Contents
Fleet Rewind Ltd ("we", "us", "our"), trading as ÉascaDesk, is committed to compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) as it applies in Ireland and across the European Economic Area, and with the Irish Data Protection Act 2018.
This document sets out our GDPR obligations and practices as both a data controller (for our own business data and manager account data) and a data processor (for employee data entered into ÉascaDesk Scheduler by business customers).
It is intended for:
Fleet Rewind Ltd is the data controller for:
When a business customer (manager) uses ÉascaDesk Scheduler to store and manage their employees' data — including names, phone numbers, availability, clock-in/out records, and NIF — that business customer is the data controller and Fleet Rewind Ltd acts as the data processor.
As processor, we only process employee data:
GDPR Article 28 requires that processing by a processor be governed by a binding contract. Our Data Processing Agreement is incorporated into and forms part of our Terms & Conditions. By accepting the Terms & Conditions and using ÉascaDesk Scheduler Pro, business customers enter into this DPA.
The DPA includes, at minimum:
If you require a standalone signed DPA for your own compliance records, please contact [email protected].
| Category | Data subjects | Examples |
|---|---|---|
| Identity data | Managers, employees | Name, email address, NIF (optional, employees only) |
| Contact data | Managers, employees | Email address, WhatsApp phone number (E.164) |
| Authentication data | Managers | Password hash, JWT tokens, last login timestamp |
| Employment & scheduling data | Employees | Skills, availability preferences, shift assignments |
| Working time records | Employees | Clock-in/out timestamps, break durations, source (WhatsApp / manual / auto), estimated flag |
| Audit & correction data | Employees, managers | Audit log entries, edit requests, correction reasons, manager identity on edit/delete |
| Financial data | Managers | Stripe customer ID, subscription status (no card data stored by us) |
| Technical data | All users | IP address, user agent, request logs (max 90 days) |
| Conversation state | Employees | WhatsApp session state (30-min TTL) |
We do not process special category data (Art. 9 GDPR) unless inadvertently included in free-text fields by the manager or employee. If you become aware of special category data in the system, please contact us immediately.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Manager account & authentication | Art. 6(1)(b) — performance of contract |
| Providing scheduling features | Art. 6(1)(b) — performance of contract |
| Processing payments via Stripe | Art. 6(1)(b) — performance of contract |
| Employee scheduling (Pro) | Art. 6(1)(f) — legitimate interests of the controller (efficient workforce management); employees informed by their employer |
| WhatsApp clock-in/out bot | Art. 6(1)(c) — legal obligation of the employer (Real Decreto-ley 8/2019, where applicable); Art. 6(1)(f) — legitimate interests otherwise |
| Compliance CSV export & audit log | Art. 6(1)(c) — legal obligation (as processor acting on controller's behalf) |
| Security & fraud prevention | Art. 6(1)(f) — legitimate interests |
| Responding to support queries | Art. 6(1)(f) — legitimate interests |
As data processor, we use the following sub-processors. We ensure each is bound by a data processing agreement providing at least equivalent protections to this policy (Art. 28(4) GDPR).
| Sub-processor | Role | Location | Safeguard |
|---|---|---|---|
| Stripe Inc. | Payment processing | USA | SCCs + Stripe DPA |
| Meta Platforms Ireland Ltd | WhatsApp Business Cloud API | EU / USA | Meta DPA + SCCs |
| Cloud infrastructure provider | PostgreSQL hosting, compute | EU | DPA with provider |
We will notify business customers of any intended changes to sub-processors (additions or replacements) with reasonable advance notice, giving them the opportunity to object. Objection details are in our Terms & Conditions.
Where personal data is transferred outside the EEA — including to Stripe (USA) and Meta (USA data centres) — we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission under Art. 46(2)(c) GDPR.
We conduct transfer impact assessments (TIAs) where required and apply supplementary technical measures (such as encryption in transit and at rest) where appropriate.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach, Fleet Rewind Ltd will:
Business customers who become aware of a suspected breach involving ÉascaDesk data must notify us immediately at [email protected].
Fleet Rewind Ltd is obliged under Art. 28(3)(e) to assist business customers (controllers) in fulfilling their data subject rights obligations. The table below sets out the rights and how requests should be routed.
| Right | Route for employees | Our role as processor |
|---|---|---|
| Access (Art. 15) | Contact your employer first | Provide data export to the controller on request |
| Rectification (Art. 16) | Contact your employer | Update records on controller's instruction |
| Erasure (Art. 17) | Contact your employer | Delete records subject to legal retention (clock events: 4-year minimum) |
| Restriction (Art. 18) | Contact your employer | Flag records as restricted on controller's instruction |
| Portability (Art. 20) | Contact your employer | Export data in CSV format (available via compliance export) |
| Object (Art. 21) | Contact your employer | Cease processing on controller's instruction where lawful |
Fleet Rewind Ltd maintains internal Records of Processing Activities as required by Art. 30 GDPR, covering both our controller activities and processor activities on behalf of business customers. These records are available to the Data Protection Commission on request.
Business customers are themselves required to maintain their own ROPA for their employee data processing activities, including their use of ÉascaDesk Scheduler. The data categories, purposes, and legal bases set out in this document should assist customers in completing their own records.
Real Decreto-ley 8/2019 requires Spanish employers to maintain a daily record of each employee's working hours, retain records for four years, and make them available to labour inspectors, employees, and employee representatives.
| Regulatory requirement | ÉascaDesk implementation |
|---|---|
| Daily clock-in and clock-out record | WhatsApp bot records timestamps at the moment of message receipt; manual entry also available |
| Records retained for 4 years | Clock events are soft-deleted only; the physical record is never removed from the database |
| Traceability of corrections | Immutable audit log records every create, edit, and delete; edit requests record the proposing manager and the employee's WhatsApp approval or rejection |
| Traceability of deletions | Soft-delete captures deleted_at, deleted_by_user_id, and delete_reason |
| Export for inspection | Compliance CSV export (audit=true) includes all above fields plus original timestamps, for direct presentation to inspectors |
| Employee NIF | Optional field on employee record; included in compliance CSV where present |
| Auto-generated records flagged | Auto-close clock-outs are marked is_estimated=true and source=auto; managers are prompted to review |
Processing of employee working-time records by Spanish employers is supervised by the Agencia Española de Protección de Datos (AEPD). Employees with complaints relating to Spanish-law processing may contact the AEPD at www.aepd.es.
| Data type | Retention | Deletion mechanism |
|---|---|---|
| Manager account | Active account + 12 months post-deletion request | Account deletion request to support |
| Schedule run JSON | Active account duration | Deleted by manager or on account deletion |
| Uploaded Excel files | Immediately after solve completes | Automatic |
| Employee records | Active account duration | Manager-deletable at any time (subject to clock event retention) |
| Clock events (incl. soft-deleted) | Minimum 4 years (Spanish law); otherwise active account duration | Soft-delete only; physical deletion after retention period |
| Clock event audit log | Minimum 4 years; immutable | Not deletable during retention period |
| WhatsApp session state | 30-minute TTL | Automatic expiry |
| Server access logs | Up to 90 days | Automatic rolling deletion |
On account closure, we will delete or anonymise all personal data within 30 days, except where retention is required by law (e.g. clock event records for Spanish-law accounts).
Fleet Rewind Ltd does not currently have a designated Data Protection Officer (DPO) as we do not meet the thresholds requiring mandatory DPO appointment under Art. 37 GDPR. All data protection queries are handled by the company's management.
Contact for data protection matters:
Supervisory authorities:
You have the right to lodge a complaint with your local supervisory authority at any time, without prejudice to any other administrative or judicial remedy.