Legal
Privacy Policy
Last updated: 10 August 2026
This Privacy Policy explains how Leckware (“we”, “us” or “our”), an Irish business based in the European Union, collects and processes personal data through the DESKREG platform (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. Who we are and our role
Leckware acts as a Data Controller for the personal data processed to operate, bill, and administer the Service. Where your organisation submits data about its employees or operations into DESKREG, your organisation acts as the Data Controller and Leckware acts as a Data Processor operating strictly under your documented instructions. For detailed terms regarding data processing, see our GDPR Compliance Statement.
2. Data we collect and process
- Account data: Name, business email address, password hash, or third-party account identifiers if you choose to sign in via Google or Microsoft Azure OAuth, and company setup details.
- Employee and operational data: Profiles created by your organisation, including names, contact details, roles, departments, rota and scheduling information, time-off records, clock-in and attendance data, task assignments, training logs, quiz scores, and internal employee requests.
- Billing data: Payment references, subscription plans, billing addresses, and tax identifiers processed securely through Stripe. We never store full card numbers on our servers.
- Technical & security data: IP addresses, browser types, device identifiers, HTTP headers, and access logs collected for operational security, threat detection, and service maintenance.
3. How we use data
- To deliver and operate DESKREG functionality (rotas, leave management, tasks, attendance, training, and requests).
- To manage subscriptions, issue invoices, handle billing, and provide customer support.
- To secure the Service, prevent unauthorized access or abuse, and enforce two-factor authentication.
- To maintain infrastructure stability and diagnose application errors.
- To comply with statutory legal and accounting obligations under Irish law.
4. Legal bases for processing
- Performance of a contract: Delivering the Service in accordance with our Terms and Conditions.
- Legitimate interests: Securing our systems, routing web traffic safely, preventing fraud, and improving platform reliability.
- Legal obligation: Retaining financial records for tax authorities or obeying legal directives.
- Consent: Where explicitly given, such as accepting optional preference cookies or promotional updates.
5. Where your data is stored & transfers
Primary application data and databases are stored in the European Union on infrastructure provided by Hetzner (Germany). Where external sub-processors handle limited operational functions (such as payment gateway processing or OAuth authentication), we ensure appropriate transfer mechanisms under Chapter V of the GDPR (such as Standard Contractual Clauses or the EU-US Data Privacy Framework) are active.
6. Sharing and third-party processors
We do not sell personal data or share it with third parties for advertising. We engage vetted sub-processors necessary to run the Service:
- Hetzner Online GmbH: Primary EU cloud hosting and database storage.
- Stripe Payments Europe Ltd: Secure subscription billing and payment processing.
- Cloudflare, Inc.: DNS routing, DDoS protection, and edge security.
- Google Ireland Ltd & Microsoft Ireland Operations Ltd: Optional single sign-on (SSO) authentication.
A complete and up-to-date disclosure is maintained on our dedicated Sub-processors page.
7. Data retention
We keep account and customer data for as long as your subscription is active. Upon subscription cancellation or account termination, you may export your data during the grace period, after which customer data is purged from active databases and deleted from backup systems in line with our standard backup retention cycles.
8. Security measures
We implement technical and organizational safeguards including end-to-end TLS encryption in transit, AES-256 encryption at rest, tenant-level data isolation, strict role-based access controls, and support for multi-factor authentication. Learn more in our GDPR Compliance Statement.
9. Data subject rights
Under the GDPR, individuals have the right to access, rectify, erase, restrict, and object to the processing of their personal data, alongside the right to data portability. You may exercise these rights through the Service interface or by emailing [email protected].
You also have the right to lodge a complaint with the lead supervisory authority, the Irish Data Protection Commission (DPC), or your local EU data protection authority.
10. Cookies and local storage
We use essential session cookies and local storage tokens to keep you authenticated, maintain session security, and store interface preferences (such as dark mode settings). We do not deploy third-party advertising or cross-site tracking cookies.
11. Contact
For privacy questions or data protection requests, contact us at [email protected].