Privacy Policy
At Buesuite, we are committed to protecting your privacy and being transparent about how we collect, use, and safeguard your personal information.
01 Who We Are
Buesuite Technologies Pvt. Ltd. ("Buesuite", "we", "us", or "our") is a global provider of cloud-based Human Capital Management (HCM) software. We help organizations manage their workforce through our comprehensive platform that includes performance management, learning & development, recruitment, and workforce administration.
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website, platform, mobile applications, and services (collectively, the "Services").
For the purposes of applicable data protection laws, Buesuite Technologies Pvt. Ltd. is the data controller for personal data collected through our website and marketing activities. For data processed on behalf of our customers through the HCM platform, we act as a data processor.
02 Data We Collect
We collect information in several ways depending on how you interact with our Services:
2.1 Information You Provide
| Category | Examples | Purpose |
|---|---|---|
| Account Information | Name, email, phone, company name, job title | Account creation, communication |
| Profile Information | Photo, bio, preferences, settings | Personalization, user experience |
| Employment Data | Resume, work history, skills, certifications | HCM platform functionality |
| Payment Information | Billing address, payment method details | Subscription billing |
| Communication Data | Support tickets, feedback, survey responses | Customer support, improvement |
2.2 Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Device Information | Device type, OS, browser, screen resolution | Compatibility, troubleshooting |
| Usage Data | Pages visited, features used, click patterns | Analytics, product improvement |
| Log Data | IP address, access times, referring URLs | Security, debugging |
| Location Data | Country, region, timezone (from IP) | Localization, compliance |
| Cookies & Trackers | Session cookies, analytics cookies | Functionality, analytics |
2.3 Information from Third Parties
- Single Sign-On Providers: When you use Google, Microsoft, or other SSO to log in
- Integration Partners: Data from connected applications (with your consent)
- Public Sources: Business information from public databases
- Referrals: Contact information when someone refers you to our services
03 How We Use Your Data
We use the information we collect for the following purposes:
3.1 Service Delivery
- Providing and maintaining the Buesuite HCM platform
- Processing transactions and sending related information
- Authenticating users and managing account access
- Providing customer support and responding to inquiries
3.2 Improvement & Development
- Understanding how users interact with our Services
- Developing new features and functionality
- Conducting research and analytics
- Testing and troubleshooting new products
3.3 Communication
- Sending service-related announcements and updates
- Responding to comments, questions, and requests
- Sending marketing communications (with consent)
- Providing product tips and training resources
3.4 Security & Compliance
- Detecting and preventing fraud, abuse, and security incidents
- Enforcing our terms of service and policies
- Complying with legal obligations
- Protecting the rights and safety of our users
04 Legal Basis for Processing
Under applicable data protection laws, we process your personal data based on the following legal grounds:
Contractual Necessity
Processing necessary to perform our contract with you, such as providing the Services you've subscribed to.
Consent
Where you've given explicit consent, such as for marketing communications or optional features.
Legitimate Interests
Processing necessary for our legitimate business interests, such as improving our Services and security.
Legal Obligation
Processing necessary to comply with applicable laws, regulations, or legal processes.
05 How We Share Data
We do not sell your personal data. We may share your information in the following circumstances:
5.1 Service Providers
We share data with trusted third-party service providers who assist us in operating our Services, such as cloud hosting, payment processing, analytics, and customer support. These providers are contractually bound to protect your data and use it only for specified purposes.
5.2 Business Partners
With your consent, we may share data with integration partners to enable connected functionality (e.g., calendar sync, SSO providers).
5.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, privacy, safety, or property.
5.4 Business Transfers
In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change and your choices regarding your data.
Buesuite does not sell, rent, or trade your personal information to third parties for their marketing purposes. Your data is not a product we monetize.
06 International Data Transfers
As a global company, we may transfer your personal data to countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers.
Global Compliance Framework
We comply with regional data protection regulations worldwide
GDPR
European Union
CCPA / CPRA
California, USA
DPDP Act
India
LGPD
Brazil
6.1 Transfer Mechanisms
- Standard Contractual Clauses (SCCs): EU-approved clauses for international transfers
- UK IDTA: UK International Data Transfer Agreement
- Adequacy Decisions: Transfers to countries with adequate protection levels
- Data Residency: Options to store data in specific regions
07 Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.
When data is no longer needed, we securely delete or anonymize it. In some cases, we may retain anonymized data for statistical purposes indefinitely.
08 Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restriction
Request limitation of processing in certain circumstances.
Right to Portability
Receive your data in a portable, machine-readable format.
Right to Object
Object to processing based on legitimate interests or marketing.
Automated Decisions
Right not to be subject to solely automated decision-making.
Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Lodge Complaint
File a complaint with your local data protection authority.
To exercise any of these rights, please contact us at privacy@buesuite.com. We will respond to your request within 30 days (or as required by applicable law).
09 Security Measures
We implement robust technical and organizational measures to protect your personal data:
Encryption
AES-256 encryption at rest, TLS 1.3 in transit for all data.
Access Control
Role-based access, MFA, and principle of least privilege.
Monitoring
24/7 security monitoring, intrusion detection, and logging.
Certifications
SOC 2 Type II, ISO 27001, ISO 27701 certified.
For more details about our security practices, please visit our Security page or contact security@buesuite.com.
10 Children's Privacy
Our Services are not directed to individuals under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children.
If we learn that we have collected personal information from a child without proper parental consent, we will take steps to delete that information promptly. If you believe we may have collected information from a child, please contact us at privacy@buesuite.com.
11 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Effective Date" at the top of this page
- Notify you via email (for significant changes)
- Display a prominent notice on our website
- Provide a summary of key changes
We encourage you to review this Privacy Policy periodically. Your continued use of our Services after changes indicates your acceptance of the updated policy.
12 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Registered Office
Buesuite Technologies
Tower A, 15th FloorCyber City, Gurugram 122002
Haryana, India
EU/UK Representatives
EU Representative
Buesuite EU B.V.
Herengracht 4201017 BZ Amsterdam
Netherlands
UK Representative
Buesuite UK Ltd.
71-75 Shelton StreetCovent Garden, London
WC2H 9JQ, UK
US Office
Buesuite Inc.
123 Innovation DriveSuite 500
San Francisco, CA 94105