1.Overview
This Privacy document sets out the obligations that apply to the processing of personal data in connection with the BambooHR human resource information system ("HRIS") platform and related services. It should be read together with the Customer Terms of Service and the Data Processing Agreement ("DPA"), both of which are incorporated by reference.
In this document: "Customer Personal Data" means all personal data (as defined in the Data Protection Legislation) controlled by a Customer which is processed by the Provider in connection with the Services; "Data Protection Legislation" means all applicable laws relating to data protection and privacy, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the EU Privacy and Electronic Communications Directive 2002/58/EC as implemented in each jurisdiction, and any amending or replacement legislation from time to time; "Security Incident" means an accidental, unauthorised, or unlawful destruction, loss, alteration, disclosure of, or access to, personal data; and "Authorised Persons" means any person who processes personal data on behalf of the Provider, including employees, officers, partners, contractors, and sub-contractors.
2.Roles in Data Processing
In this document, the terms "personal data", "process", "data controller", "data processor", "data subject", and "supervisory authority" have the meanings set out in the Data Protection Legislation.
The Provider (as data processor) is appointed by the Customer (as data controller) to process Customer Personal Data on behalf of the Customer as is necessary to provide the Services and in accordance with such other written instructions as the Customer may issue from time to time.
Each party shall comply with its obligations under the Data Protection Legislation in respect of any personal data it processes under or in relation to the Agreement. Without prejudice to the foregoing, the Provider shall not process Customer Personal Data in a manner that will or is likely to result in the Customer breaching its obligations under the Data Protection Legislation.
The Provider will at all times process Customer Personal Data only for the purpose of providing the Services to the Customer and in accordance with the Customer's documented instructions, unless the Provider is required to process the Personal Data for other purposes by applicable law. Where such a requirement applies, the Provider shall provide prior notice to the Customer unless the relevant law prohibits giving such notice.
The Provider shall promptly notify the Customer if it determines that it cannot comply with its obligations under this document, and shall work with the Customer and take all reasonable steps to stop and remediate any non-compliant processing. The Provider shall immediately cease (and request all sub-contractors to immediately cease) processing Customer Personal Data if the Customer determines that non-compliance cannot be corrected within a reasonable time frame.
3.Categories of Personal Data Processed
The categories of Customer Personal Data processed in connection with the Services include data relating to employees and candidates of the Customer. This may include: personal information such as name, identification number(s), photograph(s), address, date of birth, gender, marital status, emergency contact, telephone number(s), academic and professional qualifications, CV or resume, employment history, and language proficiency; information in connection with employment such as title, grade, location, reporting lines, hire date, working hours, contract details, performance and evaluation data, employee discipline information, benefits and insurance, assets assigned, training, and time-off documentation; payroll-related information such as salary and compensation, tax and social security information, bank details, pensions, bonuses, and other benefits. Where applicable, the Services may also process reference and referee contact details, and special categories of data such as health status and disability information.
The processing of Customer Personal Data is carried out for the purpose of providing and maintaining the HRIS platform, including the collection, hosting, processing, and support of HR data. The duration of processing corresponds to the period during which the Services are provided to the Customer in accordance with the Agreement, including any applicable support period thereafter.
4.Sub-processing
The Provider shall not appoint any third party to process Customer Personal Data ("Sub-processor") without the Customer's prior written consent. Subject to such consent, the Provider shall: (a) provide reasonable prior notice to the Customer of the identity and location of any new or replacement Sub-processor and a description of the intended processing; (b) impose legally binding data protection terms on each Sub-processor that are the same as those applicable to the Provider under the Agreement; and (c) remain fully liable to the Customer for any breach of the Agreement caused by an act, error, or omission of any Sub-processor.
BambooHR LLC acts as the technology provider and processes Customer Personal Data to provide the platform services pursuant to the BambooHR Data Processing Agreement. All personal data, including employee data, saved on the platform is hosted in Ireland by BambooHR, with Amazon Web Services (AWS) as the primary hosting sub-processor. Additional operational sub-processors used by BambooHR include, amongst others: Cloudflare (web application firewall), Datadog (infrastructure monitoring), Microsoft (workspace collaboration and document storage), Mailgun (application communications), Twilio (multi-factor authentication via SMS), Snowflake (data analytics), and OneTrust (privacy rights and cookie management). A current list of sub-processors is available on request.
