BookkeeperHR
Log in

Privacy Policy

This notice explains how IG Consulting Services Kft. handles personal data when you visit BookkeeperHR, contact us or use a workspace. Our responsibilities differ for account and enquiry data and for HR or accounting records managed by our customers.

Who operates BookkeeperHR

IG Consulting Services Kft. operates BookkeeperHR. For privacy questions or requests, contact support@bookkeeperhr.com. Our registered address and company details appear below.

Our role and your organisation’s role

We act as a controller for account administration, enquiries, booking and support correspondence, and the security of our service. This means we decide why and how we use that information for those purposes.

For employee, client and accounting records placed in a workspace, the customer organisation normally decides the purposes and acts as controller. BookkeeperHR processes those records on its instructions as a processor. Where a bookkeeper acts for its client, their agreement determines their respective roles. Your employer or the organisation managing your workspace should explain its own use of your records and the legal basis for that use.

Leave types, explanations and supporting documents can reveal health information. The customer must establish the applicable legal basis and any additional condition for special-category data. Record only what is needed for the relevant employment or accounting purpose; avoid diagnoses, medical histories or unrelated sensitive details in free-text fields.

Categories of Data

  • Account identifiers, name, email address and authentication information; profile information returned by Google if you choose Google sign-in.
  • Workspace names, invitations, membership status, roles, country, employment start date and leave allowance.
  • Documents such as payslips, bank statements, invoices and employee files, together with names, descriptions, upload dates and uploader/assignee details. Their contents may include employee, customer, supplier and financial information. Statements and invoices also include a user-selected accounting month. The accounting month groups documents into the customer’s monthly close checklist; it is supplied by an authorised member, not inferred from upload time.
  • Clients and projects; daily hours and monthly timesheets; leave dates, types and descriptions; submission, approval and rejection records.
  • Booking and founding-seat enquiries: name, email, optional firm name, language, meeting details and correspondence you provide.
  • Technical and security information, such as request times, IP addresses used for abuse prevention, error information and records of administrative or deletion operations.

Purposes and Legal Bases

  • Account and service administration: performance of our contract with you when you are the contracting person; otherwise our legitimate interests in delivering the service to your organisation and managing authorised access.
  • Access control, troubleshooting and abuse prevention: our legitimate interests in protecting users, customer records and the service.
  • Compliance with applicable legal obligations and responding to valid official requests; establishing or defending legal claims where necessary.
  • Replying to enquiries, arranging a requested meeting and providing support: steps requested before a contract, performance of a contract, or our legitimate interests in business communication, as applicable. Login and invitation emails support requested account access.
  • Optional embedded booking content: your choice to load Calendly. Any additional optional cookies offered by Calendly are governed by its own cookie controls. Customer HR processing follows the customer’s instructions and legal basis, not a blanket consent inferred from using this site.

Who can receive information

Workspace records are available to authorised workspace members according to their role and the record’s access rules. Providers also process information needed for their services:

  • Supabase provides authentication, the application database and private file storage.
  • Vercel hosts the website and application endpoints and handles associated technical requests.
  • Brevo delivers service emails and enquiry notifications, including recipient addresses and the relevant message content.
  • Calendly provides optional meeting booking. Loading it shares technical connection data; booking shares the details you enter.
  • Google handles authentication if you choose Google sign-in. Its own services are also subject to Google’s privacy notice.

View full Subprocessors list

Collection of Information

Information comes from you and from people authorised to manage the workspace.

  • Details supplied during sign-in, invitation acceptance and profile changes.
  • Membership and employment settings supplied by your organisation or its authorised administrator.
  • Timesheets, leave requests and uploaded documents supplied by you, your employer, bookkeeper or other authorised workspace members.
  • Enquiry forms, meeting bookings and messages sent to support.

Information Collected Automatically

  • Hosting and authentication providers receive technical request information needed to deliver and secure their services.
  • The application uses IP addresses for rate limiting and abuse prevention. For shared abuse limits, the application stores keyed hashes of source IP addresses and email addresses, with counters and expiry times, in our existing database; raw identifiers are not stored in these counters. Windows last at most one hour. Expired counters are removed during later requests and by daily cleanup, normally within about 25 hours when that job operates; failures may delay deletion, and backups follow separate retention settings. Operational errors and maintenance activity may be logged. When security reporting is enabled, your browser may send blocked-resource reports to our hosting service. These can include page/resource addresses and technical request information. The application discards raw addresses, query strings, referrers and script samples and logs only the affected security rule, enforcement mode and a fixed resource category. Hosting providers may separately process request metadata under their operational log settings. These reports are used to diagnose security-policy failures, not for analytics; no additional cookie or browser identifier is created.
  • Cookies and browser storage maintain sign-in, language, workspace selection and unsaved timesheet drafts. See the storage inventory for details.

