Legal
Privacy policy
Last updated: 11 July 2026
This privacy policy explains how Leavely collects, uses, stores, and protects personal data when you visit our website, create an account, use our leave-management service, contact support, or receive communications from us.
Leavely is built for UK employers and is operated with UK GDPR and Data Protection Act 2018 requirements in mind. This policy is not a substitute for your own legal advice, but it sets out the practical privacy commitments that apply to the service.
Who we are
Leavely is operated by Xtraphones UK Ltd and provides leave, sickness, employee record, approval, calendar, reporting, and notification tools for organisations. For privacy questions, contact us at privacy@leavely.online.
Controller and processor roles
For customer workspace data, including employee records and absence information added to the service by a customer, the customer is normally the controller and Leavely acts as processor. We process that data according to the customer's instructions, our terms, this policy, and any Data Processing Agreement agreed with the customer.
Leavely is controller for data we collect for our own business purposes, such as website analytics, account administration, security monitoring, billing administration, support, and marketing communications.
Personal data we process
- Account information, including names, email addresses, authentication details, roles, and workspace membership.
- Organisation information, including company name, departments, teams, working patterns, leave years, approval rules, and public holiday settings.
- Employee and absence records, including employee profiles, leave requests, sickness records, balances, approvals, comments, calendar entries, and audit history.
- Billing and subscription information, including plan, checkout status, invoices, and payment metadata handled through Stripe.
- Support and communication records, including messages sent to Leavely, service emails, product notifications, and consent preferences.
- Technical and usage data, including IP address, device and browser details, session data, security logs, analytics events, and error reports.
How we use personal data
We use personal data to provide and secure the service, manage accounts, calculate leave and sickness records, route approvals, send transactional notifications, provide support, process subscriptions, monitor reliability, investigate misuse, improve Leavely, and meet legal obligations.
Lawful bases under UK GDPR
- Contract: to provide the Leavely service, maintain accounts, process subscriptions, and deliver support.
- Legitimate interests: to secure the service, improve product reliability, prevent abuse, understand feature usage, and communicate relevant service updates.
- Legal obligation: to keep accounting, tax, security, and compliance records where UK law requires it.
- Consent: for optional marketing or non-essential tracking where consent is required.
Special category data
Leavely may contain sickness or health-related absence information if a customer chooses to record it. Customers are responsible for deciding what employee information to enter, for providing any required notices to employees, and for identifying an appropriate UK GDPR Article 9 condition where special category data is processed. Leavely processes that data as processor for the customer.
Cookies and analytics
We use essential cookies and similar technologies to keep the service working securely, including authentication, session management, fraud prevention, and preference storage. Optional analytics and chat tools are used to understand website usage, improve the product, and support visitors before signup. We only load those optional tools after you accept optional cookies.
You can reject optional cookies from the banner or change your choice here at any time. Rejecting optional cookies opts this browser out of optional analytics and prevents marketing chat cookies from loading on public pages.
Cookie preferences
Essential cookies always stay on because Leavely needs them for security, login sessions, and consent storage. Optional analytics and chat cookies only run if you accept them.
Current choice: no optional cookie choice saved
Sub-processors
We use trusted suppliers to host and operate Leavely, including infrastructure, database, payments, email delivery, analytics, error monitoring, customer support, and security tooling. These suppliers only process personal data where needed to provide their services to us and must protect it under contractual obligations.
Payment card details are handled by Stripe. Leavely does not store full card numbers on its own systems.
International transfers
Some suppliers may process data outside the United Kingdom. Where this happens, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
Retention
Customer workspace data is kept while the account is active and needed to provide the service. After account closure, workspace data is normally retained for up to 30 days for export or recovery, then deleted or anonymised unless a longer period is required for legal, accounting, security, backup, or dispute-resolution reasons.
Billing, security, audit, and legal records may be retained for longer where necessary to meet legal obligations, resolve disputes, enforce agreements, or protect the service.
Security
We use technical and organisational safeguards designed to protect personal data, including encrypted traffic, SSL-required database connections, password hashing, server-side session protection, role-based access controls, audit history, protected secrets, restricted operational access, and monitoring for service reliability and abuse.
Your UK GDPR rights
- Access a copy of personal data held about you.
- Ask for inaccurate or incomplete personal data to be corrected.
- Ask for deletion of personal data where there is no continuing lawful reason to keep it.
- Object to or restrict certain processing.
- Ask for data portability where the UK GDPR gives that right.
- Withdraw consent where processing is based on consent.
- Complain to the UK Information Commissioner's Office if you are unhappy with how personal data is handled.
If your employer uses Leavely, requests about employee workspace data should usually go to your employer first because they are the controller. We will support customers with valid data-rights requests where Leavely acts as processor.
Marketing communications
You can unsubscribe from marketing emails using the unsubscribe link in the email or by contacting us. We may still send service emails that are necessary for account, security, billing, or product operation.
Changes to this policy
We may update this policy as Leavely, our suppliers, or legal requirements change. The updated version will be published on this page with a new last-updated date.
Related documents
Read our terms of service and GDPR compliance overview for more detail about how Leavely is operated.
