DRAFT — pending legal review. Not yet a published policy.

BMS Privacy Policy

Last updated: DRAFT (not yet in force)

This policy explains, in plain language, what personal information BMS collects, why we collect it, and the choices you have. It is written to comply with the Protection of Personal Information Act, 2013 (POPIA).

Who we are

BMS is operated by Kgolaentle Solutions (Pty) Ltd (registration number 2014/077326/07), a South African company. In POPIA terms, we are the responsible party for the personal information described here.

What we collect

  • Account details — your name, email address, and the business details you give us when you create a workspace.
  • Financial records you upload — bank statements, receipts, and invoices you load into your workspace.
  • Supplier and transaction data — the contacts, categories, and transaction records you build up while using BMS.
  • Connected email accounts (optional) — if you choose to connect a Gmail or Outlook mailbox, we store an encrypted connection token and sync the emails and attachments needed to find your invoices and receipts. We only access mail for that purpose, we never send mail from your account, and you can disconnect a mailbox at any time, which stops all syncing. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • Technical logs — basic records of sign-ins and system activity that we need to keep the Service running and secure.

Why we process it

  • to provide the bookkeeping and compliance features you signed up for;
  • to keep your account and your data secure;
  • to help you when you contact support;
  • to meet our own legal obligations.

We do not sell your personal information, and we do not use it for advertising.

AI features

Some features — like automatically classifying a receipt or a bank transaction — are powered by third-party AI providers. When you use these features, bounded samples of the relevant document may be sent to the provider to produce the classification. Our agreements with these providers do not allow them to train their models on your data.

Who helps us run BMS (subprocessors)

We use a small number of service providers to run BMS. They process data only on our instructions:

  • Railway — application hosting and database;
  • Vercel — web hosting;
  • OpenAI — AI classification (see above);
  • Google / Microsoft — mailbox access, only when you connect a Gmail or Outlook account;
  • Apple — app distribution, when you use the iOS app.

How long we keep it

  • We keep your data while your account is active, and for 30 days after you delete your account, then we remove it.
  • Some records must be kept longer because tax law requires it — those we keep for the statutory period, then delete.

How we protect it

  • Your data is encrypted in transit and at rest.
  • Each business's workspace is isolated at the database layer — one tenant cannot see another tenant's data.

Your rights under POPIA

You may ask us to:

  • show you the personal information we hold about you (access);
  • fix information that is wrong (correction);
  • delete information we no longer need to keep (deletion);
  • stop certain processing (objection).

If you are not happy with how we handle a request, you may complain to the Information Regulator (South Africa) — inforeg.org.za.

Cookies

BMS uses a single essential session cookie to keep you signed in. We do not use advertising or tracking cookies.

Children

BMS is a business tool and is not directed at anyone under 18. We do not knowingly collect personal information from children.

Changes to this policy

If we make material changes, we will tell you in the app or by email before they take effect.

Contact

Questions about privacy or your data: privacy@kgolaentle.com.

Terms of Use · Back to signup