Encrypted leave data flows
LeaveManager uses TLS for application traffic, SSL-required database connections, protected secrets, and Stripe-hosted payment collection so card numbers are not stored by LeaveManager.

Leave management security UK
LeaveManager protects employee leave records with encrypted connections, role-based access, managed database backup capability, business continuity planning, and UK GDPR aligned processing.
A practical trust review for UK employers before inviting staff into LeaveManager.
LeaveManager uses TLS for application traffic, SSL-required database connections, protected secrets, and Stripe-hosted payment collection so card numbers are not stored by LeaveManager.
Workspace data is stored in managed PostgreSQL infrastructure with provider-managed backup capability, recovery processes, and operational checks for critical business records.
LeaveManager runs on managed cloud services with edge delivery, monitored operational dependencies, documented sub-processors, and restore paths for service-impacting incidents.
Customer organisations remain controller for employee records. LeaveManager acts as processor for workspace, leave, sickness, approval, user, and audit data entered into the service.
Encryption and access
Leave data can reveal sickness patterns, absence history, team cover, and payroll relevant dates. LeaveManager keeps the control model simple: encrypted connections, scoped roles, protected authentication, and audit history for important workspace changes.
Backups and recovery
LeaveManager stores production workspace records in managed PostgreSQL infrastructure and keeps recovery planning focused on the data customers need to keep leave approvals, employee balances, sickness records, and audit history available.
Managed PostgreSQL storage for production workspace, employee, leave, sickness, approval, and audit data.
Provider-managed backup capability for database recovery scenarios.
Workspace export and deletion support for active and closed accounts.
Service restoration priorities that put authentication, workspace access, leave records, and approval workflows first.
Business continuity
LeaveManager uses managed cloud services and documented operational dependencies to reduce single points of failure. If an incident affects the service, restoration priorities focus on account access, workspace availability, leave history, approval queues, and payroll-relevant absence data.
Security controls reduce avoidable incidents through encryption, access roles, protected credentials, rate limiting, hosted checkout, and restricted operational access.
Operational logs, error capture, analytics signals, payment events, and support channels help surface service or account issues that need investigation.
Recovery work prioritises customer access, database availability, leave records, approval queues, and payroll-relevant absence history.
GDPR compliance
Your organisation controls the employee data entered into LeaveManager. We process that data to provide the service, secure the platform, send operational messages, support your account, and meet legal or billing obligations.
The formal legal terms remain the Privacy Policy, Terms of Service, and any Data Processing Agreement agreed with LeaveManager.
Sub-processors
LeaveManager keeps the sub-processor list short and operational. These providers help deliver hosting, database storage, payments, email, analytics, and support chat.
PurposeApplication hosting, CDN, routing, DDoS protection, edge security, and request handling
Data handledApplication traffic, IP addresses, request metadata, security logs
PurposeManaged PostgreSQL database hosting for workspace, employee, and leave-management data
Data handledAccount, organisation, employee, leave, absence, approval, and audit records
PurposePayment processing, subscription checkout, customer portal, and invoices
Data handledBilling contact details, payment metadata, subscription status
PurposeTransactional email delivery for account, trial, and leave-management notifications
Data handledRecipient email addresses, message content, delivery metadata
PurposeEU-hosted product analytics to understand feature usage and improve LeaveManager
Data handledUsage events, device information, feature interaction metadata
PurposeOptional sales and trial support chat when the chat widget is enabled
Data handledSupport messages, contact details provided in chat, chat metadata