Version: 1.3
Effective Date: September 22, 2026
This Privacy Policy explains how NyxDay Inc. ("NyxDay", "PeopleEvo", "we", "us", or "our") collects, uses, discloses, stores, and protects Personal Information in connection with the PeopleEvo website, applications, and related services (collectively, the "Service").
PeopleEvo is a software-as-a-service platform used by organizations to manage employee leave, absence planning, approvals, balances, team availability, and related workforce processes.
This Privacy Policy applies to information that NyxDay collects or Processes through:
- the PeopleEvo public website;
- PeopleEvo Customer accounts;
- PeopleEvo applications;
- Customer support;
- communications with us; and
- related Service operations.
Where an organization uses PeopleEvo to manage information about its employees, contractors, workers, or other personnel, that organization (the "Customer") generally determines why that information is collected and how PeopleEvo is configured to Process it.
In those circumstances, NyxDay generally Processes the information on behalf of the Customer.
For additional contractual information regarding such Processing, see the PeopleEvo Data Processing Addendum ("DPA").
---
1. Definitions
For purposes of this Privacy Policy:
Customer
"Customer" means an organization that creates, subscribes to, receives authorized access to, or otherwise uses a PeopleEvo organizational environment.
Customer Data
"Customer Data" means information submitted to, stored in, or Processed through PeopleEvo by or on behalf of a Customer, as further described in the PeopleEvo Terms and Conditions.
Customer Data may include Personal Information concerning Customer employees and other personnel.
Personal Information
"Personal Information" means information about an identified or identifiable individual and includes equivalent concepts such as "personal data" where applicable.
Depending on how PeopleEvo is used, this may include information relating to:
- Customer administrators;
- employees;
- workers;
- contractors;
- managers;
- supervisors;
- approvers;
- authorized users; and
- other personnel whose information is managed through PeopleEvo.
Processing
"Processing" or "Process" means operations performed on Personal Information, including collecting, recording, storing, organizing, retrieving, using, transmitting, displaying, modifying, exporting, deleting, or otherwise handling such information.
---
2. Information We Collect
The information we collect depends on how you interact with PeopleEvo and how a Customer configures the Service.
2.1 Account and Registration Information
When an account is created, we may collect information such as:
- name;
- optional profile photograph, to personalize your account and help other authorized users within your organization identify you;
- business email address;
- authentication information;
- organization name;
- Customer or company code;
- role or permission information;
- account status;
- timezone and preferences;
- subscription-related information; and
- information required for account verification or administration.
2.2 Employee and Workforce Information
Customers may enter or manage information about employees and other personnel through PeopleEvo.
Depending on Customer configuration and use, this may include:
- employee name;
- business email address;
- employee identifiers;
- job or organizational information;
- team or group membership;
- roles and permissions;
- employment or account status;
- reporting or approval relationships;
- timezone information; and
- other workforce information submitted by the Customer.
2.3 Leave and Absence Information
PeopleEvo may Process information relating to:
- leave types;
- leave requests;
- leave dates;
- leave durations;
- leave balances;
- leave adjustments;
- approval or rejection information;
- approval history;
- backup or coverage assignments;
- team availability;
- working days;
- holidays;
- comments or notes;
- uploaded attachments; and
- related audit or activity information.
The specific information Processed depends on the Customer's configuration and how its authorized users use PeopleEvo.
2.4 Sensitive Leave and Absence Information
Leave and absence information may reveal or relate to sensitive personal circumstances, including:
- health;
- disability;
- pregnancy;
- family circumstances;
- accommodation needs; or
- other private personal matters.
Customers are responsible for determining what information is necessary and lawful to collect and Process through PeopleEvo.
Customers should not enter diagnoses, detailed medical records, clinical notes, or other unnecessary sensitive information unless an applicable PeopleEvo feature expressly supports that information and the Customer has determined that doing so is lawful and necessary.
PeopleEvo is not a medical-record system and is not intended to evaluate diagnoses, determine medical eligibility, or independently make accommodation or employment decisions.
Customers should limit sensitive information entered into PeopleEvo to information reasonably necessary for their legitimate workforce-management purposes.
