Privacy Policy
Last Updated: July 14th, 2026
Your privacy matters to us and we are committed to protecting your privacy and your personal information.
This Privacy Policy applies to our website and all our services, including the related mobile applications that belong to Day Off and are controlled by Day Off LTD.
This Privacy Policy contains all the information regarding personal data protection and information regarding cookies.
1. Personal Data Collection
We are not the Controller of the data entered by our Clients in Day Off. In this area, Day Off is Processor at the request of the Client based on the Data Processing Agreement. The client is fully responsible for fulfilling legal obligations in their own company.
2. Purposes and Objectives of The Processing of Personal Data
Your personal data shall be processed in order to perform a contract or provide a service according to Article 6(1)(b) of the GDPR, in the context of the fulfillment of a legal obligation pursuant to Article 6(1)(c) of the GDPR. Personal data may be processed based on the opt-in consent referred to in Article 6(1)(a) of the GDPR.
Your personal data may be processed for necessary purposes resulting from Data Controller’s business interests according to Article 6 (1)(f) GDPR, i.e. marketing, settlement of claims, cooperation, maintaining the security of our services, and preventing fraud, supporting and improving our services, data analysis, processing credit card payments, supporting and improving our services through trend analysis, better understanding of the functionality of our service on a mobile device, collecting demographic information about the user base as a whole. We are also processing navigation data in connection with your use of our website. By contacting us, filling out web forms, or registering to use our services, we will receive personal data and process them in accordance with the stated purposes.
We use mobile analytics software to allow us to better understand the functionality of our service on your mobile device. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from. When you use our mobile apps we may also collect your city location, device model and version, device identifier (or “UDID”), and OS version.
We may store information about your computer hardware and software that is automatically collected by our infrastructure mechanisms and service providers. This information can include: your IP address, browser type, domain names, internet service provider (ISP), length of visits, the files viewed on our site (e.g., HTML pages, graphics, etc.), clickstream data, access times, and referring website addresses, operating system, device screen size, page views. We process this information based on our legitimate interest (Article 6(1)(f) GDPR) to provide you with high-quality services. Log files provide us with general statistical information about the use of services, in addition, it is important to maintain security and prevent fraud.
Day Off’s own application data and databases are hosted with our infrastructure provider in Frankfurt, Germany (EU-Central), meaning the core data you and your company enter into Day Off is stored within the European Union. Where we use third-party service providers described throughout this Policy (e.g., for SSO, calendar sync, chat platform integrations, payments, and email delivery), those providers may process or store data on their own infrastructure, which can be located outside the EU/EEA; details are noted under each relevant section below.
3. Period of Data Processing
The personal data you provide us with will be stored and processed for as long as it is based on reasonable business needs (for example, as long as it is necessary to contact you with respect to your Subscription or other our services) or as long as it is necessary to comply with legal obligations, resolve disputes and perform our contracts.
We shall store your personal data only for as long as it is needed to achieve the purposes mentioned herein or for as long as the various storage deadlines envisaged by the legislator allow. After cessation of the respective purpose or expiration of these deadlines, the corresponding data shall be locked or deleted in accordance with statutory provisions.
We may use your name, business email address, company name, and information about your use of Day Off to invite you to provide feedback or review our services. To facilitate these invitations, we may share limited personal information with trusted third-party review platforms and survey providers (such as G2) solely for the purpose of collecting authentic customer feedback. These providers process the information in accordance with their own privacy policies and applicable data protection laws.
If you do not wish to receive review invitation emails, you may opt out by following the unsubscribe instructions included in the email or by contacting us at [email protected]
4. Retention of Personal Data
In the case not having requirements to process your personal data, it will be anonymized or deleted from our systems and backups as soon as possible and within a maximum of 90 days. If, for technical or other reasons, we are unable to delete your data, we will take measures to ensure that your personal data further processing is blocked.
5. Single Sign-On
Day Off offers the option to register your company, import employees, and log in using single sign-on (“SSO”) through Microsoft and, once available, Google. SSO is optional and provided as a convenience alongside standard email/password registration and login.
