NightRota service privacy notice
Updated 21 September 2026 · Controlled testing
This notice covers our website, invited test workspaces and connected WhatsApp interactions. NightRota is in controlled founder testing. General customer registration and live agency staffing automation are not open. The waiting-list notice covers that separate activity if registration opens.
Who is responsible
DREAMPATH LTD, United Kingdom, operates NightRota. Contact the owner about privacy at givemorebaseradne2@outlook.com. We determine how personal information is used for our controlled testing, service administration, support and security.
When an agency uses NightRota to manage its staffing records and conversations, the agency determines those staffing purposes and we process the records on its documented instructions. Its own privacy notice also applies. Customer data-processing arrangements and the agency’s operating rules must be in place before real agency records are onboarded.
Information we use and where it comes from
We receive information you provide, information an authorised agency supplies, and information returned by authentication and messaging providers. Depending on your interaction, this includes:
- Name, email, phone number, account identifier, agency membership and contact permissions.
- WhatsApp messages, sender and recipient identifiers, timestamps, delivery/read status, replies and opt-out or permission records.
- Staffing requests, shift and booking details, availability, relevant agency-supplied eligibility information, site instructions and a worker’s reported arrival time.
- Business-account, sender and template identifiers and connection credentials needed to operate an authorised WhatsApp connection.
- Technical request information, access/security records and an audit of operational actions.
Current founder tests use synthetic staffing scenarios and authorised test contacts. Do not send patient details, medical records, identity documents, passwords or unnecessary health information in a staffing conversation. If such information arrives, access is limited to handling the issue and deciding appropriate removal or other lawful action.
Why we use information
We use information to provide and test the requested service: authenticate participants, connect messaging, understand operational requests, apply agency rules, send relevant responses, involve a coordinator, investigate faults and protect accounts. We do not sell personal information or use staffing conversations to build advertising audiences.
For our own controlled testing, business enquiries, service administration and security, we rely on legitimate interests in developing a reliable service, responding to requests and preventing misuse. We consider the need for the information and its effect on the person concerned, limit access and use synthetic records where possible. Where we must process information to meet a specific legal obligation, that obligation is the basis. An agency is responsible for establishing the lawful basis for its own staffing processing.
Giving permission to receive WhatsApp messages is recorded separately from the legal basis for keeping an operational record. You can ask to stop further WhatsApp contact. Where we rely on consent for a particular optional purpose, you can withdraw it without affecting earlier lawful processing. Providing account and contact information is necessary to use the corresponding signed-in or messaging feature; if you do not provide it, that feature may be unavailable.
Automation and people
NightRota can interpret message text and use structured rules to assist with requests, matching and operational replies. Selected messages may be processed by the OpenAI API for interpretation. The model receives the message, its receipt time, contact category and any unfinished staffing-request details; it is not given unrestricted database access.
General staffing automation remains paused during the current test. A coordinator can review a conversation, take over and correct information. A worker’s ETA is their report, not proof of location or attendance. NightRota does not provide clinical advice. Contact us or the responsible agency if you want a person to review an automated response or action.
Who receives information
Authorised agency users can see records within their permitted workspace. Operational messages may be shared with the relevant worker, authorised care-home contact or on-call person to handle the request. Access is checked separately from a person’s claimed role; scanning a site QR code does not grant booking authority.
- Netlify hosts the web application and background processing, including incoming webhook requests.
- Supabase provides database storage and account authentication.
- Twilio and Meta/WhatsApp carry messages, connection information, templates and delivery events.
- OpenAI API interprets selected message content. We request that responses are not stored as retrievable API response objects; this does not remove the provider’s separate safety or legal retention.
- Resend sends account emails through Supabase. It does not receive complete staffing conversations through that email integration.
- Microsoft Outlook hosts correspondence you send to our current contact mailbox. Avoid including unnecessary sensitive information in an initial request.
Providers may use their own contracted subprocessors. We may also disclose limited information to professional advisers or a public authority where there is an appropriate lawful basis. A request alone does not automatically authorise disclosure. We check its basis and scope and limit what is disclosed.
International processing
Our application database is hosted in London. Hosting, communications, model processing and provider support can involve other countries, including the United States; the service does not provide UK-only processing.
The providers’ data-processing agreements contain international-transfer provisions. These include the UK Extension to the EU–US Data Privacy Framework where applicable and contractual safeguards such as standard contractual clauses with a UK addendum for transfers that need them. Their applicability depends on the provider, recipient and service. You can request information about the safeguards relevant to your data using our contact address.
Provider information: Netlify, Supabase, Twilio, OpenAI, Resend and Microsoft.
How long we keep information
During controlled testing we retain identifiable records only while they are needed to complete the relevant test, investigate an unresolved delivery/security issue, respond to a request or meet a documented legal obligation. We review that need at test closure and at least every 30 days while testing continues. Once that need ends, records are deleted or irreversibly anonymised through a reviewed process.
Account details are needed while the invited account is active; permissions and relevant audit records may need to remain while an associated request, incident or dispute is unresolved. Support correspondence is kept until the enquiry and any related issue are resolved, with any longer retention recorded and reviewed. A reason for retaining information is not permission to keep unrelated message content indefinitely.
Deletion from the active application does not instantly erase provider logs or backup copies. Those copies have separate provider retention and recovery processes and may be retained for security or legal reasons. We identify applicable limitations when handling a deletion request. We do not promise an automatic deletion interval for every provider copy. Real customer agency retention arrangements will be documented before that agency’s live data is accepted.
Cookies and technical information
Signed-in features use necessary cookies for authentication, invitation handling and agency selection. Hosting providers receive technical information needed to deliver and secure requests. We have not installed advertising pixels or behavioural analytics in the current application. Following a link to another service is subject to that service’s own notice.
Your right to object
You can object to processing based on legitimate interests by contacting us. We will consider your circumstances and explain our response. Asking for review does not require you to keep using WhatsApp.
Other rights and requests
Depending on the circumstances, you can request access, correction, deletion, restriction or portability of your information. You can also withdraw consent where it is the basis for processing. Rights are subject to applicable conditions and exceptions. If an agency controls the records, contact it or ask us to help identify the responsible agency.
Use our data-deletion and contact instructions. We may need proportionate information to verify identity and scope, and will explain the outcome within the applicable legal timeframe. You can raise a concern with us or complain to the Information Commissioner’s Office.
Changes to this notice
We will update this notice when processing changes, publish the revision date and bring material changes to affected users’ attention as appropriate. Opening customer onboarding will require updated operating and data-processing arrangements.