POPIA & DATA PROTECTION NOTICE

Effective Date: 25 August 2026
Last Updated: 25 August 2026

1. Introduction

MemberSure, a product of BOMANDA GENERAL TRADING (Pty) Ltd, respects the privacy and protection of personal information.

MemberSure provides cloud-based software designed to help funeral parlours manage members, funeral policies, premium payment records, beneficiaries, receipts, reports and related business administration.

This POPIA & Data Protection Notice explains how personal information may be processed when using the MemberSure platform and website.

MemberSure is committed to processing personal information responsibly and in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA) and other applicable South African laws.

POPIA establishes minimum requirements for the lawful processing of personal information by public and private bodies.


2. Who Is Responsible for the Personal Information?

When a funeral parlour uses MemberSure to manage its members and customers, the funeral parlour generally determines why and how its members’ personal information is collected and used.

For purposes of POPIA, the funeral parlour will generally act as the Responsible Party, while MemberSure may act as an Operator when processing personal information on the funeral parlour’s behalf in order to provide the software services.

An Operator must process personal information only with the knowledge or authorisation of the Responsible Party and must treat information obtained through its services as confidential.


3. Information That May Be Processed

Depending on how the MemberSure platform is used, information may include:

  • Member names and surnames

  • Contact details

  • Identification or other identifying information

  • Residential or postal information

  • Funeral policy information

  • Premium payment records

  • Beneficiary and dependant information

  • Policy and membership dates

  • Account and transaction information

  • Documents uploaded by the funeral parlour

  • User account information

  • Information required to provide support and maintain the platform

The specific information processed will depend on the funeral parlour’s use of the MemberSure platform.


4. Why Personal Information Is Processed

Personal information may be processed to provide and operate the MemberSure services, including:

  • Creating and managing member records

  • Managing funeral policy information

  • Recording and tracking premium payments

  • Generating receipts

  • Managing beneficiaries and dependants

  • Producing reports

  • Managing user accounts

  • Providing technical and customer support

  • Maintaining and improving the platform

  • Protecting the security and integrity of the platform

  • Complying with legal and regulatory obligations

MemberSure will not use Customer Data for unrelated purposes without appropriate authorisation or a lawful basis.


5. Customer Data

The funeral parlour remains responsible for the personal information it captures and manages through its MemberSure account.

The funeral parlour is responsible for ensuring that it has a lawful basis for collecting and processing the personal information of its members, beneficiaries, dependants and other individuals.

The funeral parlour should ensure that the information it captures is accurate, relevant and kept up to date.

MemberSure does not claim ownership of Customer Data.


6. MemberSure’s Role as a Technology Provider

MemberSure provides the technology and infrastructure used by funeral parlours to manage their information.

Where MemberSure processes personal information on behalf of a funeral parlour, MemberSure will:

  • Process information for the purposes of providing the contracted services.

  • Treat Customer Data as confidential.

  • Apply reasonable measures designed to protect personal information.

  • Limit access to authorised persons where appropriate.

  • Assist the Customer where reasonably required in relation to personal information processed through the platform.

  • Take appropriate action where a suspected security compromise is identified.

The Information Regulator’s guidance states that Operators should implement measures to protect confidentiality and integrity and should notify the Responsible Party where there are reasonable grounds to believe that a compromise has occurred.


7. Security of Personal Information

MemberSure takes reasonable measures to protect personal information against unauthorised access, loss, damage, destruction or unlawful processing.

Security measures may include appropriate technical and organisational controls, access management and other safeguards appropriate to the nature of the information and the risks involved.

No internet-based system can be guaranteed to be completely secure. MemberSure therefore cannot guarantee that unauthorised access, cyber incidents or other security events will never occur.

POPIA requires appropriate and reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised destruction, unlawful access or processing.


8. Passwords and User Access

Each funeral parlour is responsible for managing its authorised users and protecting its login credentials.

Users should:

  • Keep passwords confidential.

  • Never share passwords with unauthorised persons.

  • Use strong passwords.

  • Notify MemberSure if they believe an account has been compromised.

  • Remove access for employees or users who are no longer authorised to use the system.

The funeral parlour remains responsible for activities performed through its authorised user accounts, subject to applicable law.


9. Data Accuracy

The funeral parlour is responsible for ensuring that information entered into MemberSure is accurate and kept up to date.

MemberSure will not be responsible for losses or disputes resulting from incorrect information, inaccurate member records, incorrect payment information or accidental changes or deletion made by the Customer or its authorised users.


10. Data Retention

When a funeral parlour’s MemberSure subscription ends, Customer Data may be retained for 60 days, subject to the terms of the Customer’s agreement with MemberSure.

This retention period allows the Customer an opportunity to request an export of its information before the applicable data is permanently deleted.

The Customer should request any required data export before the end of the retention period.