2.5 Technical and Usage Information
When PeopleEvo is accessed, we may collect technical or operational information such as:
- IP address;
- browser type;
- device or operating-system information;
- access times;
- session information;
- authentication events;
- security events;
- application activity;
- error and diagnostic information;
- audit information; and
- information reasonably necessary to operate, secure, troubleshoot, and maintain the Service.
2.6 Support and Communications
If you contact us or request support, we may collect:
- your name and contact information;
- Customer or organization information;
- support requests;
- correspondence;
- troubleshooting information;
- screenshots or files you choose to provide; and
- other information reasonably necessary to investigate or respond to your request.
Customers and users should avoid including unnecessary sensitive Personal Information in support requests, screenshots, or attachments.
Support communications and related information may be Processed using authorized customer-support service providers identified in our Subprocessor disclosures where applicable.
2.7 Billing and Subscription Information
We may Process information relating to:
- subscription plan;
- employee capacity;
- billing status;
- subscription status;
- renewal or cancellation status;
- transaction references;
- other information necessary to administer a PeopleEvo subscription;
- billing frequency;
- billing-period and next-billing-date information;
- subscription-change status;
- prorated billing adjustments;
- account-credit information; and
- invoice and billing-document references.
Payment-card and similar payment information may be collected and Processed directly by our payment provider or merchant of record rather than by PeopleEvo.
---
3. How We Use Personal Information
Depending on the context, we may use Personal Information to:
- create and administer accounts;
- authenticate users;
- provide the PeopleEvo Service;
- operate leave and absence functionality;
- calculate and maintain leave balances;
- route Customer-configured approval workflows;
- display Customer-authorized team availability or coverage information;
- maintain Customer-configured roles and permissions;
- provide reporting and export functionality;
- provide Customer support;
- communicate about the Service;
- administer subscriptions, subscription changes, billing status, billing history, account credits, and related transaction records;
- maintain security and prevent fraud or abuse;
- troubleshoot errors;
- monitor reliability and technical performance;
- maintain audit and operational records;
- comply with applicable legal obligations;
- establish, exercise, or defend legal claims;
- enforce applicable agreements and policies; and
- personalize user profiles and help authorized users identify individuals within the Customer's PeopleEvo environment.
Where NyxDay Processes Personal Information contained in Customer Data on behalf of a Customer, we Process that information according to the applicable Customer instructions, PeopleEvo Terms and Conditions, DPA, Customer configuration, authorized user actions, and applicable law.
---
4. Customer-Controlled Information
Where a Customer uses PeopleEvo to manage information about its personnel, the Customer generally determines:
- which individuals are entered into PeopleEvo;
- which information is collected;
- which leave policies are configured;
- which leave types are available;
- who may view information;
- who may approve or manage leave;
- what permissions users receive;
- whether optional integrations are enabled; and
- how PeopleEvo is used within the Customer's organization.
The Customer is responsible for determining that its collection and use of Personal Information through PeopleEvo is lawful and appropriate.
This may include responsibility for:
- providing required privacy notices;
- obtaining required consents or other lawful authority;
- responding to employee or Data Subject requests;
- limiting unnecessary collection;
- maintaining appropriate access permissions; and
- complying with employment, workplace, privacy, recordkeeping, and other laws applicable to the Customer.
Individuals with questions about information entered into PeopleEvo by their employer or another Customer should generally contact that Customer first.
---
5. Automated Processing and Decisions
PeopleEvo uses software-based calculations, rules, workflows, alerts, and other automated functionality to support Customer workforce-management processes.
For example, PeopleEvo may:
- calculate leave balances;
- calculate working-day durations;
- apply configured leave rules;
- route approval requests;
- identify configured approval relationships;
- display coverage or availability information;
- generate alerts or notifications; and
- perform reconciliation or other system calculations.
PeopleEvo does not currently make decisions about an individual's employment, leave entitlement, approval, rejection, discipline, compensation, termination, or accommodation solely through automated Processing.
PeopleEvo's calculations, workflows, alerts, balances, and other automated functionality support Customer processes and remain subject to review, configuration, or action by authorized Customer users.
