Legal
Last updated: July 30, 2026
Privacy policy
1. Who we are
Bueggio HR (bueggiohr.eu) is staff leave management software for companies. The service is operated by a company under incorporation in France; this section will be updated with the legal name, registered address and registration number as soon as incorporation is complete. For anything related to personal data, write to team@bueggiohr.eu.
2. Two roles: controller and processor
Bueggio HR acts as data controller for the data of website visitors and of the people who create and administer an account (signup, billing, support). When your employer uses Bueggio HR to manage your leave, the employer is the data controller and we act as data processor on its documented instructions, under our Data Processing Agreement. If you are an employee with questions about your data in Bueggio HR, your first point of contact is your employer — we assist them in answering you.
3. Data we collect as controller
- Account & signup: first and last name, email address, password (stored only as a bcrypt hash), company name, country, team size, the tool you used before.
- Billing details (optional, entered by the admin): legal company name, VAT number, registered address, billing email, SDI recipient code.
- Correspondence: any communication you exchange with us through any channel — the contact form on this site, email, WhatsApp, live chat or traditional mail.
- Website visitors: we use no analytics, no advertising trackers and no fingerprinting. Our hosting provider processes IP addresses in technical server logs for security and abuse prevention.
4. Data we process on behalf of your employer
- Profile: name, email, job title (optional), language, country, profile photo (optional), notification preferences, department, role, annual allowance, start date and working schedule.
- HR record (optional, entered by your employer's admins): phone number, home address, emergency contact (name and phone), payroll ID. All optional — the service works without them; your employer decides whether to use them. Visible to admins only.
- Leave & absences: dates, leave type, optional notes and decline reasons (free text that may indirectly reveal health information), and optional attachments — which may include medical certificates, a special category of data under Art. 9 GDPR, processed strictly on the employer's instructions.
- Security log: sign-in history (timestamp, IP address, browser, sign-in method). Retention is chosen by the employer (3 to 24 months maximum); older entries are deleted automatically.
- Sessions: IP address and browser of active sessions, deleted at logout or account deletion.
- Optional integrations you activate: encrypted OAuth tokens for Google Calendar / Outlook sync (deleted when you disconnect), Slack account linking (when your organization installs our Slack app, your Slack identity is matched automatically by your work email; you can request leave from Slack and the app's Home tab shows you your own balance and upcoming absences; notifications arrive as direct messages, and administrators can choose channels that receive a daily summary of who is absent; if you choose, you can additionally authorize the app to set an automatic out-of-office status on your own Slack profile while you are on approved leave — this stores a personal access token encrypted at rest, the status shows only that you are away and your return date, never the type of absence, and disconnecting revokes and deletes the token; removing the app from your workspace deletes the link for everyone at once), web push subscriptions for the devices where you explicitly enable notifications (deleted when you turn them off or erase your account; the notification carries only the requester's name and leave type — never notes or reasons), iCal feed tokens (anyone holding a feed URL can read that feed — treat it like a password), API keys your administrators create for programmatic access (shown once, stored hashed, revocable), webhook endpoints your administrators configure — the URLs you choose receive only the events you select, signed so you can verify us — and AI assistants you connect through our MCP server (e.g. Claude) — either with an administrator API key or by authorizing the assistant yourself on our consent screen (the access tokens are stored only as cryptographic hashes and are revocable at any time, by you from the assistant and by administrators in the settings): the assistant receives only the data your role allows, its actions are attributed to you by name, and any booking it makes goes through your normal human approval flow.
We deliberately do not collect: birthdays, or any data the service doesn't need. Phone numbers, home addresses and emergency contacts exist only as the optional fields above, filled in solely at your employer's choice.
5. Purposes and legal bases
- Providing the service (accounts, leave tracking, notifications) — performance of a contract, Art. 6(1)(b) GDPR.
- Security (sign-in log, rate limiting, session management, 2FA) — legitimate interest, Art. 6(1)(f).
