Last updated: 21 June 2026
BMS operates under the Protection of Personal Information Act, 2013 (POPIA). This page summarises how we comply and what that means for you.
When you use BMS to run your business, you are the responsible party for the personal information of your own clients and employees. BMS acts as your operator under POPIA - we process that information only on your lawful instructions, to deliver the service.
Where we collect information about you directly to operate your BMS account, we are the responsible party.
Our POPIA Information Officer can be contacted at neville@bmssa.co.za. Queries, complaints, access requests and deletion requests should go to that address.
BMS processes personal information in line with POPIA's eight conditions:
Personal information is stored on cloud infrastructure physically hosted in South Africa. Where a specific third-party service (for example email delivery or payment processing) may process information outside South Africa, we use providers that offer POPIA-equivalent protection or contractual safeguards.
We use the following categories of sub-operators under written agreements that commit them to POPIA-equivalent protection:
We use encryption in transit (HTTPS), encryption at rest for backups, role-based access control, audit logging and regular security reviews. Access to personal information is strictly need-to-know for BMS staff.
If we become aware of a compromise that affects your personal information we will notify you and the Information Regulator as soon as reasonably possible, in line with section 22 of POPIA.
South African Information Regulator:
For any POPIA-related query or complaint: neville@bmssa.co.za.