Last Updated: October 29, 2025
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law that came into effect on May 25, 2018, across the European Union (EU) and European Economic Area (EEA). It is designed to give individuals more control over their personal data and to harmonize data protection laws across Europe.
Who does GDPR apply to? GDPR applies to:
EU residents: Anyone residing in the EU or EEA, regardless of their nationality
Organizations processing EU data: Any company that processes personal data of EU residents, even if the company is located outside the EU
EpicShifts' Commitment: We are committed to full GDPR compliance and protecting your privacy rights. This page explains your rights under GDPR and how to exercise them. For general privacy information, please see our Privacy Policy.
GDPR grants EU residents the following rights regarding their personal data:
You have the right to request access to your personal data and obtain a copy of all information we hold about you. This includes details about how we process your data, the categories of data we collect, and with whom we share it.
You have the right to correct inaccurate or incomplete personal data we hold about you. You can update most information directly through your profile settings.
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes it was collected, or if you withdraw your consent. Note that some data may need to be retained for legal compliance purposes (e.g., tax records).
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON) and to transfer that data to another service provider without hindrance.
You have the right to object to the processing of your personal data for specific purposes, such as direct marketing, scientific research, or processing based on legitimate interests. You can opt out of marketing communications at any time.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing based on legitimate interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. EpicShifts does not engage in automated decision-making that produces legal or similarly significant effects.
If you have an EpicShifts account, you can exercise most of your GDPR rights directly through our platform:
How: Log in → My Profile → Privacy & Data → "Download My Data"
What you get: A comprehensive JSON file containing all your personal data, including profile information, organization memberships, shifts, availability, and settings.
Timeframe: Instant download (data is generated on-demand)
How: Log in → My Profile → Edit your information directly
What you can update: Name, email, phone, address, date of birth, emergency contacts, preferences, and notification settings
How: Log in → My Profile → Privacy & Data → "Delete My Account"
Grace period: 30 days before permanent deletion (you can cancel anytime during this period)
What gets deleted: All personal data, organization memberships (if not owner), shifts, availability, settings, and MFA configuration
Important: Organization owners must transfer ownership to another user before deleting their account.
Marketing communications: Use the "Unsubscribe" link in any marketing email, or update your notification preferences in Settings
Other processing: Contact us at [email protected] with specific details of your objection
Timeframe: We will respond within 30 days
For all other requests (or if you don't have an account), please email us at [email protected] with:
Your full name and email address
The specific right you wish to exercise
Any additional details relevant to your request
We will verify your identity before processing your request and respond within 30 days as required by GDPR.
Under GDPR Article 6, we process your personal data based on the following legal grounds:
Processing is necessary to provide our scheduling and workforce management services to you. This includes creating shifts, managing schedules, team communication, and time tracking.
We rely on your explicit consent for marketing communications, analytics, and non-essential cookies. You can withdraw consent at any time through your account settings.
We process certain data based on our legitimate interests in fraud prevention, security monitoring, improving our services, and ensuring platform stability. We balance these interests against your privacy rights.
We process and retain certain data to comply with legal requirements, such as tax laws, labor laws, and data breach notification requirements.
For detailed information about what data we collect and how we use it, please see our Privacy Policy. The categories of personal data we process include:
Identity data: Name, email, phone number, date of birth
Contact data: Address, emergency contact information
Employment data: Organization, location, position, schedules, shifts, availability
Account data: Login credentials, MFA settings, preferences
Technical data: IP address, browser type, device information, usage data
Communication data: Messages, notifications, support inquiries
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations:
Active accounts: Data is retained indefinitely while your account is active and you continue using our services
Deleted accounts: 30-day grace period for account recovery, then permanent deletion
Backup data: Retained for 90 days in encrypted backups for disaster recovery, then automatically purged
Financial records: Retained for 7 years to comply with tax and accounting regulations
Legal holds: Data may be retained longer if required by law, litigation, or regulatory investigation
EpicShifts is based in the United States. If you are located in the EU or EEA, your personal data may be transferred to and processed in countries outside the EU/EEA, including the United States.
Data Transfer Safeguards: We ensure appropriate safeguards are in place to protect your data during international transfers:
Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses for data transfers to countries without adequate data protection
Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
Secure infrastructure: Data is hosted on AWS, whose data centers hold ISO 27001 and SOC 2 certifications, under strict security controls
Limited access: Access to EU resident data is restricted to authorized personnel who need it to provide services
For questions about how we process your personal data or to exercise your GDPR rights, you can contact our privacy team:
Email: [email protected]
Subject Line: "GDPR Request" or "Privacy Inquiry"
Response Time: We will respond to all GDPR requests within 30 days
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
Find your supervisory authority:
However, we encourage you to contact us first at [email protected] so we can address your concerns directly.
We may update this GDPR Compliance page from time to time to reflect changes in our data processing practices or to comply with legal requirements.
How we notify you of changes:
Update the "Last Updated" date at the top of this page
Send an email notification to all registered users for material changes
Display a prominent notice on our platform for significant updates
We encourage you to review this page periodically to stay informed about how we protect your privacy rights under GDPR.
Legal Disclaimer: This GDPR compliance documentation has been prepared to comply with the General Data Protection Regulation (EU) 2016/679. It is provided for informational purposes and should not be construed as legal advice. For specific legal questions about your data protection rights, please consult with a qualified legal professional or contact your local data protection authority.
We use cookies to improve your experience on our platform. Essential cookies are required for the site to function properly (authentication, security). Optional cookies help us understand how you use the site and improve our services. Learn more about cookies