Legal

Data Processing Addendum

Effective: 20 August 2026 · Version 1.0

This Data Processing Addendum (“DPA”) forms part of the Leavely Terms of Service or other agreement for the Service (the “Agreement”). It applies automatically where XTRA PHONES UK LTD processes personal data on behalf of a customer through a Leavely workspace.

Parties

Processor:XTRA PHONES UK LTD, company number 08204476, Suite 2 Haughmond View, Shrewsbury Business Park, Shrewsbury, Shropshire, England, SY2 6LG, trading as Leavely (“Leavely”).

Controller:the organisation identified as the Leavely customer in the Agreement, workspace, order or billing record (“Customer”).

Data protection contact: privacy@leavely.online

1. Status and definitions

For Customer Personal Data, Customer is the controller and Leavely is the processor, except where either party acts as a controller under applicable law for its own independent purposes. “Customer Personal Data” means personal data processed by Leavely on Customer's behalf through the Service. “Data Protection Law” means the UK GDPR, Data Protection Act 2018, and other binding UK data-protection law that applies to the processing. Controller, processor, personal data, processing, personal data breach, data subject and supervisory authority have the meanings given by Data Protection Law.

2. Customer instructions and responsibilities

Customer instructs Leavely to process Customer Personal Data to provide, secure, support and maintain the Service; carry out the Customer's configured workflows; send operational communications; prevent abuse; and comply with the Agreement and lawful written instructions. Customer is responsible for the lawfulness, accuracy and quality of Customer Personal Data, required employee notices, its legal bases and Article 9 conditions, its user permissions, and the instructions it gives Leavely.

3. Article 28 commitments

1. Documented instructions

Leavely processes Customer Personal Data only on the Customer’s documented instructions, including the instructions in the Agreement and the Customer’s authorised use and configuration of the Service, unless UK law requires otherwise. If legally permitted, Leavely will inform the Customer before processing required by law. Leavely will immediately tell the Customer if, in its opinion, an instruction infringes applicable data protection law.

2. Confidentiality

Leavely ensures that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and receive access only where needed for their responsibilities.

3. Security

Leavely maintains appropriate technical and organisational measures having regard to the nature, scope, context and purposes of processing and the risks to individuals. The current measures are described in Schedule 2 and the Security page.

4. Sub-processors

The Customer gives general written authorisation for the sub-processors listed on the Security page. Leavely will impose data-protection obligations that provide an equivalent level of protection and remains responsible for their performance to the extent required by law.

5. Data subject rights

Taking account of the nature of the processing, Leavely will provide reasonable assistance for requests to access, correct, erase, restrict, object to, or port Customer Personal Data. If Leavely receives a request directly, it will refer the requester to the Customer unless law requires a different response.

6. Compliance assistance

Leavely will provide reasonable assistance with the Customer’s security, breach-notification, data-protection impact assessment and prior-consultation duties, taking account of the processing and information available to Leavely.

7. Delete or return

At the end of the Services, Leavely will, at the Customer’s choice and subject to applicable law, make Customer Personal Data available for reasonable export and then delete it. Production workspace data is normally deleted within 30 days after a verified closure request. Copies in protected backups are put beyond ordinary use and deleted through the applicable backup-expiry cycle unless UK law requires retention.

8. Information and audits

Leavely will make available information reasonably necessary to demonstrate compliance with this DPA. On reasonable written notice, the Customer may request relevant current evidence or an audit by an independent auditor bound by confidentiality. Audits must avoid disruption, normally occur no more than once per year, and be at the Customer’s cost unless they identify a material breach by Leavely.

4. Personal data breaches

Leavely will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. Where information is available, the notice will describe the nature of the breach, affected categories and approximate volumes, likely consequences, mitigation and a contact point. Leavely may provide information in phases as the investigation progresses. Notification is not an admission of fault or liability. Customer is responsible for deciding whether it must notify the ICO, another supervisory authority, or affected individuals.

5. International transfers

Leavely will not transfer Customer Personal Data outside the United Kingdom unless a lawful transfer mechanism applies. Depending on the destination and supplier, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised by UK law. Customer authorises transfers carried out by the authorised sub-processors on that basis.

6. Changes to sub-processors

The current sub-processor register is published on the Security page. Leavely will give reasonable notice of a new sub-processor where the change materially affects processing of Customer Personal Data. Customer may object on reasonable data-protection grounds during the notice period. The parties will work in good faith on a practical solution; if none is reasonably available, Customer may stop using the affected feature or terminate the affected Service.

7. Liability and precedence

Each party's liability arising from this DPA is subject to the exclusions and limits in the Agreement to the maximum extent permitted by law. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA prevails. The Agreement's governing law and jurisdiction apply to this DPA.

Schedule 1 — processing details

Subject matter
Provision and operation of the Leavely HR, leave and workforce-management Service.
Duration
The term of the Agreement plus the verified export, closure and deletion period.
Nature and purpose
Collection, hosting, organisation, calculation, retrieval, display, transmission, support, security, backup, export and deletion needed to provide the Service and Customer-configured workflows.
Data subjects
Customer users, workers, employees, former employees, candidates or contractors whose information Customer enters, emergency contacts, and people represented in Customer communications or documents.
Personal data
Identity and contact details; account and role data; employment, team, schedule and working-pattern data; leave, absence, sickness and approval records; payroll-adjacent information entered by Customer; emergency contacts; documents; performance, onboarding, learning, expense and time records; audit, device, security and support metadata.
Special-category data
Health, sickness, fit-note, ethnicity or other special-category information only where Customer chooses to enter or generate it.
Frequency
Continuous and event-driven while Customer uses the Service.

Schedule 2 — technical and organisational measures

  • TLS for application traffic and SSL-required database connections.
  • Password hashing, protected server-side sessions, secure cookies, and optional supported OAuth sign-in.
  • Tenant isolation and role-based access for owners, administrators, managers, and employees.
  • Server-side projection of sensitive employee information according to role and management scope.
  • Audit records for important workspace, approval, employee, billing, export, and administrative actions.
  • Managed hosting and PostgreSQL infrastructure, protected production credentials, and restricted operational access.
  • Stripe-hosted payment collection so Leavely does not store complete payment-card numbers.
  • Deployment verification, public database readiness checks, application error capture, and rollback procedures.
  • Document access through authenticated application routes and tenant-prefixed object storage.
  • Procedures for incident triage, containment, recovery, customer communication, and post-incident review.

Measures may evolve as technology, risks and the Service change, provided the overall level of protection is not materially reduced. Current operational detail is available through the Security page and reasonable customer security-review requests.

Related documents

Read the Terms of Service, Privacy Policy, GDPR overview and Security page.