Learn how Offly collects, uses and protects your information.
Built with European data protection principles at its core.
Encrypted at rest and in transit with modern TLS standards.
Employees, managers and admins see only what they need.
Every access and change is recorded for accountability.
Offly ("we", "our", "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, store and protect information when you use our leave management platform.
This policy applies to all users of Offly, including organisation administrators, managers, and employees. By using Offly, you acknowledge that you have read and understood this policy.
We process personal data as both a data controller (for our direct relationship with you) and as a data processor (when processing employee data on behalf of your organisation).
We collect the following categories of personal information to provide our leave management services:
We only collect information that is necessary to provide our leave management services. We do not collect sensitive personal data such as health records, biometric data, or political opinions.
We use the information we collect for the following purposes:
We process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
Where your organisation is our customer, they act as the data controller for employee data processed through Offly, and we act as their data processor under a Data Processing Agreement.
Your data is stored securely using industry-standard measures:
We follow the principle of least privilege — every system component and team member has access only to the minimum data required for their function.
Offly integrates with the following third-party services when enabled by your organisation:
Each integration only shares the minimum data required for its function. Integrations are activated by organisation administrators and can be disconnected at any time.
Where personal data is transferred outside of the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
You can request information about the specific safeguards applied to your data by contacting us.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
Organisation administrators can request earlier deletion of data by contacting our support team.
Under data protection law, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data where there is no compelling reason for continued processing.
Receive your data in a structured, machine-readable format.
Request restricted processing in certain circumstances.
Object to processing based on legitimate interests.
To exercise any of these rights, contact us at the address below. We will respond within 30 days. Where your data is processed on behalf of your organisation, we may direct your request to your organisation's administrator.
You can request deletion of your account at any time. For individual users, contact your organisation administrator. For organisation accounts, contact our support team.
Upon account deletion:
We take the security of your data seriously. Our security practices include:
In the event of a data breach that poses a risk to your rights, we will notify affected organisations within 72 hours in accordance with GDPR requirements.
Offly is a business-to-business platform designed for workplace leave management. Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children.
If you believe a child has provided personal data to us, please contact us immediately and we will take steps to delete such information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes:
If you have questions about this Privacy Policy or wish to exercise your data protection rights, you can reach us at:
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been infringed.
Our team is happy to answer any questions about how we handle your data.
Contact Privacy Team