Microsoft Sign-In
Day Off Users and company administrators can register a company, import employees, and log in using Microsoft Sign-In. When you or your company use Microsoft Sign-In, we may collect and process:
- Your name, email address, and profile picture from your Microsoft account, used to create or authenticate your Day Off account.
- Basic company/organization information (e.g., domain, organization name) when a company registers Day Off using Microsoft Sign-In, used to set up the company workspace.
- Where an administrator chooses to import employees from their Microsoft (Azure AD / Microsoft 365) organizational directory, the names and business email addresses of those employees, used solely to create employee accounts within the company’s Day Off workspace. This import is initiated and authorized by the company administrator, who is responsible for having the appropriate rights to share this information.
We do not receive or store your Microsoft account password. Authentication is handled directly by Microsoft using the OAuth 2.0 protocol, and Day Off only receives the limited profile and directory information described above, based on the permissions (scopes) granted at the time of sign-in. Data received through Microsoft Sign-In and the Microsoft Graph API is used solely for the purposes described above (account creation, authentication, and, where authorized, employee import) and is handled in accordance with Microsoft’s applicable API terms and this Privacy Policy.
You or your company administrator can revoke Day Off’s access to your Microsoft account at any time through your Microsoft account/admin settings. Revoking access will not delete data already stored in Day Off; to request deletion, please contact us at [email protected].
Authentication itself takes place directly between you and Microsoft, on Microsoft’s own servers, which may be located outside the European Economic Area (EEA) and are governed by Microsoft’s own data location and security policies. The profile and directory data Day Off receives as a result (e.g., name, email, imported employee records) is stored on Day Off’s own servers in Frankfurt, Germany (EU-Central).
Google Sign-In
Day Off Users and company administrators can register a company, import employees, and log in using Google Sign-In. When you or your company use Google Sign-In, we may collect and process:
- Your name, email address, and profile picture from your Google account, used to create or authenticate your Day Off account.
- Basic company/organization information (e.g., domain, organization name) when a company registers Day Off using Google Sign-In, used to set up the company workspace.
- Where an administrator chooses to import employees from their Google Workspace organizational directory, the names and business email addresses of those employees, used solely to create employee accounts within the company’s Day Off workspace. This import is initiated and authorized by the company administrator, who is responsible for having the appropriate rights to share this information.
We do not receive or store your Google account password. Authentication is handled directly by Google using the OAuth 2.0 protocol, and Day Off only receives the limited profile and directory information described above, based on the permissions (scopes) granted at the time of sign-in.
Day Off’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You or your company administrator can revoke Day Off’s access to your Google account at any time through your Google Account security settings. Revoking access will not delete data already stored in Day Off; to request deletion, please contact us at [email protected].
Authentication itself takes place directly between you and Google, on Google’s own servers, which may be located outside the European Economic Area (EEA) and are governed by Google’s own data location and security policies. The profile and directory data Day Off receives as a result (e.g., name, email, imported employee records) is stored on Day Off’s own servers in Frankfurt, Germany (EU-Central).
6. Day Off Email Notifications and Newsletter
Our newsletter and emails are sent via “Mailgun”, a customer communication platform for transactional and marketing email distribution. The use of Mailgun represents a transmission of personal data to a third-party company. The email addresses of our newsletter recipients, as well as further data described within the scope of this Privacy Policy, are stored on Mailgun servers in the USA. Mailgun uses this information for the purpose of distributing and evaluating the newsletters on our behalf.
If you no longer want to read our newsletter, you are entitled to object to the use of your email address at any time by clicking the unsubscribe link.
7. Payment Processing
Day Off uses “Stripe” to process subscription payments. When you or your company purchase a Day Off subscription, your payment card details and billing information are collected and processed directly by Stripe; Day Off does not store full payment card numbers on its own servers. Stripe is a PCI-DSS compliant payment processor and processes this information in accordance with its own privacy policy and applicable data protection laws. Information Day Off may retain in connection with billing includes your name, business email address, country and any extra billing information added by the customer such as billing address, Tax ID, and subscription/transaction history.
