GDPR compliance

GDPR-ready leave management for employee data

Leavely helps UK SMEs handle leave, sickness, and employee records with clear data roles, secure cloud storage, practical retention controls, and transparent security measures.

Compliance summary

A practical overview for teams reviewing Leavely before inviting employees.

  • Customer remains controller for workspace employee data
  • Leavely acts as processor for leave-management records
  • Published Data Processing Addendum
  • Workspace export and deletion support
  • Documented security controls and sub-processors

Controller and processor roles

Customer organisations control the employee data they add to Leavely. Leavely acts as processor for workspace, employee, leave, sickness, approval, and audit records entered into the service.

Data minimisation

Leavely is designed around practical leave management, so the service asks for the employee, organisation, and absence information needed to run approvals, balances, reports, and notifications.

Secure cloud storage

Production application delivery runs through Cloudflare, with workspace records stored in managed PostgreSQL infrastructure and database connections requiring SSL.

Operational safeguards

The platform uses encrypted traffic, hashed passwords, role-based access controls, audit history, protected secrets, and restricted operational access.

Data storage

What Leavely stores to run the service

Leavely stores customer workspace data for as long as the account is active and needed to provide leave management. After closure, workspace data is normally kept for up to 30 days for export or recovery, then deleted or anonymised unless a longer period is required for legal, accounting, security, or dispute-resolution reasons.

  • Account details such as names, email addresses, authentication records, roles, and workspace membership.
  • Organisation settings such as departments, teams, working patterns, public holidays, approval rules, and subscription status.
  • Employee and absence records such as profiles, leave requests, sickness records, balances, approvals, comments, calendar entries, and audit history.
  • Operational records such as support messages, transactional email delivery data, security logs, billing metadata, analytics events, and error reports.

Security measures

Controls that protect HR and leave records

Employee absence records are sensitive operational data. Leavely uses layered safeguards across access, authentication, hosting, payment handling, and operational monitoring to reduce risk and support GDPR accountability.

TLS encryption for application traffic and SSL-required database connections.

Password hashing, server-side session protection, and optional OAuth sign-in through supported identity providers.

Role-based permissions for owners, admins, managers, and employees.

Audit logs for important workspace actions and leave-management changes.

Stripe-hosted checkout and card handling, so Leavely does not store card numbers.

Sub-processor transparency for hosting, database, payments, email, analytics, and support tooling.

Data rights

Support for access, export, correction, and deletion

Workspace owners can manage users and employee records inside Leavely. For GDPR rights requests involving employee records, Leavely supports the customer organisation as controller. For account, billing, sales, or support data controlled by Leavely, requests can be sent directly to us.

Access and export support

Correction and deletion support

Published Article 28 DPA

Need a GDPR or DPA answer?

Read the published Data Processing Addendum or contact Leavely with data protection, sub-processor, workspace export, or deletion questions.