What Bumara does
Regulator credentials
If you supply credentials so Bumara can review your position at a regulator, they are held using layered encryption — the credentials themselves are encrypted with a key that is separately encrypted, and the keys can be rotated without re-entering your details. Access is limited to the specific work you have asked for, and every use is logged.You are never required to supply regulator credentials. You can provide statements and notices
yourself instead. That regulator’s review will simply take longer.
What you control
The audit trail
Every meaningful action is recorded: who did it, what changed, and when. This covers status changes, submissions, payments, document uploads, comments and assignments. Records cannot be edited or deleted, by you or by Bumara. Corrections appear as further entries. This is not only a security feature. It is what lets you answer “was this actually filed”, “who approved these figures”, and “when did we pay” — the questions that come up under pressure.Your responsibilities
Use a unique password
Use a unique password
Not one you use anywhere else. A reused password means a breach elsewhere becomes a breach here.
Remove leavers the same day
Remove leavers the same day
Not at the end of the month. A former employee with live access is the commonest security gap
in any business.
Give the narrowest role that works
Give the narrowest role that works
Widening access takes ten seconds when someone asks. Narrowing it after they have seen
something is not possible.
Review access quarterly
Review access quarterly
Who is in the list, and whether their role still matches what they do.
Handling employee data
Payroll data is the most sensitive thing in your account.Exported data
An export leaves Bumara’s protection. A spreadsheet of employee bank details on a laptop is protected by that laptop, not by Bumara.1
Export only when you actually need to
Not routinely, and not “just in case”.
2
Store it somewhere controlled
Not a personal device, and not a shared drive everyone can open.
3
Delete it when you are finished
Including from your downloads folder.
4
Never email it unencrypted
Particularly anything containing bank details or identification numbers.
If something goes wrong
1
Change your password immediately
If you think it has been seen or guessed.
2
Review your team list
Remove anyone who should not be there.
3
Check the audit trail
Look for actions you do not recognise.
4
Contact support
Through Settings, with what you have found.
5
Consider what may have been seen
If employee data was exposed, you may have obligations to those employees.
Data retention
Your data is retained while your account is active. Records are kept because Zambian regulators expect them to be — deleting a filing you made two years ago would leave you unable to evidence compliance. Retention after account closure follows your agreement. Export what you need before closing. See Organisation settings.Privacy between organisations
If your login belongs to more than one organisation — as a consultant’s often does — the separation is absolute. Nothing you can see in one is visible from another, and switching organisations switches everything.Related: Team and roles and
Create your account.