Data Processing Addendum
Last updated 26 September 2026
Contents
The rota drafting changes apply from 26 September 2026. The new personal data in clause 4 can be entered from 26 September 2026.
This Addendum forms part of the agreement between the customer ("Controller") and Mately Limited ("Processor") and applies where Mately processes personal data on the Controller's behalf (i.e. the staff data a business manages in Mately). It reflects UK GDPR Article 28.
1. Roles
The Controller determines the purposes and means of processing its team's personal data. Mately processes that data only as a Processor, on the Controller's documented instructions (which include using the features of the app).
2. Subject matter and duration
Processing lasts for the term of the agreement plus the retention period in clause 11. The subject matter is the provision of the Mately service.
3. Nature and purpose
Scheduling (including drafting suggested rotas from the Controller's own scheduling history, which the Controller reviews before publishing), time and attendance, leave, payroll preparation, internal communication and document handling for the Controller's workforce, together with the moderation of that internal communication (clause 5).
When the Controller’s manager asks Mately to pick who works on a rota, Mately analyses the Controller’s own records from, at most, the preceding 12 months (past shifts, leave and recorded unavailability; earlier records only to identify roles previously worked, or the usual pattern of a staff member returning from a long absence) to identify each staff member’s usual working days, hours and roles. The Controller’s data is never combined with any other customer’s. Leave recorded as sickness absence is not used to derive any pattern, and days recorded as leave of any type or as unavailability are excluded when deriving a staff member’s usual working pattern. Derived patterns set the order in which staff are suggested, limit suggestions to roles a staff member has previously worked or is recorded as able to do, and draft each staff member for up to their usual hours. Derived patterns are not retained beyond the request that produced them. The Controller can switch this processing off for all staff or for an individual staff member. Where it is switched off for an individual, nothing from that staff member’s past shifts is used to derive any pattern or figure. The output is a draft with no effect until the Controller reviews and publishes it. Mately never publishes a rota itself, and takes no significant decision about any data subject based solely on automated processing within the meaning of Articles 22A–22D UK GDPR. The Controller is responsible for making sure a manager genuinely reviews each draft before publishing it, for informing its staff of this processing, and for the data protection impact assessment this processing requires. Mately provides a starter impact assessment and further help under clause 8.
4. Types of data and data subjects
- Data subjects: the Controller's staff (owners, managers, employees).
- Personal data: names, contact details, role and the roles a staff member can do, pay rate and contracted hours, whether a staff member is under 18 or below school leaving age, whether planning from past rotas is switched off for them, worked time and leave, scheduling patterns derived from those records (clause 3), messages, signed documents, and limited device/technical data.
Reported chat messages. Where a staff member reports a message in team chat, a copy of the message text (capped at 500 characters) is stored with the report, together with the identity of its author and of the reporter, the reason selected and any note added. The copy is retained even if the underlying message is later deleted, since removal is the usual outcome of an upheld report and the Controller would otherwise be adjudicating a complaint it can no longer read. Where the reported item is a photo, video or voice note, only its type is recorded, not the file. Mately also stores the fact that one staff member has chosen to hide another, and the Controller's own optional list of blocked words. All of this sits within the Controller's data — see clause 5 for the circumstances in which Mately may access it.
5. Moderation of team chat
This clause sets out the only circumstances in which Mately may have access to the content of the Controller's employees' messages.
The default position. Reports are visible in full to the Controller's owners and managers, excluding any person the report concerns. A manager is never shown, and cannot open, a report about themselves. Mately receives only the organisation identifier, the timestamps and the status of a report — no message content and no names.
The exception. Where the person reported is the only owner or manager of the Controller, there is nobody within the Controller who could review the report without it concerning themselves. In that case alone, Mately is notified automatically. The notification carries the organisation identifier and a timestamp only, and contains no message content and no names. There is no time-based escalation and no other automatic route.
Mately's undertaking on content. No Mately interface displays the content of a report. Mately will not access that content except on the Controller's documented written instruction, or where required to do so by law. Where Mately acts on an account — to warn, suspend or close it — it does so on the organisation identifier and timestamp alone, and does not require access to content. The report and its contents remain within the Controller's own data at all times.
Special category data. A report may disclose data falling within Article 9 of the UK GDPR — a complaint of racist or homophobic abuse, for example, necessarily reveals the alleged content. That data is processed by the Controller. The Controller is responsible for identifying the condition under Schedule 1 of the Data Protection Act 2018 on which it relies, and for any appropriate policy document that condition requires. Mately does not receive that content.
6. Clock-in presence checks
Where the Controller enables them, Mately verifies at the moment of a clock-in that the person is connected to the workplace Wi-Fi, or is within a distance of the workplace set by the Controller. To do so the staff member's device transmits a Wi-Fi network identifier and/or a device position; Mately compares it against the Controller's own settings and discards it immediately.
The value is not written to Mately's database, is not made available to the Controller, and is not used to construct any location history. There is no background or continuous location tracking, and these checks are disabled by default. The only record retained is the time entry itself — that a clock-in occurred, and when. Location data accordingly does not form part of the personal data processed and stored under this Addendum.
