Third Party Index

Snapshot 25419

Document
Data processing addendum
URL
https://www.roundrobinbot.eu/dpa
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
39979 bytes
SHA-256 (raw)
ffa4ad9ad9dcb5e85d99e90709492b8225eb7b6ce39fac50be15f50a755cb8e0
SHA-256 (normalized text)
2d4d164d8e2d067fc38461f64508113b52e9234b364f2c8a90d7202e150bd691

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Data Processing Agreement
Last updated: August 13, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Irrelevant Labs OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia ("we", "us", the "Processor") and the organization whose Slack workspace uses Round Robin (the "Customer", the "Controller"). It applies whenever we process personal data on the Customer's behalf under the GDPR or UK GDPR, and takes effect automatically when the Customer installs or uses Round Robin — no signature is required. Organizations that need a countersigned copy can request one at support@irrelevantlabs.com.
1. Roles and Scope
The Customer is the controller of the workspace personal data processed in Round Robin; we are the processor. For data where we act as an independent controller — our own websites, billing, and product analytics — our Privacy Policy applies instead of this DPA.
2. Details of Processing
Subject matter and purpose: operating on-call and duty rotations for the Customer's Slack workspace — scheduling, notifications, user-group updates, and the related dashboard, API, and integrations.
Duration: the term of the Customer's use of Round Robin, plus the deletion period in Section 9.
Nature: hosting, storage, transmission, display, and automated scheduling logic.
Categories of data subjects: the Customer's workspace members involved in or interacting with rotations.
Categories of personal data: Slack user identifiers, display names, avatars, time zones, email addresses (where the Customer's Slack plan and settings expose them), rotation membership and duty history, out-of-office periods (where the Google Calendar integration is connected), and content the Customer places in rotations (names, descriptions, notes).
Special categories: none are required by the service, and the Customer agrees not to submit any.
3. Instructions
We process workspace personal data only on the Customer's documented instructions — which consist of the Customer's configuration and use of Round Robin, the Terms of Service, and this DPA — unless processing is required by law, in which case we will inform the Customer unless the law prohibits it. We will inform the Customer if, in our opinion, an instruction infringes applicable data protection law.
4. Confidentiality
Access to workspace personal data is limited to persons who need it to operate the service and who are bound by confidentiality obligations.
5. Security
We implement the technical and organizational measures described on our Security page — including encryption in transit and at rest, application-level encryption of credentials, per-workspace data segregation, and least-privilege access — and keep them under review as required by Article 32 GDPR.
6. Subprocessors
The Customer grants general authorization for the subprocessors listed in our Privacy Policy. We will update that list before engaging a new subprocessor; the Customer may object on reasonable data protection grounds within 30 days of the update, in which case the parties will discuss in good faith and, failing resolution, the Customer may terminate and receive a proportionate refund of prepaid fees. We remain fully liable for our subprocessors' performance.
7. Assistance
Taking into account the nature of the processing, we will assist the Customer with reasonable measures to fulfil its obligations regarding data subject rights (Articles 12–23), security, breach notification, data protection impact assessments, and prior consultation (Articles 32–36). Data subject requests we receive directly for the Customer's workspace data will be forwarded to the Customer without undue delay. The dashboard and API already provide self-service access, correction, and deletion for most workspace data.
8. Data Breach Notification
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's workspace data, providing the information reasonably available to us to support the Customer's own notification obligations.
9. Deletion and Return
Upon deletion of the Customer's account or uninstallation of Round Robin, all workspace personal data is permanently deleted from our live systems within 7 days, and from encrypted backups as they expire (no later than 5 weeks). Where a paid subscription is still live, or an invoice is unpaid, deletion runs within 7 days of the subscription being cancelled or the invoice being settled; the Customer may request earlier deletion in writing. Before deletion, the Customer can export its data through the dashboard and API. We retain only data we are legally required to keep.
10. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA — including our Security page, subprocessor list, and answers to reasonable written security questionnaires (at most once per year). Where an audit right cannot be satisfied this way under Article 28(3)(h), the Customer may conduct or mandate an audit at its own expense, remotely, on at least 30 days' notice, no more than once per year, without access to other customers' data.
11. International Transfers
Our primary infrastructure is in the European Union, with encrypted backup copies additionally stored in Switzerland (adequacy decision). Where a subprocessor processes personal data outside the EU/EEA or UK, the transfer is protected by the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) or an adequacy mechanism such as the EU–US Data Privacy Framework, as described in our Privacy Policy.
12. Liability and Precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where applicable data protection law does not permit such limitation. In case of conflict between this DPA and the Terms of Service regarding the processing of workspace personal data, this DPA prevails.
13. Governing Law
This DPA is governed by the same law as the Terms of Service, without prejudice to mandatory requirements of the GDPR or UK GDPR.
Contact
Irrelevant Labs OÜ Sepapaja tn 6, 15551 Tallinn, Estonia support@irrelevantlabs.com
Download this document (Markdown)