If, within a reasonable time following receipt of notice of a new Sub-processor, the Customer objects to that Sub-processor on data protection grounds, then either the Provider will not engage the Sub-processor or the Customer may elect to suspend or terminate the Agreement.
5.Technical and Organisational Security Measures
The Provider implements and maintains appropriate technical and organisational security measures to protect Customer Personal Data against unauthorised and unlawful processing and against accidental loss, destruction, disclosure, damage, or alteration. Such measures are reviewed and updated regularly to take account of industry standards, costs of implementation, and the nature, scope, context, and purposes of processing.
Physical access controls: data processing equipment and servers where Customer Personal Data is processed are held in enclosed areas with restricted access. All access to the data centre is logged, monitored, and tracked. The data centre is secured by a security alarm system and other appropriate security measures, including restrictions on the issuance and use of access credentials.
System access controls: industry-standard encryption is used to prevent unauthorised access to data processing systems. Measures include automatic time-out of user terminals if left idle, identification and password requirements (including minimum length and special character requirements), automatic log-off of user IDs inactive for a substantial period, and full logging and monitoring of all access to data.
Data access controls: only personnel required to assist in providing the Services have access to Customer Personal Data, and such access is strictly limited to the scope of their access permissions. Employees are bound by appropriate obligations of confidentiality and receive relevant training. Access is controlled through application security and data is separated at the database level by module and function. Effective disciplinary measures apply to any unauthorised access.
Transmission controls: firewall and encryption technologies protect data gateways and pipelines during transmission. Data is not stored on unencrypted mobile storage media or mobile devices. The completeness and correctness of all data transfers are monitored.
Availability and continuity controls: infrastructure redundancy, off-site backup storage, and disaster recovery and business continuity plans are maintained to ensure Customer Personal Data can be restored in a timely manner in the event of a Security Incident. Permanent local workstation storage of Customer Personal Data is prohibited.
Separation of processing: data collected for different purposes is processed separately through application security, database-level separation, and purpose-specific interfaces and batch processes.
Testing: BambooHR regularly tests, assesses, and evaluates the effectiveness of its technical and organisational security measures.
6.Security Incidents and Breach Notification
The Provider shall notify the Customer in the most expedient time possible and in any event within 48 hours of becoming aware of any actual or suspected Security Incident. Such notification shall include: (a) a detailed description of the Security Incident; (b) the type of Customer Personal Data that was the subject of the Security Incident; (c) the identity of each affected data subject, or where not possible, the approximate number of data subjects and personal data records concerned; and (d) a description of the measures taken or proposed to be taken to address the Security Incident, including measures to mitigate its possible adverse effects.
The Provider agrees to take action immediately, at its own expense, to investigate the Security Incident and to identify, prevent, and mitigate its effects. The Provider shall keep the Customer up to date on all material developments. The Provider shall also provide timely information and cooperation as the Customer may require to fulfil the Customer's data breach reporting and notification obligations under applicable data protection law.
The content and provision of any notification, regulatory communication, or press release concerning a Security Incident shall be solely at the Customer's discretion, except as otherwise required by applicable law. The Provider may not issue, publish, or make available to any third party any such communication without the Customer's prior approval. Where BambooHR is referenced by name in any such communication, BambooHR shall be provided with an opportunity to review and approve the communication for accuracy, such approval not to be unreasonably withheld.
7.Data Transfers and International Processing
All Customer Personal Data, including employee data, saved on the BambooHR platform is hosted in Ireland. The Provider shall ensure that Customer Personal Data is processed inside the European Economic Area (EEA) or any other territory in which restrictions are not imposed on the transfer of personal data across borders under the Data Protection Legislation, with the following exceptions where BambooHR is authorised to transfer data outside the Ireland datacentre: (1) in the case of an emergency, such as a data breach at the Irish data centre; (2) in the course of a support request where access by the US support team is required and written confirmation has been received from the Customer; and (3) at the Customer's verified written request to move the hosting outside Ireland.
