Skip to main content

Odoo Connector for BambooHR

Privacy policy

This policy covers the Odoo module "Odoo Connector by Flexigotech" for BambooHR and the OAuth service it uses. The website flexigotech.com has its own privacy policy. Leer en español.

Who we are

Flexibles y Accesorios Gobe, S.L., which sells software under the FlexigoTech brand, develops the Odoo module "Odoo Connector by Flexigotech" and runs the OAuth service at bamboohr.connect.flexigotech.com. Tax ID (NIF) B56727993. Calle Roger de Llúria 54, principal 1.ª B, 08009 Barcelona (Spain). Contact: comercial@flexigobe.com.

How the integration works

The module runs inside the customer's own Odoo database. Employee data travels directly between the customer's BambooHR account and the customer's Odoo and never passes through Flexigotech servers. Our OAuth service only handles authorization: it exchanges the one-time code for access and refresh tokens, hands them to the customer's Odoo once, and refreshes them when that Odoo asks.

The service keeps authorization data (state, PKCE verifier, one-time relay) for 15 minutes at most. So that each customer's Odoo can refresh its tokens safely, it keeps the last refresh response, encrypted, for 2 minutes at most. It also keeps a register of connected companies with no tokens in it: the BambooHR company ID and subdomain, the customer's Odoo host and database identifier, a hash of the connection key, and dates. Each entry is deleted 30 days after the connection is revoked or stops refreshing. The service never stores employee data. Its web access log is off (only health checks are logged), and IP addresses are used in memory for rate limiting and never stored.

Data the module processes in the customer's Odoo

Only the categories the customer turns on:

The module never processes ethnicity, EEO data, veteran status, credit cards, or dependants' personal data beyond the number of children and, if turned on, the spouse's name and date of birth. It does not request health-specific scopes. Time-off categories, employee files and custom fields chosen by the customer can still contain special-category data, such as sick or parental leave. The OAuth service processes the BambooHR company subdomain and, briefly, the identifiers of the administrator who authorizes the app.

Purpose and legal basis

The data is processed only to provide the integration the customer configures. The customer is the controller. Flexigotech does not sell or share the data, does not profile anyone with it or use it for advertising, and does not use it to train or improve any AI system.

Sub-processors

Netcup GmbH (Germany) hosts the OAuth service. If the customer hosts Odoo with Odoo S.A. (Odoo.sh), Odoo S.A. is the customer's own provider.

Retention and deletion

When a customer disconnects through the disconnect wizard, the module deletes the tokens and all BambooHR mirror data at once, and the customer chooses whether the records it created are kept unlinked, anonymised or deleted. If the connection ends without the wizard (the app is uninstalled in BambooHR, the BambooHR account is closed or the authorization is revoked), the module deletes the mirror data automatically 25 days later. On Flexigotech systems only the connection register described above remains, for 30 days. We confirm deletion in writing on request.

Individual rights

Employees exercise their rights (access, rectification, deletion, restriction, portability, objection) with their employer, who controls both systems. If a request reaches us, we forward it to the customer concerned within 5 business days.

Support access

Flexigotech enters a customer's Odoo only when the customer asks, only for that support case, and records each access. Support copies of a database have their tokens removed and their personal data anonymised, and are deleted within 30 days. Customer data is never entered into AI tools.

Security

TLS for all traffic; PKCE and single-use state and relay codes; tokens readable only by Odoo system administrators; encrypted short-lived storage in the OAuth service; HMAC-verified webhooks; least-privilege scopes; no tokens or personal data in logs. We report security incidents to BambooHR and to the affected customers within the deadlines of our agreements and of applicable law.

Changes

We tell customers in advance about any material change to the data the connector accesses.

Last updated: 7 October 2026.