Record of Processing Activities (GDPR Article 30(2))¶
Purpose. Soon's processor record of processing activities, required by Article 30(2) GDPR. It is the document a supervisory authority asks for first, and the one enterprise buyers request during security review. It also satisfies A.5.34 (privacy and protection of PII) and supports A.5.31 (legal requirements).
Soon is a processor, not a controller, for customer workforce data. The customer decides why and how their employees' data is processed; Soon processes it on their documented instructions. Soon is a controller for its own employee and prospect data, which is recorded separately in §6.
1. The processor and its representative¶
| Processor | Soon Technologies B.V., Netherlands |
| Contact for data protection | security@soon.works |
| Representative in the EU | Not applicable — Soon is established in the EU |
| Data Protection Officer | Not appointed. Assessed under Art. 37: Soon does not carry out large-scale systematic monitoring, nor large-scale processing of special categories, as a core activity. The analysis is recorded in the Privacy and Personal Data Protection Policy §2.6 and is revisited annually |
2. Controllers on whose behalf Soon processes¶
Article 30(2)(a) asks for each controller. Naming every customer in a document that is shared externally would itself disclose the customer list, so controllers are recorded here by category, with the identified list held in the CRM and the executed DPAs in Drive.
| Category of controller | Relationship | Where identified |
|---|---|---|
| Enterprise customers | Signed MSA + DPA | Google Drive → Legal → Customers |
| Self-serve customers | DPA incorporated into the online terms at soon.works/legal/terms | Attio (CRM) + billing records in Stripe |
| Trial and pilot accounts | Same terms as self-serve for the trial period | Attio |
An identified, current controller list is available to a supervisory authority on request.
3. Categories of processing carried out for controllers¶
Article 30(2)(b). Soon carries out these operations on customer personal data:
| Processing activity | Purpose (set by the controller) | Categories of data subject | Categories of personal data |
|---|---|---|---|
| Workforce scheduling | Creating, publishing and amending shift schedules | The controller's employees and contractors | Name, work email, role, team, skills, employment identifiers |
| Availability and leave management | Recording availability, leave requests and approvals | Same | Working hours, availability, leave dates and types — may include absence records (see §7) |
| Demand forecasting and auto-scheduling | Predicting demand and proposing assignments | Same | Historical schedule and activity data |
| Time and activity tracking | Recording worked time and intraday activity | Same | Timestamps, activity categories |
| Authentication and access | Letting users into the controller's tenant | Same | Email address, authentication identifiers, SSO attributes, IP address |
| Notifications | Sending schedule and account notifications | Same | Name, email address, device push tokens |
| Support | Responding to user questions | Users who contact support | Name, email, the contents of the conversation |
| Optional integrations | Only where the controller enables them — calendar sync, contact-centre platforms | Same | Calendar identifiers, agent identifiers, activity data |
| Optional location features | Where the controller uses location-based scheduling | Same | Work location, address input |
Retention. For the duration of the customer contract, then deleted 90 days after contract end; backups age out on their own cycle. Per the Records Retention & Protection Policy.
4. Sub-processors and third-country transfers¶
Article 30(2)(c). The full list, with what each one does, is the Vendor & Sub-processor Register. Recorded here is the transfer position for each.
| Sub-processor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (incl. SES) | Hosting, database, transactional email | eu-west-1, Ireland | No transfer — data remains in the EU |
| PostHog | Product analytics | EU Cloud | No transfer |
| Cloudflare | DNS, CDN, hosting | Global edge | TODO(owner): record the mechanism — DPF certification or SCC module — and the date checked |
| Stripe | Payments | EU / US | TODO(owner): as above |
| WorkOS | Enterprise SSO | US | TODO(owner): as above |
| Intercom | Support | US | TODO(owner): as above — and a transfer impact assessment, as this carries identifiable conversation content |
| Sentry | Error tracking | To confirm | TODO(owner): confirm the project region first; the mechanism follows from it |
| Cloudinary | Media hosting | EU / US | TODO(owner): as above |
| OpenAI | AI features | US | TODO(owner): mechanism, plus the zero-retention / no-training API terms |
| Google (Workspace, Maps) | Collaboration, address lookup | EU / global | TODO(owner): as above |
These are the register's genuine open items. Each needs the mechanism recorded — an adequacy decision under the EU-US Data Privacy Framework, with the provider's certification checked on the DPF list and the date noted, or the relevant SCC module — and a short transfer impact assessment for those carrying identifiable customer data. Intercom first. Tracked as S-411.
Sub-processor changes are notified to controllers per the DPA before the new sub-processor begins processing.
5. Technical and organisational measures¶
Article 30(2)(d), by reference to Article 32(1). Described in full in the Security Overview and the policies it cites. In summary: encryption in transit (TLS 1.2+) and at rest (AES-256); role-based least-privilege access with MFA on the AWS console and Google Workspace; segregated environments; centralised logging with continuous threat detection; peer-reviewed change management; automated dependency and vulnerability scanning; Multi-AZ hosting with point-in-time recovery; and a documented incident-response process with a defined breach-notification path.
6. Soon as controller (its own data)¶
Recorded for completeness — this part falls under Article 30(1).
| Activity | Data subjects | Data | Retention | Basis |
|---|---|---|---|---|
| Employment and payroll | Founders, contractors | Contract, payroll, banking | Statutory (NL) | Legal obligation / contract |
| Sales and marketing | Prospect contacts | Name, work email, company | Until objection or 24 months inactive | Legitimate interest |
| Website analytics | Site visitors | Usage events, IP | Per provider settings | Consent — gated by the cookie banner |
| Support and billing | Customer contacts | Name, email, billing details | Contract + statutory | Contract |
7. Absence and sickness data — a deliberate position¶
Leave management is a core function, so the product can hold absence records. Dutch law is unusually strict here: the Autoriteit Persoonsgegevens permits an employer to record that someone is absent and the expected duration, but not the nature of the illness.
Soon's position: the product records absence as a category and a period. It does not ask for, and controllers should not enter, a medical reason. Where a controller's own configuration permits free-text entry against an absence, that field is under the controller's control and Soon's guidance is that it must not carry health information.
TODO(owner): confirm with Thomas which absence-related fields the product exposes,
including whether any free-text field can reach an absence record, so this position is
stated from the schema rather than from intent.
8. Assisting controllers¶
Under Article 28(3)(e) Soon assists controllers with data-subject requests. In practice a controller can export or delete their own tenant's data through the product; where they cannot, security@soon.works handles the request and Soon responds within 5 working days so the controller can meet its own one-month deadline. Deletion actions are recorded in Linear.
Related documents¶
- Privacy and Personal Data Protection Policy · Personal Data Breach Notification Procedure
- Vendor & Sub-processor Register · Records Retention & Protection Policy
- Information Asset Inventory · System Description
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-08-22 | ISMS | First version — the Article 30(2) processor record the Privacy Policy referenced but which had never been written. Controllers recorded by category; nine processing activities described; transfer mechanisms listed per sub-processor with the open ones marked; the Dutch absence-data position stated. |