Book a demo
LegalData Act

Data portability, hosting and switching

On this page, Rostify GmbH, as provider of Rostify® (Software-as-a-Service), provides the information required by Regulation (EU) 2023/2854 (Data Act) on switching, data export, locations of data processing and charges. The binding rules are set out in the respective contract or in the Terms and Conditions (section 12).

As of
1 October 2026
Language
EnglishDeutsch
Contents
6 ·

Draft — open points are highlighted · 1

01Switching and data export

1.1 Request. The Customer may at any time request in writing that Rostify transfer its exportable data to another provider or to the Customer’s own infrastructure, or that Rostify delete it. An e-mail to office@rostify.app is sufficient. The notice period is two months.

1.2 Process.

  • Transition period: no more than 30 calendar days. During this time Rostify continues to provide the contractual services, supports the Customer with the switch and informs it of known risks to continuity.
  • If the transition period is technically not feasible, Rostify notifies the Customer within 14 working days of the request, stating the reasons. The transition period is then no more than seven months. The Customer may extend it once by a reasonable period.
  • Retrieval period: the Customer can then retrieve its data for at least a further 30 calendar days.
  • Deletion: Rostify then deletes Customer Data completely. Backup copies are deleted when their 14-day retention period expires. Rostify confirms deletion in writing on request.

1.3 Methods and formats. Rostify provides the exportable data as files in CSV and JSON format (UTF-8 encoding). There is one file per data category, together with a description of the data structure. The files are made available for download over an encrypted connection or delivered by a method agreed with the Customer.

1.4 Known limitations.

  • Rostify does not transfer data directly into another provider’s software. Converting data into that provider’s format is not part of the switch (see section 5).
  • Settings and planning rules are exported. Their effect, however, depends on Rostify’s calculation logic. Another system may evaluate them differently or not at all.
  • Passwords are stored only as hashes and are not exported. Participants need new credentials at the new provider.
  • Interfaces set up for a single customer are not transferred.

02Exportable data (data structures and formats)

Exportable data means exhaustively the following data entered by the Customer and its participants or generated by their use of the software:

Data category Format
Organisation, units and their settings CSV, JSON
Participants with master data, contact data, roles and assignments CSV, JSON
Duties, duty types and patterns CSV, JSON
Rosters including targets, changes, publications and archived versions CSV, JSON
Absences, follow-up reports, leave requests and leave accounts CSV, JSON
Requests and shift swaps CSV, JSON
Time recording, time accounts, overtime and overtime requests CSV, JSON
Licences, ratings, their renewals and licence requirements per duty CSV, JSON
Daily OPS plans, sectors and sector times CSV, JSON
E-briefing content, recipients and read confirmations CSV, JSON
Uploaded files (e-briefing) original format
Settings, planning rules, thresholds and text templates defined by the Customer JSON
Logs of notifications sent and of participants’ logins CSV, JSON
Metadata for these data, in particular the time and author of creation and modification within the respective files

Not exportable are exhaustively:

  • the program code, algorithms and calculation logic of the software,
  • internal operating and security logs of Rostify’s infrastructure,
  • access secrets that serve only the operation of the software (password hashes, session and device tokens).

Rostify provides the field description for each file together with the export. [Publish field description per file here once the export tool is ready]

03Locations and jurisdiction

3.1 Rostify operates the software on servers in data centres in Austria, Germany and France. The infrastructure is subject to the law of the European Union and of the respective Member State.

3.2 Rostify GmbH has its registered office in Vienna, Austria. Data centre services are provided by Host Europe GmbH and STRATO AG, both with their registered office in Germany.

3.3 Outside Rostify’s servers, only messages are processed:

  • Push notifications to mobile devices are delivered via Apple and Google, including in the USA. Only the device token and the text of the message are transmitted, not the data sets.
  • Text messages (SMS) are sent via a service provider in the Czech Republic.

04Protection against government access from third countries

Rostify takes the following measures against government access from third countries to data stored in the EU where such access would conflict with Union law or the law of a Member State.

Technical measures

  • Customer Data is stored exclusively in data centres in the EU.
  • Access takes place only over encrypted connections (HTTPS/TLS); backups are stored encrypted.
  • Administrative access is protected by two-factor authentication.

Organisational measures

  • Rostify examines every request from a third-country authority or court for the disclosure of Customer Data.
  • Rostify discloses data only where the conditions of Article 32 of Regulation (EU) 2023/2854 are met, and then only the minimum amount.
  • Rostify informs the Customer before complying with such a request, except for requests for law enforcement purposes for as long as informing the Customer would undermine their effectiveness.

Contractual measures

  • For personal data, the data processing agreement applies in addition.

05Charges

5.1 Standard service charges: the usage fees set out in the offer or licence certificate (per module and participant tier).

5.2 Switching charges: none. Switching, export and deletion are free of charge.

5.3 Early termination: contracts run for a fixed term (initial term as set out in the offer, then renewed by 12 months at a time). If a contract ends through a switch before the end of the current term, the Customer pays as compensation the usage fees until the end of that term, less the expenses Rostify saves. The compensation is capped at six monthly fees.

5.4 Additional services: services beyond the statutory obligations, such as converting data into another provider’s format, are charged on a time-and-materials basis.

06Contact

Rostify GmbH, Tigergasse 17, 1080 Vienna, Austria · office@rostify.app · +43 1 4120052

↑ Back to top