11. Data Export

Following cancellation of the MemberSure service, the Customer may request one free export of its Customer Data within the applicable 60-day retention period.

The export may be provided in an appropriate electronic format, such as CSV or Excel, depending on the type of information being exported.

Additional or specialised data extraction services may be subject to reasonable charges where applicable.


12. Third-Party Service Providers

MemberSure may use reputable third-party technology and infrastructure providers where necessary to operate and maintain the platform.

Such providers may include services relating to:

  • Cloud hosting

  • Data storage

  • Email

  • Messaging

  • System monitoring

  • Security

  • Technical infrastructure

  • Other services required to operate the platform

Where third parties process personal information on behalf of MemberSure or the Customer, appropriate contractual and security considerations will be applied.

MemberSure will not knowingly permit a service provider to process Customer Data for purposes unrelated to providing the relevant service without appropriate authorisation or a lawful basis.


13. International Processing

Depending on the technology providers used by MemberSure, personal information may potentially be processed or stored outside South Africa.

Where cross-border transfers of personal information are applicable, MemberSure will take reasonable steps to ensure that the processing is undertaken in accordance with applicable POPIA requirements.

Certain transfers of personal information outside South Africa may be subject to specific POPIA requirements and protections. Where applicable, these requirements will be considered before information is transferred.


14. Data Breach and Security Compromise

If MemberSure becomes aware of a suspected or confirmed security compromise affecting personal information processed on behalf of a Customer, MemberSure will take reasonable steps to investigate and respond to the incident.

Where MemberSure is acting as an Operator, it will notify the relevant Customer as required by the applicable agreement and POPIA.

The Responsible Party remains responsible for fulfilling its statutory obligations regarding notification of security compromises to the Information Regulator and affected data subjects where required.

The Information Regulator’s guidance states that an Operator should notify the Responsible Party immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.


15. Your Privacy Rights

Under POPIA, individuals may have rights relating to their personal information, including rights concerning:

  • Access to personal information

  • Correction of inaccurate information

  • Updating personal information

  • Objection to certain processing

  • Complaints regarding the processing of personal information

The exact rights and applicable procedures depend on the circumstances and the requirements of POPIA.

The Information Regulator identifies access, correction and objection to processing among the privacy rights recognised under POPIA.


16. Requests Concerning Member Information

Because funeral parlours generally determine the purpose and means of processing their members’ information, requests relating to a member’s personal information should normally first be directed to the relevant funeral parlour.

MemberSure may assist the funeral parlour where reasonably required and where permitted by law and the applicable service agreement.


17. Privacy of the MemberSure Website

When visitors use the MemberSure website, certain information may be collected automatically or provided voluntarily, such as:

  • Name

  • Email address

  • Telephone number

  • Funeral parlour name

  • Information submitted through contact or demo forms

  • Technical information required for website operation

  • Information relating to website usage where applicable

This information may be used to:

  • Respond to enquiries

  • Arrange demonstrations

  • Communicate with prospective customers

  • Provide requested information

  • Improve the website

  • Maintain website security

  • Meet legal obligations

MemberSure will not sell personal information to third parties.


18. Marketing Communications

Where MemberSure sends marketing communications, it will do so in accordance with applicable laws.

Recipients may request that marketing communications stop, subject to applicable legal requirements.


19. Children’s Information

The MemberSure platform is intended primarily for use by funeral parlours and their authorised personnel.

Funeral parlours must ensure that any information relating to children is collected and processed lawfully and in accordance with POPIA.

Where the processing of children’s information is subject to additional legal requirements, the responsible party must ensure that those requirements are met.


20. Changes to This Notice

MemberSure may update this POPIA & Data Protection Notice from time to time to reflect:

  • Changes to the MemberSure platform

  • Changes to technology

  • Changes to applicable laws

  • Changes to third-party services

  • Improvements to privacy and security practices

The latest version will be published on the MemberSure website.


21. Contact MemberSure

If you have questions regarding this notice, the MemberSure platform or the processing of personal information, please contact us.

BOMANDA GENERAL TRADING (Pty) Ltd
Trading as MemberSure

Email: inquiry@membersure.co.za
Telephone: 062 510 5916
Website: https://membersure.co.za

For privacy-related requests concerning information held by a funeral parlour, individuals should also contact the relevant funeral parlour directly.


22. Information Regulator

The South African Information Regulator is responsible for monitoring and enforcing compliance with POPIA and PAIA.

Information about POPIA, privacy rights, complaints and security compromises is available through the Information Regulator.

Information Regulator of South Africa

Information Regulator – Official Website

Information Regulator eServices Portal


MemberSure Privacy Commitment

Your data. Your business. Your trust.

MemberSure is committed to helping South African funeral parlours move from paper-based administration to a more organised, secure and digitally connected way of managing their businesses.