Who controls your information
Bundlegridbase, at Level 9, 37 Aurora Drive, Umhlanga 4319, is the responsible party for personal information collected through this site and our audit engagements. Privacy questions may be sent to info@bundlegridbase.digital.
Information we collect
We collect contact details, enquiry content, service choices and correspondence. During an engagement we may process applicant identifiers, academic records, payment evidence, programme choices, portal screenshots and admissions correspondence. We ask clients not to provide passwords, full card numbers, unrelated bank transactions or information outside scope.
Why and on what basis we use it
We use information to respond to requests, quote and perform agreed services, reconcile records, manage payment, meet legal obligations, prevent misuse and maintain limited business records. Processing is based on contract, steps requested before contract, legal duties, consent where required and legitimate operational interests balanced against your rights.
Sharing and processors
Information is accessible only to people who need it for the engagement. We may use vetted hosting, secure file-transfer, email, accounting and professional-advisory providers under appropriate terms. We do not sell personal information or provide applicant records to universities unless you give specific authority.
Retention
Unaccepted enquiry messages are normally retained for 12 months. Working application files are normally deleted within 90 days after final handover; final reports and contractual records may be retained for five years where required for tax, legal and dispute purposes. A longer hold applies where law or an active dispute requires it.
International transfers
Some service providers may store or support data outside South Africa. Where this occurs, we use providers and safeguards intended to ensure an adequate level of protection, including contractual protections and transfer assessments where appropriate.
Your rights
Subject to applicable law, you may ask for access, correction, deletion, restriction or objection; withdraw consent where processing relies on it; and complain to South Africa’s Information Regulator. We may need to verify identity before acting. Some records cannot be deleted immediately where retention is legally required.
Security and incidents
We use access controls, limited collection, secure transfer arrangements and retention schedules proportionate to the records. No method is risk-free. If a breach creates a material risk, we will follow applicable notification duties.
Updates
We may revise this notice when our practices or law change. The effective wording appears on this page. Related browser-storage information is in our cookie notice.