Effective date: 24 June 2026
This Data Processing Agreement ("DPA") is between Staff Track Limited ("Staff Track Limited", "we", "us") and the company or individual ("Customer", "you") who has agreed to the Staff Track Limited Terms of Service.
In providing the Staff Track Limited platform, we process the following categories of Customer data:
We process your data solely for the following purposes:
Each company's data is isolated at the database level using Row Level Security (RLS). No company can access another company's data through the application.
Staff Track Limited personnel access customer data only via our internal superadmin tools. Every access is logged and visible to you on the Data Privacy page of your dashboard.
We use the following sub-processors to deliver the service. Each is bound by its own data processing terms:
| Sub-processor | Purpose | Country |
|---|---|---|
| Supabase | Database, authentication & file storage | EU (AWS eu-west-1, Ireland) |
| Vercel | Application hosting | EU (Ireland); global edge |
| Resend | Transactional email delivery | USA |
| Stripe | Card payment processing | USA / Ireland |
| Revolut | Card & Revolut Pay payment processing (where enabled) | UK / EU |
| Anthropic | AI document scanning (invoices, certificates) & AI assistant | USA |
| Google Maps | Address lookup & maps | USA |
| Apple Push Notification Service | iOS push notifications | USA |
| Firebase Cloud Messaging | Android push notifications | USA |
| Twilio | Telephony for the AI voice receptionist (where enabled) | USA |
| LiveKit | Real-time voice transport for the AI voice receptionist (where enabled) | USA |
| Deepgram | Speech-to-text for the AI voice receptionist (where enabled) | USA |
| Cartesia | Text-to-speech for the AI voice receptionist (where enabled) | USA |
Sub-processors marked "where enabled" apply only if you use the relevant optional feature. Where a sub-processor is located outside the EU, the transfer is covered by appropriate safeguards such as Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
We retain your data for the duration of your subscription plus a 30-day grace period. After cancellation and expiry of the grace period, all company data is permanently deleted from our systems, including backups, within 30 days.
You may request immediate deletion by contacting us at admin@staff-track.com. We will action deletion requests within 14 days.
We implement the following security measures to protect your data:
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact admin@staff-track.com. We will respond within 30 days.
Where you have enabled Enhanced Data Protection, some of these rights in respect of the encrypted data can only be exercised by you, because only you and your authorised devices hold the decryption keys. See Section 11.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach. Notification will include the nature of the breach, categories of data affected, likely consequences, and steps taken to address it.
Where a breach affects data protected by Enhanced Data Protection, that data is held by us only in encrypted form to which we hold no key. We will take this into account when assessing the risk to your rights and freedoms and our notification obligations.
Staff Track Limited is established in Ireland and complies with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. For customers located in the United Kingdom, we align our practices with the UK GDPR and the UK Data Protection Act 2018. For customers located in the United States, we align our practices with applicable US federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the CPRA. For customers located in Australia, we align our practices with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. We also align with applicable international privacy standards for customers in other jurisdictions. This DPA is governed by the laws of Ireland and the parties submit to the exclusive jurisdiction of the Irish courts.
Enhanced Data Protection is an optional feature you can switch on for your account. When enabled, designated data — which, depending on the features you use, may include in-app team chat messages; customer and client records; quotes, invoices and their line items; purchase orders; receipts; HR form submissions and signatures; service requests and their messages; and photos, videos and voice notes — is encrypted on your own browser and devices using keys held only by you and your authorised devices.
Zero-knowledge. We do not hold your encryption keys and cannot decrypt this data. It is stored by us, our hosting provider and our sub-processors only in encrypted form, and is technically inaccessible to Staff Track Limited personnel.
Your responsibilities when Enhanced Data Protection is enabled:
Enhanced Data Protection is an additional layer on top of the standard encryption described in Section 7. Where our hosting or other sub-processors are located outside the EU (see Section 5), they only ever process Enhanced Data Protection data in unreadable, encrypted form.
For any data privacy questions, requests, or concerns:
Staff Track Limited
Email: admin@staff-track.com