Payment data collected by Stripe is stored and processed on Stripe’s own global infrastructure, which may be located outside the EU/EEA, under Stripe’s data location and security policies. Billing information retained by Day Off itself (as listed above) is stored on our servers in Frankfurt, Germany (EU-Central).
8. Cookies
Day Off, like many other websites, retrieves information on your browser using cookies. When you visit Day Off websites for the first time, you will be informed that you authorize Day Off to collect and use cookies in accordance with this Privacy Policy. You have the ability to accept or decline cookies. Most browsers are initially set up to accept cookies, but you can usually modify your browser settings to decline cookies if you prefer. A cookie is a file containing an identifier (a string of letters and numbers) that is sent by a web server to a web browser and then stored by the browser. Usually, the identifier is sent back to the server each time the browser requests a page from the server. Cookies may be either “persistent” cookies or “session” cookies:
- A persistent cookie will be stored by a web browser and will remain valid until its expiry date unless earlier deleted by the user.
- A session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.
Cookies are used to:
- Keep our service secure and prevent fraud.
- Help us improve our websites and service by.
- Administering and selecting content on the websites.
- Tracking user movements across the websites.
- Gathering demographic information about our user base as a whole.
To find out more about cookies, including information about what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org.
Can choose to decline cookies. You will find instructions in the following places:
- in Microsoft Edge tutorial;
- in Firefox tutorial;
- in Safari tutorial;
- in Chrome tutorial;
Blocking all cookies will have a negative impact on the usability of many websites, including ours. You can also delete cookies already stored on your computer, but deleting cookies will have a negative impact on the usability of our websites.
9. Integrations and Third-Party Service Providers
This section distinguishes between two types of third parties: (a) Integrations, which are optional features a company or User actively chooses to connect for their own use within Day Off, and (b) Third-Party Service Providers, which are vendors Day Off itself relies on to operate and improve the service, and which are not something companies configure or opt into individually.
Integrations
The following are optional, User- or company-initiated connections between Day Off and another platform.
Google Calendar
Calendar Information. A Day Off User may connect their Google Calendar with Day Off. Our calendar integration only checks the duration and free/busy status of the events in your calendar so that we don’t book you when you’re busy. We never store who you are meeting with, their email address, the meeting title, or any other details about the appointments in your connected calendar.
This check is performed via a live request to Google’s servers, which may be located outside the EU/EEA; Day Off does not retain a copy of your calendar data beyond the momentary free/busy check described above.
Outlook Calendar
A Day Off User may similarly connect their Outlook / Microsoft 365 Calendar with Day Off using the Microsoft Graph API. As with Google Calendar, our integration only checks the duration and free/busy status of events so that we don’t book you when you’re busy. We do not store meeting attendees, subjects, locations, or other appointment details from your connected Outlook Calendar.
This check is performed via a live request to Microsoft’s servers, which may be located outside the EU/EEA; Day Off does not retain a copy of your calendar data beyond the momentary free/busy check described above.
Slack
Day Off offers an optional Slack integration that a company administrator may connect to their Slack workspace. Once connected, this integration may be used to:
- Import employees from the connected Slack workspace to create or match their Day Off accounts.
- Receive leave-related notifications directly in Slack (such as new requests, approvals, and status updates).
- Submit leave requests, approve or reject leave requests, and check leave balances directly from within Slack, without needing to open the Day Off web or mobile app.
To provide this integration, we may process your Slack user ID, display name, and business email address (for account matching/import), your workspace/team ID, and the leave request, approval, and balance information necessary to display and action these features within Slack. We do not access or store the content of unrelated Slack channels or messages.
Messages and interactive actions are exchanged with Slack Technologies’ own servers, which may be located outside the EU/EEA, under Slack’s data location and security policies. The underlying leave data (requests, approvals, balances) remains stored on Day Off’s own servers in Frankfurt, Germany (EU-Central).
Microsoft Teams
Day Off offers an optional Microsoft Teams integration that a company administrator may connect to their Microsoft 365 tenant. Once connected, this integration may be used to:
- Import employees from the connected Microsoft/Azure AD organizational directory to create or match their Day Off accounts.
