Buyer’s manual
💳 For decision-makers
A bright residential corridor in the morning, looking out onto greenery
Manual 4 of 5 · buyer’s manual · release r396

Rosie — the basis for your decision

What Rosie is, what it does, who it suits and how safe your data is. This manual gathers everything a decision-maker needs: features, compliance evidence, the migration path and the route from first contact to live use. Prices are in this manual; the scope of rollout and support is settled in the advisory meeting.

💳 Decision-makers 🇨🇭 Swiss made 🔒 Swiss FADP 📋 DPA Release r396
❓

What is Rosie?

An honest description

Rosie is web-based rostering software for shift-based organisations — usable as an app on a phone or in a web browser. Swiss made, mobile first. Staff can see their roster at any time, complete the tasks for their shift, report sick or request holidays. Managers plan more efficiently — by hand, with the brush tool or fully automatically using AI.

🤖
What Rosie is NOTRosie is not a staffing agency, not payroll accounting software (it only prepares the figures via the month-end close), not a time clock with a physical terminal, and not a performance-appraisal tool. Rosie focuses on rostering, task management, communication and absence management.
🇨🇭
Swiss made
Swiss data-protection standards, cantons and public holidays built in. A legal engine aligned with the Swiss Employment Act.
☁️
Web app / cloud
No installation, no app store required. Open the browser, sign in, get going.
🔒
Encrypted hosting
Encrypted in transit (TLS 1.3) and at rest (AES-256). Built to the revised Swiss FADP; a data processing agreement with a complete sub-processor list.
📱
Mobile first
Works on any smartphone. Installable straight from the browser. Starts instantly thanks to the service worker; a connection is needed to actually work.
🎯

Which organisations is Rosie for?

Healthcare as the lead sector — and other shift-based organisations

Rosie was developed around the requirements of care work . The architecture is sector-neutral: any shift-based organisation with early, late and night patterns, break rules and role-based approvals can be modelled. We name reference customers only with their written consent; ask us in the advisory meeting.

🏥
Healthcare (lead sector)
Care homes, hospitals, home care — a dedicated care-management role, hospital defaults, early/late/night rotation.
🍽️
Hospitality
Restaurants, hotels, catering — changing shifts with a break mode per shift type.
🛍️
Retail
Shops with early and late shifts and weekend cover.
🔒
Security
Security services with round-the-clock cover and a relief pool for absences.
👶
Social services
Nurseries and social services — changing part-time teams with a preference budget.
🚌
Transport / industry
Timetables, production and warehouse teams. Configurable on request.
💡
Best suited to 5–200 staffRosie is designed for medium-sized organisations. Below five people, planning by hand is often enough. Above 200 people we recommend an Advisory meeting for a tailored configuration.
⭐

Why Rosie?

Five things that set Rosie apart today
🇨🇭
Swiss made
Provider, development and data hosting in Switzerland. Digital Passion GmbH (Olten SO) is both the provider and the processor — you have one contracting party, not a middleman.
📱
A web app — usable straight away
No app store, no rollout headaches. Open the browser, sign in, done.
🔒
Real compliance
Built to the revised Swiss FADP, a data processing agreement with a sub-processor list, HSTS preload (a two-year pin), and a hash-chained audit trail for tasks and shift changes.
🔁
Multi-device sync
Synced with the server in seconds — phone, tablet, browser. Chat messages can be written offline and go out as soon as the network is back.
🌐
Multiple languages
Four interface languages (DE/FR/IT/EN) and chat translation into 14 languages, performed on the device.
🧩