The Customer remains responsible for employment and workforce decisions made using PeopleEvo.
If PeopleEvo introduces functionality that materially changes how automated decision-making is used, we may update this Privacy Policy and provide additional notices or controls where required by applicable law.
---
6. How We Share Personal Information
We do not sell Customer employee or leave information.
We do not use Customer employee or leave information for third-party advertising.
We may disclose or make Personal Information available in the circumstances described below.
6.1 Customer-Authorized Users
Information may be made available to Customer administrators, managers, approvers, employees, or other authorized users according to:
- Customer configuration;
- roles and permissions;
- approval workflows;
- PeopleEvo functionality; and
- actions taken by authorized Customer users.
6.2 Service Providers and Subprocessors
We use third-party service providers to help operate PeopleEvo.
Depending on their role, providers may support functions such as:
- application hosting;
- database hosting;
- object storage;
- transactional email;
- customer support;
- application error monitoring and technical diagnostics;
- security;
- infrastructure;
- payment processing; and
- related Service operations.
Where a provider Processes Personal Information contained in Customer Data on our behalf, we require appropriate contractual or other safeguards as applicable to the provider's role and applicable law.
Our current material Subprocessors and Processing locations are maintained on the PeopleEvo Subprocessors and International Processing page.
Error-monitoring providers may receive limited technical and diagnostic information necessary to identify and investigate application failures. PeopleEvo configures such monitoring to minimize Personal Information and to avoid intentionally transmitting Customer content such as leave details, request or response bodies, authentication credentials, cookies, or other unnecessary sensitive information.
6.3 Customer-Directed Integrations
PeopleEvo supports optional integrations with Google Calendar and Microsoft Outlook / Microsoft 365 Calendar.
These integrations are enabled only at the direction of the Customer or an authorized user. Where an integration is enabled, information may be transmitted to or received from the applicable provider as necessary to provide the requested integration.
Customer-directed external integration providers are generally treated separately from PeopleEvo's infrastructure Subprocessors where the Customer or authorized user independently elects to connect the external service.
Customers are responsible for determining whether enabling an optional integration is appropriate for their organization and users.
6.4 Legal Requirements
We may disclose information where reasonably necessary to:
- comply with applicable law;
- respond to valid legal process;
- comply with a lawful government or regulatory request;
- enforce our agreements or legal rights;
- investigate fraud, abuse, or security incidents;
- protect PeopleEvo, NyxDay, Customers, users, or others; or
- establish, exercise, or defend legal claims.
Where legally permitted and reasonably practicable, we may seek to notify an affected Customer before disclosing Customer Data in response to a legally binding government or public-authority request.
6.5 Corporate Transactions
Information may be disclosed or transferred as part of an actual or proposed:
- merger;
- acquisition;
- financing;
- corporate reorganization;
- sale of assets;
- transfer of the PeopleEvo business; or
- similar transaction.
Where appropriate, information will remain subject to applicable confidentiality and privacy obligations.
---
7. No Sale of Personal Information
NyxDay does not sell Customer employee or leave information.
We do not disclose Customer employee or leave information to third parties for their independent use in targeted advertising.
This does not prevent NyxDay from:
- using authorized service providers;
- processing payments;
- providing Customer-enabled integrations;
- responding to lawful requests;
- protecting the Service;
- completing a corporate transaction; or
- otherwise Processing or disclosing information as described in this Privacy Policy.
---
8. Security
NyxDay maintains administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, use, disclosure, alteration, loss, or destruction.
Depending on the applicable functionality and environment, safeguards may include:
- authenticated access;
- role- and permission-based access controls;
- server-side authorization controls;
- logical tenant isolation;
- encrypted network communication using HTTPS/TLS;
- controlled database and object-storage access;
- restricted production access;
- logging and audit functionality;
- anti-abuse and security controls;
- multi-factor authentication where provided by the Service;
- controlled administrative access; and
- security and privacy incident-response processes.
Access to Customer Data by NyxDay personnel is limited according to legitimate operational requirements, such as:
- providing support;
- troubleshooting;
- maintaining or securing the Service;
- investigating suspected misuse or security issues; or
- complying with legal obligations.
