BridgeOne
Privacy commitment 2026

Find out how BridgeOne protects corporate information and guarantees the standards of the General Data Protection Regulation (EU) 2016/679.

🔒Secure infrastructure · Data in the EU

1. ROLES IN DATA PROCESSING

BridgeOne as data processor

When contracting our Human Resources services, your company acts as the Data Controller (the entity deciding on employee data), and BridgeOne acts strictly as the Data Processor. We store, process, and structure clock-ins, shifts, and profile information following solely the instructions stipulated in the service agreement.

Rights of employees

Since the ultimate control of the data belongs to the client company, any employee wishing to exercise their ARCO+ rights (Access, Rectification, Erasure, Objection, Restriction, and Portability) must address their request to the human resources department of their respective organization. BridgeOne will provide the necessary software mechanisms so that the administrator can execute these actions quickly.

2. SECURITY AND STORAGE

Location of servers

All cloud infrastructure and databases supporting the BridgeOne portal are hosted in high-security data centers physically located within the territory of the European Union (EU), strictly complying with the data residency principle of the GDPR.

Technical protection measures

We implement advanced technical protocols and audits to safeguard information: - Data encryption in transit using secure TLS/SSL protocols. - Data encryption at rest on our storage servers. - Automated and isolated daily backups. - Strict control of logical access through strong password policies and differentiated user roles.

3. ENGAGEMENT OF SUB-PROCESSORS

Technology providers

To ensure software availability and scalability, BridgeOne uses infrastructure and support services from top-tier third-party providers (such as cloud storage providers and technical analytics systems). All of them have been selected under rigorous legal compliance criteria and maintain signed data processing agreements aligned with Article 28 of the GDPR.

Notification of changes

In the event of making modifications or additions to our list of essential technological sub-processors, administrative users of the companies will be kept informed in accordance with current contractual terms.

4. SECURITY BREACHES AND CONTACT

Incident protocol

In the hypothetical event that a security breach affecting personal data hosted on BridgeOne is detected, we commit to mitigating the incident immediately and transparently notifying the administrators of the affected companies within a maximum period of 72 hours from becoming aware of it, providing all relevant information as required by the regulation.

Legal support channel

If you have any technical questions or require additional documentation on the portal's security measures or the data processing addendum (DPA), you can write directly to our specialized channel: support@bridgeone.es.