Feature overview

What Rosie actually does — release r396
🤖
AI rostering with a legal engine
The solver takes account of preferences, absences, holidays, cantonal public holidays and Employment Act rules (11 hours’ rest, maximum shift length, early→late→night rotation, weekly hours).
🎨
Brush tool and carry-over
Fast painting of shifts, an interactive monthly matrix with coverage percentages and blueprint presets.
🔄
Shift swaps (mutations)
A multi-level approval workflow with a timeline and approval straight from the push notification.
💰
Cover bonuses and stand-in assignments
Advertise open shifts with a cover bonus, or manage stand-in assignments with allowances — kept separate in the payroll export.
✋
Preference budget
Configurable per area and priority (1–3), on a rolling or fixed window. Planners can enter preferences on someone’s behalf.
🏖️
Holiday workflow
A request with start and end dates, approval directly from the notification, automatic entry in the calendar.
📋
Tasks per shift
A shift-flow view, AI pattern recognition (four levels, anonymised prompts) and links to quality-management documents.
🤒
Absence management
Automatic sync with the calendar and the roster, configurable approver roles, an audit trail secured by a hash chain.
📊
Month-end close
An editor for hours, breaks and allowances; export as CSV and PDF for payroll. An XLSX export is in progress but not yet available.
🔐
Hash-chained audit trail
A tamper-evident hash chain for tasks, absences and shift changes, in line with the revised Swiss FADP.
👥
Multiple roles and fine-grained rights
Several roles per person and four separate approval levels (rostering, working hours, task ownership, shift swaps).
🔔
Push notifications (RFC 8291)
Organisation-wide quiet hours, controllable per category, with a persistent inbox behind the bell.
🎙️
Voice control
Seven commands (sickness, shift preference, holidays, swap, status, navigation, help). ROSIE receives no audio recordings; speech-to-text conversion is handled by the speech recognition service of the browser or operating system. Only the recognized text is sent, with consent, to an AI for recognition.
📎
Documents on tasks
Attach photos and PDFs from the device to tasks — on a phone directly with the camera, up to 3 MB, stored encrypted, visible only to those involved.
An empty reception desk in the evening
Security and law

What you can rely on

Data protection, employment law, tenant separation and the sectors Rosie is designed for.

🔒

Data protection & Security

Promises with evidence — not marketing noise

Rosie is built and operated to the revised Swiss data protection act. We rely on demonstrable measures rather than slogans. Every point below can be verified in the code, in the migrations or in the operating documentation.

PromiseEvidence
Hosting & Data hosted in SwitzerlandCompute, database, object storage and backups run at Infomaniak in Switzerland. Everyone else involved is named in the sub-processor list of the data processing agreement.
No trackingThe Do Not Track signal is honoured; no third-party analytics, no cookies.
Security headersHSTS preload (two-year max-age), SRI, a strict CSP, X-Worker-Version for forensics.
Audit trailA hash chain for tasks and absences, an audit ledger for shift changes.
Data minimisationA personal-data scrubber runs before any analytics; AI prompts carry no personal reference (the data-protection firewall).
AvailabilityA service-worker cache for fast start-up and consistency across devices.
AccessibilityA global Escape key and focus trap in modal dialogs, an ARIA progress bar for the setup wizard.
Multiple languagesFour interface languages DE/FR/IT/EN, chat translation into 14 languages, definitions available for Romansh, Albanian and Bosnian.
📜
Revised Swiss FADP
Data minimisation and the rights of access, rectification and erasure. Consent under Art. 6(6) FADP before voice control, art. 25 FADP for access and export.
🇨🇭
Data hosted in Switzerland
Compute, database, object storage and backups sit at Infomaniak in Switzerland. Everyone else involved — the protective service in front of the public website, the payment provider, email delivery — is named in the sub-processor list of the data processing agreement.
🤖
Human in the loop
Art. 21 FADP: AI suggestions (open-shift suggestions, task pattern recognition) require human approval.
🗝️
Key destruction
Destroying the keys and wiping local storage and the service worker is the operational revocation at the end of the contract.
🔍
Verifiable in one commandThe security headers can be checked at any time — for example with curl -I https://rosie-app.ch. The HSTS preload pin lasts two years (max-age=63072000); X-Worker-Version shows the active release number, for forensics and support.
🏥

Suitable sectors

Healthcare as the lead sector, generic coverage elsewhere

Rosie was developed with the healthcare sector — care management as a role of its own, hospital defaults, early/late/night rotation, wards, areas and tasks per shift. Other sectors are covered generically: early/late/night shifts, break modes (paid or unpaid), night-rest rules, weekend and public-holiday logic.

🏥
care work & Home care
Care homes, home care and hospitals are modelled through roles, areas and shift types — the special employment-law rules for care work can be switched on, but are not a prerequisite.
⚙️
Shift work in general
Every shift type is freely definable (name, abbreviation, times, break, colour, area, role restriction). No rigid sector templates.
🌍
Multilingual in daily use
DE/FR/IT/EN for the interface, chat translation into 14 languages — a fit for multilingual teams.
A nurse in a bright corridor, tablet in hand
Getting started

From decision to first roster

Data migration, trial phase, purchase process and the data processing agreement, in plain words.

