LeaveVia — a product by Aegean Astraea

Subprocessors & Payment Provider

These are the service providers LeaveVia relies on today, together with the independent payment provider used for paid subscriptions.

Last updated: 12 September 2026

Current subprocessors

Lovable (Lovable Cloud)

Purpose
Application hosting and delivery of the LeaveVia web application and its server functions.
Data category / function
All workspace data in transit through the application, plus technical and security logs.
When used
Always in use.

Lovable (Lovable Cloud) — managed database, authentication and file storage

Purpose
Stores workspace and employee records, leave policies, the leave ledger, notifications and audit records, and enquiry form submissions; provides account authentication.
Data category / function
Workspace configuration, employee records, leave data, authentication data, notification and audit records, enquiry form details.
When used
Always in use.

Lovable managed email service

Purpose
Sends transactional email (invitations, request and approval notifications, authentication emails) from notifications@notify.aegeanastraea.com.
Data category / function
Recipient email address, sender/recipient metadata and the minimal content of the transactional message.
When used
Always in use for email notifications.

Google (Google Calendar API)

Purpose
One-way publication of approved leave into a user's Google Calendar.
Data category / function
Availability entries only (dates and an away indication) plus the connection's authorisation data.
When used
Only when a user connects Google Calendar.

Microsoft (Microsoft Graph / Outlook Calendar)

Purpose
One-way publication of approved leave into a user's Outlook calendar.
Data category / function
Availability entries only (dates and an away indication) plus the connection's authorisation data.
When used
Only when a user connects Microsoft Outlook.

Paddle — Merchant of Record for paid subscriptions

Paid subscription orders and payments are handled by Paddle in its role as Merchant of Record and authorised reseller. Paddle receives and processes buyer and billing information needed for checkout, payment-method processing, invoicing, applicable taxes, fraud prevention, refunds, chargebacks and subscription billing. Depending on the buyer's location, the relevant Paddle contracting entity processes that information under Paddle's own buyer terms and privacy notice.

Paddle acts independently for those buyer/payment purposes and is not a subprocessor of the employee leave records stored inside a LeaveVia workspace. LeaveVia receives only the billing and subscription information needed to identify the customer workspace, confirm subscription state and provide the purchased entitlement; LeaveVia does not receive raw card details from Paddle.

No advertising or third-party font providers

LeaveVia does not use advertising or third-party tracking services in the application. Fonts are served from LeaveVia itself, so no third-party font service is involved. Google and Microsoft are listed above for authentication/calendar functionality a user chooses to use; Paddle is separately disclosed above because its Merchant-of-Record role is independent from the employee-data subprocessors used to run the LeaveVia workspace.

Hosting region

The LeaveVia application backend — managed database, authentication and file storage — is hosted in a European region of Lovable Cloud (Ireland, EU). Email delivery and the optional calendar integrations run on the relevant provider's own infrastructure. Paddle processes buyer/payment information on its own infrastructure for paid transactions. We do not make further data-residency or transfer-mechanism guarantees beyond the facts stated here and in the Privacy Policy.

Changes

This page is updated when a service provider or material payment-processing arrangement is added, removed or materially changed. The date at the top shows when it was last changed.