Legal & Compliance
Privacy Policy
This policy explains how BME Software Ltd collects, uses, stores and protects personal data when you visit businessmanerp.com, contact our team, request a demonstration, or use Business Manager Enterprise. It covers both our website and the accounts we operate for our customers.
We never sell your data
Personal data is never sold, rented or traded. We share it only with the providers that help us run the service.
Your BME data stays yours
Inside Business Manager Enterprise your organisation is the controller. We act only as a processor on your instructions.
Encrypted and access-controlled
Data is encrypted in transit and at rest, with role-based access, multi-factor admin sign-in and full audit logging.
You stay in control
Access, correct, export or delete your data at any time. We respond to every request within one month.
Who is responsible for your personal data?
BME Software Ltd is the data controller for personal data collected through this website and for the account records we hold about our customers.
We are registered in [England and Wales] under company number [00000000], with our registered office at [Full registered address, City, Postcode, United Kingdom]. We are registered with the Information Commissioner's Office (ICO) under registration number [ZA000000]. Our United States operations are conducted by [US entity name] and are covered by this same policy.
For any question about how we use your data, contact our data protection contact at [privacy@businessmanerp.com].
What personal data do we collect?
We collect three categories of personal data: information you give us directly, information collected automatically as you use the website, and information we receive from third parties.
Information you provide directly
- Contact and enquiry details — name, business email address, telephone number, company name, job role, and the content of your message when you complete a contact form, request a demonstration, or ask for a quotation.
- Account details — username, password (stored in hashed form), user permissions, and profile information created when a Business Manager Enterprise account is set up for you.
- Billing details — billing contact, billing address, VAT or tax registration number, purchase order references, and subscription or licence details. Card details are handled by our payment provider and are not stored on our systems.
- Support records — the content of support tickets, emails, call notes, and any files or screenshots you send to our support team.
- Recruitment data — CVs, cover letters and application details, if you apply for a role with us.
Information collected automatically
- Device and connection data — IP address, browser type and version, operating system, device type, and screen resolution.
- Usage data — pages viewed, referring URL, time spent on pages, links clicked, and the date and time of each visit.
- Application logs — sign-in events, IP address, and system actions recorded for security and audit purposes within Business Manager Enterprise.
- Cookie data — identifiers set by essential, functional, analytics and marketing cookies, as described in section 5.
Information from third parties
- Business contact data from publicly available sources such as company websites, Companies House and professional networks, used to verify business enquiries.
- Referral and partner data where a reseller, implementation partner or existing customer introduces you to us.
- Analytics and advertising data from providers such as [Google Analytics, LinkedIn, Microsoft Advertising], in aggregated or pseudonymised form.
We do not intentionally collect special category data — such as health, biometric, religious or political data — through this website. Please do not include such information in enquiry forms or support messages.
Why do we process your personal data?
We process personal data only where we have a lawful basis to do so under the UK GDPR and EU GDPR. The table below sets out each purpose and the basis we rely on.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Responding to enquiries and demonstration requests | Contact and enquiry details | Legitimate interests — replying to a request you initiated |
| Providing, hosting and supporting Business Manager Enterprise | Account, billing and support data | Performance of a contract |
| Processing payments, invoicing and credit control | Billing details | Performance of a contract; legal obligation |
| Maintaining statutory accounting and tax records | Billing and contract data | Legal obligation |
| Securing our systems, preventing fraud and investigating misuse | Device data, application logs | Legitimate interests — protecting our service and customers |
| Improving the website, product and user experience | Usage and analytics data | Consent (analytics cookies); legitimate interests |
| Sending marketing communications about our software | Contact details | Consent, or legitimate interests for existing business customers |
| Managing recruitment applications | Recruitment data | Steps prior to entering a contract; legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. You can object to this processing at any time using the contact details in section 15.
How do we handle data inside Business Manager Enterprise?
When you use Business Manager Enterprise, your organisation is the data controller for the data it enters into the system and BME Software Ltd acts as a data processor.
This includes records about your customers, suppliers, employees, orders, stock and accounts held in the CRM, ERP, MRP, inventory and accounting modules. As a processor, we only handle that data on your documented instructions and under the terms of our Data Processing Agreement. Specifically, we:
- process customer data solely to deliver, host, support and maintain the platform;
- do not sell customer data or use it to train third-party artificial intelligence models;
- apply the security measures set out in section 9 and impose equivalent obligations on our sub-processors;
- assist you in responding to data subject requests and reportable personal data breaches;
- return or delete customer data at the end of the contract, in line with section 8.
If you are an individual whose data is held in a customer's Business Manager Enterprise system, contact that organisation directly to exercise your rights. We will refer such requests to the relevant customer.
A copy of our Data Processing Agreement is available on request from [privacy@businessmanerp.com].
Do we use cookies and tracking technologies?
Yes. We use cookies and similar technologies on businessmanerp.com.