🚚

Migration & Initial setup

From spreadsheet to a live system

Migration from an existing system runs through a CSV import for master data. A built-in data-protection filter automatically blocks sensitive fields (social security number, IBAN, religion, salary, health data) — they are entered separately and under control.

1
Create the organisation — name, sector, canton, default language.
2
Wards / departments — define structures and areas.
3
Configure shift types — per shift type: name, abbreviation, times, break (paid or unpaid), colour, area.
4
Invite staff — by email from support@rosie-app.ch; everyone signs in themselves.
5
Confirm compliance — accept the data-protection notice and the AI consent, then create the first roster.
⏱️
A realistic estimateA first sign-in takes about 30 minutes. A clean setup with roles, areas, preference budgets and configured approval levels realistically takes two to four hours — we will guide you through it if you wish.
🧪

Trial mode

Try it out calmly before deciding

You can try Rosie free of charge and without obligation — 14 days with the full feature set. After that, access stays open read-only for 30 days so nothing is lost; your data remains exportable for 90 days. We warn you seven days and one day before each change. Which optional modules are enabled during the trial is settled in the Advisory meeting.

🎯
What is worth tryingRun through the setup wizard, build one roster by hand and one with the AI, simulate a sickness report, request and approve a shift swap, create a task linked to a quality document. Feel free to experiment: everything is reversible.
🛒

From first contact to live use

Six steps, no surprises
1
Contact — an enquiry via the advisory form or by email to support@rosie-app.ch.
2
Advice — we clarify needs, sector, headcount, modules and timing, and demonstrate the features that fit your situation.
3
Trial — you get your own tenant to try out, with test data or your own structures.
4
Sign the data processing agreement — sign the data processing agreement before going live.
5
Contract & Activation — service terms are set out in the contract, then your live tenant is activated.
6
Training & Go-live — administrator training, optional staff onboarding, then live operation.
📞
What Rosie costsEntry plan: CHF 199 per month for up to 15 staff. Compliance plan: CHF 399 per month plus CHF 2.90 per active staff member — adding the audit trail, month-end close, payroll export and evidence packages. Enterprise on request. All prices exclude VAT, billed annually, payable within 30 days. Rollout is invoiced separately; its scope and support are matched to your organisation.
📋

The data processing agreement, in plain words

What a data processing agreement covers

The data processing agreement is the legal basis on which Rosie processes personal data on behalf of your organisation. It sets out who carries which responsibility and which security measures apply.

🏢
Controller and processor
Your organisation is the controller of your staff’s data. Rosie processes it on your instructions — and nothing beyond that.
🔒
Technical measures
Encryption (TLS 1.3 and AES-256 at rest), access control, audit logs, backup and recovery.
📍
Sub-processor list
Every provider involved, with its seat and purpose, as required by art. 19 para. 4 FADP. Standard contractual clauses apply to those outside Switzerland. We announce changes 30 days in advance; you may object and terminate at the end of the quarter.
🚪
End of contract
Export of your data and demonstrable erasure — including destruction of the keys.
A team on a coffee break in the staff room
Afterwards

Operation, support and exit

What happens after the purchase, what support there is, and how you take your data with you.

🚀

What happens after the purchase?

Four steps to the first live roster
1
Activation email — you receive your administrator access with a first sign-in link. If you sign up your organisation yourself, ROSIE suggests matching entries from the commercial register (Zefix) and fills in the company name and address; everything stays editable.
2
Setup wizard — six steps: privacy notice → organisation → shift types → import staff → target hours → done. Weekly hours at 100% and working days per week are required; ROSIE doesn’t suggest a number. An accessible progress bar shows how far you are; you can pause at any time.
3
Invite staff — an email invitation per person; everyone signs in themselves and completes their own details.
4
Create the first roster — by hand, with the brush tool or straight from the AI. Publishing sends a notification to all staff.
🤝
Support is optionalYou can start on your own or book on-site or remote training. We recommend brief support for the first two month-end closes.
📤

Termination & Getting your data out

Fair, transparent, documented

You can try Rosie terminate at any time. After termination you have a 30-day export window in which you can download all master data, rosters, tasks and audit logs. Final erasure follows, with a certificate of erasure — in line with the retention duties under art. 958f of the Swiss Code of Obligations and the data processing agreement.

