At 2LZ, we take your privacy seriously. This privacy policy explains how we handle your personal data when you visit our website, use our mobile application, or subscribe to our services.
Primary EU hosting
Core storage in Ireland; integrations may process internationally
No sale to third parties
We never sell your data
No tracking cookies
Only functional cookies
Full GDPR rights
Access, rectification, erasure
Encryption
In transit and, where described, at rest; no E2EE claim
No minors
Service only for ages 16+
2LZ B.V. is a Dutch software company that provides an online platform (SaaS) and mobile application for workforce planning and business operations. We assist installation companies and technical SMEs with work orders, leave management, VCA compliance, and more.
Company name
2LZ B.V.
Chamber of Commerce number
42022298
VAT number
NL869336605B01
Privacy email
Website
Registered office
Griendakker 22, 2809 RR Gouda, the Netherlands
We are the data controller for the processing of personal data of:
We are a data processor when our customers (employers) use the 2LZ platform for their workforce administration. In that case:
Tip: If you have questions about data your employer processes via 2LZ, please contact your employer directly.
| Data | Description |
|---|---|
| Name | First name, middle name, surname |
| Email address | For login and communication |
| Telephone number | Contact details |
| Profile photo | Optional, for identification within the platform |
When your employer uses the 2LZ platform, the following data may be processed:
The active sickness-reporting module records only that a person is sick and therefore unavailable for planning, the necessary dates and duration, status, and limited project/processing metadata. It does not ask for a diagnosis, symptoms, cause, doctor visit, nursing address, telephone number, work-relatedness or medical/HR free text. Medical assessment remains with the occupational physician or occupational health service.
| Data | Description |
|---|---|
| IP address | For security and access control |
| Device information | Device type, browser, operating system |
| Login data | Time of last login, number of failed attempts |
| Trusted devices | For multi-factor authentication (MFA) |
Our mobile application (available for iOS and Android) may, depending on the features you use and the permissions you grant, process additional data:
Depending on the feature enabled by your employer, location data may be used for trips, planning, work orders, attendance, damage reports or SOS. Device permission and the in-app confirmation give you control, but your employer must also establish a valid GDPR legal basis, proportionality, employee information, a retention period and, where required, a DPIA and works council approval.
Permission: "While Using" or "Always" (your choice)
Used for taking photographs for damage reports, work orders, and document uploads. We do not have access to your other photographs.
Permission: Camera and Photo Library (limited)
Face ID or Touch ID for secure login. Biometric data is processed locally on your device by Apple/Google and is never transmitted to our servers.
Permission: Face ID / Touch ID (optional)
For notifications regarding leave requests, work orders, and important updates. You may disable notifications at any time via your device settings.
Permission: Notifications (optional)
Important notice regarding app permissions
You have full control over the permissions you grant to our application. You may withdraw permissions at any time via your device settings. Some features may not function without the corresponding permission.
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and securing the website | Legitimate interest (Art. 6(1)(f)) |
| Trial account and onboarding | Pre-contractual steps (Art. 6(1)(b)) |
| Contact and support | Legitimate interest / pre-contractual steps |
| Newsletter | Consent (Art. 6(1)(a)); sending is not currently activated |
| Service delivery | Performance of contract (Art. 6(1)(b)) |
| - Executing workforce planning | Performance of contract |
| - Time registration and leave administration | Performance of contract |
| - Service-related communication | Performance of contract |
| Security | Legitimate interest (Art. 6(1)(f)) |
| - Preventing unauthorised access | Legitimate interest |
| - Detecting misuse | Legitimate interest |
| Legal obligations | Legal obligation (Art. 6(1)(c)) |
| - Fiscal retention requirements | Legal obligation |
Analysis and signalling within the platform
For sickness absence, the platform only calculates aggregate reporting and, on request, a factual count. At the technical default of three or more separate sickness reports in twelve months, an authorised user may see a suggestion to consider a supportive conversation. Personal sickness percentages, absence frequency and the conversation signal are not included in an employee performance or overall score. This is not a statutory threshold, medical assessment, risk score or prediction; it is not stored as a separate profile and has no automatic consequence. Your employer must inform you in advance, include the use in its sickness-absence policy, assess works council/employee representation involvement and the need for a DPIA, and must not use the signal by itself for pay, disciplinary, dismissal, monitoring, medical or reintegration decisions. Other signals, such as login risks and trip anomalies, also require an appropriate legal basis and human review.
We do not retain personal data longer than necessary. The retention periods are as follows:
| Data type | Retention period | Reason |
|---|---|---|
| Contact and support correspondence | Generally 2 years after the last contact | Handling, follow-up and possible claims |
| Unsuccessful trial/onboarding request | Generally 2 years after the last contact | Pre-contractual follow-up |
| Newsletter | Until unsubscribe; minimal objection/suppression evidence may remain longer | Consent and preventing unwanted re-enrolment |
| Invoices and fiscal base records | 7 years from the applicable statutory starting point | Only for data covered by the fiscal retention duty |
| Platform/employee data | According to the employer's documented instruction for each data category | There is no general seven-year duty for an entire personnel file |
| Sickness absence | As short as possible. The platform default for a recovered regular sickness record is 2 years after recovery; the employer must document any other necessary period, for example in relation to the end of employment, a closed reintegration file, self-insurance obligations or a dispute. | Health data and purpose limitation; the default is not a statutory period |
| Live 'Who is Where' location | Maximum 90 days; shorter where possible | Operational use and storage limitation |
| Security/access logs | Generally no more than 1 year | Security and incident investigation; the immutable evidence record is minimised and excludes names, email addresses, user agents, location and business payloads |
| Notifications | 90 days | Operational necessity |
| Migration service upload | 7 days; results 90 days | Processing and support |
Technical platform defaults are not automatically the lawful period. Your employer must set a period for each category and, where needed, give 2LZ a tenant-specific instruction. The current technical defaults and open remediation items are documented in Annex A to the data processing agreement.
Core platform data is primarily hosted in AWS data centres in Ireland (region eu-west-1). Depending on activated integrations, push, support and edge services, limited processing or access may take place outside the EEA. We require an applicable adequacy decision, EU Standard Contractual Clauses and, where necessary, supplementary safeguards.
Under the GDPR, you have the following rights:
You may request information about the personal data we process about you.
You may request the correction of inaccurate data or the completion of incomplete data.
You may request the deletion of your data. This right is limited when we are legally obliged to retain the data.
You may request the restriction of the processing of your data.
You may request to receive your data in a structured, commonly used, and machine-readable format.
You may object to processing based on legitimate interest.
Submit your request to: privacy@2lz.ai
Please include in your request:
We shall respond to your request within 1 month. For complex requests, this period may be extended by 2 months.
Please note: When your employer uses the 2LZ platform, your employer is the data controller. In that case, please contact your employer directly.
Our service is intended for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children.
If you believe we have inadvertently collected data from an individual under the age of 16, please contact us immediately at privacy@2lz.ai so that we may delete this data.
We may amend this privacy policy. The most recent version is always available on this page. In the event of material changes, we shall inform you via the platform, by email, or via a notification in our application.
Last amended: 18 July 2026 (version 2.7) — supplier and international-transfer information aligned with the active contract set; the Dutch version is the binding onboarding document.
If you are dissatisfied with how we handle your data, please contact us first at privacy@2lz.ai. We shall endeavour to reach a resolution together.
If this is not successful, you may lodge a complaint with the Dutch Data Protection Authority:
Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
PO Box 93374
2509 AJ The Hague
The Netherlands
Website: www.autoriteitpersoonsgegevens.nl