1. Responsible party
Better Business Toolkit is the responsible party for account, billing, support, security and platform-administration information. The operator’s configured address is South Africa. The Information Officer is The designated Information Officer.
Each business using the service is generally the responsible party for personal information it enters about its customers, suppliers, workers and contacts. In that context, the operator processes information on the business’s instructions to provide the service.
2. Information we process
Account and identity information
Name, email address, phone number, authentication records, account metadata, team role and workspace memberships.
Business information
Business names, registration and VAT details, addresses, branding, banking details, compliance information, capability content and settings.
Operational records
Customers, contacts, opportunities, quotations, invoices, payments, job cards, attachments, signatures, cash entries, action plans and delivery activity created by users.
Billing and transaction information
Plan, subscription state, payment references, dates, amounts and provider identifiers. Card details are entered into the payment provider’s hosted checkout and are not stored by Better Business Toolkit.
Technical and support information
IP and device information, browser details, timestamps, security events, error reports, support messages and request history.
3. Why information is processed
- create and secure accounts and organisation workspaces;
- provide the modules and documents requested by users;
- process subscriptions, verify payments and enforce plan access;
- send authentication, security, support and service communications;
- prevent fraud, investigate misuse and maintain audit trails;
- diagnose errors, improve reliability and understand aggregate usage;
- comply with legal, accounting, tax, dispute and regulatory duties;
- protect the rights, systems and safety of users, customers and the operator.
We do not sell personal information to advertisers.
4. Sources of information
Information comes directly from account holders, invited team members, businesses using the service, customer documents uploaded by users, payment and infrastructure providers, and automatically generated technical records. A user must not submit personal information obtained unlawfully or beyond the purpose for which it was collected.
5. Recipients and operators
Information may be shared only as necessary with:
- authorised members of the relevant business workspace;
- customers who receive a secure quotation or invoice link;
- hosting, database, authentication, storage, email, monitoring and support providers;
- the payment provider for checkout, subscription and fraud controls;
- professional advisers, insurers, auditors and authorities where reasonably required;
- a successor in a lawful business restructuring, subject to suitable confidentiality and privacy safeguards.
Service providers may use information only for contracted purposes and must apply appropriate safeguards.
6. Cross-border processing
Infrastructure and service providers may process or store information outside South Africa. Where personal information crosses borders, we use providers and contractual or other safeguards intended to provide an appropriate level of protection consistent with POPIA requirements.
7. Retention
Information is retained while an account or workspace is active and thereafter only as reasonably necessary for data export, dispute resolution, security, backups, legal obligations and legitimate operational records. Different categories may have different statutory or contractual retention periods.
Deletion does not always remove information immediately from encrypted backups; backup copies are isolated from ordinary use and expire through the backup lifecycle. Records required by law or for the establishment, exercise or defence of legal claims may be retained for the applicable period.
8. Security
Safeguards include encrypted transport, managed infrastructure, organisation-scoped access rules, role controls, private document storage, signed and expiring document links, password controls, audit records, restricted service credentials and security monitoring. Access is limited to people and systems that need it for authorised purposes.
No system is immune from risk. Users must protect credentials, keep devices secure, assign roles carefully and report suspected compromises promptly through Support.
9. Your rights
Subject to applicable law and verification, a data subject may request:
- confirmation of whether personal information is held and access to it;
- correction or deletion of inaccurate, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- objection to certain processing or withdrawal of consent where consent is relied on;
- information about the source, recipients and purpose of processing;
- review of a decision based solely on automated processing where applicable;
- a complaint to the Information Regulator.
Submit a request through the Data Rights Centre. We may require identity and authority verification and may refuse or limit a request where the law permits or requires it.
10. Children and special personal information
The service is intended for business users aged 18 or older. Do not use it to process children’s information, health information, biometric information, criminal-behaviour information or other special personal information unless the business has a lawful basis, necessary authorisation and safeguards appropriate to the risk.
11. Marketing and communications
Transactional messages about authentication, security, billing, support and material service changes are necessary to operate the account. Marketing communications, when introduced, will include a practical opt-out and will be sent only where permitted.
12. Complaints and contact
Privacy questions and rights requests should first be sent through the Data Rights Centre. The operator’s configured privacy email is available through the Support request channel.
A data subject may also lodge a complaint with the Information Regulator (South Africa). Contact information and complaint services are available on the Regulator’s official website.
13. Changes to this notice
We may update this notice when the service, providers or law changes. Material changes will be communicated through the service or registered email address, and the effective date will be updated.