Last Updated On 08-Jan-2026
Effective Date 08-Jan-2026
This Privacy Policy describes how Leaveasy Ltd., a company registered in Bangladesh (Business Registration No.: [TBD]), with registered office at [Complete Address TBD], Dhaka, Bangladesh ("Leaveasy", "we", "us", or "our") (email: contact@leaveasy.io) collects, uses, stores, and discloses information when you use our leave management platform and services available at https://www.leaveasy.io/ (the "Service"). This policy applies to both organizational customers ("Customers") and their employees who use the Service ("End Users").
EU Representative: For users in the European Union, our representative under Article 27 GDPR is [EU Representative Name and Address TBD]. Contact: eu-representative@leaveasy.io
UK Representative: For users in the United Kingdom, our representative under Article 27 UK GDPR is [UK Representative Name and Address TBD]. Contact: uk-representative@leaveasy.io
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use the Service.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
We collect different types of information depending on how you interact with our Service:
When you use AI-powered features (leave pattern analysis, scheduling suggestions), we process:
AI Data Processing: We do not use your personal data to train general AI models. AI features use your organization's data in real-time for analysis specific to your account only. We do not share your data with third-party AI providers. All AI processing occurs within our secure infrastructure.
Opting Out of AI Features: You can disable AI-powered features in your account settings. This will not affect core leave management functionality.
Biometric Data: We do not process biometric data or perform facial recognition on profile photos. Profile photos are stored as image files only for display purposes.
For users in the European Economic Area (EEA) and UK, we process your personal data based on the following legal grounds:
We do not sell your personal information. We may share your information in the following circumstances:
Your leave requests, balances, and related data are shared with your employer's authorized administrators and managers.
We share data with trusted partners who help us operate the Service. A complete and up-to-date list of sub-processors is available at www.leaveasy.io/sub-processors. We will notify you at least 30 days before adding new sub-processors or changing existing ones.
Categories of sub-processors include:
All sub-processors are bound by data protection agreements and are required to implement appropriate technical and organizational measures to protect your data.
When you enable integrations (Slack, Google Calendar), we share relevant data with those services according to your integration settings.
We may disclose information when required to:
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
Your data is primarily stored on secure servers hosted by Amazon Web Services (AWS) in the United States, with backup servers in the European Union (Frankfurt, Germany). Data may be processed in other countries where we or our service providers operate.
If you are located in the EEA, UK, or other regions with data protection laws, your data may be transferred to countries that do not have equivalent data protection laws. We implement the following safeguards for international transfers:
Privacy Shield Notice: We do not rely on the EU-US Privacy Shield framework, which was invalidated by the European Court of Justice in July 2020 (Schrems II decision). We use alternative transfer mechanisms as described above.
Copies of our data transfer agreements and SCCs are available upon request by contacting privacy@leaveasy.io.
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy:
After these periods, we will delete or anonymize your data unless retention is required by law.
Depending on your location, you may have the following rights:
To exercise your rights: Contact us at contact@leaveasy.io or privacy@leaveasy.io with "Data Subject Rights Request" in the subject line. Please include:
Response Timeframes:
Identity Verification: To protect your privacy, we may request additional information to verify your identity before fulfilling requests. This may include:
Fees: We do not charge fees for most requests. However, we may charge a reasonable fee for:
For End Users: Your employer is the data controller for employment-related data. For requests regarding employee data (leave records, balances, approval history), please contact your employer's HR or IT department first. We will assist your employer in fulfilling such requests.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority (EEA/UK), the California Attorney General's office (California), or other applicable regulatory body.
We use cookies and similar technologies to enhance your experience. Upon your first visit, you will see a cookie consent banner allowing you to manage your preferences.
For EEA/UK Users: We use an opt-in consent mechanism compliant with GDPR and UK GDPR. Non-essential cookies will only be set after you provide explicit consent. You can withdraw consent at any time via our cookie preference center.
Managing Cookies: You can control cookies through:
Note that disabling essential cookies may limit Service functionality. Disabling analytics cookies will not affect core features.
For complete details about cookies, retention periods, and third-party cookies, see our Cookie Policy.
We implement industry-standard security measures to protect your information:
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.
In the event of a data breach that compromises your personal information, we will notify affected users and relevant authorities as required by law, typically within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, types of data affected, and steps being taken to address it.
We use automated systems and AI for the following purposes:
Important Limitations:
Your Rights Regarding Automated Processing:Under GDPR and similar laws, you have the right to:
To exercise these rights or learn more about our automated processing, contact privacy@leaveasy.io.
The Service is intended for business use and is not directed to individuals under 16 years of age (or the age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect personal information from children without appropriate consent.
If we become aware that we have collected data from a child under the applicable age without proper parental consent or legal authorization, we will take immediate steps to delete it within 30 days.
Customers are responsible for ensuring compliance with age requirements under applicable employment and data protection laws in their jurisdiction, including obtaining necessary consents for employees under 18 years of age where required by law.
For B2B customers: Your organization is the data controller of employee data, and Leaveasy acts as a data processor. We process employee data on your behalf according to your instructions and our Data Processing Agreement (DPA).
For End Users: Your employer controls your employment data. For questions about how your employer handles your data, please contact them directly.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Leaveasy Ltd.
Registered Address: [Complete Address TBD], Dhaka, Bangladesh
Business Registration No.: [TBD]
General Inquiries: contact@leaveasy.io
Data Protection Officer: privacy@leaveasy.io
EU Representative (GDPR Article 27): [Name and Address TBD], Email: eu-representative@leaveasy.io
UK Representative (UK GDPR Article 27): [Name and Address TBD], Email: uk-representative@leaveasy.io
Website: https://www.leaveasy.io
We will respond to your inquiry within the timeframes specified in Section 8.4.
Supervisory Authorities: If you are in the EEA or UK and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority or the Information Commissioner's Office (ICO) in the UK.
This Privacy Policy was last updated on 08-Jan-2026. We encourage you to review it periodically for any changes. Your continued use of the Service after updates constitutes acceptance of the revised policy.