To the extent that any Customer Personal Data is transferred outside the EEA, such transfers are governed by the EU Standard Contractual Clauses for the transfer of personal data to processors, as approved by the European Commission and incorporated into the Agreement. For transfers from the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses applies. For transfers from Switzerland, the same clauses apply with amendments to reflect Swiss law, including reference to the Federal Act on Data Protection (FDAP) and the jurisdiction of the Federal Data Protection and Information Commissioner.
The Provider will at all times provide an adequate level of protection for Customer Personal Data, wherever processed, in accordance with the requirements of applicable data protection law. The Model Clauses or Standard Contractual Clauses shall prevail in the event of any conflict with the terms of the Agreement or this document. In no event does this document restrict or limit the rights of any data subject or of any competent supervisory authority.
8.Data Subject Rights
Data subjects whose personal data is processed in connection with the Services may, in accordance with applicable data protection law, have the right to: access a copy of their personal data; require correction of inaccurate personal data; request erasure of their personal data where there is no legitimate reason for its continued processing; restrict or object to the processing of their personal data; receive their personal data in a structured, commonly used, and machine-readable format (data portability); and withdraw consent where processing is based on consent.
The Provider shall, at no additional cost, provide full cooperation and assistance to the Customer to allow the Customer to comply with its obligations as a data controller, including in relation to: data security; data breach notification; data protection impact assessments; prior consultation with supervisory authorities; the fulfilment of data subjects' rights; and any enquiry, notice, or investigation by a supervisory authority or any other regulatory authority. Any request from a data subject received directly by the Provider shall, unless prohibited by applicable law, be passed promptly to the Customer without being responded to without the Customer's express authorisation.
9.Security Reports, Inspections and Audits
BambooHR maintains records in accordance with ISO 27001, SOC II, or other similar Information Security Management System ("ISMS") standards and shall provide the Customer with copies of relevant ISMS certifications, audit report summaries, and/or other documentation reasonably required by the Customer to verify compliance with applicable data protection obligations, upon request.
The Provider shall, upon receipt of a written request from the Customer, make available such information as is reasonably necessary to demonstrate compliance with applicable data protection law and permit the Customer and/or its authorised agents to audit records to the extent reasonably required to confirm compliance with applicable obligations, provided that any such audit does not involve the review of any third-party data and that the records accessed are treated as confidential. The Customer shall bear its own costs to conduct any such audit. Unless the Customer's request follows a Security Incident or is otherwise required by applicable data protection law, the Customer shall not make such a request more than once in any 12-month period.
The Provider shall assist the Customer in carrying out any data protection impact assessment of the Services as is reasonable in light of the personal data being processed, and shall reasonably cooperate to implement mitigation actions required to address privacy risks identified in any such assessment.
10.Deletion and Return of Data
At the request and option of the Customer (whether during or following termination of the Agreement), the Provider shall promptly and as specified by the Customer return or destroy all Customer Personal Data in the possession or control of the Provider or its sub-processors. This requirement shall not apply to the extent the Provider is required by applicable law to retain some or all of the Customer Personal Data, in which event the Provider shall isolate and protect such data from any further processing except to the extent required by law.
Following termination or expiration of the Agreement, BambooHR provides a period during which the Customer may export its Customer Data from the platform. The Customer is solely responsible for ensuring it completes any required export of data before that period expires. The Provider will provide reasonable assistance with data export, subject to any applicable fees for such assistance being agreed in advance.
11.General
This Privacy document and the data processing obligations it sets out are incorporated into the Agreement and shall be governed by and construed in accordance with the laws of the country where the Customer has its main establishment in the European Union, the EEA, Switzerland, or the United Kingdom, unless otherwise required by applicable data protection law. In the event of a conflict between the Agreement and these data processing obligations, the data processing obligations shall prevail.
The obligations placed upon the Provider under these terms shall survive for so long as the Provider and/or its sub-contractors process Customer Personal Data on behalf of the Customer. These obligations may not be modified except by a subsequent written instrument signed by both parties. If any part of these obligations is held unenforceable, the validity of all remaining parts will not be affected.
We may update this Privacy document from time to time to reflect changes in applicable law, our processing activities, or our organisational measures. Material changes will be notified to Customers in advance. If you have questions or concerns about the processing of your personal data, please contact us via our contact page.








































