Data processing agreement
Version 2026-09-26
This is an earlier version of this document. See the current version.
This is an English translation. In case of any discrepancy, the Dutch version (Verwerkersovereenkomst) prevails.
1. Parties and scope
This data processing agreement (version 2026-09-26) is entered into between:
- the organisation that uses PowerShift (the “customer”), as controller; and
- [TODO: naam eigenaar/eenmanszaak zoals in het KVK-register] (sole proprietorship (eenmanszaak)), trading as PowerShift, KvK number [TODO: KvK-nummer], address: [TODO: zakelijk adres of postadres (straat, postcode, plaats)] (“PowerShift”), as processor.
The organisation’s owner accepts this agreement and the terms of service on the customer’s behalf during onboarding, confirming they are authorised to represent the customer; we record when and which version. PowerShift is represented by its owner, [TODO: naam eigenaar/eenmanszaak zoals in het KVK-register]. This agreement forms part of the Terms of service. In case of conflict, this data processing agreement prevails in matters of personal data protection. Terms have the meaning given in the General Data Protection Regulation (GDPR).
2. Subject matter, duration, nature and purpose
- Subject matter: providing the PowerShift scheduling application to the customer.
- Nature: storing, organising, consulting, displaying, transmitting (notifications) and deleting data within the application, and computing planning signals.
- Purpose: staff scheduling by the customer: inviting staff, collecting availability, building and publishing rosters, trading and claiming shifts, and giving the customer signals based on the Dutch Horeca CAO and the Working Hours Act.
- Duration: for as long as PowerShift processes personal data for the customer, i.e. during the agreement and its wind-down afterwards (see clause 11).
PowerShift does not process the personal data for its own purposes, except for the following, for which PowerShift is itself the controller (see the Privacy policy):
- account data, security logs and billing;
- counting the number of members scheduled per billing period, to calculate the fee;
- per membership, the time the app was last used (updated at most once an hour) and the usage statistics per organisation derived from it, to run and improve the service.
PowerShift does not use this data for any other purpose and does not share it with third parties.
3. Data subjects and categories of personal data
Data subjects: employees and other users that the customer invites or records in PowerShift (including schedulers and administrators), including young workers aged 13 and over.
Personal data:
- name and email address as visible within the organisation;
- date of birth and the age band derived from it;
- membership and contract: role, contract type, contracted hours, start and end date, locations, teams and qualifications;
- scheduling: availability, preferred shifts, assigned and open shifts, trade, claim and hand-over requests with free-text explanations, and event notes;
- the content of notifications about this data (email and, if the user enables them, push notifications).
Special categories of personal data (such as health data) are not needed for the service. The customer ensures they are not recorded in free-text fields.
4. Instructions
PowerShift processes the personal data only on documented instructions from the customer. The agreement, this data processing agreement and the customer’s settings and actions in the application constitute those instructions. PowerShift only processes otherwise where required by law, and informs the customer beforehand unless the law prohibits this. If, in PowerShift’s opinion, an instruction infringes the GDPR or other data protection rules, PowerShift informs the customer immediately. PowerShift may then suspend carrying out that instruction until the customer confirms or changes it, and does not carry out an instruction that is clearly unlawful.
5. Confidentiality
PowerShift ensures that everyone under its authority with access to the personal data is bound by confidentiality, and that access is limited to what is needed to provide, secure and support the service.
6. Security (GDPR Art. 32)
PowerShift takes appropriate technical and organisational measures, including:
- encrypted connections (TLS) between browser and service;
- passwords stored only as argon2 hashes;
- session cookies that are httpOnly, Secure and SameSite=Strict, with short-lived access tokens and rotating refresh tokens with reuse detection;
- protection against cross-site request forgery (CSRF);
- separation of data per organisation in the application and in the database (row-level security), and role-based access within an organisation;
- optional two-step verification for users; mandatory two-step verification for PowerShift administrators;
- encrypted storage of sensitive identifiers, such as calendar links and payment IDs;
- rate limiting against abuse;
- hosting, database and backups at Scaleway SAS in data centres in the EU (region fr-par (Paris, France)).
PowerShift may adjust these measures, provided the level of security is not reduced.
