Privacy Policy
 

Privacy Policy

1. About this policy and who we are

1.1 This Privacy Policy explains how Intellectual Bunch Limited, a company registered in England and Wales under company number with its registered office at ("we", "us", "our", "Intellectual Bunch"), trading as EveryShift, collects, uses, shares and protects personal data.

1.2 It applies to the everyshift.co.uk website, to our marketing and sales activities, and to the personal data we hold about our own business contacts, account holders and prospective customers. It also explains our role in respect of the personal data that our customers process through the EveryShift software.

1.3 We are the "controller" of the personal data described in this policy except where we state that we act as a "processor". Where we act as a processor, our obligations are set out in the Data Processing Agreement that forms part of our SaaS Terms and Conditions, not in this policy. The distinction is explained in section 3.

1.4 We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).

2. How to contact us

2.1 Our Data Protection Officer can be contacted at dpo@intellectualbunch.com, or in writing at the registered office address above marked for the attention of the Data Protection Officer.

2.2 Please contact the DPO with any question about this policy, any request to exercise your rights, or any concern about how we handle personal data.

3. Our two roles: controller and processor

EveryShift handles personal data in two distinct capacities. Which capacity applies determines who is responsible for the data and which document governs it.

3.1 When we act as a controller

We are the controller — meaning we decide why and how the data is used — for the personal data we hold to run our own business. This includes:

  • data about the individuals who create and administer a customer account (for example the account owner, billing contact and administrators);
  • data about prospective customers, website visitors and people who contact us or request a demo;
  • data about our own suppliers, partners and business contacts.

This policy governs that data.

3.2 When we act as a processor

When a customer uses the EveryShift software to manage their own workforce, the customer decides what staff data to collect and why. The customer is the controller of that workforce data. We only store and process it on the customer's documented instructions in order to provide the service. In relation to that data we are a processor.

Examples of workforce data for which the customer is the controller and we are the processor include employee names and contact details, availability, rotas, timesheets, signed shift records, pay rates, leave and absence records, training records, uploaded documents, and — in the Care edition — care visit records.

Care edition — health data Care visit records and certain training or absence records may include health information, which is special-category data under Article 9 UK GDPR. The customer, as controller, is responsible for establishing a lawful basis and any Article 9 condition for processing that data, for completing any required Data Protection Impact Assessment, and for handling data-subject requests relating to it. Our processor obligations and security commitments for this data are set out in the Data Processing Agreement.

3.3 If you are an employee, worker or client of one of our customers and you have a question about how your data is used, please contact your employer or the organisation that invited you to EveryShift, as they are the controller of that data. We will assist that organisation in responding to you.

4. The personal data we collect (as controller)

The categories below relate to data for which we are the controller, as described in section 3.1.

Category Examples Source
Account and identity data Name, job title, business email, business phone, account username You, when you register or contact us
Billing and transaction data Billing name and address, subscription plan, invoices, partial card details and payment references (full card data is handled by our payment provider, not by us) You / our payment provider
Communications data Emails, support tickets, demo and sales correspondence, feedback You
Marketing data Marketing preferences, consents, campaign engagement You / analytics tools
Website and technical data IP address, device and browser type, pages visited, referral source, and cookie identifiers (see our Cookie Policy) Automatically, via cookies and logs

4.1 We do not intentionally collect special-category data about our own account contacts. If you volunteer such data (for example in a support message), we ask you not to, and we will process it only as necessary to respond to you.

5. Why we use your data and our lawful bases

Under UK GDPR we must have a lawful basis for each use of personal data. Our purposes and bases (as controller) are:

Purpose Lawful basis
Creating and administering your account; providing and supporting the service Performance of a contract with you, or steps to enter into one
Taking payment and managing subscriptions Performance of a contract; legal obligation (tax and accounting records)
Responding to enquiries, demos and support requests Legitimate interests (responding to people who contact us); contract
Sending service and administrative messages (e.g. security, billing, changes to terms) Performance of a contract; legal obligation
Direct marketing to business contacts about our products Legitimate interests, subject to your right to object; consent where required by PECR
Improving and securing the website and service; preventing fraud and abuse Legitimate interests (running a secure, functioning service)
Meeting legal, regulatory and accounting obligations Legal obligation

5.1 Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights and freedoms. You may ask us for details of that assessment using the contact details above.

