This policy describes how SOC Rotate handles personal data for visitors to our website and users of our scheduling product. We keep it short, specific, and free of dark patterns.
SOC Rotate ("SOC Rotate", "we", "us") provides shift-scheduling and rotation software for Security Operations Centers, delivered as a hosted web application.
This policy explains how we handle personal data. For most data processed in the product, our customer (the organisation that subscribes to SOC Rotate) is the data controller and we act as the data processor on their instructions. For our own website, marketing, and account administration, we are the controller.
Questions about this policy or your data can be sent to privacy@socrotate.com.
We collect only what is needed to run the service:
We do not intentionally collect special categories of personal data. Please do not enter health, biometric, or other sensitive details into free-text fields such as handover or leave notes.
We do not sell personal data, and we do not use customer operational data to train machine learning models or for advertising.
Where the GDPR applies, we rely on the following legal bases:
We use a small set of vetted infrastructure providers to operate SOC Rotate:
Each sub-processor is bound by a data processing agreement. A current list of sub-processors is available on request from privacy@socrotate.com.
We aim to host customer data in the region agreed with the customer. Where personal data is transferred outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Customers with specific data-residency requirements should contact us at privacy@socrotate.com before onboarding.
We retain customer operational data for as long as the customer's account is active. After an account is closed, data is deleted or anonymised within 90 days unless a longer period is required by law. Customers may request export or deletion of their data at any time.
We apply technical and organisational measures appropriate to the risk, including:
To report a vulnerability, contact security@socrotate.com.
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Because much of the data in SOC Rotate is controlled by your employer, please direct requests to your organisation's administrator first; we will support them in fulfilling your request.
You can also contact us directly at privacy@socrotate.com. If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection authority.
We may update this policy from time to time. Material changes will be communicated through the product or by email. The "last updated" date above always reflects the current version.
For any privacy question or request, email privacy@socrotate.com. For security matters, email security@socrotate.com.