📅
30-day export window
Master data, rosters, tasks and the audit trail — as CSV and JSON.
🗑️
certificate of erasure
Written confirmation of final erasure, including destruction of the keys.
📜
Retention under the Code of Obligations and the DPA
Retention and erasure duties are documented; the ten-year retention under art. 958f of the Code of Obligations remains your duty as the employer.
🎓

Support & Training

How we support you

The scope of service is not forced into rigid tiers — we match it to your organisation. The following building blocks are available:

📧
Email support
support@rosie-app.ch — an address you can reply to. Response times are governed by the service contract.
🤖
AI-assisted help
Contextual help inside the app (the ℹ️ button), including an AI assistant for common questions and explanations.
🏫
Administrator training
Setup wizard, structures, shift types, preference budget, first roster, month-end close — remote or on site.
👥
Staff training
Install the app, read the roster, enter preferences, complete tasks, report sick.
📍
On-site support
On request, on site for the go-live and the first month-end closes.
🧑‍💼
A named contact
A permanent point of contact for larger organisations — the scope is agreed in the advisory meeting.
❓

Frequently asked questions before buying

What decision-makers usually ask
Do we have to install anything?
No. Rosie is a progressive web app: open the browser, sign in, done. On a phone, “Add to home screen” gives it the feel of an app and enables notifications on iOS.
Does Rosie work offline?
Only partly — and that is deliberate. The service worker keeps the app itself locally, so it starts without a network. The roster data is deliberately not cached on the device: it contains particularly sensitive personal data (reasons for absence, sickness reports), and Rosie often runs on shared ward computers. We trade offline convenience for data protection. Working with Rosie requires a connection; chat messages can be written offline and go out as soon as the network returns, as long as the app stays open.
Can we bring data over from our existing system?
Yes. A CSV import for master data with a built-in filter: social security number, IBAN, religion and salary are blocked and entered afterwards under control. The migration follows the data processing agreement.
Which languages are supported?
The interface is available in four languages : DE, FR, IT, EN. In addition, the 🌐 button translates chat messages into 14 languages on the device — a fit for multilingual teams.
How long does setup take?
A first sign-in takes about 30 minutes. A clean setup with roles, areas, preference budgets and approval levels realistically takes two to four hours. We will guide you through it if you wish.
What happens to our data at the end of the contract?
A 30-day export window, then final erasure with a written certificate. Destroying the keys serves as the operational revocation.
How does the AI square with data protection?
The data-protection firewall: prompts sent to the AI are anonymised, with no identifiers and no personal reference. A sanitiser strips email addresses, social security numbers, IBANs, phone numbers and dates before every model call.
How reliable is the audit trail?
A hash chain for tasks and an audit ledger for shift changes. Each entry is chained to the previous one, so tampering shows up immediately.
Does Rosie work without internet?
The service worker keeps the app itself locally, so it starts instantly. Roster data is deliberately not cached on the device, to protect it on shared ward computers.
Can staff and administrators have different rights?
Yes. Fine-grained access control with freely definable roles, several roles per person and four separate approval levels (rostering, working-time changes, task ownership, shift swaps).
📞

Request an advisory meeting

We work out your needs with you

The prices are set: entry plan CHF 199, compliance plan CHF 399 plus CHF 2.90 per active staff member, enterprise on request — per month, excluding VAT. What remains open is what your organisation needs in terms of rollout and support. That is exactly what we discuss.

📧
Email
support@rosie-app.ch — response times per the service contract.
🌐
Web
rosie-app.ch — advisory form and demo access.
🔒
Data protection requests
datenschutz@rosie-app.ch — access, rectification, erasure, export.
🎯
What you can prepare for the meetingHeadcount, number of sites or wards, typical shift patterns (early/late/night), your current system (spreadsheet, other software) and the go-live date you have in mind. That gets us to a concrete proposal faster.

Rosie buyer’s manual · version 9.9 · r396
Provider and processor: Digital Passion GmbH, Haldenstrasse 16, 4600 Olten, Switzerland · CHE-154.512.796
Questions? support@rosie-app.ch · rosie-app.ch
← Back to the overview