Data, privacy and retention
Where the data is, how long it is kept, how medical certificates are protected, what happens when a person is deleted, the use of artificial intelligence, measurement and cookies.
This page is a practical summary of what the legal documents establish. In case of doubt the Privacy notice and the Data processing agreement prevail.
The public page Security and trust gathers in one place what people usually ask during a review: where the data is, which security measures are applied, how artificial intelligence is used, the legal documents and the list of providers, plus twelve frequently asked questions about access, export, deletion and changes to the documents. It is public and you do not need to be signed in: you can send the link to whoever in your company has to assess the platform.
Where the data is
- Each organisation's database is separate and sits in the European Union (Frankfurt region).
- The application, the sending of emails and the AI commentary on reports use providers based in the United States, on the basis of the European Union's standard contractual clauses. The full list, with the function and the location of each one, is on the Subprocessors page.
Who the controller is
The company that uses LeavePilot is the controller of its employees' data; LeavePilot processes it on the company's behalf as processor, under the data processing agreement accepted by the administrator. People's requests about their own data (access, rectification, erasure) go to the company; if they reach LeavePilot they are passed on to the company within five working days.
How long data is kept
| Data | Retention |
|---|---|
| Accounts, requests, balances, departments | for the duration of the contract; still exportable for 30 days after termination |
| Medical certificates | 12 months from upload, then deleted automatically; deleted at once if the request or the person is deleted |
| Sign-in log (successful and failed sign-ins, lockouts) | 12 months |
| Log of AI report generations (without the text produced) | 24 months |
| Unfinished signups of new organisations | 30 days (the password hash after 24 hours) |
Medical certificates
They are health data and are handled with particular care:
- the file is encrypted before it is stored;
- only administrators and the person who uploaded it can download it;
- it stays available for 12 months, then a monthly cleanup deletes it;
- it is deleted at once together with the request it is attached to, or with the person;
- the request form reminds you to upload the sickness certificate summary (the Italian "attestato") with the protocol number and the dates, not the certificate with the diagnosis.
When a person is deleted
An administrator can delete an account from the Employees section: personal data, all requests, medical certificates (files included) and the photo are deleted. The entries in the operations log remain. As an alternative the account can be deactivated, keeping the history. See Employee management.
Exporting the data
Administrators export the organisation's data in PDF and Excel from the Reports section. There is no self-service export for an individual employee: the person asks their own company for it.
If the contract ends, the data can still be recovered for 30 days. While access is still working, the quickest way is to export everything from Reports choosing the period From the Beginning and the format Both - Complete Package. If access is no longer available, write to support@leavepilot.app within the 30 days quoting the address of your workspace: after that deadline the data is deleted and cannot be recovered.
Artificial intelligence
The only use of artificial intelligence is the commentary in the AI report, available on the Business plan and generated when the administrator asks for it. The model receives only aggregate figures for the period, never names, email addresses or the data of an individual person; departments with fewer than three people are merged or left out; the generated text is discarded if it names a person or expresses judgements or recommendations. The data is not used to train models. The document produced is labelled as automatically generated. The full rules are in the AI instructions for use.
Measurement and cookies
- On the public site (landing page, signup, legal documents, this guide) the banner Before takeoff, cookies appears on the first visit, with Accept all, Reject all and Customize. There are three categories: Necessary, always on because the site does not work without them; Measurement, which governs visit statistics; Marketing, in place but inactive today. Without consent to Measurement no statistics are collected. You can change your choice at any time from the Cookie preferences link in the footer, which reopens the panel with Save preferences.
- In the application only technical cookies are used and there is no banner. The collection of technical events, when it is on, writes nothing on the device, does not record email addresses or names (they are replaced by hashes or removed) and masks text fields. An organisation can ask for it to be turned off for its own users by writing to support.
The emails
Operational emails go out from the platform's own service or, if the administrator has configured it, from the company's mail service. They contain the data that is needed (name, dates, status) and never the medical certificates.