Your data and your rights

What Bueggio HR knows about you (and deliberately doesn't), the self-service GDPR export, erasure, EU hosting and the one-cookie story.

For everyone Updated July 25, 2026

Bueggio HR is GDPR-first by design: your data lives in the EU, we collect the minimum a leave tracker needs, and your rights aren't a support ticket — they're buttons. This guide is the honest tour of what exists about you and what you can do with it.

What Bueggio HR knows about you

  • Your profile — name, work email, role, department, job title, language, holiday country, photo if you uploaded one.
  • Your leave — requests with dates, types, notes you wrote, decisions and their reasons, attachments (a medical certificate is sensitive data and is treated as such).
  • Account security — your sessions and sign-in history (browser, network, method), your notification preferences, push subscriptions, connected AI assistants.

Just as telling is what's deliberately not collected: no birthday, no home address, no phone number. A leave tracker doesn't need them, so they don't exist here.

Export your data yourself

My profile → Security → Export my data downloads a JSON file with everything above — profile, requests and their history, sign-in events, preferences, connected assistants. That's your GDPR right of access and portability, self-service: no request to write, no one to wait for.

The right to be forgotten

Erasure is deliberately not a self-service button — it's irreversible and usually follows offboarding. Ask an admin: their Erase (GDPR) tool anonymizes your identity, notes and sessions permanently, leaving only anonymous leave statistics (the people guide explains the difference from a simple deactivation).

Where it all lives

  • EU hosting — the application and database run in Frankfurt; there is no data transfer outside the EU in normal operation.
  • Minimal retention — sign-in logs are pruned on a schedule your organization chooses (up to two years); tokens for calendars and assistants are deleted the moment you disconnect them.
  • No trackers — the product uses one essential session cookie. That's the whole cookie story.

The precise, legally binding version of everything here is the privacy policy — a living document we update with every change to the product, same commit.

Good to know

  • Admins also have org-level tools (whole-organization export, per-person export) in Settings → GDPR.
  • What integrations can see is covered in their guides — e.g. calendars carry only leave type and dates, never your notes.