Privacy Policy

Last updated: June 15, 2026

YOTR is operated by Codiya Cyprus Ltd, a company registered in Cyprus under registration number HE 455523, with its registered address at 24 Vasili Michailidi, L'Angolo Building, Floor 2, 3026 Limassol, Cyprus. This policy explains how we handle personal data when organizations and their users use YOTR.

Privacy and data protection contact: hello@yotr.io. We have not appointed a formal Data Protection Officer at this time. If that changes, we will update this policy with the DPO's contact details.

1. Our Role Under GDPR

For most account and workplace data, your organization is the data controller and we act as its data processor. This includes employee profiles, time-off requests, calendars, allocations, time entries, clients, projects, tasks, and related administrative records.

We act as an independent controller for limited business operations, such as managing our relationship with customer administrators, responding to support or legal requests, maintaining service security, and operating this website.

2. Information We Process

Depending on how your organization configures and uses YOTR, we may process:

  • Google sign-in data from OpenID Connect, including your Google account identifier, primary email address via userinfo.email, and profile information via userinfo.profilesuch as name and avatar
  • Organization data, including organization name, approved email domains, locations, timezones, working days, and holiday country
  • Time-off data, including requests, approvals, dates, duration, recurrence, balances, manual adjustments, and reasons or notes entered by users or admins
  • Time-tracking data, including clients, projects, tasks, assignees, timer entries, notes, rounding settings, and internal hourly-rate or amount fields visible to admins
  • Integration data, including Google Calendar OAuth tokens, calendar identifiers, sync metadata, ICS subscription tokens, and external sync mappings
  • Uploaded assets, such as user avatars and client or project logos
  • Technical data, including session cookies, request metadata, device/browser information, logs, and security events

3. Google Calendar Data

If an authorized organization administrator connects Google Calendar for a location, YOTR requests the sensitive Google Calendar scope https://www.googleapis.com/auth/calendar. Google describes this scope as permission to see, edit, share, and permanently delete all calendars you can access using Google Calendar.

YOTR requests the full Calendar scope because the integration must create and manage a dedicated location calendar, not only individual events. That includes creating the calendar, updating and deleting its events, optionally granting domain-level reader access to approved organization domains, and deleting the dedicated calendar when an administrator disconnects the integration and chooses not to keep it. A narrower events-only scope would not allow these calendar-management operations.

We use this access only to provide the Google Calendar integration selected by your organization:

  • Create a dedicated calendar for the selected YOTR location
  • Create, update, and delete calendar events that represent eligible PTO, out-of-office, or availability records from YOTR
  • Store the created calendar ID, event IDs, sync timestamps, selected domain sharing settings, and a Google refresh token so the integration can keep working
  • Optionally grant reader access to the dedicated calendar for approved organization domains selected by an administrator
  • Delete the dedicated calendar if an administrator disconnects the integration and chooses not to keep the calendar

We do not use Google Calendar data for advertising, sell Google user data, or use it to train generalized AI or machine learning models. YOTR's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Personal Data

We process personal data to:

  • Authenticate users through Google OAuth and maintain secure sessions
  • Provide PTO, availability, calendar, allocation, and time-tracking features
  • Apply tenant separation, role-based access control, and organization-level permissions
  • Send or support operational notifications and calendar updates requested by your organization
  • Maintain, troubleshoot, secure, and improve the Service
  • Respond to support, contractual, legal, or compliance requests

5. Legal Bases

Where we act as a processor, we process personal data on your organization's documented instructions. Where we act as a controller, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where required.

6. Sharing and Subprocessors

We do not sell personal data. Personal data is shared only as needed to provide the Service, comply with law, or protect the Service and our users. Within your organization, visibility depends on configured roles and workflows; for example, managers and administrators may see requests, balances, team calendars, and time-tracking information within their permitted scope.

We use third-party service providers as subprocessors, including hosting and database providers, authentication providers such as Google OAuth, file storage providers such as Cloudinary for uploaded images, calendar and email-related providers where configured, and observability or support tools needed to operate the Service.

We do not transfer Google user data except as necessary to provide or improve user-facing features, comply with applicable law, protect against abuse or security threats, or as part of a merger, acquisition, or sale of assets after appropriate notice and protections.

7. International Transfers

Codiya Cyprus Ltd is established in Cyprus, within the European Union. Some service providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards, such as European Commission standard contractual clauses, adequacy decisions, or equivalent protections required by applicable law.

8. Cookies and Sessions

YOTR uses cookies and similar technologies that are necessary for authentication, session security, routing requests, and protecting accounts. We do not use these necessary cookies for cross-site advertising.

9. Retention and Deletion

We retain customer data for as long as the organization maintains an active account or as otherwise instructed by the organization. Some records may be retained longer where necessary for backups, audit logs, security, dispute resolution, legal obligations, or legitimate business records. Deactivated user accounts may be retained so organization administrators can preserve employment and PTO history.

If your organization disconnects Google Calendar, we delete the stored refresh token, calendar ID, sync metadata, and selected sharing settings from YOTR. Depending on the administrator's choice, we may also ask Google to delete the dedicated calendar created by YOTR. You can also revoke Google access through your Google Account permissions.

10. Security

We use technical and organizational measures designed to protect personal data, including HTTP-only session cookies, tenant isolation, role-based permissions, restricted access to sensitive authentication and integration tokens, and operational safeguards. No system is perfectly secure, but we work to reduce risks appropriate to the nature of the Service.

11. Your Rights

If you are in the EEA, UK, or a similar privacy jurisdiction, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. Because most workplace data is controlled by your organization, you should usually contact your organization administrator first. You can also contact us at hello@yotr.io, and we will help route the request appropriately.

You also have the right to lodge a complaint with your local data protection authority. For Cyprus, this is the Office of the Commissioner for Personal Data Protection.

12. Contact Us

If you have questions about this privacy policy or our privacy practices, contact Codiya Cyprus Ltd at hello@yotr.io.