Cookies are small text files stored on your device that allow the site to function correctly and help us understand how it is used.
| Cookie type | What it does | Consent required |
|---|---|---|
| Strictly necessary | Enables core functions such as page navigation, session management, form submission and security. | No |
| Functional | Remembers preferences such as your language, region and currency selection. | Yes |
| Analytics | Measures traffic, page performance and how visitors move through the site. | Yes |
| Marketing | Measures campaign performance and supports remarketing on third-party platforms. | Yes |
Non-essential cookies are only set after you give consent through our cookie banner. You can change or withdraw your consent at any time via [cookie settings link], and you can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the site from working.
Who do we share your personal data with?
We share personal data only with organisations that help us operate our business, and only to the extent necessary. We do not sell personal data.
- Professional advisers — accountants, auditors, insurers and legal advisers, where required.
- Authorities and regulators — where disclosure is required by law, court order, or to establish or defend legal claims.
- Acquirers — if our business, or part of it, is sold or reorganised, personal data may transfer to the acquiring entity under equivalent protections.
Each provider acting on our behalf is bound by a written contract requiring appropriate security measures and prohibiting any use of the data for their own purposes.
Where is your data stored and transferred?
Personal data is primarily stored on servers located in [the United Kingdom / the European Economic Area].
Some of our service providers process data in the United States and other countries outside the UK and EEA. Where personal data leaves the UK or EEA, we protect it using one or more of the following safeguards:
- an adequacy decision or UK adequacy regulations covering the destination country;
- the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum;
- a documented transfer risk assessment together with supplementary technical measures such as encryption in transit and at rest.
You can request details of the safeguards applied to a specific transfer by contacting us.
How long do we keep your personal data?
We keep personal data only for as long as it is needed for the purpose it was collected, or for as long as the law requires.
| Record type | Retention period |
|---|---|
| Website enquiries that do not become customers | [24] months from last contact |
| Customer account and contract records | Duration of the contract plus [6] years |
| Invoices and accounting records | [6] years from the end of the relevant financial year |
| Support tickets and correspondence | [36] months from closure |
| Customer data held in the platform | Deleted or returned within [30] days of contract termination, unless you request otherwise |
| Marketing subscriber records | Until you unsubscribe, plus a suppression record kept indefinitely |
| Unsuccessful job applications | [12] months from the decision |
| Server and security logs | [12] months |
Backups containing deleted data are overwritten on a rolling [30]-day cycle.
How do we keep your personal data secure?
We apply technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration and disclosure.
- Encryption of data in transit using TLS, and encryption at rest for stored data and backups.
- Role-based access controls, unique user accounts and enforced password policies within the platform.
- Multi-factor authentication for administrative access to our systems.
- Regular patching, vulnerability scanning and [annual penetration testing].
- Logging and monitoring of access to production environments.
- Staff confidentiality obligations and data protection training.
- Documented backup, disaster recovery and incident response procedures.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and inform affected individuals and customers without undue delay.
What are your data protection rights?
Under the UK GDPR and EU GDPR you have the following rights over your personal data.
Access
Obtain confirmation that we process your data and receive a copy of it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure
Request deletion where there is no continuing lawful reason to keep it.
Restriction
Ask us to pause processing while a concern is investigated.
Portability
Receive data you provided in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests, and to direct marketing at any time.
Withdraw consent
Withdraw consent where we rely on it, without affecting earlier processing.
Automated decisions
We do not make legally significant decisions using automated processing alone.
To exercise any right, email [privacy@businessmanerp.com]. We respond within one month and may ask for proof of identity before releasing information. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
What rights do United States residents have?
Residents of California and other states with comprehensive privacy laws have additional rights over their personal information.
Where those laws apply, you may request to know what personal information we collect and disclose, request its correction or deletion, and opt out of any sale or sharing of personal information.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act. We will not discriminate against you for exercising any privacy right. To make a request, use the contact details in section 15 and state the state law you are relying on. An authorised agent may submit a request on your behalf with written proof of authorisation.
How do you opt out of marketing communications?
You can opt out of marketing at any time by clicking the unsubscribe link in any marketing email, or by emailing [privacy@businessmanerp.com].
We action opt-out requests within [5] working days. We only send marketing emails where you have consented, or where you are an existing business customer receiving information about similar products.
Opting out of marketing does not stop service messages such as invoices, security notices, maintenance windows and product release notes, which are necessary to operate your account.
Do we collect data from children?
No. Business Manager Enterprise and this website are intended for business use by adults, and we do not knowingly collect personal data from anyone under 16.
If you believe a child has provided us with personal data, contact us and we will delete it.
How do we update this policy?
We review this Privacy Policy at least annually and update it whenever our processing activities, service providers or legal obligations change.
The current version and its effective date are shown at the top of this page. Where a change materially affects how we use your personal data, we will notify you by email or through a notice on the website before it takes effect. We recommend reviewing this page periodically.
How do you contact us or make a complaint?
Contact us with any privacy question, data subject request or complaint using the details below. We aim to acknowledge every enquiry within [5] working days.
2 Bridge Court, Kingsmill Road, Saltash, Cornwall PL12 6LS
If you are not satisfied with our response, you have the right to complain to a supervisory authority. In the United Kingdom this is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk. If you are in the European Economic Area, you may complain to the supervisory authority in your country of residence.