Data Processing Agreement

How we process carer and client data on your organisation's behalf.

Last updated: 26 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between FillMy Shift, a business based in Coventry, United Kingdom ("Processor", "we", "us"), and the care organisation using the Service ("Controller", "Customer", "you"), and applies whenever we process personal data on your behalf in connection with your use of FillMyShift (the "Service").

This DPA reflects the requirements of the UK GDPR and the Data Protection Act 2018.

1. Roles of the parties

For the purposes of this DPA:

  • You (the Customer) are the data controller for personal data relating to your carers and any other individuals you input into the Service, meaning you determine the purposes and means of processing that data.
  • We (FillMyShift) are the data processor, processing that data solely on your documented instructions, as set out in this DPA and our Terms of Service.

This DPA does not apply to data where FillMyShift is itself the controller (for example, data about your organisation's own coordinator accounts and billing, which is covered by our Privacy Policy).

2. Subject matter and duration

We process personal data on your behalf for the duration of your subscription to the Service, for the purpose of providing shift coordination functionality — specifically, carer matching, sending shift offer notifications, and reporting.

3. Nature and purpose of processing

We process the following categories of personal data, as input by you:

  • Carer names and phone numbers
  • Carer availability, skills, and shift history
  • Shift offer records (sent, viewed, accepted, declined, expired)
  • Push notification subscription tokens, where a carer has opted in

This data is processed for the purpose of:

  • Matching carers to available shifts
  • Sending automated shift offer notifications (push and/or SMS)
  • Tracking and reporting on offer responses and shift coverage

4. Categories of data subjects

  • Carers (employed or engaged by you) whose details you input into the Service
  • Any other individuals you choose to record within the Service in connection with shift coordination (e.g. named clients/placements, to the extent identifying information is entered)

5. Our obligations as processor

We agree to:

  • Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by UK law (in which case we will inform you, unless prohibited from doing so)
  • Ensure personnel authorised to process the data are subject to confidentiality obligations
  • Implement appropriate technical and organisational security measures (see section 7)
  • Assist you, insofar as reasonably possible, in responding to data subject requests (access, erasure, correction, etc.) relating to data you control
  • Assist you in meeting obligations relating to data protection impact assessments and consultations with the ICO, where applicable
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide reasonable information to help you meet your own breach notification obligations
  • At your choice, delete or return all personal data to you at the end of the provision of Service, and delete existing copies unless UK law requires retention
  • Make available information necessary to demonstrate compliance with this DPA, and allow for reasonable audits or inspections on reasonable notice

6. Sub-processors

We use the following categories of sub-processors to help provide the Service:

  • Cloud hosting and database infrastructure (e.g. Supabase and our hosting provider) — for secure data storage
  • Push notification and SMS delivery providers — solely to deliver shift offer messages to carers
  • Payment processing (Stripe) — for billing your organisation (this does not involve carer data)

We remain responsible for our sub-processors' compliance with data protection obligations equivalent to those in this DPA. We will notify you of any intended changes to sub-processors, giving you the opportunity to object on reasonable grounds relating to data protection.

7. Security measures

We maintain appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorised personnel on a need-to-know basis
  • Secure authentication for all accounts
  • Regular review of security practices as the Service evolves

8. International transfers

Where any sub-processor processes personal data outside the UK, we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or another mechanism recognised as adequate under UK GDPR.

9. Data subject requests

If we receive a request directly from a data subject (e.g. a carer) relating to data you control, we will inform you promptly and will not respond directly except to acknowledge receipt and direct them to you, unless legally required to do otherwise.

10. Return or deletion of data

On termination of your subscription, you may request export of your data within [30] days. After this period, or on your instruction, we will delete personal data from our active systems within a reasonable timeframe, except where retention is required by law.

11. Liability

Liability under this DPA is subject to the limitations of liability set out in our Terms of Service.

12. Contact

For questions about this DPA or to raise a data protection concern, contact us at hello@cm16digital.com.