Information from Other Sources

An administrator may invite you or enter your workspace details before you sign in. Google may return identity information when you select Google sign-in. Other authorised members may upload records relating to you.

Enquiries, booking and optional services

The calendar stays blocked until you choose to load it. You can contact support by email instead. A founding-seat enquiry is stored in our application database and may also be sent to our support inbox. Booking or enquiring does not automatically create a BookkeeperHR account or subscribe you to a newsletter.

An email address and the information needed to identify your account are required for sign-in. Enquiry forms require a name and email; the firm name is optional. Without required details we cannot provide the requested access or reply. Your organisation determines which employment records are needed in its workspace.

BookkeeperHR does not use these records for automated employment decisions or advertising profiles. Managers make approval decisions. The app applies validation rules, such as leave-allowance checks. Optional analytics is described below; it contains no HR contents.

Optional product analytics

With your consent, BookkeeperHR uses PostHog to measure completed enquiries and calendar bookings, new-account setup, workspace creation, uploads, invitation acceptance, and timesheet/leave submissions and approvals. We send only the action name, time, environment, schema version, an opaque event identifier and a pseudonymous identifier (your internal account ID when signed in, otherwise a random ID held in page memory). We do not send names, email addresses, document contents or filenames, hours, leave details, page URLs, query strings, sign-in tokens or referrers. There is no automatic page/click tracking, session replay, advertising, location enrichment or person-profile creation. Anonymous visits are not linked across page reloads or merged with accounts. PostHog necessarily receives network connection information; our project is configured to discard client IP data and each event disables location enrichment. Events use the EU ingestion endpoint; European hosting does not exclude international provider operations. The selected free plan currently provides one year of event retention; this is not a guarantee of deletion on an exact day. We act as controller for this optional service-improvement processing, based on your consent. You can refuse or withdraw in the Cookies page without affecting app access. Withdrawal stops future collection and cancels pending sends where possible; it cannot recall data already received. Contact support to exercise your rights. We review retention and this notice before changing the plan or collection.

Optional performance and error diagnostics

With the same optional analytics permission, and only when configured, your browser sends fixed operation categories, duration, outcome, HTTP status and a random per-request correlation ID to BookkeeperHR’s own diagnostic endpoint. These help us find slow navigation, session loading and API requests. Browser errors are reported as a fixed category; messages, stacks, page addresses, form contents and account identifiers are excluded. No additional tracking cookie or persistent identifier is created. These diagnostics go to our hosting logs, not PostHog. Essential server-side request, email-attempt and cleanup-job measurements may also be recorded to operate and protect the service, independently of optional browser consent. Email success means provider acceptance, not inbox delivery. Our application records exclude HR contents, credentials, raw IP addresses and user agents; the hosting service necessarily receives network information and may separately retain request metadata. Access, retention and processing locations follow the hosting account configuration and applicable agreements; no fixed retention or EU-only guarantee is made here. Optional browser collection stops when you reject analytics; records already received follow the applicable retention and rights process.

International Transfers

Using a European hosting region does not mean all provider processing stays in Europe. Providers may use support, delivery or infrastructure services outside the EEA, including in the United States. The provider list links to their published terms. Contact us for the processing locations and transfer arrangements relevant to your service agreement.

Security

The service uses authenticated access, workspace membership and role checks, private file storage, and server-side validation for sensitive operations. These controls reduce risk but do not make any internet service risk-free. Protect your email account and sign-in links, and use care when downloading records to shared devices.

Retention

  • Account and contact information is kept while needed to operate the account, respond to the enquiry or support the customer relationship, and to meet applicable legal obligations or resolve disputes.
  • Workspace content is kept for the customer’s use until deleted or otherwise handled under its instructions. Archiving restricts access; it does not delete records. A workspace deletion request schedules cleanup after a 30-day grace period; completion depends on successful cleanup, including retries.
  • Operational records, correspondence and provider logs have separate retention needs. We do not promise a single retention period covering every provider, audit record or backup. Contact support for the schedule relevant to your records.

