Legal

Privacy notice

Last updated: 20 July 2026

BeeLevel is operated by Aurion Creative ("we", "us"). This notice explains what personal information we process, why, and the rights you have under the Protection of Personal Information Act, 4 of 2013 (POPIA). It covers both this website and the BeeLevel platform.

Information we collect on this website

  • Contact form submissions: your name, work email address, company (optional), and your message. We use these solely to respond to your enquiry and to follow up on it. They are not used for marketing lists and are not shared with third parties.
  • Technical basics: standard server logs (IP address, user agent, pages requested) kept for security and troubleshooting. This site does not use advertising trackers.

Information processed in the platform

The platform processes information about beneficiary businesses and their contact people on behalf of the corporate client running the ESD programme. In POPIA terms, the corporate client is the responsible party for its programme data and BeeLevel is the operator processing it under agreement. That information includes business registration details, B-BBEE compliance documents, contact details of beneficiary representatives, programme spend records, and contact history.

How the platform is built for POPIA

  • Tenant isolation. Every query is scoped to the corporate tenant it belongs to. Beneficiary personal information is never visible outside that tenant, and beneficiary users see only their own business.
  • Scoped operator access with provenance. Capture agents see only beneficiaries covered by an explicit assignment, and every record they enter permanently records who entered it and on whose behalf.
  • Role-based access. Capabilities are defined centrally and enforced in every page, action, and file download route.
  • Immutable audit trail. The audit log is append-only. Approved financial records cannot be edited, only corrected by visible reversal entries.
  • Private file serving. Uploaded documents and evidence are served only through authenticated, tenant-checked routes, never from a public directory, and are marked not to be cached.
  • Minimal collection. Only fields needed for ESD programme administration and B-BBEE verification are modelled. Deleted records are archived rather than destroyed immediately, preserving the audit trail, and are removed from all listings and reports.

Retention

Contact form messages are kept for as long as the enquiry is live and then archived. Platform data is retained for the duration of the client agreement and thereafter per the retention schedule agreed with the responsible party, after which records are destroyed or anonymised.

Security

Traffic is encrypted in transit. Access to production systems is limited to authorised operators. Passwords are stored only as salted hashes. Infrastructure access and application activity are logged.

Your rights

Under sections 23 to 25 of POPIA you may request access to, correction of, or deletion of personal information we hold about you. Beneficiary contact people may route requests through the corporate running their programme or directly to us. Write to support@beelevel.co.zawith the subject line "Data subject request" and we will respond within a reasonable time, verifying identity before acting. You may also lodge a complaint with the Information Regulator of South Africa.

Contact

Privacy questions: support@beelevel.co.za. We will update this notice when our practices change, and the date at the top reflects the latest revision.