Privacy Policy

Last updated: 6 August 2026

This Privacy Policy explains how SAS The Jeffrey Company ("BuddiesHR", "we", "us") collects, uses and shares personal information across the BuddiesHR products.

It covers all of our apps — Alfy (connections), Billy (celebrations), Clappy (recognition), Linky (directory), Palmy (leave management), Pulsy (surveys), Stany (check-ins) and SimplePerf (performance reviews) — whether you use them in Slack, Microsoft Teams, Pumble, or through our dashboard at dashboard.buddieshr.com. It also covers our website and sales enquiries.

Our role: who is responsible for your data

When we act as a processor. Almost everything in the apps is your employer's data. Your employer decides which apps to install, what information to put in them, who can see it, and how long to keep it. They are the controller; we are the processor, and we only process that information on their documented instructions. Our Data Processing Agreement governs this relationship.

If you are an employee and you want to access, correct or delete information held in a BuddiesHR app, please contact your employer's HR or IT team. They can action it themselves, and we will help them do so.

When we act as a controller. We are the controller for our own business data: visitors to our website, demo and sales enquiries, waitlist signups, billing contacts, workspace administrator accounts and support conversations. The rights described in "Your rights" below apply directly to that data.

Information we process on behalf of your employer

What we hold depends on which apps your employer has installed, and which features they have turned on.

Everyone. Your name, work email address, profile picture, job title, timezone and the identifier your messaging platform assigns you. We receive these from Slack, Microsoft Teams or Pumble when your workspace syncs its members, and store them so the apps can address you correctly.

Alfy — who you were matched with and when, the meeting times you suggested or selected, and, if you choose to connect a calendar, your busy/free periods. See "Calendar access" below.

Billy — birthdays and work anniversaries (day, month and, where provided, year), your reminder preferences, and whether you have opted out of celebrations. Your employer may enter these manually, let you enter them yourself, or sync them from BambooHR or Lattice. We also keep a record of the celebration messages we posted.

Clappy — the recognition messages you send and receive, including their text, the people named in them, points awarded, the company values selected, leaderboard standings, reward claims, and any GIF you upload.

Linky — the profile fields your employer configures. These can include first and last name, job title, department, work email, phone number, start date, end date, date of birth, profile picture, and custom fields your employer defines. Linky also holds your position in the org chart and who you report to. Your employer may import this from a spreadsheet.

Palmy — your leave requests (dates, leave type, any note you add), their status, who approved or rejected them and why, and your leave balances and accruals.

Pulsy — your answers to surveys and polls, including free-text comments, and any follow-up conversation between you and a survey administrator.

Stany — your check-in updates: answers to your team's questions, the mood you select and any comment on it, blockers you flag, and skip reasons.

SimplePerf — the performance reviews you write and receive: answers, comments and ratings across self, peer, upward and downward reviews, plus who reviews whom in each cycle.

Message records. For any message an app posts on your behalf or sends to you, we store a reference to it — the channel and message identifier — so we can keep it up to date, and in some cases the content we generated. We do not read, index or store your general conversation history, and we never access messages, channels or files that our apps did not create or that were not sent directly to them.

Information we process as controller

Website and sales. If you request a demo we collect your name, work email, phone number, company, role, company size, the apps you're interested in, your timing, and anything you write in the notes field. We also record the referral and advertising parameters attached to your visit (such as Google and Meta click identifiers) so we can tell which campaigns work. Waitlist signups collect your email and the app you're waiting for.

Accounts and sign-in. When you sign in to the dashboard we create a session and record your email address, IP address, browser user-agent and the time you last used it. If you sign in with Google or Microsoft, we receive your name, email address and profile picture from them. Sessions expire after 30 days.

Billing. Stripe handles payment. We store the resulting customer and subscription records, which contain your billing contact details and plan. We never see or store full card numbers.

Support and product feedback. Conversations you have with us, and — for workspace administrators of actively used apps — occasional product feedback requests and lifecycle emails, which you can opt out of at any time.

Why we process it, and on what legal basis

As a processor, we process employee data only to provide the apps to your employer, on their instructions.

As a controller:

WhatWhyLegal basis
Demo requests, waitlistResponding to your enquiry, preparing a contractSteps prior to a contract; consent
Accounts, sign-in, sessionsProviding and securing the servicePerformance of a contract
BillingTaking payment, meeting accounting obligationsContract; legal obligation
Error monitoring, product analyticsKeeping the service working and improving itLegitimate interests
Lifecycle and product-feedback email to adminsSupporting and improving the productLegitimate interests (opt-out available)
Advertising attributionMeasuring which campaigns workConsent

We do not sell personal information, and we do not share it for advertising purposes.

AI features

Some features use AI to make suggestions: improving a review question, analysing a review cycle, coaching follow-up questions in SimplePerf, classifying check-in questions in Stany, mapping columns when you import a spreadsheet, and generating celebration content in Billy.

