Skip to content

Privacy and Personal Data Protection Policy

Purpose. Sets out how Soon complies with the GDPR. Soon's core business is processing workforce data (schedules, leave, work location) on behalf of its customers as a data processor; it is also a controller for its own employee, prospect and website data. All customer data is hosted in AWS eu-west-1 (EU).

1. Scope

Applies to all personal data Soon processes: customer workforce data (as processor), and Soon's own employee, applicant, customer-contact, marketing and website-visitor data (as controller). Applies to all employees and contractors and to every system that stores personal data.

2. Policy

2.1 GDPR principles

Soon processes personal data in line with the GDPR principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. In practice this means: we collect only what the service or business purpose needs, keep it only as long as needed (see the Records Retention & Protection Policy), protect it with encryption (TLS 1.2+ in transit, AES-256 at rest) and role-based access, and can demonstrate compliance through the records in this ISMS.

2.2 Soon as data processor (core business)

For customer workforce data, the customer is the controller and Soon is the processor. Soon must:

  • Process customer personal data only on the customer's documented instructions, as set out in the DPA, and never for Soon's own purposes.
  • Keep customer data in the EU (AWS eu-west-1); any transfer outside the EU requires a valid GDPR transfer mechanism and must be reflected in the DPA.
  • Maintain a published sub-processor list and notify customers of changes as the DPA requires. TODO(owner): confirm where the sub-processor list is published and the notice period committed.
  • Engage sub-processors only under contracts imposing equivalent data-protection obligations (see the Supplier Relationships Security Policy).
  • Assist customers with data subject requests: because workforce data is segmented per tenant, Soon supports customers' access, rectification, erasure and portability obligations via the product or on request; requests received directly from data subjects are forwarded to the relevant customer.
  • Notify the affected customer without undue delay after becoming aware of a personal data breach involving their data, providing the information the customer needs for its own 72-hour notification duty.
  • Return and/or delete customer data at the end of the service per the DPA.
  • Inform the customer if, in Soon's view, an instruction infringes the GDPR, and if Soon is legally compelled to disclose customer data (unless prohibited).

2.3 Soon as controller (own data)

For its own employee, applicant, prospect and website data, Soon must have a lawful basis for each processing activity, provide privacy notices at the point of collection, and obtain valid consent where consent is the basis (e.g. non-essential cookies/analytics) — freely given, informed, and as easy to withdraw as to give. TODO(owner): confirm the public privacy notice location and that PostHog/Intercom tracking is covered by it.

Data subjects can exercise their GDPR rights against Soon as controller. Requests must be handled within these timescales:

Right Timescale
To be informed At collection (or within one month if data not collected from the subject)
Access, rectification, portability, objection One month
Erasure, restriction of processing Without undue delay

TODO(owner): confirm the intake channel for data subject requests (e.g. privacy@ alias) and who handles them.

2.4 Privacy by design

New or significantly changed features and systems that process personal data must consider privacy from the design stage: data minimisation, pseudonymisation where practical, access restrictions, and retention. Where processing is likely to result in a high risk to individuals, a Data Protection Impact Assessment (DPIA) must be completed before go-live. TODO(owner): confirm whether any DPIAs exist today and where they are stored.

2.5 Records of processing

Soon maintains a record of processing activities (RoPA) covering: purposes, categories of data subjects and data, recipients and sub-processors, transfers, retention, and security measures. TODO(owner): confirm RoPA location and owner.

2.6 Data Protection Officer analysis

Soon has assessed the GDPR Article 37 criteria and concluded a DPO is not mandatory:

  • Public authority: Soon is a private SaaS company — not a public authority.
  • Large-scale systematic monitoring: Soon processes workforce data segmented per customer tenant; this is not large-scale systematic monitoring of the public.
  • Special categories at scale: Soon does not process special-category data at scale (occasional sick-leave flags are limited in volume and scope).

Although not required, Soon has assigned internal accountability for privacy to a designated Privacy Officer role, which oversees GDPR and ISO 27001 privacy obligations. TODO(owner): confirm who currently holds the Privacy Officer role. This analysis is reviewed annually and whenever processing changes materially.

2.7 Personal data breaches

Personal data breaches are handled under the Information Security Incident Response Procedure. Where Soon is controller and the breach is likely to risk individuals' rights and freedoms, the supervisory authority is notified within 72 hours (and affected individuals where the risk is high). Where Soon is processor, the affected customer is notified without undue delay (see 2.2). All breaches, notified or not, are documented.

3. Roles & responsibilities

  • Privacy Officer (TODO(owner): confirm holder) — owns this policy, the RoPA and the DPO analysis; handles data subject requests and breach notifications; advises on DPIAs.
  • Engineering — implements privacy by design, EU residency, deletion and export capabilities.
  • All staff — handle personal data per this policy and report suspected breaches immediately.

Change log

Version Date Author Comments
0.1 2023-10-23 Olaf Jacobson First draft document
0.2 2026-07-18 Andrea Cardinali Tailored to Soon (ISMS overhaul) — condensed GDPR lecture/definitions, kept processor obligations, DPO analysis and breach handling