Area. Where the GDPR requires a transfer safeguard, the relevant controller must use an adequacy decision, approved standard contractual clauses, or another lawful mechanism, together with supplementary safeguards where required. You may ask for information about the safeguard relevant to your data.

5. How long data is kept

RotaLoom keeps personal data only for as long as needed for the purpose for which it was collected, customer instructions, legal and accounting duties, security, dispute resolution, and backup recovery. The applicable period therefore depends on the record:

  • unverified registration links expire after 24 hours;
  • public enquiries are delivered to the configured mailbox and are not stored in the RotaLoom application database; mailbox retention is controlled operationally;
  • account and service records are generally retained while the account or customer relationship is active and then for the period needed to complete deletion, meet legal duties, resolve disputes, and cycle protected backups;
  • workforce, attendance, payroll, and audit evidence follows the subscribing organization's instructions and applicable employment, tax, accounting, and limitation requirements; and
  • security and technical logs are retained for a proportionate operational period based on risk and investigation needs.

Authorized deletion removes or de-identifies data unless retention is required or permitted by law. Some evidence is intentionally append-only to prevent silent alteration; access and retention remain restricted. Backup copies may persist until the relevant protected backup cycle expires.

6. Cookies, local storage, and device permissions

RotaLoom uses essential cookies and similar browser storage for sessions, sign-in, cross-site request forgery protection, security, navigation continuity, accessibility and interface preferences, and one-time notices. These are necessary to provide the requested website or service. The current RotaLoom application does not set advertising or third-party analytics cookies.

Optional geolocation and browser notifications depend on an explicit user action and browser or operating-system permission. You can change those permissions in your device or browser settings. Disabling essential storage may prevent sign-in, forms, and protected workflows from operating correctly.

7. Your data-protection rights

Subject to the GDPR's conditions and exceptions, you may have rights to be informed; obtain access; correct inaccurate data; request erasure or restriction; receive portable data; object to processing based on legitimate interests; withdraw consent where consent is the basis; and receive human review of a qualifying solely automated decision.

Exercising a right is normally free. We or the relevant employer may need enough information to verify identity and protect other people's data. A request may be limited or refused where the law permits, in which case the responsible controller will explain why and describe available complaint options.

For organization-controlled workforce data, contact the organization or employer first. For data controlled by RotaLoom, email rotaloom@geoffslab.com.

8. Security

RotaLoom uses measures designed to protect personal data, including named accounts, email verification, password hashing, optional passkeys and authenticator-based two-factor security, server-side authorization and tenant scoping, encrypted sensitive statutory fields, audit records, and verified PayPal webhooks. No internet service can guarantee absolute security, so users should protect credentials, recovery codes, and registered devices and report suspected misuse promptly.

9. Contact, complaints, and policy changes

Questions and requests concerning data controlled by RotaLoom can be sent to rotaloom@geoffslab.com. Questions about employer-controlled workforce data should normally be sent to that employer.

This policy may change when the service, providers, or legal requirements change. Material updates will be identified by a revised effective date and communicated through an appropriate channel where required.