To provide them we send the relevant content to OpenAI, our AI sub-processor, which processes it in the United States under Standard Contractual Clauses. OpenAI does not use this content to train its models. Under our agreement it may retain it for up to 30 days for abuse monitoring before deletion.

AI output is always a suggestion for a person to accept, edit or reject. We never use AI to make automated decisions about individuals, and no AI output determines anyone's evaluation, compensation or employment. We keep a record of AI requests and their responses so administrators can rate the quality of the output; those records are deleted with the rest of your workspace data.

Calendar access

Two apps can connect to your Google or Microsoft calendar. Connecting is always your choice, and you can disconnect at any time — we delete the stored authorisation immediately when you do.

Alfy requests read-only access. It uses it for one purpose: finding times when you are free, so it can suggest a slot for a match. It reads your availability, not the content of your events.

Palmy requests read and write access. It uses it for one purpose: adding approved leave to the shared team calendar your administrator selects, and removing it if the leave is cancelled.

BuddiesHR's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use calendar data for advertising, we do not sell it, we do not use it to train AI models, and no human reads it except where you ask us to, where it is necessary for security, or where the law requires it.

Optional features that share information with your colleagues

Some features are switched off by default and only work if your workspace administrator turns them on.

Leave status on your messaging platform (Palmy). If your administrator enables this optional feature, Palmy sets your status on Slack or Microsoft Teams while you are on approved leave — typically an emoji and the name of the leave type — so colleagues know you are away. Your colleagues can see it. The feature is off unless your administrator enables it, and they can switch it off again at any time; ask them if you would prefer your status not to be set.

Public celebration posts (Billy) and recognition posts (Clappy) are posted to the channels your administrator configures, and are visible to everyone in those channels. You can opt out of celebrations for yourself.

Sensitive information

BuddiesHR is not designed for special categories of data such as health information. We ask administrators not to put health or other sensitive details into leave type names, request notes, directory fields or free-text answers. Where such information is entered anyway, we process it solely as a processor on your employer's instructions.

Dates of birth in Linky and Billy are optional, and you can ask your administrator to remove yours or opt out of celebrations.

A note on anonymous surveys

When your administrator marks a Pulsy survey or poll as anonymous, your name is never shown in results, reports or exports, and administrators cannot see who gave which answer.

To be completely transparent: your response is still linked to your user account in our database, because we need to know who has already answered so we don't send you duplicate reminders. That link is never exposed in the product. It is not the same as a response that carries no identity at all, and we would rather tell you that than overstate it.

Sub-processors

We use a small number of vetted providers. The current list, with their purpose and location, is published at buddieshr.com/security and kept up to date.

Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission's Standard Contractual Clauses.

Where your data is stored

Your data is stored in the European Union: on AWS in Paris (eu-west-3), which hosts our databases and file storage, and on Hetzner in Germany, which runs our load balancers and application servers.

Security

We protect your data with:

  • encryption in transit (HTTPS/TLS) and at rest;
  • strong encryption of every stored access token — for messaging platforms, calendars and HR integrations — using AES-256 with an authentication tag;
  • cryptographic verification of every webhook we receive from Slack and Microsoft Teams;
  • least-privilege permissions, requesting only the platform scopes each app needs;
  • login links that can only be used once, and sessions that expire after 30 days;
  • rate limiting, HSTS, and protections against server-side request forgery;
  • access limited to the employees who need it to do their job.

We are not SOC 2 certified. We build and operate the service according to SOC 2 principles, and our CTO has previously overseen a SOC 2 certification.

For troubleshooting, a small number of our staff can access a customer's workspace in a support capacity. This access is logged and used only to resolve a reported problem.

How long we keep data

DataRetention
Workspace and employee dataDeleted within 12 months of an app being removed from your workspace, or sooner if you ask
Data deletion on requestActioned for any customer who asks, at any time
Web sessions30 days
Demo requests and waitlist entries3 years from your last contact with us
Billing and accounting records10 years, as French law requires
Support conversations3 years

Where we have signed a Data Processing Agreement with your employer, the retention terms of that agreement apply to their data.

Customers can also export their data from the apps at any time.

Your rights

Where we are the controller, you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent at any time. To exercise any of these, email privacy@buddieshr.com. We respond within one month, as the law requires.

Where we are the processor — anything inside a BuddiesHR app — please contact your employer, who controls that data. We will support them in responding to you.

You also have the right to lodge a complaint with your data protection authority. Ours is the CNIL in France (cnil.fr).

Cookies

We use cookies that are strictly necessary to make the site and dashboard work, cookies that help us understand how the product is used, and — with your consent — cookies that measure the performance of our advertising. You can accept or refuse non-essential cookies when you first visit, change your mind at any time, and control cookies through your browser settings.

Children

BuddiesHR is a workplace tool. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

We will post any change to this policy on this page and update the date at the top. Please check back from time to time.

Contact

Privacy questions, requests and complaints: privacy@buddieshr.com
SAS The Jeffrey Company, France.
Our Data Processing Agreement: https://buddieshr.com/dpa-template