Personnel authorized to access Customer Data are subject to appropriate confidentiality obligations.
No Internet-based service or electronic storage system can guarantee absolute security.
Customers are responsible for protecting their own account credentials, configuring roles and permissions appropriately, maintaining secure devices and networks, and promptly disabling users who should no longer have access.
---
9. Personal Information Breaches
NyxDay maintains processes designed to investigate suspected unauthorized access to, use of, disclosure of, loss of, alteration of, or destruction of Personal Information.
Where we become aware of a confirmed Personal Information Breach affecting Customer Data, we will notify the affected Customer without undue delay where required by applicable law or the applicable DPA.
Where reasonably available, we may provide information concerning:
- the nature of the incident;
- information or Data Subjects affected;
- identified risks;
- containment or remediation actions; and
- information reasonably available to assist the Customer with applicable legal obligations.
Information may be provided in phases as an investigation progresses.
Customers generally remain responsible for determining whether notifications to their personnel, regulators, or other parties are required where the Customer controls the affected Personal Information, except where applicable law places an obligation directly on NyxDay.
---
10. International Processing
PeopleEvo is operated from Canada but uses service providers and infrastructure that may Process information in other jurisdictions.
PeopleEvo's current standard infrastructure includes Processing in Canada and the United States, together with object storage within Cloudflare's Eastern North America (ENAM) region and other locations used by applicable service providers and their authorized subprocessors.
The current material Processing locations associated with PeopleEvo's Subprocessors are described on the PeopleEvo Subprocessors and International Processing page.
When Personal Information is Processed outside the jurisdiction in which the Customer or individual is located, it may become subject to the laws of the jurisdiction where it is Processed, including lawful access by courts, law-enforcement authorities, regulators, or other public authorities.
NyxDay uses contractual or other appropriate safeguards for international Processing where required by applicable law.
The standard PeopleEvo Service does not guarantee that Customer Data will remain exclusively within:
- a particular country;
- province;
- state;
- territory; or
- other Customer-selected jurisdiction.
Specific data-residency, regional-hosting, dedicated-infrastructure, or Customer-specific deployment requirements must be expressly agreed with NyxDay.
Customers are responsible for determining whether PeopleEvo's standard Processing locations are appropriate for their organization's legal and regulatory requirements.
---
11. Data Retention
We retain Personal Information for periods reasonably necessary for the purposes described in this Privacy Policy, subject to applicable legal, contractual, security, operational, and recordkeeping requirements.
Different categories of information may be retained for different periods.
11.1 Customer Data During Active Service
While a Customer has valid authorized access to PeopleEvo, Customer Data is generally retained as necessary to provide the Service.
11.2 Customer Data Following Expiry or Termination
Following subscription expiry or termination, PeopleEvo may retain the Customer environment and associated Customer Data for a recovery period of up to 90 days.
During this period:
- normal operational access may be restricted;
- an eligible subscription may be restored where available;
- an authorized Customer administrator may request a support-assisted export of reasonably available Customer Data; and
- an authorized Customer administrator may request earlier permanent deletion.
If no earlier deletion request is received, Customer Data becomes eligible for permanent deletion after the recovery period.
The recovery period is provided for account-recovery purposes and should not be relied upon as a Customer-controlled archival or backup service.
11.3 Early Deletion
During the recovery period, an authorized Customer administrator may request permanent deletion of the Customer environment and associated Customer Data.
We may verify the identity and authority of the requester before processing the deletion request.
Once permanent deletion has been processed, restoration may no longer be possible.
11.4 Backups
Residual copies of Customer Data may remain in backups until those backups expire or are overwritten through normal backup lifecycles.
Information remaining solely in backups will continue to be subject to applicable protection requirements and will not ordinarily be restored except for:
- disaster recovery;
- business continuity;
- security;
- legal preservation; or
- other legitimate operational requirements.
11.5 Business and Legal Records
We may retain certain information for longer periods where reasonably necessary or required for:
- accounting;
- taxation;
- billing and transaction records;
- fraud prevention;
- security;
- legal compliance;
- dispute resolution;
- enforcement of agreements; or
- establishing, exercising, or defending legal claims.
