ROCteams Privacy & Data Protection Policy
Last Updated: July 13, 2026 v2026-07-13
1. Data Controller and Processor Relationship
For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR), the Customer acts as the "Data Controller" and ROCteams LLC acts as the "Data Processor." ROCteams shall process Personal Data only for the purposes of providing the Services as defined in the Service Agreement and under the documented instructions of the Customer.
2. Processing Scope and Data
ROCteams processes Personal Data—including geolocation coordinates, timestamps, and fleet activity logs—solely as necessary to provide the workforce management services requested by the Customer. ROCteams shall not process such data for any independent commercial purpose.
3. Geolocation and Sensitive Data
3.1. Purpose: The platform utilizes real-time geolocation tracking to facilitate fleet management and workforce scheduling.
3.2. Customer Warranty: The Customer represents and warrants that it has obtained all necessary consents from its employees (the Data Subjects) to track their location through the ROCteams mobile application during work hours or as otherwise permitted by local law.
3.3. Minimized Processing: ROCteams commits to processing geolocation data only for the duration required to satisfy the specific workforce management task requested (e.g., active shift tracking) and will not use such data for any profiling or automated decision-making outside the scope of the Services.
4. Data Security and Integrity
ROCteams implements industry-standard technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access Control: Strict role-based access control (RBAC) ensures only authorized personnel at the Customer's organization can view fleet/employee location data.
- Isolation: Infrastructure is logically isolated to prevent unauthorized access between tenant datasets (tenant-level isolation).
- Auditing: Regular access control reviews and log-based auditing monitor administrative actions and modifications to sensitive data.
5. Sub-processors
The Customer provides general authorization for ROCteams to engage third-party sub-processors (e.g., cloud hosting, database services, or third-party email providers) provided that such sub-processors are bound by data protection obligations at least as restrictive as those herein.
6. Data Subject Requests
The Customer is solely responsible for responding to any request from an employee or individual to access, rectify, or erase their Personal Data. ROCteams will provide reasonable technical assistance to the Customer to facilitate such requests.
7. Data Deletion and Retention
7.1. Retention: ROCteams shall retain Personal Data only for as long as is necessary to provide the services or to comply with applicable legal obligations.
7.2. Post-Termination: Upon termination of the Service Agreement, ROCteams will, upon the Customer's written request, delete or anonymize all Personal Data in its possession within thirty (30) days, except to the extent that storage is required by applicable law.