Privacy Policy
for the Ferio service
Effective date: 15 July 2026 · Version 1.0
This Privacy Policy ("Policy") explains how LOGINET INTERNATIONAL LTD ("Ferio", "we", "us" or "our") handles personal data in the course of providing the leave- and absence-management software service known as Ferio (the "Service").
This Policy is prepared in accordance with the UK General Data Protection Regulation ("UK GDPR"), the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR") where applicable, and other applicable data protection law. It satisfies our information obligations under Articles 13 and 14 of those Regulations.
1. Who we are
| Company name | LOGINET INTERNATIONAL LTD |
|---|---|
| Company number | 15778724 |
| Registered office | 2nd Floor College House, 17 King Edwards Road, RUISLIP, London, HA4 7AE, United Kingdom |
| Data protection contact | hello@theferio.com |
| Customer support | support@theferio.com |
| Website | theferio.com |
We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Article 37 of the UK GDPR. For any data protection question, please contact us at the email address above.
2. Two roles: when we are a controller and when we are a processor
We may act in one of two roles in relation to personal data. It matters which role applies to which data:
a) Ferio as an independent controller. For data relating to our own customers (the representatives of the businesses that subscribe to the Service), our website visitors, and marketing subscribers, we act as a controller — we decide why and how that data is processed. This Policy primarily concerns that processing.
b) Ferio as a processor. When a customer (an employer) uses the Service to manage the data of its own employees and managers (for example, leave requests, balances, team allocation), that customer is the controller of that data and Ferio acts solely as a processor under Article 28 of the UK/EU GDPR. In that case we act on the customer's instructions, under a data processing agreement (DPA) entered into with the customer. If you are an employee of an employer that uses Ferio and you want information about your own data, you should contact your employer (as controller) in the first instance.
3. What data we process, why, and on what lawful basis
The table below summarises the processing we carry out as an independent controller.
| Purpose | Data processed | Lawful basis (Art. 6) |
|---|---|---|
| Registration; creating and managing an account | name, email address, password (encrypted), company name, job title | performance of a contract (Art. 6(1)(b)) |
| Providing the Service to the customer | account and workspace data, usage data | performance of a contract (Art. 6(1)(b)) |
| Billing and payment | billing details, payment references (from the payment processor) | performance of a contract and legal obligation (Art. 6(1)(b) and (c)) |
| Customer support and communication | name, email address, content of the enquiry | performance of a contract and legitimate interests (Art. 6(1)(b) and (f)) |
| Security of the Service; prevention of misuse | log data, IP address, device data | legitimate interests (Art. 6(1)(f)) |
| Improving the Service; statistics | aggregated and usage data | legitimate interests (Art. 6(1)(f)) |
| Newsletter and marketing (if any) | name, email address | consent (Art. 6(1)(a)) |
| Establishing and defending legal claims; compliance | the relevant data, to the extent necessary | legal obligation and legitimate interests (Art. 6(1)(c) and (f)) |
Where we rely on legitimate interests, our interest is the secure, reliable and improving operation of the Service, and the legal and commercial protection of our business. We balance that interest against your rights and freedoms in every case. You may ask us for more detail on this balancing assessment.
4. Do you have to provide your data?
The data needed to register and use the Service is required to enter into and perform the contract. Without it, we cannot provide the Service. Marketing-related processing is based on voluntary consent; declining it does not affect your use of the Service.
5. Who has access to the data (recipients)
We do not sell personal data. The following recipients or categories of recipient may access the data, strictly to the extent necessary:
- authorised staff of Ferio;
- hosting and cloud infrastructure provider(s);
- payment processor (processing of card payments);
- email delivery and customer-support system providers;
- calendar and integration providers, where the customer uses them (for example, iCal, Google Calendar);
- accounting, invoicing and legal service providers;
- public authorities and courts, where required by law.
Our processors may act only on our instructions and under appropriate contractual safeguards.
6. International transfers (outside the UK / EEA)
Ferio is operated by a company established in the United Kingdom, and some of our providers may operate outside the United Kingdom or the European Economic Area (EEA). Where such a transfer takes place, we ensure appropriate safeguards under the UK/EU GDPR, in particular:
- transfers based on an adequacy decision / adequacy regulations (for example, the adequacy status recognised between the UK and the EEA); or
- the use of Standard Contractual Clauses (SCCs) approved by the European Commission, and/or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, together with any other appropriate safeguards.
We will provide further information on the basis for, and safeguards applying to, any transfer on request, using the contact details above.
7. How long we keep data
We keep data only for as long as necessary to achieve the purpose, and to comply with our legal obligations:
- Account and contract data: for the duration of the contract, and then for a reasonable period after it ends (during which the data can be exported), after which it is deleted.
- Billing data: for the retention period required by applicable tax and accounting law.
- Log and security data: for the limited period necessary to achieve the security purpose.
- Marketing data: until consent is withdrawn.
Workspace data created during the Trial Period is permanently deleted when a subscription is activated, and may likewise be deleted after the Trial Period ends, with an opportunity to export it first.
8. Your rights
Under the UK/EU GDPR you have the following rights in relation to your personal data:
- right of access (to be told what data of yours we process);
- right to rectification (correction of inaccurate data);
- right to erasure (the "right to be forgotten", within legal limits);
- right to restriction of processing;
- right to data portability (to receive your data in a machine-readable format);
- right to object to processing based on legitimate interests;
- right to withdraw consent, which does not affect the lawfulness of processing before withdrawal.
You can exercise your rights using the contact details above. We will respond without undue delay and within the time limits set by the GDPR.
If you are an employee of an employer that uses Ferio, and you wish to exercise your rights in relation to your own data held within the workspace, please contact your employer (as controller) in the first instance; Ferio, as processor, acts on the employer's instructions.
9. Complaints
If you believe your data has been handled unlawfully, you have the right to lodge a complaint with a supervisory authority, or to seek a judicial remedy.
- In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO); its contact details are at ico.org.uk.
- If you are in Hungary or another EEA state, you may also contact your local supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), at naih.hu.
We would ask you to contact us first, using the details above — we aim to resolve any concern quickly and fairly.
10. Cookies
Our website and the Service may use cookies that are strictly necessary for operation and — where you consent — statistical and functional cookies. A separate Cookie Notice and the cookie settings interface on the website provide detailed information about cookies and how to manage them.
11. Automated decision-making
Ferio does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The Service performs certain calculations automatically (for example, leave balances), but these are based on rules defined by the customer (employer) and do not constitute automated decision-making within the meaning of Article 22 of the GDPR.
12. Changes to this Policy
We may update this Policy in the event of a change in law or a change to the Service. We will notify data subjects of changes on the website and, for material changes, by email. The current version of this Policy is available at all times on our website.