Skip to main content
Bumara holds employee bank details, salary figures, identification numbers and regulator credentials. This page covers what is done to protect that and what you are responsible for.

What Bumara does

Regulator credentials

If you supply credentials so Bumara can review your position at a regulator, they are held using layered encryption — the credentials themselves are encrypted with a key that is separately encrypted, and the keys can be rotated without re-entering your details. Access is limited to the specific work you have asked for, and every use is logged.
You are never required to supply regulator credentials. You can provide statements and notices yourself instead. That regulator’s review will simply take longer.

What you control

The audit trail

Every meaningful action is recorded: who did it, what changed, and when. This covers status changes, submissions, payments, document uploads, comments and assignments. Records cannot be edited or deleted, by you or by Bumara. Corrections appear as further entries. This is not only a security feature. It is what lets you answer “was this actually filed”, “who approved these figures”, and “when did we pay” — the questions that come up under pressure.

Your responsibilities

Not one you use anywhere else. A reused password means a breach elsewhere becomes a breach here.
Invite the person properly. Shared logins destroy the audit trail — you cannot tell who did what — and they cannot be revoked for one person without locking out the others.
Not at the end of the month. A former employee with live access is the commonest security gap in any business.
Widening access takes ten seconds when someone asks. Narrowing it after they have seen something is not possible.
Particularly on a shop-floor device used by several people.
Who is in the list, and whether their role still matches what they do.

Handling employee data

Payroll data is the most sensitive thing in your account.

Exported data

An export leaves Bumara’s protection. A spreadsheet of employee bank details on a laptop is protected by that laptop, not by Bumara.
1

Export only when you actually need to

Not routinely, and not “just in case”.
2

Store it somewhere controlled

Not a personal device, and not a shared drive everyone can open.
3

Delete it when you are finished

Including from your downloads folder.
4

Never email it unencrypted

Particularly anything containing bank details or identification numbers.

If something goes wrong

1

Change your password immediately

If you think it has been seen or guessed.
2

Review your team list

Remove anyone who should not be there.
3

Check the audit trail

Look for actions you do not recognise.
4

Contact support

Through Settings, with what you have found.
5

Consider what may have been seen

If employee data was exposed, you may have obligations to those employees.

Data retention

Your data is retained while your account is active. Records are kept because Zambian regulators expect them to be — deleting a filing you made two years ago would leave you unable to evidence compliance. Retention after account closure follows your agreement. Export what you need before closing. See Organisation settings.

Privacy between organisations

If your login belongs to more than one organisation — as a consultant’s often does — the separation is absolute. Nothing you can see in one is visible from another, and switching organisations switches everything.
Check the organisation switcher before acting. Posting a client’s payroll into the wrong organisation is not a security breach, but unwinding it is unpleasant.
Last modified on August 4, 2026