LeaveVia — a product by Aegean Astraea
Privacy Policy
This notice explains what information LeaveVia handles, why it is handled, and the choices available to organisations and the people who use the service.
Last updated: 12 September 2026
Who this notice covers
LeaveVia is a leave-management product operated by the LeaveVia operator, an independent operator trading under the Aegean Astraea brand from Cyprus. In most cases the organisation (your employer or the workspace that invited you) decides what employee information is entered into LeaveVia and how it is used. LeaveVia handles that workforce information on the organisation's behalf.
Information you provide
- Account details: your work email address, name and the password or sign-in method you use.
- Workspace details: organisation name, departments, teams, locations and working-week configuration.
- Employee records: names, work email addresses, employment/hire dates, working schedules, managers and reporting relationships.
- Leave-management data: leave requests, dates, part-days, leave types, entitlements, balances, carry-over, adjustments, approvals, rejections, cancellations and modifications, plus any comment or reason text entered by users.
- Billing administration: for an organisation that chooses a paid plan, LeaveVia stores limited subscription facts such as selected plan, billing interval/currency, provider customer/subscription references, payment status and renewal/cancellation state. Raw card details are not collected or stored by LeaveVia.
Information generated by the service
- Authentication information such as sign-in events, email confirmation and password-reset activity.
- Notification records: in-app notifications and the delivery state of notification emails.
- Activity and audit records of significant actions (for example approvals, role changes and invitation acceptance) so administrators can see what happened and when.
- Technical and security logs generated when the application is used, used to keep the service running correctly and to investigate faults or abuse.
- Billing event records needed to verify subscription status, prevent duplicate processing and keep paid entitlements in sync with the payment provider.
Billing and payment information — Paddle
Paid subscription orders are handled by Paddle as Merchant of Record and authorised reseller. When an organisation proceeds to a paid subscription, Paddle collects and processes buyer and payment information needed for checkout, payment-method processing, invoicing, applicable taxes, fraud prevention, refunds, chargebacks and subscription administration. This can include contact, location, transaction and billing information.
Paddle processes that buyer/payment information for its own Merchant-of-Record purposes under its own buyer terms and privacy notice. LeaveVia receives only the billing and subscription information needed to identify the workspace, verify the subscription and provide the purchased entitlement. LeaveVia does not receive raw payment-card numbers or card security codes. More information about this provider relationship is published on the Subprocessors & Payment Provider page.
Why this information is processed
- To provide the service: recording requests, calculating balances and showing team availability.
- To authenticate users and protect accounts and workspaces.
- To send transactional notifications about requests, approvals and invitations.
- To maintain accurate, auditable leave records for the organisation.
- To administer trials and paid subscriptions, verify payment-provider events and apply the correct product entitlement.
- To keep the service secure, reliable and free from misuse, and to support customers.
LeaveVia does not sell personal information, does not use it for advertising, and does not use customer content for advertising profiling.
Lawful bases for processing (EU/EEA)
Where the EU General Data Protection Regulation applies to processing that LeaveVia carries out for its own purposes, we rely on the following bases:
- Service, account and subscription administration — Article 6(1)(b), where applicable: processing the account, contact and limited billing-status information needed to provide the service that has been requested, or to take steps requested before the service is activated or purchased.
- Security, service integrity and operational logging — Article 6(1)(f), legitimate interests: keeping accounts and workspaces protected, preventing abuse or fraudulent sign-ups, verifying payment-provider events, investigating faults, and keeping the service reliable.
- Legal obligations — Article 6(1)(c): where processing is required to comply with applicable law.
- Support and contact enquiries — Article 6(1)(b) where the enquiry relates to a service you have requested or steps before it starts, otherwise Article 6(1)(f), legitimate interests, for ordinary operational correspondence with the person who contacted us.
- Enquiry form submissions — Article 6(1)(b), where applicable: acting on steps requested by the person making the enquiry before entering into a service relationship; otherwise Article 6(1)(f), legitimate interests, for ordinary operational correspondence.
We do not rely on consent for the processing described above, because consent is not collected for it. Where consent is ever required for a specific new purpose, it will be requested separately and can be withdrawn.
Customer workforce data: who decides the lawful basis
When LeaveVia processes employee and workforce information inside a customer's workspace, the customer organisation is the controller: it determines the purposes, the content of the records and the lawful basis for processing them under its own employment and local law. LeaveVia acts as a processor on the customer's instructions. We do not independently determine an employer's employment-law basis for keeping leave records, and we do not state a single Article 6 basis on behalf of every customer. If you are an employee, your employer's own privacy information explains that basis.
Enquiry form submissions
If you use the enquiry form to tell us about your team, the form collects your full name, work email address, company name, country, team size, your role or job title, an optional message, and basic submission and status metadata.
- Purpose: to review and answer your enquiry, to communicate with you about it, to help the organisation get started with LeaveVia if it decides to do so, and for basic administration of these enquiries.
- Sending an enquiry does not enrol you in any newsletter or marketing list.
- Retention: where an enquiry does not lead to a customer relationship, the enquiry data is kept for up to 12 months after the latest meaningful interaction relating to it and is then deleted automatically, unless a longer period is needed for a specific legal claim or obligation.
- Where the organisation goes on to create a workspace, the resulting service and account records follow the normal service retention and deletion rules described below.
Notification email
Transactional email (invitations, request and approval notifications, authentication emails) is sent through a managed email service using the sender address notifications@notify.aegeanastraea.com. Email content is written to be minimal: it identifies the workspace and the action needed, and links back to the application rather than reproducing sensitive leave detail.