- Legal obligations (accounting, responding to authorities) — Art. 6(1)(c).
- Optional integrations (calendar sync, Slack) — activated by you or your employer; processed to perform the requested feature.
- We send no marketing without your consent, and we never sell personal data.
6. Subprocessors and recipients
Your data lives in the European Union. We use a short, deliberate list of subprocessors:
- Render — application hosting and database, Frankfurt (Germany) · privacy policy.
- Cloudflare — file storage (R2: profile photos, leave attachments, data exports) hosted in data centres in the European Union, and the cookie-less bot-protection check (Turnstile) on our sign-in page · privacy policy.
- ImprovMX — forwarding of the email we receive (contact form, support, privacy requests) to our inbox · privacy policy.
- Resend — transactional email delivery, EU region · privacy policy.
Some of these providers are US companies: transfers are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses. When your organization activates an integration, the corresponding provider (Slack, Google, Microsoft) receives the data strictly needed for that integration. The always-current subprocessor list is part of our Data Processing Agreement.
7. Retention
- Account and organization data: for the duration of the contract; deleted after account closure.
- Sign-in log: per your employer's setting, never beyond 24 months.
- Deactivated people: hidden and blocked immediately; the employer can anonymize them at any time with the built-in erasure tool (identity, notes, sessions and files are scrubbed; anonymous leave statistics remain).
- Backups: encrypted, automatic, rotated on a short cycle.
8. Security
TLS for every connection; passwords hashed with bcrypt; OAuth tokens, Slack credentials and two-factor secrets encrypted at rest; optional two-factor authentication (TOTP) that an organization can make mandatory; role-based access; an append-only audit trail on leave decisions; EU hosting. Built-in GDPR tooling lets each organization export its full data set (JSON), export a single person's data, and permanently anonymize a person. Our own support staff access customer accounts only when support requires it, from a separate internal console with dedicated accounts and mandatory two-factor authentication — and every support action is recorded in an append-only audit log. If support ever needs to act inside your account, that access requires a stated reason, is marked as such (never disguised as a normal sign-in), expires by itself after one hour, shows a visible banner for its whole duration, and appears in your organization's sign-in log.
9. Your rights
Under Articles 15–22 GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. You can exercise access and portability yourself, instantly: Profile → Security → Export my data downloads everything Bueggio HR stores about you as JSON, no request needed. For everything else, write to team@bueggiohr.eu — we answer within 30 days. For data your employer manages in Bueggio HR, we will loop your employer in, as the law requires. You can also lodge a complaint with a supervisory authority: the CNIL (France, our lead authority), the Garante (Italy), the AEPD (Spain), or your local authority.
10. Cookies
Bueggio HR uses only one essential cookie: the session cookie that keeps you signed in and protects against request forgery. No third-party cookies, no advertising cookies. Your theme preference is stored locally in your browser (localStorage) and never sent to us. Because we only use strictly necessary cookies, no cookie banner is required.
11. Children
Bueggio HR is a workplace tool and is not directed at children under 16.
12. Changes to this policy
When the product changes — a new feature, a new subprocessor, a data type we start or stop collecting — this policy is updated the same day, with the revision date shown at the top. Material changes are announced to account administrators by email.
Terms of service
1. The agreement
These terms govern the use of Bueggio HR (bueggiohr.eu), operated by a company under incorporation in France (this section will name the legal entity once incorporation is complete). By creating an account you accept these terms, the privacy policy and the Data Processing Agreement above, on behalf of the organization you register. The service is intended for businesses, charities and public bodies — not for consumers.
2. The service
Bueggio HR is software as a service (SaaS) for managing staff leave and absences, accessed online through a subscription. We provide it with reasonable skill and care, but we do not guarantee it will be error-free or uninterrupted; we may carry out maintenance and evolve features over time. Leave balances and calculations are an operational aid, not legal advice — checking compliance with employment law and collective agreements remains your responsibility.
