Legal

Privacy policy

Last updated: 30 August 2026

This privacy policy explains how Leavely collects, uses, stores, and protects personal data when you visit our website, create an account, use our leave-management service, contact support, or receive communications from us.

Leavely is built for UK employers and is operated with UK GDPR and Data Protection Act 2018 requirements in mind. This policy is not a substitute for your own legal advice, but it sets out the practical privacy commitments that apply to the service.

Who we are

Leavely is operated by XTRA PHONES UK LTD (company number 08204476), Suite 2 Haughmond View, Shrewsbury Business Park, Shrewsbury, Shropshire, England, SY2 6LG. Leavely provides leave, sickness, employee record, approval, calendar, reporting, and notification tools for organisations. For privacy questions, contact us at privacy@leavely.online.

Controller and processor roles

For customer workspace data, including employee records and absence information added to the service by a customer, the customer is normally the controller and Leavely acts as processor. We process that data according to the customer's instructions, our terms, this policy, and the Data Processing Addendum that forms part of our terms.

Leavely is controller for data we collect for our own business purposes, such as website analytics, account administration, security monitoring, billing administration, support, and marketing communications.

Personal data we process

  • Account information, including names, email addresses, authentication details, roles, and workspace membership.
  • Organisation information, including company name, departments, teams, working patterns, leave years, approval rules, and public holiday settings.
  • Employee and absence records, including employee profiles, leave requests, sickness records, balances, approvals, comments, calendar entries, and audit history.
  • Billing and subscription information, including plan, checkout status, invoices, and payment metadata handled through Stripe.
  • Support and communication records, including messages sent to Leavely, service emails, product notifications, and consent preferences.
  • Technical and usage data, including IP address, device and browser details, session data, security logs, analytics events, and error reports.

How we use personal data

We use personal data to provide and secure the service, manage accounts, calculate leave and sickness records, route approvals, send transactional notifications, provide support, process subscriptions, monitor reliability, investigate misuse, improve Leavely, and meet legal obligations.

Lawful bases under UK GDPR

  • Contract: to provide the Leavely service, maintain accounts, process subscriptions, and deliver support.
  • Legitimate interests: to secure the service, improve product reliability, prevent abuse, understand feature usage, and communicate relevant service updates.
  • Legal obligation: to keep accounting, tax, security, and compliance records where UK law requires it.
  • Consent: for optional marketing or non-essential tracking where consent is required.

Special category data

Leavely may contain sickness or health-related absence information if a customer chooses to record it. Customers are responsible for deciding what employee information to enter, for providing any required notices to employees, and for identifying an appropriate UK GDPR Article 9 condition where special category data is processed. Leavely processes that data as processor for the customer.

Cookies and analytics

We use essential cookies and similar technologies to keep the service working securely, including authentication, session management, fraud prevention, and preference storage. Optional analytics, advertising measurement (including Google Ads, Microsoft Advertising UET, and the OpenAI advertising pixel), and chat tools are used to understand website usage, attribute a completed trial signup to an advert, improve the product, and support visitors before signup. We only load those optional tools after you accept optional cookies.

On the public accountant-partner registration page only, accepted optional analytics may include a masked interaction recording so we can understand the referral journey. All form inputs are masked. We do not record authenticated workspaces, employee pages, sickness or absence records, admin pages, or the general signup journey.

You can reject optional cookies from the banner or change your choice here at any time. Rejecting optional cookies opts this browser out of optional analytics and prevents advertising measurement and marketing chat cookies from loading on public pages.

If you accept optional cookies, Microsoft may collect or receive browser, device, page, advert-click, and conversion-event data through Microsoft Advertising UET to measure whether an advert led to a completed trial signup. We do not include signup names, email addresses, or workspace form data in the UET event. Microsoft handles the data it receives under its Privacy Statement.

If you accept optional cookies, the OpenAI advertising pixel may receive browser, device, page, advert-click, and trial-conversion information so we can understand whether a ChatGPT advert led to a completed Leavely trial signup. The conversion event does not include the signup name, email address, company name, or employee records.

Essential cookies always stay on because Leavely needs them for security, login sessions, and consent storage. Optional analytics, advertising measurement, and chat cookies only run if you accept them.

Current choice: no optional cookie choice saved

Sub-processors

We use trusted suppliers to host and operate Leavely, including infrastructure, database, payments, email delivery, analytics, error monitoring, customer support, and security tooling. These suppliers only process personal data where needed to provide their services to us and must protect it under contractual obligations.

Payment card details are handled by Stripe. Leavely does not store full card numbers on its own systems.

International transfers

Some suppliers may process data outside the United Kingdom. Where this happens, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.

Retention

Customer workspace data is kept while the account is active and needed to provide the service. After account closure, workspace data is normally retained for up to 30 days for export or recovery, then deleted or anonymised unless a longer period is required for legal, accounting, security, backup, or dispute-resolution reasons.

Billing, security, audit, and legal records may be retained for longer where necessary to meet legal obligations, resolve disputes, enforce agreements, or protect the service.

Security

We use technical and organisational safeguards designed to protect personal data, including encrypted traffic, SSL-required database connections, password hashing, server-side session protection, role-based access controls, audit history, protected secrets, restricted operational access, and monitoring for service reliability and abuse.

Your UK GDPR rights

  • Access a copy of personal data held about you.
  • Ask for inaccurate or incomplete personal data to be corrected.
  • Ask for deletion of personal data where there is no continuing lawful reason to keep it.
  • Object to or restrict certain processing.
  • Ask for data portability where the UK GDPR gives that right.
  • Withdraw consent where processing is based on consent.
  • Complain to the UK Information Commissioner's Office if you are unhappy with how personal data is handled.

If your employer uses Leavely, requests about employee workspace data should usually go to your employer first because they are the controller. We will support customers with valid data-rights requests where Leavely acts as processor.

Marketing communications

You can unsubscribe from marketing emails using the unsubscribe link in the email or by contacting us. We may still send service emails that are necessary for account, security, billing, or product operation.

Changes to this policy

We may update this policy as Leavely, our suppliers, or legal requirements change. The updated version will be published on this page with a new last-updated date.

Related documents

Read our Data Processing Addendum, terms of service and GDPR compliance overview for more detail about how Leavely is operated.