Calendar integration
If a user connects Google Calendar or Microsoft Outlook, LeaveVia publishes approved leave one way into that calendar. The projection is deliberately limited to availability information — it does not publish leave reasons or sensitive leave detail. Connections can be disconnected in the application, which stops further publication. LeaveVia remains the source of truth: changes made in an external calendar do not silently alter an approved leave record.
Access controls and visibility
Access inside LeaveVia is role-based. Owners and administrators can see workspace configuration and employee records; managers see the information needed to approve requests for the people they manage; colleagues may only see that someone is away, not why. Each workspace's data is isolated from every other workspace.
Potentially sensitive information
LeaveVia does not require medical or other special-category details, and we do not claim that the service never handles potentially sensitive information: a leave type name or a comment entered voluntarily by a user can reveal something about health, religion or family circumstances.
- Users should avoid entering unnecessary medical diagnoses or other sensitive detail in free-text fields such as request reasons or comments.
- Organisations should configure leave types and approval processes in line with their own legal obligations, and decide what detail their employees are asked to record.
- General team availability uses privacy-safe availability labels — a colleague may only see that someone is away, not the reason.
- Detailed leave information is limited by role and permission, and leave types can be marked as sensitive so that visibility is further restricted.
- Calendar publication and notification email are deliberately limited to availability information and do not reproduce leave reasons.
Organisation responsibilities
Organisations using LeaveVia decide who is invited, what roles they are given, what employee information is entered and how long records are kept in the workspace. Organisations are responsible for informing their own employees about that use and for handling employee requests about it. If you are an employee and want to know how your employer uses LeaveVia, contact your workspace administrator.
Security
LeaveVia is built with workspace isolation, role-based access, database-level access rules, encrypted transport, restricted handling of integration credentials, and audit records of significant actions. See the Security page for a high-level overview. No service can promise absolute security.
Retention and deletion
Leave records are retained while they are needed by the organisation for leave administration and for the audit trail the service maintains. Because the leave ledger is designed to be immutable, corrections are recorded as new entries rather than by editing history. Authorised administrators can export available report data in CSV format through the reporting tools provided by LeaveVia.
Workspace deletion
- A workspace owner can request deletion of the workspace from within the application.
- The request then runs a 30-day grace period, during which it can be cancelled by the owner.
- After the grace period, a scheduled deletion process finalises the request; it is not instantaneous and runs as part of routine daily maintenance.
- When it runs, organisation-scoped application data is purged in line with that implemented process, and calendar credentials stored locally by LeaveVia are removed.
- Platform sign-in identities that are left without any remaining workspace membership are removed where they are eligible; a person who still belongs to another workspace keeps their login.
Individual account deletion
- Deleting your personal LeaveVia account does not automatically destroy historical workforce or leave records that a customer organisation controls.
- Those records may remain in the customer's workspace under that organisation's control, and requests about them are directed to the organisation.
- Your LeaveVia account, profile and access data are removed or anonymised in line with the implemented account-deletion process, which also follows a 30-day grace period that can be cancelled.
Operational deletion receipts
To run deletion reliably and to retry an interrupted step, the service keeps a minimal operational record of each deletion run. These records contain non-content operational information only — such as identifiers, timing, status and a short failure category — and never leave detail or employee content. They are retained for 30 days and are pruned automatically.
More generally, we keep information only for as long as it is necessary to provide and secure the service and to meet applicable legal obligations. After deletion, copies may persist in our providers' routine backups for a limited period before they are removed in the ordinary course; we do not state an exact backup-erasure period because that period is determined by our hosting provider. Payment records retained by Paddle are governed by Paddle's own legal and retention obligations in its Merchant-of-Record role.
International processing
LeaveVia is delivered as an internet service and may be accessed by users in different countries; its infrastructure and service providers may process information outside the country where an organisation is based. The services LeaveVia relies on, and Paddle's separate payment role, are described on the Subprocessors & Payment Provider page.
The application backend for LeaveVia — the managed database, authentication and file storage — is hosted in a European region of Lovable Cloud (Ireland, EU). Support, administration and access by users travelling or working elsewhere can still involve access from outside that region, and optional calendar integrations and Paddle payments operate on the relevant provider's own infrastructure.
Your rights
Depending on where you live and the law that applies to you, you may have rights to access, correct, delete, restrict or object to the processing of your personal information, or to receive a copy of it. Where LeaveVia handles information on an organisation's behalf, requests are normally directed to that organisation, and LeaveVia assists it in responding. Contact your workspace administrator first, or email us at hello@aegeanastraea.com. Requests about information processed directly by Paddle for a purchase should be directed to Paddle under its own privacy notice.
Complaints to a supervisory authority
If you are in the EU/EEA you have the right to lodge a complaint with a competent data protection supervisory authority. For the current Cyprus-based operation of LeaveVia, that authority is the Commissioner for Personal Data Protection of the Republic of Cyprus, whose official website is dataprotection.gov.cy. You may also lodge a complaint with the authority in your country of residence or place of work.
Who provides LeaveVia
LeaveVia is provided by the LeaveVia operator, an independent operator trading under the Aegean Astraea brand from Cyprus. Aegean Astraea is a trading brand and is not represented here as a separate incorporated company. Email is our contact channel for privacy questions: hello@aegeanastraea.com.
Changes
This notice may be updated as the product develops. The date at the top of the page shows when it was last changed.