11.6 Security and Operational Records
Security, audit, diagnostic, and operational records may be retained for periods reasonably necessary to:
- protect PeopleEvo;
- investigate incidents;
- detect fraud or abuse;
- maintain reliability;
- troubleshoot technical issues; and
- meet legal or compliance requirements.
Retention periods may vary according to the nature of the record, infrastructure provider, security requirements, and applicable law.
---
12. Data Export and Deletion Requests
During an active subscription and during the applicable recovery period following subscription expiry, an authorized Customer administrator may request a support-assisted export of reasonably available Customer Data.
Exports will be provided using formats and capabilities reasonably supported by PeopleEvo at the time of the request.
Exports may exclude:
- internal security information;
- fraud-prevention information;
- platform diagnostics;
- proprietary system information;
- information that cannot reasonably be separated from information relating to other Customers;
- aggregated or de-identified information;
- information that we are legally prohibited from providing; or
- information not reasonably available through the Service or applicable infrastructure.
We may verify the identity and authority of a requesting administrator before processing an export or deletion request.
Custom migration, transformation, reconstruction, extraction, or specially formatted exports may require separate agreement and may be subject to additional fees.
Customers are responsible for obtaining information they wish or are legally required to retain before applicable deletion periods expire.
Once Customer Data has been permanently deleted, NyxDay has no obligation to reconstruct, recreate, or recover that information.
---
13. Aggregated and De-Identified Information
We may generate or use aggregated, statistical, or appropriately de-identified information derived from use of PeopleEvo where permitted by applicable law.
Such information may be used for purposes including:
- understanding Service usage;
- security;
- fraud and abuse prevention;
- troubleshooting;
- capacity planning;
- performance analysis;
- improving PeopleEvo;
- developing PeopleEvo functionality;
- business analysis; and
- producing aggregate insights that do not identify individual Customers or individuals.
Where information has been aggregated or de-identified so that it no longer identifies and cannot reasonably be associated with an identifiable individual, we may retain and use that information for legitimate business purposes, subject to applicable law.
We will not attempt to re-identify information that we maintain as de-identified except where reasonably necessary to:
- validate the effectiveness of the de-identification process;
- investigate security or fraud;
- comply with applicable law; or
- where otherwise permitted by applicable law.
Aggregated or appropriately de-identified information may be retained after identifiable Customer Data has been deleted where permitted by applicable law.
---
14. Privacy Rights and Requests
Depending on applicable law and the circumstances, individuals may have rights concerning their Personal Information, such as rights to:
- request access;
- request correction;
- request deletion;
- withdraw consent where Processing is based on consent;
- object to or restrict certain Processing;
- request information about Processing;
- obtain information about automated decision-making; or
- submit a complaint.
These rights are subject to applicable legal requirements, exceptions, and limitations.
14.1 Customer-Controlled Information
If your Personal Information was entered into PeopleEvo by your employer or another Customer, that Customer generally controls the information.
You should normally submit your privacy request directly to that Customer.
If we receive a request concerning Customer-controlled information, we may:
- identify the applicable Customer;
- direct the requester to that Customer;
- notify the Customer of the request; or
- assist the Customer where required by applicable law or the DPA.
We will not ordinarily make employment or workforce decisions concerning Customer-controlled information.
14.2 Information Controlled by NyxDay
Where NyxDay is responsible for the Personal Information, requests may be submitted to:
We may request information reasonably necessary to:
- verify identity;
- verify authority;
- locate relevant records;
- understand the request; and
- protect against unauthorized disclosure or deletion.
An authorized representative may submit a request where permitted by applicable law, subject to appropriate verification of the representative's authority.
We will respond within the period required by applicable law.
Where a request cannot be fulfilled in whole or in part, we may explain the applicable reason where required by law.
---
15. Cookies and Similar Technologies
The PeopleEvo website and Service may use cookies and similar technologies that are necessary for:
- authentication and session management;
- application functionality;
- security;
- fraud and abuse prevention;
- preference management; and
- maintaining the reliability of the Service.
