Encrypted leave data flows
Leavely uses TLS for application traffic, SSL-required database connections, protected secrets, and Stripe-hosted payment collection so card numbers are not stored by Leavely.
Leave management security UK
Leavely protects employee leave records with encrypted connections, role-based access, managed database infrastructure, documented restoration priorities, and UK GDPR controller and processor role clarity.
A practical trust review for UK employers before inviting staff into Leavely.
Leavely uses TLS for application traffic, SSL-required database connections, protected secrets, and Stripe-hosted payment collection so card numbers are not stored by Leavely.
Workspace data is stored in managed PostgreSQL infrastructure. Leavely does not publish a customer-specific backup SLA or recovery point and recovery time objectives.
Leavely runs on managed cloud services with edge delivery and documented operational dependencies. Operational signals help investigate service-impacting incidents.
Customer organisations remain controller for employee records. Leavely acts as processor for workspace, leave, sickness, approval, user, and audit data entered into the service.
Encryption and access
Leave data can reveal sickness patterns, absence history, team cover, and payroll relevant dates. Leavely keeps the control model simple: encrypted connections, scoped roles, protected authentication, and audit history for important workspace changes.
Data storage and recovery
Leavely stores production workspace records in managed PostgreSQL infrastructure. Restoration priorities focus on account access, leave approvals, employee balances, sickness records, and audit history; no customer-specific backup SLA is published.
Managed PostgreSQL storage for production workspace, employee, leave, sickness, approval, and audit data.
No published customer-specific backup SLA, recovery point objective, or recovery time objective.
Workspace administrators can export key operational records from the product.
Service restoration priorities that put authentication, workspace access, leave records, and approval workflows first.
Business continuity
Leavely uses managed cloud services and documented operational dependencies to reduce single points of failure. If an incident affects the service, restoration priorities focus on account access, workspace availability, leave history, approval queues, and payroll-relevant absence data.
Security controls reduce avoidable incidents through encryption, access roles, protected credentials, rate limiting, hosted checkout, and restricted operational access.
Operational logs, error capture, analytics signals, payment events, and support channels help surface service or account issues that need investigation.
Recovery work prioritises customer access, database availability, leave records, approval queues, and payroll-relevant absence history.
Data protection
Your organisation controls the employee data entered into Leavely. We process that data to provide the service, secure the platform, send operational messages, support your account, and meet legal or billing obligations.
The formal legal terms remain the Privacy Policy, Terms of Service, and any Data Processing Agreement agreed with Leavely.
SOC 2 status
Leavely does not currently publish a SOC 2 Type I or Type II report. This page describes the security and data handling controls currently communicated to customers and prospects.
Customers reviewing Leavely can contact us for current answers about encryption, access controls, sub-processors, data storage, recovery arrangements, data export, and incident handling.
Ask a security questionSub-processors
Leavely keeps the sub-processor list short and operational. These providers help deliver hosting, database storage, payments, email, analytics, product feedback, and support chat.
PurposeApplication hosting, CDN, routing, DDoS protection, edge security, and request handling
Data handledApplication traffic, IP addresses, request metadata, security logs
PurposeManaged PostgreSQL database hosting for workspace, employee, and leave-management data
Data handledAccount, organisation, employee, leave, absence, approval, and audit records
PurposePayment processing, subscription checkout, customer portal, and invoices
Data handledBilling contact details, payment metadata, subscription status
PurposeTransactional email delivery for account, trial, and leave-management notifications
Data handledRecipient email addresses, message content, delivery metadata
PurposeProduct analytics and consented, masked replay limited to the public accountant-partner registration page
Data handledUsage events, device information, feature interaction metadata, and masked public-page interactions; authenticated workspaces are not recorded
PurposeAuthenticated product feedback and feature-request portal
Data handledAccount identifier, name, email address, workspace metadata, and feedback content
PurposeOptional sales and trial support chat when the chat widget is enabled
Data handledSupport messages, contact details provided in chat, chat metadata