Skip to content

Record of Processing Activities (GDPR Article 30(2))

Purpose. Soon's processor record of processing activities, required by Article 30(2) GDPR. It is the document a supervisory authority asks for first, and the one enterprise buyers request during security review. It also satisfies A.5.34 (privacy and protection of PII) and supports A.5.31 (legal requirements).

Soon is a processor, not a controller, for customer workforce data. The customer decides why and how their employees' data is processed; Soon processes it on their documented instructions. Soon is a controller for its own employee and prospect data, which is recorded separately in §6.

1. The processor and its representative

Processor Soon Technologies B.V., Netherlands
Contact for data protection security@soon.works
Representative in the EU Not applicable — Soon is established in the EU
Data Protection Officer Not appointed. Assessed under Art. 37: Soon does not carry out large-scale systematic monitoring, nor large-scale processing of special categories, as a core activity. The analysis is recorded in the Privacy and Personal Data Protection Policy §2.6 and is revisited annually

2. Controllers on whose behalf Soon processes

Article 30(2)(a) asks for each controller. Naming every customer in a document that is shared externally would itself disclose the customer list, so controllers are recorded here by category, with the identified list held in the CRM and the executed DPAs in Drive.

Category of controller Relationship Where identified
Enterprise customers Signed MSA + DPA Google Drive → Legal → Customers
Self-serve customers DPA incorporated into the online terms at soon.works/legal/terms Attio (CRM) + billing records in Stripe
Trial and pilot accounts Same terms as self-serve for the trial period Attio

An identified, current controller list is available to a supervisory authority on request.

3. Categories of processing carried out for controllers

Article 30(2)(b). Soon carries out these operations on customer personal data:

Processing activity Purpose (set by the controller) Categories of data subject Categories of personal data
Workforce scheduling Creating, publishing and amending shift schedules The controller's employees and contractors Name, work email, role, team, skills, employment identifiers
Availability and leave management Recording availability, leave requests and approvals Same Working hours, availability, leave dates and types — may include absence records (see §7)
Demand forecasting and auto-scheduling Predicting demand and proposing assignments Same Historical schedule and activity data
Time and activity tracking Recording worked time and intraday activity Same Timestamps, activity categories
Authentication and access Letting users into the controller's tenant Same Email address, authentication identifiers, SSO attributes, IP address
Notifications Sending schedule and account notifications Same Name, email address, device push tokens
Support Responding to user questions Users who contact support Name, email, the contents of the conversation
Optional integrations Only where the controller enables them — calendar sync, contact-centre platforms Same Calendar identifiers, agent identifiers, activity data
Optional location features Where the controller uses location-based scheduling Same Work location, address input

Retention. For the duration of the customer contract, then deleted 90 days after contract end; backups age out on their own cycle. Per the Records Retention & Protection Policy.

4. Sub-processors and third-country transfers

Article 30(2)(c). The full list, with what each one does, is the Vendor & Sub-processor Register. Recorded here is the transfer position for each.

Sub-processor Role Location Transfer mechanism
Amazon Web Services (incl. SES) Hosting, database, transactional email eu-west-1, Ireland No transfer — data remains in the EU
PostHog Product analytics EU Cloud No transfer
Cloudflare DNS, CDN, hosting Global edge TODO(owner): record the mechanism — DPF certification or SCC module — and the date checked
Stripe Payments EU / US TODO(owner): as above
WorkOS Enterprise SSO US TODO(owner): as above
Intercom Support US TODO(owner): as above — and a transfer impact assessment, as this carries identifiable conversation content
Sentry Error tracking To confirm TODO(owner): confirm the project region first; the mechanism follows from it
Cloudinary Media hosting EU / US TODO(owner): as above
OpenAI AI features US TODO(owner): mechanism, plus the zero-retention / no-training API terms
Google (Workspace, Maps) Collaboration, address lookup EU / global TODO(owner): as above

These are the register's genuine open items. Each needs the mechanism recorded — an adequacy decision under the EU-US Data Privacy Framework, with the provider's certification checked on the DPF list and the date noted, or the relevant SCC module — and a short transfer impact assessment for those carrying identifiable customer data. Intercom first. Tracked as S-411.

Sub-processor changes are notified to controllers per the DPA before the new sub-processor begins processing.

5. Technical and organisational measures

Article 30(2)(d), by reference to Article 32(1). Described in full in the Security Overview and the policies it cites. In summary: encryption in transit (TLS 1.2+) and at rest (AES-256); role-based least-privilege access with MFA on the AWS console and Google Workspace; segregated environments; centralised logging with continuous threat detection; peer-reviewed change management; automated dependency and vulnerability scanning; Multi-AZ hosting with point-in-time recovery; and a documented incident-response process with a defined breach-notification path.

6. Soon as controller (its own data)

Recorded for completeness — this part falls under Article 30(1).

Activity Data subjects Data Retention Basis
Employment and payroll Founders, contractors Contract, payroll, banking Statutory (NL) Legal obligation / contract
Sales and marketing Prospect contacts Name, work email, company Until objection or 24 months inactive Legitimate interest
Website analytics Site visitors Usage events, IP Per provider settings Consent — gated by the cookie banner
Support and billing Customer contacts Name, email, billing details Contract + statutory Contract

7. Absence and sickness data — a deliberate position

Leave management is a core function, so the product can hold absence records. Dutch law is unusually strict here: the Autoriteit Persoonsgegevens permits an employer to record that someone is absent and the expected duration, but not the nature of the illness.

Soon's position: the product records absence as a category and a period. It does not ask for, and controllers should not enter, a medical reason. Where a controller's own configuration permits free-text entry against an absence, that field is under the controller's control and Soon's guidance is that it must not carry health information.

TODO(owner): confirm with Thomas which absence-related fields the product exposes, including whether any free-text field can reach an absence record, so this position is stated from the schema rather than from intent.

8. Assisting controllers

Under Article 28(3)(e) Soon assists controllers with data-subject requests. In practice a controller can export or delete their own tenant's data through the product; where they cannot, security@soon.works handles the request and Soon responds within 5 working days so the controller can meet its own one-month deadline. Deletion actions are recorded in Linear.

Change log

Version Date Author Comments
0.1 2026-08-22 ISMS First version — the Article 30(2) processor record the Privacy Policy referenced but which had never been written. Controllers recorded by category; nine processing activities described; transfer mechanisms listed per sub-processor with the open ones marked; the Dutch absence-data position stated.