LeaveVia — a product by Aegean Astraea
Data Processing Addendum
This addendum describes how LeaveVia processes employee information on behalf of an organisation using the service. It supplements the Terms of Service.
Last updated: 13 August 2026
1. Roles
The organisation using LeaveVia determines what employee information is entered, why, and who may access it, and therefore acts as the controller of that information. LeaveVia, as provider of the service, processes it on the organisation's behalf as a processor. Where we handle information for our own purposes — for example operating and securing the service or administering our customer relationship — we act on our own behalf.
In this addendum, “LeaveVia” means the operator of the LeaveVia service under the Aegean Astraea brand, based in Cyprus.
2. Subject matter and duration
The processing consists of providing leave management: recording employees, leave policies and entitlements; processing leave requests, approvals, cancellations and modifications; maintaining balances and the leave ledger; showing team availability; sending transactional notifications; producing reports and exports; and, if enabled, publishing approved leave to a connected calendar. Processing lasts for as long as the organisation uses the service, plus the limited period needed to delete or return data.
3. Categories of data and data subjects
- Data subjects: the organisation's employees, managers and administrators, and invited users.
- Categories: identification and contact details (name, work email), employment attributes (hire date, working schedule, department, team, location, manager), leave data (types, dates, balances, entitlements, adjustments, approvals and any text entered by users), authentication and notification records, activity/audit records and technical logs.
- Sensitive-category information may be present if the organisation chooses to record leave reasons or supporting documents. LeaveVia restricts visibility of sensitive leave information by role and does not require it.
4. Documented instructions
We process customer data only to provide and support the service, in accordance with the organisation's configuration and use of the application, the Terms of Service and this addendum, and any further written instructions the parties agree. We do not use customer data for advertising and do not sell it. If we believe an instruction conflicts with applicable law, we will tell the organisation.
5. Confidentiality
Access to customer data by our personnel is limited to those who need it to operate, support or secure the service, and they are bound by confidentiality obligations.
6. Security
We maintain technical and organisational measures appropriate to the risk, including workspace isolation, role-based access, database-level access rules, encrypted transport, restricted handling of integration credentials and audit records of significant actions. A high-level overview is published on the Security page. Measures may evolve, but will not be reduced in a way that materially weakens protection. We do not claim any third-party certification.
7. Subprocessors
The organisation authorises the use of the subprocessors listed on the Subprocessors page, which is kept current. Subprocessors are engaged under written terms imposing data protection obligations appropriate to their role. We will publish changes to that list; an organisation that objects to a new subprocessor on reasonable data-protection grounds may raise it with us and, if it cannot be resolved, stop using the affected functionality or the service.
8. Assistance with data-subject rights
The application gives administrators the tools to access, correct, export and request controlled deletion of employee records. Where a request cannot be handled with those tools, we will provide reasonable assistance, taking into account the nature of the processing. If an employee contacts us directly, we will refer them to their organisation.
9. Security incidents
If we become aware of a personal-data breach affecting customer data, we will notify the organisation without undue delay and provide the information reasonably available to us so that it can meet its own obligations, together with reasonable assistance in investigating and mitigating the incident.
10. Deletion and return
Administrators can export workspace data at any time. On termination, or on written request, we will delete or return customer data, except where retention is required by law. Because the leave ledger is designed to be immutable, corrections during the service term are recorded as new entries rather than by editing history; deletion at the end of the relationship removes the records themselves.
Customer data is retained only for as long as necessary to provide and secure the service and to meet applicable legal obligations. Deletion and return follow the applicable account and workspace process. After deletion, copies may persist in our providers' routine backups for a limited period before removal in the ordinary course.
11. Audits and information
On reasonable written request, we will provide the information reasonably necessary to demonstrate compliance with this addendum. We do not currently offer third-party audit reports or certifications.
12. International transfers
Customer data may be processed outside the organisation's own country by us or our subprocessors, as described on the Subprocessors page.
The application backend — managed database, authentication and file storage — is hosted in a European region of Lovable Cloud (Ireland, EU). Support and administrative access, and the optional calendar integrations a user chooses to connect, can involve processing outside that region. Where mandatory EU/EEA data-protection law applies to the organisation, that law takes precedence over this addendum and over the governing-law clause of the Terms of Service, and the parties will put in place any transfer mechanism it requires.
13. Governing law
This addendum is governed by the laws of the Republic of Cyprus, without prejudice to mandatory data-protection law applicable to the organisation, which prevails to the extent of any conflict.