Security

Find all information about our security processes, server locations and best practises in place.


  Data

Data collection
BuddiesHR will only collect the data needed for the operation of its apps.
Data encryption
We follow the OWASP best practices and encrypt data (both at rest and in transit).
Data storage
We do not store any data that we don’t need for our operations.
Data deletion
All data related to the Slack workspace are automatically deleted 12 months after any app is removed from the Slack workspace.
Servers location
AWS data center located in Paris, France (eu-west-3).
Data hosting country
France
Data hosting company
AWS

  Security policies

Contact us to receive any of these security policies. (security@buddieshr.com)
  • Acceptable Use Policy
  • Access Control and Termination Policy
  • Business Continuity and Disaster Recovery Plan
  • Change Management Policy
  • Code of Conduct
  • Configuration and Asset Management Policy
  • Data Classification Policy
  • Data Retention and Disposal Policy
  • Encryption and Key Management Policy
  • Information Security Policy
  • Internal Control Policy
  • Network Security Policy
  • Performance Review Policy
  • Physical Security Policy
  • Risk Assessment and Treatment Policy
  • Secure Development Policy
  • Security Incident Response Plan
  • Vendor Management Policy
  • Vulnerability and Patch Management Policy

  Certifications

HIPAA
No
SOC2
No
Security Questionnaire
$500, on-demand

  Sub-processors

We use a small number of trusted sub-processors to operate BuddiesHR. Each provider is vetted for GDPR compliance and bound by equivalent data protection obligations.

Last updated: October 2025
NamePurposeLocationLegal basis
AWSCloud hosting and infrastructureEU (Paris)GDPR compliant (Data Processing Addendum)
HetznerHosting and storageEU (Germany)GDPR compliant
MailjetTransactional email deliveryEU (France)GDPR compliant (Data Processing Agreement)
MongoDB AtlasManaged database service (hosted on AWS Paris)EU (Paris)GDPR compliant (DPA + SCC)
RollbarError monitoring and application performance trackingEU (Ireland) / USStandard Contractual Clauses
PostHogProduct analyticsEU hosting (Frankfurt)GDPR compliant
CrispCustomer support chatEU (France)GDPR compliant

We may update this list as we add or remove sub-processors. Any new providers will be bound by the same data protection obligations as those listed above.

  Useful links

Privacy policy
You can access our privacy policies with this link: Privacy policies
Terms & condition
You can access our terms and conditions with this link: View Terms & conditions
Data Processing Agreement
Review our DPA template here: DPA template

  Any question?