Privacy Policy
This describes what we collect, why, and how it's protected. See our Security page for the technical detail behind these commitments.
What we collect
Account data you or your employer give us: name, work email, and the leave/attendance records your employer's admins enter or approve. If you sign in via Microsoft Entra ID, we receive the profile fields your organisation's admin has consented to share. We don't collect anything beyond what running the product requires — no ad tracking, no third-party analytics pixels on this site. The sign-up form uses Cloudflare Turnstile to block automated sign-ups, which processes technical details about your browser to do so.
Who controls your data
Your employer is the data controller for the leave and attendance records held in their account; we act as a data processor on their behalf. If you're an employee wanting your data corrected or removed, start with your organisation's admin — they control the account. If you're the admin, see "Your rights" below.
How we use it
Solely to run the product: calculating entitlement, routing approvals, sending the notifications you or your admin configure (email, Slack, Teams), and producing the reports your admins request. We do not sell data, and we do not use your leave records for advertising, profiling, or any purpose outside operating the account you or your employer signed up for.
Where it’s stored and how it’s isolated
Your data is isolated from every other customer three ways: explicit scoping in every query, an application-level guard as a second line, and row-level security enforced at the database itself — see our Security page for detail. Data is hosted with providers operating in the UK/EU.
Sensitive leave categories
Sickness and family leave are treated as sensitive by default: excluded from external notifications (Slack/Teams/email digests) and restricted in reporting to authorised administrators only, not visible to every approver.
Retention
Audit log entries are kept for six years by default (longer by arrangement with us), with database-level protection against early deletion or editing. Leave and account records are retained for as long as your organisation's account is active, plus any period your admin's offboarding/erasure settings specify.
Your rights
Admins can erase an individual user’s personal data (GDPR-aligned erasure) and download a full export of the account’s data, directly from the product. Closing the whole account is done by us on request, and we export its data first. If you’re an employee and your admin is unable to help, contact us at hello@otiumone.co.uk and we’ll assist directly.
Payments
If your organisation pays for Otium One, billing is handled by Stripe. Your card details are entered directly on Stripe's own page and never touch our servers, in either direction — we store no card numbers.
Contact
Questions about this policy or a request relating to your data: hello@otiumone.co.uk.