Your Rights

  • Ask whether we process your personal data and request access or a copy.
  • Request correction of inaccurate information.
  • Request deletion where the applicable conditions are met; legal obligations or others’ rights may affect what can be removed.
  • Request portability where processing is automated and based on your consent or a contract with you.
  • Request restriction where applicable and object to processing based on legitimate interests.
  • Complain to a competent data protection authority, including the authority where you live or work or where an alleged infringement occurred.
  • Withdraw consent for processing based on consent without affecting the lawfulness of earlier processing. You can hide the optional calendar at any time.

Cookies

BookkeeperHR uses cookies and browser storage for access and requested functionality. The information banner’s acknowledgement is not consent to analytics or third-party booking. Calendly loads only after a separate choice; see the Cookies Policy for controls and storage details. Opening the homepage or legal pages does not load your profile or workspace. Existing sign-in cookies may still accompany requests to BookkeeperHR; account and app pages perform sign-in checks. Analytics requires its own explicit permission, which can be changed on the Cookies page.

See detailed Cookies Policy

How to Exercise Your Rights

Email support@bookkeeperhr.com to request access, correction, deletion or an export. For workspace HR or accounting records, contact your employer or the organisation managing the workspace; we assist it in handling requests. Account deletion controls are available in the app, subject to ownership and authorisation checks.

Children

BookkeeperHR is a business service, not a service directed at children. Customers are responsible for ensuring that any employment-related records they upload, including records of young workers where relevant, can lawfully be processed.

Contact

Questions or requests can be sent to support@bookkeeperhr.com.

Imprint

Company: IG Consulting Services Kft.. Contact: support@bookkeeperhr.com.

Legal name
IG Consulting Services Kft.
Registered address
2724 Újlengyel, Nyári Pál utca 15.
Company registration number
13-09-226579
Court of Registration
Budapest Környéki Törvényszék Cégbírósága
Tax number
27729487-2-13
EU VAT ID
HU27729487
Representative
Iván Gergő
Phone
+36 70 371 5454
Hosting provider
Vercel
Hosting provider URL
https://vercel.com/

Changes to this Policy

We update this notice when our data use changes. The date below records the reviewed version, not the date you opened the page. Material changes will be explained through an appropriate service notice. New optional analytics will require a separate review of disclosures and applicable consent choices before activation.

Data Subject Requests (DSAR)

  • We may request proportionate information to confirm your identity and authority over the requested records.
  • We respond without undue delay and normally within one month of receiving a request. Where the law permits an extension for complexity or the number of requests, we explain the reason within that month; an extension may be up to two further months.
  • Deleting an account can remove files and replace personal identifiers in retained workspace records. It is not the same as deleting every business record, deleting a whole workspace, or immediately purging historical backups.
  • Request an export through support. Existing document downloads and approved-hours PDFs are not a complete personal-data export.

Retention Details

  • Workspace invitations are configured to expire after 14 days. Scheduled cleanup targets old accepted or expired invitations; expiry alone does not erase related membership, email or audit records.
  • Deletion and delivery operations can leave audit and recovery records needed to investigate outcomes, retry failures and protect the service. Provider logs follow separate settings.
  • Live-system deletion does not necessarily remove data immediately from provider backups. Database backups do not themselves back up uploaded file contents. Backup availability and retention depend on the deployed service plan and configuration; no universal recovery window is promised here.
  • A scheduled workspace deletion can be cancelled before destructive cleanup starts, subject to access checks. Interrupted cleanup is retried; it is not guaranteed to finish exactly when the grace period ends. Downloads and copies held outside BookkeeperHR are not removed by this process.

International Transfers (more)

Where a restricted international transfer applies, the relevant arrangement must provide an appropriate legal mechanism, such as an applicable adequacy decision or contractual safeguards. A link to a provider’s standard terms is not evidence of the specific contract or settings for your organisation. You may ask support for details and a copy of applicable safeguards.

Data Processing Agreements

A separate data processing agreement should govern our processing of customer workspace records. This privacy notice is not that agreement and does not establish the legal basis for an employer’s HR processing. Contact support to arrange or obtain the terms applicable to your organisation before uploading employee records.

Marketing

The current app sends service emails and handles requested enquiries and meetings. It does not automatically enrol enquirers in marketing campaigns. We do not sell workspace records or use them for targeted advertising.

Law Enforcement Requests

We review requests, require valid legal process, and limit disclosures to what is legally required.

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority.

Last updated: 2026-09-23