7. Data outside the scope of this Addendum
Sign-up security data. When a business account is first created, Mately records the account owner's sign-up IP address and browser/device information to detect and prevent bot sign-ups and abuse. Mately handles this as a controller of its own customer-account data — not as the Controller's processor — under its Privacy Policy. It is kept for up to 90 days and then automatically deleted.
Payment card details. A payment card is required before the free trial begins. It is collected and held by Stripe and never passes through Mately's systems; Mately holds only a customer and subscription reference, the billing status and the trial and renewal dates. This is Mately's own customer-billing data, processed by Mately as a controller under its Privacy Policy, and does not form part of the staff data the Controller entrusts to Mately under this Addendum.
8. Mately's obligations
- Process personal data only on the Controller's instructions.
- Ensure people authorised to process it are under a duty of confidentiality.
- Apply appropriate technical and organisational security measures (clause 10).
- Assist the Controller in responding to data-subject requests, and with security, breach and DPIA obligations.
- Notify the Controller without undue delay on becoming aware of a personal-data breach.
- Delete or return personal data at the end of the service (clause 11).
- Make available information needed to demonstrate compliance.
9. Sub-processors
The Controller authorises Mately to use the sub-processors listed in our Privacy Policy (Render, Stripe, Resend, Google Firebase, Cloudflare, Sentry). We impose equivalent data-protection terms on each, and will give reasonable notice of changes so the Controller can object. This authorisation extends to the sub-processors those providers themselves use, which each provider publishes (Cloudflare’s list is at https://www.cloudflare.com/gdpr/subprocessors/cloudflare-services/). Mately will tell the Controller promptly of changes to Cloudflare’s list, and the Controller may switch off Tell Mately’s use of AI if it objects.
Stripe receives the Controller's own billing and card details at account setup. It does not receive the staff data covered by this Addendum.
Cloudflare also provides the AI service that Tell Mately can use. When the Controller’s manager asks Tell Mately to build a week or a month and part of that request cannot be placed by Mately itself, the words of that part may be sent to Cloudflare. Before they are sent, the names of staff and of the Controller’s business are removed, role names are replaced by codes, and only everyday rota words, days of the week, times and small numbers are kept. Nothing is sent if the request contains a word Mately treats as personal, such as one about health, pregnancy, bereavement, religion, divorce or trouble with the law. No availability, hours, shifts, leave, pay or other staff records are sent. Mately takes from Cloudflare’s answer only which days are busier or quieter than usual and how many additional staff a role needs; which staff work each shift is decided by Mately. Cloudflare’s Data Processing Addendum allows it to process what it is sent only to provide its services to Mately, and Cloudflare does not use it to train AI models. Mately does not send it through any Cloudflare feature that keeps a copy of what is sent. Drafts have no effect until the Controller reviews and publishes them. The Controller’s owner can switch off Tell Mately’s use of AI for the whole business.
10. Security measures
Encryption in transit; hashed passwords (Argon2id); two-factor authentication; per-business data isolation enforced in the application; least-privilege access; audit logging of sensitive actions; rate limiting; and regular backups of the database.
11. Return and deletion
On termination the Controller can export its data and choose immediate deletion or a 30-day retention window, after which the data (and uploaded files) are permanently deleted from production systems, subject to any legal retention requirement.
During the term, media shared in team chat (photos, videos and voice notes) may be automatically deleted 90 days after upload as a routine storage-limitation measure; chat messages themselves and files in the Documents area are not affected by this measure.
Reports are retained while open. A closed report is deleted 12 months after closure by an automated sweep. That period allows the Controller to evidence a pattern of conduct in a grievance or tribunal, which may arise well after the event.
Account-security data that Mately records as a controller (the account owner's sign-up IP address and browser/device information — see clause 7) is kept for up to 90 days after sign-up and then automatically deleted.
Scheduling patterns derived under clause 3 are not retained beyond the request that produced them.
12. International transfers
The application and database are hosted in Frankfurt, Germany, within the European Economic Area. The EEA is covered by the United Kingdom's adequacy regulations, so no additional safeguard is required for that hosting.
Mately's sub-processors in the United States — Stripe, Resend, Google, Cloudflare and Sentry — are each certified under the UK Extension to the EU–US Data Privacy Framework. Each additionally maintains the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, which apply should that certification lapse or cease to be a valid transfer mechanism.
Mately contracts with Cloudflare, Inc., whose certification covers both human resources and other personal data. Cloudflare may process personal data outside the United Kingdom, the European Economic Area and the United States, on its own network or through its own sub-processors. Its Data Processing Addendum limits that processing to providing its services, and requires it to bind each sub-processor to data protection terms no less protective than its own. The Controller instructs Mately to make the transfers described in this clause.
13. Audit
Mately will respond to reasonable audit requests by providing relevant documentation; on-site audits may be arranged where required by law, on reasonable notice.
14. Contact
Data protection queries: support@mately.co.uk.