Privacy policy
What Rotevia stores, why it stores it, and what you can ask us to do with it.
Last updated August 2026
Who this covers
Rotevia is used by a manager to build a staff rota. That means we hold two kinds of personal data: details about the account holder, and details about the employees they add.
The business using Rotevia is the data controller for its employees’ information. Rotevia acts as a processor on their behalf.
What we store
- Account details: name, email address and a hashed password.
- Business details: pharmacy name, address, opening hours and settings.
- Employee records: name, role, employment type, hourly pay rate, contracted hours, contact details you choose to add, and any notes you write.
- Rota data: shifts, recurring schedules, recorded hours and absences.
- A change history of edits to shifts, pay rates and working patterns.
Why we store it
Solely to provide the scheduling, hours-tracking and wage-estimate features you signed up for. We do not sell data, and we do not use employee records for advertising.
Security
Passwords are stored as salted scrypt hashes and are never recoverable in plain text. Sessions use signed, http-only cookies. Access is scoped to your own pharmacy so one account cannot read another’s records.
Keeping and deleting data
Rota and pay history is kept while your account is open, because payroll reporting depends on it. Deleting an employee removes their shifts, recorded hours and pay history permanently — marking them inactive keeps the records instead.
Your rights
Under UK GDPR you can ask for a copy of your data, ask for corrections, or ask for it to be deleted. Employees should make those requests to their employer, who controls the record.
Contact
Questions about this policy can be sent through the contact page.