Legal

Security and privacy

This page is for information security, the privacy officer and the lawyer. It is written without any selling, so you can forward it as it is. Anything you do not find here, ask us at the address at the bottom.

  • Data in the EU: database and authentication in Frankfurt, no transfer outside the EU

  • No patient data: Rondus holds the roster, not the work

  • Separation per organisation at database level, access per role, data processing agreement available

  • Hosting

    The database and authentication run at Supabase in Frankfurt, inside the EU. The application itself is delivered through Vercel's network; the roster data stays in Frankfurt.

  • Encryption

    Traffic between browser and application runs over TLS. Data is stored encrypted at Supabase.

  • Access

    Every organisation sees only its own data, enforced at database level. Within that, the role decides what someone may do, and accounts are created only by invitation from your own administrator.

  • Backups and retention

    Backups follow Supabase's retention periods. At the end of the agreement Rondus returns the data in a common format or deletes it, as you choose.

  • GDPR and data breaches

    Rondus processes roster data, no patient data and no reasons for sick leave. In case of a breach we inform you without undue delay, with what you need for your own notification obligation.

  • Sub-processors

    Three parties: Supabase (database, Frankfurt), Vercel (delivery) and Resend (only the demo form on this site). We announce a change in advance, so you can object.

There is a security dossier

For a hospital's information security officer and data protection officer there is a dossier of thirteen pages with thirteen chapters. It is not on this site as a download; you ask for it and we send it to you. You do not have to ask for what is already on this page.

What is in it:

  1. What this document covers
  2. Where the data sits
  3. Which personal data Rondus processes
  4. How customers are separated from one another
  5. Access and accountability
  6. Signing in, sessions and people leaving
  7. Availability, backup and recovery
  8. Continuity of the supplier
  9. How software reaches production here
  10. Standards and certification
  11. What we consider weak ourselves
  12. What we are doing about it
  13. Contact

Ask for the dossier

The full text

Where the data sits

The database and authentication run on Supabase in the eu-central-1 region (Frankfurt), inside the European Union. Transfer outside the EU is not part of the design.

One caveat, which we raise ourselves: the application itself, meaning the styling, the images and the JavaScript, is delivered over Vercel's global network. The roster data stays in Frankfurt.

Which data, and which explicitly not

Rondus processes roster data about staff: name, email address, functiegroep, fte, role in the application, shifts, roster requests and recorded deviations.

Rondus processes no patient data. The application holds the roster of the rostering group, the group of specialists who share one rota, not the work itself. Reasons for sickness do not belong in it either: availability is available or not available.

The built-in help function uses no language model

The Rondus Gids answers questions from explanations written in advance, inside the user's own browser. No roster data, no name and no question reaches a language model or any other external service. That is enforced technically, not merely agreed.

We keep statistics on its use: the question asked (200 characters at most), which explanation was shown, whether an answer or a refusal followed, and a random session number. Account, name and organisation are not in it. The question is free text the user types, so we do not control what ends up in it, and those rows are readable by the administrators of Rondus. We clear them out periodically after twelve months. The Gids adds no sub-processor.

Access and separation

Each organisation's data is separated at database level (row level security): an organisation sees only its own data.

Within that, the role decides what someone may do: administrator, planner, trainer, staff member and a viewer role for the secretariat. Accounts are created only by invitation from an administrator at your own organisation; authentication runs through Supabase Auth.

When someone leaves, the administrator marks them inactive. Anyone without an active staff row lands on a screen saying their access has been withdrawn, at their next request. An access token already issued stays valid for an hour and a running session cannot be revoked retroactively, so the window is one hour at most.

Retention and deletion

Account data stays for as long as the customer relationship lasts. We delete data at the request of the controller, meaning your institution or rostering group. Backups follow Supabase's retention periods.

Two categories have no automatic retention period: the usage data that shows us which screens get used, and the audit log that holds the old and the new value of every roster change. Both grow with use, and we clear them out on request or periodically. We would rather say that than name a period nothing enforces.

At the end of the agreement we return the data in a common format or delete it, whichever you choose.

Data breaches

In the event of a personal data breach we inform the controller without undue delay, with the information you need for your own reporting duty towards the Dutch DPA and the people involved.

What we do not have

Rondus holds no ISO 27001 and no NEN 7510 certification. You would rather read that here than have to ask in the conversation that follows. What we can do: set out the measures above on paper, and cooperate with your own assessment.

Sub-processors

These are all the parties that process data in delivering Rondus. We announce an intended change in advance, so you can object.

PartyRoleRegion
SupabaseDatabase, authentication and invitation email for the applicationeu-central-1, Frankfurt (EU)
VercelHosting and delivery of the application and this websiteEU delivery; the CDN caches static files worldwide
ResendSending the demo form on this website. Name, rostering group, institution and email address of the requester only; no roster dataThis website only; the application does not use Resend

Data processing agreement

A read-only version is on this site; you can print it or save it as a PDF. A signable copy is available on request: write to us and we will send it.

Read the data processing agreement

Who the supplier is

Rondus B.V., established in the Netherlands. Rondus is supplied to businesses only, to institutions and rostering groups.

Contact

Questions about security, privacy or the data processing agreement reach the people who make Rondus, and are answered within one working day: security@rondus.app

See it with your own roster

Half an hour and you know whether this fits your rostering group

Request a demo