← ÉascaDesk

GDPR & Data Processing Policy

Last updated: 21 May 2026  ·  Fleet Rewind Ltd

Contents

  1. Introduction
  2. Controller & Processor Roles
  3. Data Processing Agreement (DPA)
  4. Categories of Personal Data Processed
  5. Purposes & Legal Bases
  6. Sub-processors
  7. Data Transfers Outside the EEA
  8. Security Measures (Art. 32 GDPR)
  9. Data Breach Notification
  10. Data Subject Rights & How We Support Them
  11. Records of Processing Activities (ROPA)
  12. Spanish Working Time Records — Special Obligations
  13. Data Retention & Deletion
  14. Contact & Complaints

1. Introduction

Fleet Rewind Ltd ("we", "us", "our"), trading as ÉascaDesk, is committed to compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) as it applies in Ireland and across the European Economic Area, and with the Irish Data Protection Act 2018.

This document sets out our GDPR obligations and practices as both a data controller (for our own business data and manager account data) and a data processor (for employee data entered into ÉascaDesk Scheduler by business customers).

It is intended for:

2. Controller & Processor Roles

Fleet Rewind Ltd as Controller

Fleet Rewind Ltd is the data controller for:

Fleet Rewind Ltd as Processor

When a business customer (manager) uses ÉascaDesk Scheduler to store and manage their employees' data — including names, phone numbers, availability, clock-in/out records, and NIF — that business customer is the data controller and Fleet Rewind Ltd acts as the data processor.

As processor, we only process employee data:

Business customers: By using ÉascaDesk Scheduler's Pro plan to store employee data, you are acting as data controller for that employee data. You are responsible for ensuring you have a valid legal basis to collect and process your employees' data, for informing your employees that their data is held in ÉascaDesk, and for honouring their rights. Our Terms & Conditions incorporate the data processing agreement described in Section 3.

3. Data Processing Agreement (DPA)

GDPR Article 28 requires that processing by a processor be governed by a binding contract. Our Data Processing Agreement is incorporated into and forms part of our Terms & Conditions. By accepting the Terms & Conditions and using ÉascaDesk Scheduler Pro, business customers enter into this DPA.

The DPA includes, at minimum:

If you require a standalone signed DPA for your own compliance records, please contact [email protected].

4. Categories of Personal Data Processed

CategoryData subjectsExamples
Identity dataManagers, employeesName, email address, NIF (optional, employees only)
Contact dataManagers, employeesEmail address, WhatsApp phone number (E.164)
Authentication dataManagersPassword hash, JWT tokens, last login timestamp
Employment & scheduling dataEmployeesSkills, availability preferences, shift assignments
Working time recordsEmployeesClock-in/out timestamps, break durations, source (WhatsApp / manual / auto), estimated flag
Audit & correction dataEmployees, managersAudit log entries, edit requests, correction reasons, manager identity on edit/delete
Financial dataManagersStripe customer ID, subscription status (no card data stored by us)
Technical dataAll usersIP address, user agent, request logs (max 90 days)
Conversation stateEmployeesWhatsApp session state (30-min TTL)

We do not process special category data (Art. 9 GDPR) unless inadvertently included in free-text fields by the manager or employee. If you become aware of special category data in the system, please contact us immediately.

5. Purposes & Legal Bases

PurposeLegal basis (GDPR Art. 6)
Manager account & authenticationArt. 6(1)(b) — performance of contract
Providing scheduling featuresArt. 6(1)(b) — performance of contract
Processing payments via StripeArt. 6(1)(b) — performance of contract
Employee scheduling (Pro)Art. 6(1)(f) — legitimate interests of the controller (efficient workforce management); employees informed by their employer
WhatsApp clock-in/out botArt. 6(1)(c) — legal obligation of the employer (Real Decreto-ley 8/2019, where applicable); Art. 6(1)(f) — legitimate interests otherwise
Compliance CSV export & audit logArt. 6(1)(c) — legal obligation (as processor acting on controller's behalf)
Security & fraud preventionArt. 6(1)(f) — legitimate interests
Responding to support queriesArt. 6(1)(f) — legitimate interests

6. Sub-processors

As data processor, we use the following sub-processors. We ensure each is bound by a data processing agreement providing at least equivalent protections to this policy (Art. 28(4) GDPR).

Sub-processorRoleLocationSafeguard
Stripe Inc.Payment processingUSASCCs + Stripe DPA
Meta Platforms Ireland LtdWhatsApp Business Cloud APIEU / USAMeta DPA + SCCs
Cloud infrastructure providerPostgreSQL hosting, computeEUDPA with provider

We will notify business customers of any intended changes to sub-processors (additions or replacements) with reasonable advance notice, giving them the opportunity to object. Objection details are in our Terms & Conditions.

