> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bumara.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> How your data is protected, what you control, and the habits that keep your account safe.

Bumara holds employee bank details, salary figures, identification numbers and regulator
credentials. This page covers what is done to protect that and what you are responsible for.

## What Bumara does

| Protection                 | Applies to                                                                  |
| -------------------------- | --------------------------------------------------------------------------- |
| **Encryption at rest**     | Sensitive fields — NRC, passport, TPIN, bank details, regulator credentials |
| **Encryption in transit**  | Everything, between your device and Bumara                                  |
| **Role-based access**      | Every screen and every field. See [Team and roles](/account/team-and-roles) |
| **Organisation isolation** | Data never crosses between organisations                                    |
| **Audit logging**          | Every change, with who and when                                             |
| **Immutable records**      | Timelines, evidence links and comments cannot be edited after creation      |

## Regulator credentials

If you supply credentials so Bumara can review your position at a regulator, they are held using
layered encryption — the credentials themselves are encrypted with a key that is separately
encrypted, and the keys can be rotated without re-entering your details.

Access is limited to the specific work you have asked for, and every use is logged.

<Note>
  You are never required to supply regulator credentials. You can provide statements and notices
  yourself instead. That regulator's review will simply take longer.
</Note>

## What you control

| Control                                  | Where                      |
| ---------------------------------------- | -------------------------- |
| Who has access, and at what level        | Settings → Team            |
| Who can see salaries and identification  | Through role assignment    |
| Which locations each person sees         | Location assignments       |
| Whether regulator credentials are stored | Your choice, per regulator |
| Your own password                        | Settings → Profile         |
| Where notifications are sent             | Settings → Notifications   |

## The audit trail

Every meaningful action is recorded: who did it, what changed, and when. This covers status
changes, submissions, payments, document uploads, comments and assignments.

Records cannot be edited or deleted, by you or by Bumara. Corrections appear as further entries.

This is not only a security feature. It is what lets you answer "was this actually filed", "who
approved these figures", and "when did we pay" — the questions that come up under pressure.

## Your responsibilities

<AccordionGroup>
  <Accordion title="Use a unique password">
    Not one you use anywhere else. A reused password means a breach elsewhere becomes a breach here.
  </Accordion>

  <Accordion title="Never share a login">
    Invite the person properly. Shared logins destroy the audit trail — you cannot tell who did
    what — and they cannot be revoked for one person without locking out the others.
  </Accordion>

  <Accordion title="Remove leavers the same day">
    Not at the end of the month. A former employee with live access is the commonest security gap
    in any business.
  </Accordion>

  <Accordion title="Give the narrowest role that works">
    Widening access takes ten seconds when someone asks. Narrowing it after they have seen
    something is not possible.
  </Accordion>

  <Accordion title="Sign out on shared devices">
    Particularly on a shop-floor device used by several people.
  </Accordion>

  <Accordion title="Review access quarterly">
    Who is in the list, and whether their role still matches what they do.
  </Accordion>
</AccordionGroup>

## Handling employee data

Payroll data is the most sensitive thing in your account.

| Rule                                           | Why                                                 |
| ---------------------------------------------- | --------------------------------------------------- |
| Payslips go only to the employee               | Salary is confidential between you and them         |
| Never attach several payslips to one email     | The commonest way salaries leak                     |
| Do not discuss one employee's pay with another | Including managers, unless it is their own team     |
| Printed payslips go in sealed envelopes        | Not left on a desk                                  |
| Do not export employee data without a reason   | And delete the export when you are finished with it |
| Verify email addresses before bulk sending     | Once sent, it cannot be recalled                    |

## Exported data

An export leaves Bumara's protection. A spreadsheet of employee bank details on a laptop is
protected by that laptop, not by Bumara.

<Steps>
  <Step title="Export only when you actually need to">
    Not routinely, and not "just in case".
  </Step>

  <Step title="Store it somewhere controlled">
    Not a personal device, and not a shared drive everyone can open.
  </Step>

  <Step title="Delete it when you are finished">
    Including from your downloads folder.
  </Step>

  <Step title="Never email it unencrypted">
    Particularly anything containing bank details or identification numbers.
  </Step>
</Steps>

## If something goes wrong

<Steps>
  <Step title="Change your password immediately">
    If you think it has been seen or guessed.
  </Step>

  <Step title="Review your team list">
    Remove anyone who should not be there.
  </Step>

  <Step title="Check the audit trail">
    Look for actions you do not recognise.
  </Step>

  <Step title="Contact support">
    Through Settings, with what you have found.
  </Step>

  <Step title="Consider what may have been seen">
    If employee data was exposed, you may have obligations to those employees.
  </Step>
</Steps>

## Data retention

Your data is retained while your account is active. Records are kept because Zambian regulators
expect them to be — deleting a filing you made two years ago would leave you unable to evidence
compliance.

Retention after account closure follows your agreement. Export what you need before closing. See
[Organisation settings](/account/organisation-settings).

## Privacy between organisations

If your login belongs to more than one organisation — as a consultant's often does — the separation
is absolute. Nothing you can see in one is visible from another, and switching organisations
switches everything.

<Warning>
  Check the organisation switcher before acting. Posting a client's payroll into the wrong
  organisation is not a security breach, but unwinding it is unpleasant.
</Warning>

<Note>
  Related: [Team and roles](/account/team-and-roles) and
  [Create your account](/start/create-your-account).
</Note>
