Privacy Policy
How Bright Ledger collects, uses and protects your personal information, in accordance with the Protection of Personal Information Act, 2013 (POPIA).
Responsible party
This policy explains what personal information we collect, why we collect it, and the rights you have as a data subject under POPIA.
Bright Ledger Financial Consulting (Pty) Ltd (trading as Bright Ledger), registration number 2018/456217/07, with its registered address at 45 Kloof Street, Gardens, Cape Town, 8001, South Africa, is the responsible party for the processing of personal information described in this policy. Our Information Officer can be contacted at info@halmora.pro or by phone at +27 21 418 9273.
Information we collect
Contact form and enquiry data
When you submit our contact form or email us, we collect your name, email address, phone number and any message content you provide, in order to respond to your enquiry.
Client and engagement data
If you become a client, we collect financial, tax and company information necessary to provide bookkeeping, tax and compliance services, as agreed in our engagement letter.
Cookies and site usage data
We use strictly necessary, analytics and marketing cookies as described in our Cookie Policy, subject to your consent choices via our cookie banner.
Newsletter subscription
If you subscribe to our newsletter, we store your email address to send occasional updates on tax and bookkeeping topics. You may unsubscribe at any time.
Why and how we use your data
We process personal information only where we have a lawful basis to do so, including:
We process data to
- Respond to enquiries and provide requested quotes
- Deliver bookkeeping, tax and compliance services under contract
- Meet legal and regulatory obligations (e.g. SARS, CIPC)
- Improve our website through aggregated analytics
- Send newsletters where you have consented
We do not
- Sell personal information to third parties
- Use client financial data for marketing purposes
- Process special personal information without explicit consent
- Retain data longer than necessary or legally required
Hosting, sharing & recipients
Our website is hosted with reputable service providers who may process data on our behalf under appropriate data processing agreements. We may share personal information with: our accounting and practice-management software providers; SARS, CIPC and other regulatory bodies where legally required; professional advisors (e.g. auditors, legal counsel) bound by confidentiality; and analytics providers who process aggregated, pseudonymised usage data. We do not transfer personal information outside South Africa unless the recipient is subject to a law, binding corporate rules or agreement providing an adequate level of protection, as required by POPIA.
How long we keep data
Enquiry and contact form data is retained for up to 24 months unless you become a client. Client financial and engagement records are retained for a minimum of five years in line with South African tax and company record-keeping requirements. Newsletter subscriber data is retained until you unsubscribe. Cookie-related data is retained according to the durations set out in our Cookie Policy.
Rights of the data subject
Under POPIA, you have the right to:
Access
Request confirmation of, and access to, the personal information we hold about you.
Correction & deletion
Request correction, updating or deletion of inaccurate or outdated personal information.
Objection
Object to processing of your personal information, including for direct marketing purposes.
Complaint
Lodge a complaint with the Information Regulator of South Africa if you believe your information has been mishandled.
To exercise any of these rights, contact our Information Officer at info@halmora.pro. The Information Regulator can be reached at [email protected].
How we protect your data
We implement reasonable technical and organisational measures — including encrypted connections, access controls and staff confidentiality obligations — to protect personal information against loss, unauthorised access, alteration or disclosure, in line with POPIA's security safeguard requirements.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The date of the most recent revision is provided below. We encourage you to review this page periodically.
Last updated: 1 February 2026