7. Data Transfers Outside the EEA

Where personal data is transferred outside the EEA — including to Stripe (USA) and Meta (USA data centres) — we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission under Art. 46(2)(c) GDPR.

We conduct transfer impact assessments (TIAs) where required and apply supplementary technical measures (such as encryption in transit and at rest) where appropriate.

8. Security Measures (Art. 32 GDPR)

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

Technical measures

Organisational measures

9. Data Breach Notification

In the event of a personal data breach, Fleet Rewind Ltd will:

Business customers who become aware of a suspected breach involving ÉascaDesk data must notify us immediately at [email protected].

10. Data Subject Rights & How We Support Them

Fleet Rewind Ltd is obliged under Art. 28(3)(e) to assist business customers (controllers) in fulfilling their data subject rights obligations. The table below sets out the rights and how requests should be routed.

RightRoute for employeesOur role as processor
Access (Art. 15)Contact your employer firstProvide data export to the controller on request
Rectification (Art. 16)Contact your employerUpdate records on controller's instruction
Erasure (Art. 17)Contact your employerDelete records subject to legal retention (clock events: 4-year minimum)
Restriction (Art. 18)Contact your employerFlag records as restricted on controller's instruction
Portability (Art. 20)Contact your employerExport data in CSV format (available via compliance export)
Object (Art. 21)Contact your employerCease processing on controller's instruction where lawful
Employees may also contact us directly at [email protected] if their employer is unresponsive or if the request relates to data controlled directly by Fleet Rewind Ltd.

11. Records of Processing Activities (ROPA)

Fleet Rewind Ltd maintains internal Records of Processing Activities as required by Art. 30 GDPR, covering both our controller activities and processor activities on behalf of business customers. These records are available to the Data Protection Commission on request.

Business customers are themselves required to maintain their own ROPA for their employee data processing activities, including their use of ÉascaDesk Scheduler. The data categories, purposes, and legal bases set out in this document should assist customers in completing their own records.

12. Spanish Working Time Records — Special Obligations

Real Decreto-ley 8/2019 requires Spanish employers to maintain a daily record of each employee's working hours, retain records for four years, and make them available to labour inspectors, employees, and employee representatives.

How ÉascaDesk Scheduler supports compliance

Regulatory requirementÉascaDesk implementation
Daily clock-in and clock-out recordWhatsApp bot records timestamps at the moment of message receipt; manual entry also available
Records retained for 4 yearsClock events are soft-deleted only; the physical record is never removed from the database
Traceability of correctionsImmutable audit log records every create, edit, and delete; edit requests record the proposing manager and the employee's WhatsApp approval or rejection
Traceability of deletionsSoft-delete captures deleted_at, deleted_by_user_id, and delete_reason
Export for inspectionCompliance CSV export (audit=true) includes all above fields plus original timestamps, for direct presentation to inspectors
Employee NIFOptional field on employee record; included in compliance CSV where present
Auto-generated records flaggedAuto-close clock-outs are marked is_estimated=true and source=auto; managers are prompted to review
Important: ÉascaDesk Scheduler is a tool that supports Spanish working-time compliance. The employer (manager account holder) remains legally responsible for ensuring their working-time recording practices meet the requirements of Real Decreto-ley 8/2019. We recommend obtaining independent legal advice on your specific obligations.

AEPD (Spanish Data Protection Authority)

Processing of employee working-time records by Spanish employers is supervised by the Agencia Española de Protección de Datos (AEPD). Employees with complaints relating to Spanish-law processing may contact the AEPD at www.aepd.es.

13. Data Retention & Deletion

Data typeRetentionDeletion mechanism
Manager accountActive account + 12 months post-deletion requestAccount deletion request to support
Schedule run JSONActive account durationDeleted by manager or on account deletion
Uploaded Excel filesImmediately after solve completesAutomatic
Employee recordsActive account durationManager-deletable at any time (subject to clock event retention)
Clock events (incl. soft-deleted)Minimum 4 years (Spanish law); otherwise active account durationSoft-delete only; physical deletion after retention period
Clock event audit logMinimum 4 years; immutableNot deletable during retention period
WhatsApp session state30-minute TTLAutomatic expiry
Server access logsUp to 90 daysAutomatic rolling deletion

On account closure, we will delete or anonymise all personal data within 30 days, except where retention is required by law (e.g. clock event records for Spanish-law accounts).

14. Contact & Complaints

Fleet Rewind Ltd does not currently have a designated Data Protection Officer (DPO) as we do not meet the thresholds requiring mandatory DPO appointment under Art. 37 GDPR. All data protection queries are handled by the company's management.

Contact for data protection matters:

Supervisory authorities:

You have the right to lodge a complaint with your local supervisory authority at any time, without prejudice to any other administrative or judicial remedy.