- Receive leave-related notifications directly in Teams (such as new requests, approvals, and status updates).
- Submit leave requests, approve or reject leave requests, and check leave balances directly from within Teams, without needing to open the Day Off web or mobile app.
To provide this integration, we may process your Microsoft Teams/Azure AD user identifier, display name, and business email address (for account matching/import), your tenant ID, and the leave request, approval, and balance information necessary to display and action these features within Teams. We do not access or store the content of unrelated Teams channels or chats.
Messages and interactive actions are exchanged with Microsoft’s own servers, which may be located outside the EU/EEA, under Microsoft’s data location and security policies. The underlying leave data (requests, approvals, balances) remains stored on Day Off’s own servers in Frankfurt, Germany (EU-Central).
Third-Party Service Providers
The following vendors support Day Off’s own operation of the website and service. Unlike the Integrations above, these are not connected or configured by individual companies; they apply to all use of Day Off’s website/app. (Stripe and Mailgun, also third-party service providers, are addressed in their own dedicated sections above, Sections 6 and 7.)
Google Fonts
Data processing by Google Fonts is required to ensure that the website is displayed correctly. Google Fonts checks if the respective font is stored on your device. If the font is not available, it will be transferred to the device in order to display the font and the page correctly. The following data is sent by Google Fonts to fonts.googleapis.com: Google Fonts logs records of CSS and font file requests. Aggregated usage data track how popular the font families are, and are published on our analytics page. For more information about how Google Fonts processes data, please visit: https://developers.google.com/fonts/faq
Google Analytics
Day Off uses Google Analytics, a web analytics service provided by Google, to help us understand how visitors use our website (e.g., pages viewed, time on page, traffic sources, and general geographic/device information). Google Analytics uses cookies and similar technologies to collect this information, which is transmitted to and processed by Google. We use this data based on our legitimate interest (Article 6(1)(f) GDPR) in understanding and improving our website. You can opt out of Google Analytics by adjusting your cookie preferences on our site or by installing the Google Analytics opt-out browser add-on. For more information, please refer to Google’s privacy policy at https://policies.google.com/privacy.
HubSpot
Day Off uses a service called HubSpot provided by HubSpot Inc. for live chat and customer support service. HubSpot is certified under the EU-US privacy shield. It uses “web beacons” and also installs cookies, which are stored on your computer and enable us to analyze your use of the website. The collected information (e.g. IP address, geographical location, type of browser, duration of the visit, and pages accessed) is evaluated by HubSpot on Day Off’s behalf to generate reports about the visit and the pages of Day Off that were visited. It is transmitted to http://hs-analytics.net sowie js.hs-scripts.com for this purpose.
If you subscribe to email news and download e-books and other documents, we can record the personal information you provide us with (e.g. your name and email address) and use it to present you with targeted information about your preferred areas of interest. If you generally do not want this information to be collected by HubSpot, you can prevent the storing of cookies at any time by adjusting your browser settings. Please refer to HubSpot Inc.’s privacy policy at https://legal.hubspot.com/privacy-policy for further information on how HubSpot works.
10. Your Security Matters
We take reasonable technical and organizational security measures to prevent the loss, misuse, or modification of your personal data. All our employees are obliged to maintain data confidentiality and to comply with the data protection provisions and have been instructed accordingly. Please be aware that the websites of third parties which are accessible through links connected with our service offer may be subject to other provisions that deviate from this privacy policy.
11. Your Rights
You can exercise rights to access your personal data, as well as the right to rectify, erase, or restrict the processing and the right to data portability if possible. You have the right to object to the processing. In order to exercise any of these rights, please contact us by e-mail at: info[at]day-off[dot]app we will respond to your request within a reasonable period of time, but not later than 30 days, and we will notify you of the actions we have taken.
12. Changes in Privacy Policy
We may adjust and update this Privacy Policy as necessary by posting new versions on our site. You should check this page from time to time to ensure that any changes to this Privacy Policy are acceptable to you. This Privacy Policy does not limit any rights you may have under these Terms of Use or under applicable law.
If you have any questions about our privacy policy, please send an email to [email protected]