Last updated: 22 July 2026
This Data Processing Agreement forms part of the Terms of Service between CrewInn Ltd (“Processor”, “CrewInn”) and the Customer (“Controller”). It sets out how CrewInn processes personal data on the Customer’s behalf under UK data protection law (the UK GDPR and the Data Protection Act 2018).
1. Roles
1.1 The Customer is the controller of its staff’s personal data. CrewInn is the processor, acting on the Customer’s documented instructions.
2. Subject matter and details of processing
- Subject matter: provision of the CrewInn hotel staff-management service.
- Duration: for as long as the Customer’s subscription or trial is active, plus the short retention period in the Terms.
- Nature and purpose: hosting, recording and processing staff attendance, rotas, leave, timesheets and pay information so the Customer can manage its staff.
- Types of personal data: staff names and department; personal PINs and (for managers) logins; clock in/out times and worked hours; rota and shift data; holiday and leave records and balances; pay rate, tax code and payroll figures where used; email address where provided.
- Categories of data subjects: the Customer’s staff (and any other individuals the Customer chooses to enter).
3. CrewInn’s obligations
CrewInn will:
3.1 process the personal data only on the Customer’s documented instructions (including the Terms and use of the Service), unless required to do otherwise by law, in which case it will inform the Customer first where lawful to do so;
3.2 ensure that people authorised to process the data are bound by confidentiality;
3.3 implement appropriate technical and organisational security measures (see the Annex);
3.4 not engage another processor (sub-processor) without general written authorisation; CrewInn’s current sub-processors are listed in the Annex, and CrewInn will give the Customer prior notice of any intended change so the Customer can object;
3.5 taking into account the nature of the processing, assist the Customer by appropriate measures in responding to requests from individuals exercising their rights (such as access, correction or deletion);
3.6 assist the Customer with its obligations around security, breach notification and, where relevant, data protection impact assessments;
3.7 notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data;
3.8 at the Customer’s choice, delete or return the personal data at the end of the services and delete existing copies, unless the law requires it to be kept; and
3.9 make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to reasonable audits on reasonable notice.
4. International transfers
4.1 CrewInn will store and process the personal data in the UK or the EEA where reasonably possible. Any transfer outside the UK/EEA will be made only where an appropriate safeguard recognised under UK data protection law is in place.
5. Liability and precedence
5.1 If there is any conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.
Annex A — Security measures
- Encrypted connections (HTTPS) for all access to the Service.
- Role-based access control, so users only see what their role allows.
- PIN and password protection for staff and manager accounts.
- An audit log of key changes.
- Automatic daily backups.
- Logical separation of each customer’s data, with each hotel on its own database instance.
Annex B — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Contabo | Server hosting and data storage | Germany (EU) |
| Sending account and rota notifications | EU / US |
The Customer is notified of changes to this list in advance and may object on reasonable data-protection grounds.
Contact for data protection matters: hello@crewinn.co.uk