Privacy Policy
Last updated: December 2024
1. Introduction
DCWD ("we", "our", or "us") operates the OrOut leave management platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and handling your data in an open and transparent manner. Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us, including:
- Name and email address
- Company or organization name
- Job title and department
- Profile information (such as profile photos)
- Leave request details (dates, types, notes)
- Calendar information (when you connect your calendar)
- Communication preferences
2.2 Information from Third-Party Services
When you connect third-party services to OrOut, we may collect:
- Slack: Workspace information, user profile, channel membership for notifications
- Microsoft Teams: Team information, user profile for bot interactions
- Google Calendar: Calendar events to detect conflicts and sync approved leave
- Microsoft Outlook: Calendar events and availability information
2.3 Automatically Collected Information
When you access the Service, we automatically collect:
- Device information (browser type, operating system)
- IP address and general location
- Usage data (pages visited, features used, time spent)
- Cookies and similar tracking technologies
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process leave requests and approvals
- Send notifications about leave requests and approvals
- Sync leave information with connected calendars
- Detect calendar conflicts when submitting leave requests
- Calculate leave balances and allowances
- Improve and personalize your experience
- Communicate with you about the Service
- Provide customer support
- Monitor and analyze usage patterns
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. How We Share Your Information
We may share your information in the following circumstances:
4.1 Within Your Organization
Your leave requests and related information are shared with authorized users within your organization, such as your manager, HR administrators, and colleagues who have permission to view team calendars.
4.2 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Cloud hosting providers (e.g., Microsoft Azure)
- Database services (e.g., MongoDB)
- Authentication services (e.g., Kinde)
- Payment processors (e.g., Stripe)
- Analytics services
- Email delivery services
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Multi-tenant data isolation to ensure your organization's data is kept separate
- Regular security assessments and monitoring
- Access controls and authentication requirements
- Secure OAuth 2.0 integration with third-party services
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
When you or your organization administrator requests deletion of your account, we will delete or anonymize your personal information within 30 days, unless we are required to retain it for legal purposes.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a portable format
- Objection: Object to certain processing of your personal information
- Restriction: Request restriction of processing in certain circumstances
To exercise any of these rights, please contact us at privacy@orout.co.
8. Cookies and Tracking
We use cookies and similar tracking technologies to collect and track information about your use of the Service. Types of cookies we use include:
- Essential cookies: Required for the Service to function properly
- Analytics cookies: Help us understand how the Service is used
- Preference cookies: Remember your settings and preferences
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
10. Children's Privacy
The Service is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
DCWD
Email: privacy@orout.co