+27 21 418 9273 info@halmora.pro 45 Kloof Street, Gardens, Cape Town
Legal

Privacy Policy

How Bright Ledger collects, uses and protects your personal information, in accordance with the Protection of Personal Information Act, 2013 (POPIA).

01
Who we are

Responsible party

This policy explains what personal information we collect, why we collect it, and the rights you have as a data subject under POPIA.

Bright Ledger Financial Consulting (Pty) Ltd (trading as Bright Ledger), registration number 2018/456217/07, with its registered address at 45 Kloof Street, Gardens, Cape Town, 8001, South Africa, is the responsible party for the processing of personal information described in this policy. Our Information Officer can be contacted at info@halmora.pro or by phone at +27 21 418 9273.

02
Data collection

Information we collect

Contact form and enquiry data

When you submit our contact form or email us, we collect your name, email address, phone number and any message content you provide, in order to respond to your enquiry.

Client and engagement data

If you become a client, we collect financial, tax and company information necessary to provide bookkeeping, tax and compliance services, as agreed in our engagement letter.

Cookies and site usage data

We use strictly necessary, analytics and marketing cookies as described in our Cookie Policy, subject to your consent choices via our cookie banner.

Newsletter subscription

If you subscribe to our newsletter, we store your email address to send occasional updates on tax and bookkeeping topics. You may unsubscribe at any time.

03
Purpose & basis

Why and how we use your data

We process personal information only where we have a lawful basis to do so, including:

We process data to

  • Respond to enquiries and provide requested quotes
  • Deliver bookkeeping, tax and compliance services under contract
  • Meet legal and regulatory obligations (e.g. SARS, CIPC)
  • Improve our website through aggregated analytics
  • Send newsletters where you have consented

We do not

  • Sell personal information to third parties
  • Use client financial data for marketing purposes
  • Process special personal information without explicit consent
  • Retain data longer than necessary or legally required
04
Third parties

Hosting, sharing & recipients

Our website is hosted with reputable service providers who may process data on our behalf under appropriate data processing agreements. We may share personal information with: our accounting and practice-management software providers; SARS, CIPC and other regulatory bodies where legally required; professional advisors (e.g. auditors, legal counsel) bound by confidentiality; and analytics providers who process aggregated, pseudonymised usage data. We do not transfer personal information outside South Africa unless the recipient is subject to a law, binding corporate rules or agreement providing an adequate level of protection, as required by POPIA.

05
Retention

How long we keep data

Enquiry and contact form data is retained for up to 24 months unless you become a client. Client financial and engagement records are retained for a minimum of five years in line with South African tax and company record-keeping requirements. Newsletter subscriber data is retained until you unsubscribe. Cookie-related data is retained according to the durations set out in our Cookie Policy.

06
Your rights

Rights of the data subject

Under POPIA, you have the right to:

01

Access

Request confirmation of, and access to, the personal information we hold about you.

02

Correction & deletion

Request correction, updating or deletion of inaccurate or outdated personal information.

03

Objection

Object to processing of your personal information, including for direct marketing purposes.

04

Complaint

Lodge a complaint with the Information Regulator of South Africa if you believe your information has been mishandled.

To exercise any of these rights, contact our Information Officer at info@halmora.pro. The Information Regulator can be reached at [email protected].

07
Security

How we protect your data

We implement reasonable technical and organisational measures — including encrypted connections, access controls and staff confidentiality obligations — to protect personal information against loss, unauthorised access, alteration or disclosure, in line with POPIA's security safeguard requirements.

08
Updates

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The date of the most recent revision is provided below. We encourage you to review this page periodically.

Last updated: 1 February 2026