Privacy Statement
Last updated: June 9, 2026
This Privacy Statement describes how LeaveOS ("LeaveOS", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use our leave-management platform at https://leaveos.com and related services (the "Service"). It applies to administrators, managers, and employees whose organizations use LeaveOS.
1. Data controller
LeaveOS is the data controller for personal data processed through the Service, except where your employer (the "Customer") acts as controller for employee HR data within their workspace. For questions about this statement, contact us at privacy@leaveos.com.
2. Personal data we collect
Depending on how you use the Service, we may process:
- Account data: name, work email address, password (stored hashed), role, team, country, employment start date, and workspace (company) affiliation.
- Authentication data: identifiers from sign-in providers you choose (e.g. Microsoft, Google, or Slack), including your provider account ID and email.
- Leave and HR data: leave requests, dates, leave types, balances, substitute assignments, approver notes, and related calendar information.
- Usage and technical data: IP address, browser type, device information, session timestamps, audit logs of administrative actions, and cookies required for security and sign-in.
- Communications: support requests and emails we send (e.g. invitations, password reset, notifications).
3. How we use personal data
We use personal data to:
- Provide, operate, and maintain the Service for your organization;
- Authenticate users and enforce access controls;
- Process leave requests, balances, approvals, and team visibility features;
- Send transactional emails and in-app notifications;
- Maintain security, fraud prevention, and immutable audit logs for compliance;
- Improve reliability, troubleshoot issues, and comply with legal obligations.
We do not sell your personal data. We do not use employee leave data for third-party advertising.
4. Legal bases (EEA / UK)
Where GDPR applies, we rely on:
- Contract: to deliver the Service to you and your employer;
- Legitimate interests: security, product improvement, and fraud prevention, balanced against your rights;
- Legal obligation: where required by law;
- Consent: where required (e.g. optional marketing, where offered).
5. Microsoft and other sign-in providers
If you sign in with Microsoft, Google, or Slack, we receive limited profile information from that provider as permitted by your consent and the provider's policies. We use this only to authenticate you and provision your LeaveOS account. Microsoft's privacy statement is available at https://privacy.microsoft.com/privacystatement.
6. Sub-processors and hosting
We use trusted infrastructure providers to host the Service, including database and authentication services (e.g. Supabase) and cloud hosting. These providers process data on our instructions under data-processing agreements and industry-standard security certifications (including ISO/IEC 27001 and SOC 2 where applicable). Data may be stored in the European Union or other regions where our providers operate.
7. Data sharing
We may share personal data:
- With your employer's administrators and managers within the same workspace, as required by the Service;
- With sub-processors that help us run the Service;
- When required by law, court order, or to protect rights and safety;
- In connection with a merger, acquisition, or asset sale, with notice where required.
8. International transfers
If personal data is transferred outside your country, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms approved under applicable law.
9. Retention
We retain personal data for as long as your organization maintains an active account or as needed to provide the Service. Audit logs and security records may be retained longer where required for compliance. When data is no longer needed, we delete or anonymize it within a reasonable period.
10. Security
We apply technical and organizational measures including encryption in transit (TLS 1.2+), encryption at rest, role-based access control, row-level security, session timeouts, and immutable administrative audit logs. No method of transmission over the Internet is 100% secure; we continuously work to protect your data.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, or port your personal data, and to withdraw consent where processing is consent-based. Employees should contact their employer (data controller for HR records) first; you may also contact privacy@leaveos.com. You may lodge a complaint with your local data protection authority.
12. Cookies
We use essential cookies and similar technologies for authentication, session management, and security. We do not use non-essential tracking cookies for advertising.
13. Children
The Service is intended for workplace use and is not directed at children under 16. We do not knowingly collect data from children.
14. Changes to this statement
We may update this Privacy Statement from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated by email or in-product notice where appropriate.
15. Contact
LeaveOS
Email: privacy@leaveos.com
Website: https://leaveos.com