Legal
Privacy policy
This policy explains how we handle personal information on rosterbook.app and in the RosterBook application. It applies to visitors to this website, people who request a demo, and people who use RosterBook at an agency.
It is written to the Protection of Personal Information Act 4 of 2013 (POPIA). Where the General Data Protection Regulation applies to you, the equivalent GDPR terms and rights are given alongside.
On this page
1. Our role
We handle personal information in two capacities.
- We are the responsible party under POPIA, and the controller under the GDPR, for information whose use we decide: website visitors, demo requests, account users, support correspondence and our own business records.
- We are the operator under POPIA, and the processor under the GDPR, for the information an agency puts into its RosterBook workspace. We process it on that agency's instructions and for no other purpose.
Requests about information held in an agency's workspace are dealt with by that agency, not by us. See the section on agency workspaces.
2. What we collect
Website visitors
Cloudflare records the details carried by every request to this site: IP address, browser and device type, the pages requested, the time of the request, and the referring page. These are used to serve the site and to block abuse. They are not used to build a profile of you or to track you across other websites.
Demo requests
The demo form collects your name, work email address, agency name, agency type, roster size band, and any message you add. The details are sent to our team by email. Cloudflare Turnstile checks that the submission is not automated.
Account users
For each person with a login we hold a name, email address, role and agency; authentication and two-factor settings, including recovery codes; audit log entries recording significant actions; and correspondence with our support team.
Records in an agency's workspace
An agency's workspace holds the records it keeps to run its business:
- Talent: contact details, headshots and galleries, designations and categories, experience, qualifications and expiry dates, awards, measurements where the work requires them, availability and bookouts, and payroll and billing details.
- Clients and contacts: companies, the individuals the agency deals with there, and the correspondence and notes attached to them.
- Work: opportunities, bookings, schedules, quotes, confirmations, invoices, payments, signatures and signed PDFs.
- Connected accounts: where an agency connects email or accounting, the messages and records that sync as a result. Nothing syncs until the agency connects it.
We hold these records for the agency. We do not sell them, use them for marketing, or use one agency's records to serve another.
3. Why we use it, and our lawful grounds
POPIA requires a justification for processing personal information and the GDPR requires a lawful basis. Ours are set out below.
| Purpose | Detail | Ground |
|---|---|---|
| Serving the website | Delivering pages, keeping the site available, blocking abuse | Our legitimate interests in operating a secure website |
| Answering a demo request | Replying, arranging the call and preparing for it | Steps taken at your request before entering a contract; our legitimate interest in responding to a business enquiry |
| Providing the service | Running, supporting, securing and billing for the RosterBook application | Performance of our contract with your agency |
| Improving the product | Aggregated and de-identified usage data showing which features are used | Our legitimate interests in improving the service |
| Meeting legal obligations | Tax, accounting and company records, and responses to lawful requests | Compliance with a legal obligation |
Requesting a demo does not add you to a marketing list. We send marketing email only with consent, and every such message carries an unsubscribe link.
4. Cookies
This website carries no analytics, advertising or cross-site tracking. Cloudflare may set a short-lived cookie recording that a bot check has been passed.
The RosterBook application uses strictly necessary cookies for session authentication, for the agency you are working in, and for devices recognised for two-factor authentication.
If analytics are added to either the website or the application, this policy will be updated and consent obtained where the law requires it.
5. Who we share it with
We use the service providers below. Each is bound by contract to process personal information only on our instructions and to keep it secure.
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting and delivery of this website; bot checks on the demo form | Global edge network |
| Resend | Delivery of demo requests to our inbox | United States |
| Application hosting | Operation and storage of the RosterBook application and its database | Current list available from support@rosterbook.app |
We otherwise disclose personal information only in these cases: to an integration an agency chooses to connect, and then only the data that integration requires; to our professional advisers, under a duty of confidence; where required by law, a court or a regulator; and to a buyer of the business, in which case this policy continues to apply and affected customers are notified.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
6. Transfers outside South Africa
Some of our service providers are outside South Africa, so personal information may be processed abroad. Section 72 of POPIA and Chapter V of the GDPR permit this where the recipient is subject to comparable protection. Our agreement with each provider imposes that standard, including the European Commission's standard contractual clauses where they apply.
7. How long we keep it
- Demo requests and enquiries: for the duration of the enquiry and up to 24 months afterwards, then deleted or anonymised.
- Account and workspace records: for the term of the agency's subscription. The workspace remains available for export for 30 days after the subscription ends, and is then deleted from live systems. Backups expire on their normal cycle.
- Invoices, tax and company records: for the period required by the tax and company law of South Africa, generally five to seven years.
- Security and audit logs: for the period needed to investigate an incident, then rotated out.
An agency may ask for its workspace to be deleted sooner. We will do so, except for records we are required by law to keep.
8. How we protect it
The application applies the following controls:
- Tenant isolation enforced at the database by row-level security, so one agency's records are not reachable from another agency's session.
- Roles and permissions (Owner, Administrator, Editor) enforced on the server rather than in the interface.
- Two-factor authentication with recovery codes.
- Encryption in transit on all connections to the website and the application.
- An audit log of significant actions within each workspace.
- Staff access limited to what support, security and maintenance require.
No system is entirely secure. Where a compromise creates a risk to personal information, we notify the Information Regulator (South Africa) and the people affected, as section 22 of POPIA and Articles 33 and 34 of the GDPR require.
9. Your rights
Where we hold your information as responsible party, you may ask us to:
- confirm what we hold and provide a copy;
- correct or complete anything inaccurate;
- delete information we no longer have grounds to keep;
- stop using it for a particular purpose, or object to processing based on our legitimate interests;
- restrict processing while an objection is resolved;
- provide it in a portable format, a GDPR right we extend to everyone; and
- withdraw consent, which does not affect processing carried out before the withdrawal.
Send requests to support@rosterbook.app. We respond within 30 days. We may ask you to confirm your identity before acting on a request. There is no charge, unless a request is repetitive or excessive, in which case we will tell you before any charge applies.
Complaints may be made to the Information Regulator (South Africa). If you are in the EU or the UK, you may also complain to the supervisory authority where you live or work.
10. Information held in an agency's workspace
If an agency you work with uses RosterBook, we process your details on that agency's instructions. Requests to access, correct or delete those records must be made to the agency, which decides what it holds and why.
If you contact us instead, we will forward the request to the agency and confirm that we have done so. We do not alter or delete an agency's records on the instruction of a third party. If you are not sure which agency holds your details, email support@rosterbook.app.
11. Information about people under 18
RosterBook is business software sold to agencies. It is not directed at children, and we do not knowingly collect personal information from a child through this website.
Agencies do represent talent under 18. POPIA restricts the processing of a child's personal information and generally requires the consent of a competent person, usually a parent or guardian; the GDPR provides comparable protection. An agency that records a minor's details in RosterBook is responsible for obtaining that consent and for the safeguards that apply to images, measurements and payment details.
12. Changes to this policy
We update this policy when our practices change. The date above records the last substantive revision, and the current version is the one published on this page. Account administrators are notified by email before a material change takes effect.
13. Contact
Privacy questions, requests and complaints: support@rosterbook.app. General questions: support@rosterbook.app.
RosterBook
Our Information Officer under POPIA is contactable at support@rosterbook.app.