7. Sub-processors
The customer gives PowerShift general authorisation to engage sub-processors. They currently are:
| Sub-processor | Service | Location |
|---|---|---|
| Scaleway SAS | Hosting, database and backups | EU — fr-par (Paris, France) |
| Scaleway SAS (Transactional Email) | Transactional email | EU — fr-par (Paris, France) |
| The push service of the user’s browser (e.g. Google, Microsoft, Mozilla, Apple) | Delivering push notifications, only if a user enables them | Possibly outside the EEA |
| Mollie B.V. | Payments (customer billing only, once paid plans start) | the Netherlands |
PowerShift imposes the same data protection obligations on each sub-processor as in this agreement and remains responsible to the customer for their fulfilment. Before PowerShift adds or replaces a sub-processor, it informs the customer by email at least 30 days in advance. The customer may object on reasonable grounds within that period; if the parties cannot resolve the objection, the customer may terminate the agreement free of charge before the change takes effect.
8. Transfers outside the EEA
PowerShift processes and stores the personal data within the EU and does not transfer it outside the EU/EEA. The exception is push notifications, which a user enables themselves: browser makers’ push services may process outside the EEA, on the basis of the safeguards in Chapter V GDPR (such as the EU-US Data Privacy Framework or standard contractual clauses). The content of push notifications is end-to-end encrypted under the Web Push standard.
9. Assistance to the customer
Taking into account the nature of the processing, PowerShift assists the customer:
- in handling requests from data subjects (access, rectification, erasure, restriction, portability, objection). PowerShift forwards requests it receives directly about the customer’s data without undue delay. Where the customer cannot handle a request itself in the application, PowerShift carries it out manually on request, so the customer can respond within the statutory one-month period;
- in meeting the obligations under Articles 32 to 36 GDPR, including security, data breach notification, a data protection impact assessment (DPIA) and any prior consultation of the Dutch Data Protection Authority, by providing the information reasonably needed for this.
PowerShift provides this assistance free of charge as far as it is reasonable and fits normal use of the service. For assistance beyond that, PowerShift may charge a reasonable fee at an hourly rate it announces in advance. Assistance needed because of a failure by PowerShift is always free of charge.
10. Personal data breaches
PowerShift informs the customer without undue delay after it has become reasonably certain that a personal data breach affects the customer’s data: where possible within 24 hours, and at the latest within 48 hours. This also applies to a breach at a sub-processor. The notification contains, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact person. Information that becomes available later follows as soon as possible. The customer decides on notifying the Dutch Data Protection Authority and data subjects; PowerShift assists. PowerShift keeps an internal register of all breaches.
11. End of processing: return and deletion
During the agreement, the company’s owner can download a full export of the customer’s data in the application at any time, in a common, machine-readable format (CSV files in a ZIP file). After the agreement ends, this export stays available for 30 days (the retrieval period). The workspace is then closed: only the owner can still download the export and the invoices. If the customer cannot do so, PowerShift provides the export on request within the retrieval period. Before the retrieval period ends, the customer exports the data it must keep itself as employer, such as roster and working-time records (52 weeks under the Working Hours Act): PowerShift does not keep them for the customer after deletion. After the retrieval period, PowerShift deletes the customer’s personal data automatically, at the latest within 30 days, unless a legal obligation to retain applies. Backups rotate and are overwritten within 30 days. PowerShift confirms the deletion to the owner by email.
12. Information and audits
PowerShift makes available to the customer all information necessary to demonstrate compliance with Article 28 GDPR. The customer may have an audit carried out by an independent expert bound by confidentiality, at most once a year (and additionally after a data breach), with at least 30 days’ notice, without unnecessarily disrupting operations. The customer bears the cost of an audit, unless it reveals a material failure by PowerShift.
13. Liability
The liability of the parties under this data processing agreement is governed by the Terms of service, without prejudice to data subjects’ rights under Article 82 GDPR.
14. Term, changes and governing law
This agreement runs for as long as PowerShift processes personal data for the customer. PowerShift may change this agreement, for example for a new sub-processor (clause 7) or a change in the law. It announces material changes to the owner by email at least 30 days in advance. The customer may object on reasonable grounds within that period; if the parties cannot resolve the objection, the customer may terminate the agreement free of charge before the change takes effect. This agreement is governed by Dutch law; disputes will be submitted to the competent court: [TODO: rechtbank van het arrondissement van vestiging, bijv. Rechtbank Midden-Nederland].
Permanent link to this version: /en/dpa/2026-09-26. You can save or print this page (for example as a PDF) to keep the text.
All versions:
- Version 2026-09-29 (version in force)
- Version 2026-09-26