LeaveVia — a product by Aegean Astraea

Data Processing Addendum

This addendum describes how LeaveVia processes employee information on behalf of an organisation using the service. It supplements the Terms of Service.

Last updated: 12 September 2026

1. Roles

The organisation using LeaveVia determines what employee information is entered, why, and who may access it, and therefore acts as the controller of that information. LeaveVia, as provider of the service, processes it on the organisation's behalf as a processor. Where we handle information for our own purposes — for example operating and securing the service or administering our customer relationship — we act on our own behalf.

In this addendum, “LeaveVia” means the service provided by the LeaveVia operator, an independent operator trading under the Aegean Astraea brand from Cyprus.

2. Subject matter and duration

The processing consists of providing leave management: recording employees, leave policies and entitlements; processing leave requests, approvals, cancellations and modifications; maintaining balances and the leave ledger; showing team availability; sending transactional notifications; producing reports and exports; and, if enabled, publishing approved leave to a connected calendar. Processing lasts for as long as the organisation uses the service, plus the limited period needed to delete or return data.

3. Categories of data and data subjects

  • Data subjects: the organisation's employees, managers and administrators, and invited users.
  • Categories: identification and contact details (name, work email), employment attributes (hire date, working schedule, department, team, location, manager), leave data (types, dates, balances, entitlements, adjustments, approvals and any text entered by users), authentication and notification records, activity/audit records and technical logs.
  • Sensitive-category information may be present if the organisation chooses to record leave reasons, or if users enter such detail in free-text fields. LeaveVia restricts visibility of sensitive leave information by role, does not require it, and does not currently provide document or attachment upload.

4. Documented instructions

We process customer data only to provide and support the service, in accordance with the organisation's configuration and use of the application, the Terms of Service and this addendum, and any further written instructions the parties agree. We do not use customer data for advertising and do not sell it. If we believe an instruction conflicts with applicable law, we will tell the organisation.

5. Confidentiality

Access to customer data by our personnel is limited to those who need it to operate, support or secure the service, and they are bound by confidentiality obligations.

6. Security

We maintain technical and organisational measures appropriate to the risk, including workspace isolation, role-based access, database-level access rules, encrypted transport, restricted handling of integration credentials and audit records of significant actions. A high-level overview is published on the Security page. Measures may evolve, but will not be reduced in a way that materially weakens protection. We do not claim any third-party certification.

7. Subprocessors and payment provider

The organisation authorises the use of the employee-data subprocessors listed on the Subprocessors & Payment Provider page, which is kept current. Subprocessors are engaged under written terms imposing data protection obligations appropriate to their role. We will publish changes to that list; an organisation that objects to a new subprocessor on reasonable data-protection grounds may raise it with us and, if it cannot be resolved, stop using the affected functionality or the service.

Paddle is separately disclosed on that page because it acts independently as Merchant of Record for paid subscription transactions. Paddle is not engaged as a subprocessor of the employee leave records covered by this DPA; its buyer/payment processing is governed by its own terms and privacy notice.

8. Assistance with data-subject rights

The application gives administrators the tools to access, correct, export and request controlled deletion of employee records. Where a request cannot be handled with those tools, we will provide reasonable assistance, taking into account the nature of the processing. If an employee contacts us directly, we will refer them to their organisation.

9. Security incidents

If we become aware of a personal-data breach affecting customer data, we will notify the organisation without undue delay and provide the information reasonably available to us so that it can meet its own obligations, together with reasonable assistance in investigating and mitigating the incident.

10. Deletion and return

Authorised administrators can export available report data in CSV format through the reporting tools provided by LeaveVia. On termination, or on written request, we will delete or return customer data, except where retention is required by law. Because the leave ledger is designed to be immutable, corrections during the service term are recorded as new entries rather than by editing history; controlled deletion at the end of the relationship removes the records themselves.

LeaveVia supports controlled deletion of a customer workspace through an implemented deletion process: an owner requests deletion in the application, a 30-day grace period runs during which the request can be cancelled, and after that period a scheduled process finalises the deletion of organisation-scoped application data and removes calendar credentials stored locally by LeaveVia. Deletion is not instantaneous.

Deletion of a whole customer workspace is distinct from deletion of an individual user's platform account. An individual deleting their LeaveVia login does not thereby force deletion of employment or leave records that the organisation controls: those records remain under the organisation's control and are handled as a controller request to the organisation. Minimal, non-content operational records of each deletion run are kept for 30 days and pruned automatically.

Customer data is retained only for as long as necessary to provide and secure the service and to meet applicable legal obligations. Deletion and return follow the applicable account and workspace process. After deletion, copies may persist in our providers' routine backups for a limited period before removal in the ordinary course; we do not state an exact backup-erasure period, because that period is determined by our hosting provider.

11. Audits and information

On reasonable written request, we will provide the information reasonably necessary to demonstrate compliance with this addendum. We do not currently offer third-party audit reports or certifications.

12. International transfers

Customer data may be processed outside the organisation's own country by us or our subprocessors, as described on the Subprocessors & Payment Provider page.

The application backend — managed database, authentication and file storage — is hosted in a European region of Lovable Cloud (Ireland, EU). Support and administrative access, and the optional calendar integrations a user chooses to connect, can involve processing outside that region. Where mandatory EU/EEA data-protection law applies to the organisation, that law takes precedence over this addendum and over the governing-law clause of the Terms of Service, and the parties will put in place any transfer mechanism it requires.

13. Governing law

This addendum is governed by the laws of the Republic of Cyprus, without prejudice to mandatory data-protection law applicable to the organisation, which prevails to the extent of any conflict.