For information about the technologies currently verified on the public PeopleEvo website and how to control optional categories, see our Cookie Policy. Visitors can change their optional choices at any time using Cookie Preferences in the website footer.
Our website may use security services such as Cloudflare Turnstile to distinguish legitimate activity from automated or abusive traffic.
On the public PeopleEvo website, we use Google Analytics through Google Tag Manager to understand website usage and help improve website performance and experience. These analytics technologies are optional and are activated only when a visitor grants Analytics consent through PeopleEvo Cookie Preferences.
When a visitor enables Marketing consent, PeopleEvo may use advertising technologies from providers such as Meta and Google on the public PeopleEvo website and may share or transmit limited website-interaction and advertising-related information for advertising measurement, conversion attribution, campaign-effectiveness measurement, and, where applicable, relevant advertising or remarketing.
When Marketing consent authorizes an eligible conversion event, PeopleEvo may transmit a normalized and SHA-256 hashed account email address to Meta through its Conversions API solely to support server-side conversion matching, measurement, and attribution. PeopleEvo does not use Meta Conversions API to transmit HR application content, employee records, leave data, reports, administrative data, or other Customer Data.
The use of cookies and similar technologies may differ between the public PeopleEvo website and the authenticated PeopleEvo application.
Where required, users will be provided with appropriate controls for optional technologies.
---
16. Marketing and Advertising
We may use information concerning prospective Customers, website visitors, business contacts, or existing Customer contacts to communicate about PeopleEvo where permitted by applicable law.
Marketing communications may include information concerning:
- PeopleEvo features;
- product updates;
- educational materials;
- offers;
- events;
- promotions; or
- related PeopleEvo services.
Where required, marketing communications will include an appropriate method to unsubscribe or otherwise manage communication preferences.
We do not use Customer employee or leave information for third-party advertising.
Advertising and marketing measurement technologies used by PeopleEvo are subject to applicable cookie, privacy, and consent requirements as described in this Privacy Policy and applicable cookie disclosures.
---
17. Children's Information
PeopleEvo is a business workforce-management Service and is not intended for use by children as a consumer service.
Customers are responsible for determining whether information concerning any minor may lawfully and appropriately be Processed through PeopleEvo in connection with the Customer's legitimate workforce activities.
We do not knowingly solicit children to create PeopleEvo Customer accounts for personal use.
---
18. Third-Party Websites and Services
The PeopleEvo website or Service may contain links to or interact with third-party websites, services, applications, or platforms.
Those third parties operate independently and may have their own privacy policies, terms, and practices.
NyxDay is not responsible for the privacy practices of independent third parties except to the extent responsibility cannot legally be excluded or where the third party Processes information on NyxDay's behalf under an applicable contractual relationship.
---
19. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to:
- PeopleEvo;
- our Processing activities;
- our service providers;
- our infrastructure;
- legal requirements;
- analytics or advertising technologies; or
- our privacy practices.
When we make material changes, we will take reasonable steps to provide notice where appropriate, such as:
- updating the Effective Date;
- posting the updated Privacy Policy;
- providing an in-Service notice;
- sending an email; or
- using another appropriate communication method.
Where applicable law requires consent or another specific action before a material change can apply, we will take the steps required by that law.
---
20. Privacy Governance
NyxDay Inc. is responsible for privacy governance relating to Personal Information for which NyxDay determines the purposes of Processing.
NyxDay has designated responsibility for overseeing privacy matters, including:
- privacy enquiries;
- privacy requests;
- privacy complaints;
- privacy practices;
- Personal Information Breach response; and
- coordination of applicable privacy obligations.
For Customer-controlled Personal Information Processed through PeopleEvo, the applicable Customer remains responsible for its own privacy governance and legal obligations.
---
21. Contact Us
For questions, requests, or complaints regarding this Privacy Policy or NyxDay's privacy practices, contact:
Privacy Officer
NyxDay Inc. — PeopleEvo
Nova Scotia, Canada
Email: privacy@peopleevo.com
For general PeopleEvo enquiries:
Email: contact@peopleevo.com
Where appropriate, individuals may also have the right to contact the privacy or data-protection regulator responsible for their jurisdiction.