5.2 Where we rely on consent (for example non-essential cookies or certain marketing), you may withdraw it at any time without affecting the lawfulness of earlier processing.

6. Marketing and your choices

6.1 We may send you information about EveryShift products and features where we are lawfully permitted to do so. Every marketing email contains an unsubscribe link, and you can opt out at any time by using it or by contacting us.

6.2 We will not sell your personal data. We do not use the workforce data our customers process through the platform for our own marketing.

7. Who we share data with

We share personal data only where necessary, and under appropriate contracts. Our categories of recipient are:

  • Service providers (sub-processors) who help us run the service and our business — for example cloud hosting, email delivery, SMS delivery, payment processing, analytics and customer support tools. Our current sub-processors are: . An up-to-date list is available on request.
  • Professional advisers such as accountants, auditors and lawyers, where necessary.
  • Authorities and regulators where we are required by law to disclose, or to establish, exercise or defend legal claims.
  • Buyers or successors in the event of a sale, merger or reorganisation of our business, subject to appropriate confidentiality protections.

7.1 We place a written contract with every processor that contains the data protection terms required by Article 28 UK GDPR.

8. International transfers

8.1 We aim to keep personal data within the UK. Where a sub-processor stores or accesses data outside the UK, we ensure an appropriate safeguard is in place, such as UK adequacy regulations, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.

8.2 You may request details of the safeguards in place for any specific transfer by contacting dpo@intellectualbunch.com.

9. How long we keep data

9.1 We keep personal data only for as long as necessary for the purposes for which it was collected, and to meet legal and regulatory obligations.

9.2 Account and contract data is kept for the duration of the relationship and then for after it ends.

9.3 Financial and tax records are kept for the minimum periods required by HMRC and company law.

9.4 For workforce data processed as a processor, retention is set by the customer as controller and is governed by the SaaS Terms and the Data Processing Agreement. As a general rule we retain such data only for the term of the customer's subscription and then delete or return it, except where the customer or the law requires longer retention (for example payroll records are commonly retained for at least six years, and health and care records for longer statutory periods). Deletion is scheduled against those retention rules rather than performed immediately.

10. Your rights

Where we act as controller, you have the following rights under UK GDPR:

  • to be informed about how we use your data (this policy);
  • to access a copy of your data;
  • to have inaccurate data corrected;
  • to have data erased, in certain circumstances;
  • to restrict or object to processing, in certain circumstances;
  • to data portability, in certain circumstances;
  • to object to direct marketing at any time;
  • to withdraw consent where we rely on it;
  • not to be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions).

10.1 To exercise any right, contact dpo@intellectualbunch.com. We will respond within one month, and may ask you to verify your identity. There is normally no charge.

10.2 If your request relates to workforce data held on behalf of one of our customers, we will direct you to that customer as controller, and assist them in responding.

11. How we protect data

11.1 We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, two-factor authentication, logging and monitoring, and staff confidentiality obligations. Our security measures for customer workforce data are described further in the Data Processing Agreement.

11.2 No method of transmission or storage is completely secure. If we become aware of a personal data breach we will act in accordance with our legal obligations, including notifying the Information Commissioner's Office and affected individuals where required.

12. Cookies

Our website uses cookies and similar technologies. Please see our separate Cookie Policy for full details of which cookies we use, why, and how to manage your preferences.

13. Children

EveryShift is a business service and is not directed at children. We do not knowingly collect data about children through our website or marketing. Workforce data about individuals under 18 may be processed by a customer as controller where lawful (for example a young worker); responsibility for that basis rests with the customer.

14. Changes and complaints

14.1 We may update this policy from time to time. The current version is always available on everyshift.co.uk, and we will notify account holders of material changes.

14.2 If you are unhappy with how we handle your data, please contact our DPO first so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or by calling 0303 123 1113.

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare