Data Processing Agreement
Last updated: 11 July 2026
This Data Processing Agreement (DPA) forms part of the Terms of Service between your organization (the “Controller”) and the Saudi-registered establishment holding Commercial Registration 7053617655, operating Rosterna (the “Processor”). It reflects the requirements of the Saudi Personal Data Protection Law (PDPL) and applies whenever Rosterna processes personal data of your staff on your behalf.
1. Roles
For staff data you enter into Rosterna (names, contact details, shifts, leave, preferences), your organization is the controller and Rosterna is the processor. For your account and billing data, Rosterna is the controller as described in our Privacy Policy.
2. Scope of processing
- Subject matter: workforce scheduling and related notifications.
- Duration: the term of your subscription, plus the deletion window below.
- Data subjects: your employees and team members.
- Data categories: names, work contact details, roles, shift and leave records, and schedule preferences. Rosterna does not request sensitive data categories.
3. Processor obligations
- Process personal data only to provide the service and on your documented instructions.
- Ensure staff with access are bound by confidentiality.
- Protect data with encryption in transit and at rest, strict per-organization isolation enforced at the database layer, role-based access controls, and audit logging.
- Notify you without undue delay — and no later than 72 hours after becoming aware — of any personal data breach affecting your data.
- Assist you, to a reasonable extent, in responding to data-subject requests (access, correction, deletion).
4. Sub-processors
You authorize the following sub-processors, each bound by contract to protections no weaker than this DPA: Oracle Cloud Infrastructure (cloud hosting — Riyadh, Saudi Arabia), Moyasar (payment processing), and Resend (transactional email). We will announce material changes to this list in advance, and you may object on reasonable grounds.
5. Data residency & transfers
Customer data is hosted and processed on cloud infrastructure inside the Kingdom of Saudi Arabia (Riyadh). We do not transfer your staff personal data outside the Kingdom except where permitted by the PDPL and necessary to deliver the service (for example, transactional email delivery).
6. Deletion & return
You can export your data at any time, and an organization owner can delete the account (and all its data) self-serve from Settings. On termination of the subscription, we delete your organization’s personal data within 30 days, unless a longer retention period is required by law.
7. Audit & information
We make information reasonably necessary to demonstrate compliance with this DPA available through our Trust Center and on request at hello@rosterna.com.
8. Governing law
This DPA is governed by the laws of the Kingdom of Saudi Arabia, including the PDPL and its implementing regulations.