
Privacy Policy
Last Updated: July 2026
rightWFM Ltd · Registration: 208126768 · VAT: BG208126768
Lozenets Street 17A, 1421 Sofia, Bulgaria · privacy@rightwfm.com
1. Introduction & Roles
This Privacy Policy explains how rightWFM Hub ("we", "us", or "our") processes personal data in connection with the shift availability and scheduling services.
Under the European General Data Protection Regulation (GDPR):
- Your Employer (our Customer) is the Data Controller. They determine why and how your personal data is processed for workforce management purposes.
- rightWFM is the Data Processor. We process your personal data strictly on behalf of and according to the instructions of your employer.
For any queries regarding your rights to access, change, or delete your data, please contact your employer's HR or system administrator directly.
2. Personal Data We Process
We only process the personal data necessary to provide availability coordination and scheduling services:
- Identity Details: Full name, professional email address, department, and company role.
- Workplace & Scheduling Data: Scheduled shifts, shift preferences, submitted availability timeframes, and peer swap requests.
- System Logs: IP addresses, audit log entries (tracking additions, edits, and deletions of schedules), and cookie session tokens.
3. Purpose and Lawful Basis for Processing
We process your data under the following lawful bases (as directed by your employer):
- Performance of a Contract: To manage shift schedules and coordinate workplace tasks as part of your employment.
- Legitimate Interests: To maintain system security, track audit histories, prevent abuse, and optimize availability schedules.
4. Data Retention & Secure Deletion
We adhere to strict data minimization principles and maintain a clear data lifecycle:
- Active Data: Personal information is retained only for the duration of your employer's active subscription.
- Permanent Deletion on Termination: When an employer cancels their subscription, the dedicated client database is dropped immediately.
- Backup Expiration Cycle: Local daily server dumps are automatically rotated and pruned after 14 days. Offsite encrypted backups stored on Backblaze B2 are permanently expired and deleted after 30 days via automated bucket lifecycle rules. All operational data is fully and irreversibly erased within 30 days of termination.
- Audit Log Retention: Immutable audit logs are retained for a minimum of 12 months and up to 7 years where required by applicable law or customer agreement.
- Encryption & Safety: Active records are protected with TLS 1.3 in transit and AES-256 at rest, managed with role-based access control.
5. Cookies Policy
rightWFM Hub does not utilize tracking, targeting, or advertising cookies. We only set a single, strictly functional session cookie:
- Cookie Name:
rightwfm_session - Purpose: Remembers your authenticated login session to secure your dashboard access.
- Consent: Because this cookie is strictly necessary to provide the service, it is exempt from standard cookie banner requirements under the GDPR ePrivacy Directive.
6. International Transfers
rightWFM Hub is designed to minimize reliance on non-EU infrastructure for operational customer data. Your scheduling and availability data is hosted entirely within the European Union and is not intentionally transferred outside the EEA.
Where a sub-processor is headquartered outside the EEA (e.g. GitHub, Inc. for source code hosting, or Mailgun Technologies, Inc. for email delivery), appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) are used where applicable.
7. Data Processing Agreement (DPA)
Customers may request a Data Processing Agreement (DPA) that complies with Article 28 GDPR. Please contact legal@rightwfm.com to request a signed DPA.
8. Security & Authentication
rightWFM Hub supports Multi-Factor Authentication (MFA) and Single Sign-On (SSO) through Microsoft Entra ID and SAML 2.0 providers. Passwords are never stored in plaintext and are hashed using Argon2id. Where SSO is not used, magic-link authentication ensures no password is transmitted over the network.
9. Incident Response
In the event of a confirmed security incident affecting customer data, affected customers will be notified without undue delay in accordance with applicable law. rightWFM maintains an incident response plan covering detection, containment, eradication, and recovery phases.
10. Responsible Disclosure
If you discover a security vulnerability in rightWFM Hub, please contact security@rightwfm.com. We request that you do not publicly disclose vulnerabilities until they have been investigated and resolved.
11. Your Rights under GDPR
European data protection laws grant you rights regarding access, rectification, portability, restriction, and erasure of your personal data.
To exercise these rights, please contact your employer's system administrator or HR department directly. If you have questions regarding rightWFM's processing procedures or security controls, you can contact our privacy desk at privacy@rightwfm.com.