3. Subscription and automatic renewal
The subscription starts with a free one-month trial, no payment details required. After the trial, the service is billed per active user, monthly or yearly, at the price shown on the pricing page at the time you subscribe. This is a subscription with automatic renewal: at the end of each billing period it renews automatically for a period of the same length, at the then-current rates, unless cancelled as described in section 5. We will announce any price change to account administrators by email at least 30 days before it applies to you.
4. Payment
Payments are handled by a specialised, PCI-DSS-certified payment provider; we never store full card numbers ourselves. The provider will be named in this section when online billing is enabled. If a payment fails, we notify you and retry; if it remains unpaid, we may suspend access until the balance is settled.
5. Cancellation and termination
- You can cancel the subscription at any time by writing to team@bueggiohr.eu from an administrator account.
- To stop the next renewal, the cancellation must reach us at least fourteen (14) days before the renewal date. A cancellation received less than 14 days before renewal takes effect at the end of the following billing period.
- Until the effective date, the service keeps running and remains billable; on the effective date, access ends and the account is closed.
- After closure, your data is deleted as described in section 6 of the Data Processing Agreement — export it beforehand with the built-in GDPR tools.
- We may suspend or terminate an account that breaches these terms, uses the service unlawfully, or where we are required to by law; where reasonable we will warn you first.
6. Refunds
Once an invoice has been issued — for a new licence or for a renewal — no refund is due, in whole or in part. This includes pro-rata refunds for unused time, for seats that go unused, or for periods after a cancellation that takes effect mid-cycle: cancellation stops future renewals but never refunds amounts already invoiced. Removing users during a billing period reduces the next invoice, not the current one.
7. Acceptable use
You are responsible for the accounts your organization creates, for keeping credentials safe — including API keys, which act with your organization's authority — and for what your users upload. Actions performed through the API, webhooks or connected AI assistants count as actions of your organization. You may not resell, sublicense or provide the service to third parties, attempt to breach its security, disrupt it, reverse-engineer it, or use it for anything unlawful. Accounts must belong to real people of your organization.
8. Your data and intellectual property
Your data remains yours. You grant us only the rights needed to run the service, as described in the privacy policy and the DPA. Everything that makes up Bueggio HR — software, design, brand — remains ours or our licensors'; you receive a non-exclusive, non-transferable right to use the service for your internal operations, ending with the subscription. We may mention your organization's name as a customer in our marketing; opt out any time by email.
9. Liability
Nothing in these terms excludes liability that cannot be excluded by law (such as for fraud, death or personal injury). Beyond that, the service is provided "as is" and "as available": we are not liable for indirect losses (lost profits, lost data recoverable from your own exports, business interruption), for events beyond our reasonable control, or for failures of third-party services. Our total aggregate liability is capped at the fees you paid in the twelve (12) months preceding the event giving rise to the claim.
10. Changes to these terms
We may update these terms as the product and the law evolve. The revision date at the top of this page always reflects the current version; material changes are announced to account administrators by email at least 30 days in advance. Continuing to use the service after that date means you accept the new terms.
11. Final provisions
If a clause of these terms turns out to be invalid, the rest remains in force. You may not assign this agreement without our written consent. These terms are governed by French law, and any dispute that cannot be settled amicably falls to the competent French courts. Questions: team@bueggiohr.eu.
GDPR & DPA
This Data Processing Agreement ("DPA") documents, pursuant to Art. 28 GDPR, how Bueggio HR processes personal data on behalf of the customer organization (the controller). It forms part of the service agreement and reflects practices that are actually implemented in the product.
1. Subject matter and roles
The customer (employer) is the data controller; Bueggio HR is the data processor. Processing covers the management of staff leave and absences: profiles, requests and approvals, allowances, calendars, notifications and the related security logs, for the duration of the service agreement. The categories of data subjects (employees, managers, administrators) and of personal data are detailed in section 4 of the privacy policy above — including possible health-related data in notes and attachments (Art. 9 GDPR), which we process strictly as instructed.
2. Documented instructions
We process personal data only on the customer's documented instructions: the configuration the customer sets in the product (leave types, retention periods, integrations, visibility permissions) and the actions its users take are those instructions. We never use customer data for advertising, profiling or training purposes, and we never sell it.
3. How data is processed and protected
- All data is hosted in the European Union (application and database in Frankfurt, files in EU data centres).
- TLS on every connection; passwords stored only as bcrypt hashes; OAuth tokens, Slack credentials and two-factor secrets encrypted at rest; API keys and the access tokens of connected AI assistants stored only as cryptographic hashes.
- Role-based access (employee / manager / admin), organization-level data isolation enforced on every query, optional two-factor authentication that the customer can make mandatory.
- Append-only audit trail on leave decisions; sign-in log with customer-chosen retention (3–24 months), pruned automatically.
- Personnel with production access are bound by confidentiality; access is limited to what operating the service requires. Support staff work from a separate internal console with dedicated accounts and mandatory two-factor authentication, and every support action on a customer account is recorded in an append-only audit log. Support access inside a customer account (impersonation) requires a stated reason, is marked as such, is time-limited to one hour, and is visible to the customer in their sign-in log.
4. Subprocessors and transfers outside the EU
The customer authorizes the subprocessors listed in section 6 of the privacy policy (Render, Cloudflare — R2 storage and the Turnstile sign-in check —, Resend — plus Slack, Google or Microsoft only where the customer activates those integrations). Data is stored at rest in the EU; where a provider's parent company is established in the United States, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses (Art. 46 GDPR). We will inform account administrators by email before adding or replacing a subprocessor, giving the customer the opportunity to object.
5. Assistance with data subject rights
The product gives the customer self-service tools to answer data subject requests without waiting on us: per-person data export (JSON), organization-wide export, and permanent anonymization. Where a request cannot be satisfied with these tools, we assist the customer within the timescales of Arts. 12–23 GDPR. Requests reaching us directly from employees are forwarded to the customer, as the law requires.
6. How data is deleted
- During the contract: deactivating a person immediately blocks access, ends their sessions, hides them from the product and replaces their email address with an anonymous placeholder (so the address is freed and no longer stored); disconnecting an integration or revoking a connected AI assistant deletes its tokens; sign-in log entries expire automatically per the configured retention.
- At the end of the contract: closing the account deletes the organization and, in cascade, every profile, request, notification, session, token and file belonging to it.
- Backups: encrypted and rotated on a short cycle; deleted data leaves the backup chain as it rotates.
7. How data is anonymized
The built-in erasure tool (Settings → Team, "erase") implements the right to be forgotten while preserving the anonymous statistics an employer may need for labor-law bookkeeping. In one transaction it: replaces name and email with neutral placeholders, randomizes the password, clears job title, phone, address, emergency contact, payroll ID, language, country and two-factor secrets, destroys sessions, sign-in history, notifications, calendar connections, the optional Slack status authorization and connected AI assistants, purges the profile photo and every attachment on the person's requests (they may be medical certificates), and blanks all free-text notes and decline reasons, including in the audit trail. What remains — dates, day counts, leave types, statuses — no longer points to an identifiable person and thus falls outside the GDPR (Recital 26). The operation is permanent and cannot be undone.
8. Personal data breaches
We notify the customer's administrators without undue delay after becoming aware of a personal data breach affecting their data, with the information required by Art. 33(3) GDPR, so the customer can meet its own 72-hour obligation towards the supervisory authority.
9. Audits
On request, we make available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR — this documentation, the subprocessor list and our security measures — and we contribute to audits conducted by the customer or an auditor it mandates, in a manner proportionate to the service.
10. Data Protection Officer
A Data Protection Officer is currently in the process of being designated. Until the appointment is complete, all privacy matters are handled at team@bueggiohr.eu; this section will be updated with the DPO's contact details once designated.
Contact
For any question about the service, your data or these documents: team@bueggiohr.eu · Contact us