Skip to content
brown & ferguson Advisory
Legal

Privacy Policy

Brown and Ferguson Advisory (Pty) Ltd
Registration number 2013/167618/07

Last updated: 29 July 2026

1. Introduction

Brown and Ferguson Advisory (Pty) Ltd ("Brown & Ferguson", "we", "us", "our") is committed to protecting the privacy and personal information of the people we deal with. This policy explains how we collect, use, share, store and protect personal information, and the rights you have in relation to that information, in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA").

This policy applies to personal information we process through this website and in the ordinary course of providing our accounting, tax, audit, secretarial and advisory services.

We are the responsible party (as defined in POPIA) in respect of the personal information described in this policy.

2. Information We Collect

We collect personal information in several ways: directly from you, in the course of providing professional services, and automatically when you use our website.

Information you provide directly, for example through our contact form, quote builder, client onboarding process, or when you correspond with us:

  • Identifying information such as your name, and where applicable your identity or passport number and tax reference number
  • Contact details such as your email address, telephone number and physical or postal address
  • Business information such as your company name, registration number, role, and the nature of your enquiry
  • Any other information you choose to provide to us

Information we process in providing professional services, which may include financial records, accounting data, payroll information, tax information, and information relating to third parties (such as your employees, directors, or beneficiaries) that you provide to us to enable us to perform our engagement.

Information collected automatically when you visit our website, such as your IP address, browser type, pages visited, and similar technical data collected through cookies and analytics (see section 10).

3. Why We Collect It (Purpose)

We collect and process personal information for the following purposes:

  • To respond to enquiries and provide information you request
  • To provide quotations and onboard you as a client
  • To render the accounting, tax, audit, company secretarial and advisory services we are engaged to perform
  • To comply with our legal, regulatory and professional obligations (including those under the Companies Act, Tax Administration Act, Auditing Profession Act, and the rules of IRBA and SAICA)
  • To communicate with you about our services and matters relating to your engagement
  • To maintain our business records and manage our client relationships
  • To improve our website and services

4. Lawful Basis for Processing

We process personal information on one or more of the following lawful bases recognised under POPIA:

  • With your consent
  • Where processing is necessary to conclude or perform a contract with you
  • Where processing is necessary to comply with a legal obligation imposed on us
  • Where processing is necessary to pursue our legitimate interests or those of a third party to whom the information is supplied, provided these are not overridden by your rights

5. How We Use It

We use personal information only for the purposes set out in this policy, or for a purpose directly related to those, or where you would reasonably expect us to use it in that way. We do not sell personal information.

6. Who We Share It With

We may share personal information with:

  • Service providers (operators) who process information on our behalf under a written agreement requiring them to protect it, including our software providers (such as our accounting, payroll and practice-management platforms), our IT and hosting providers, and our email provider
  • Regulatory and statutory bodies where we are required or permitted to do so by law, including the South African Revenue Service (SARS), the Companies and Intellectual Property Commission (CIPC), the Independent Regulatory Board for Auditors (IRBA), and the Information Regulator
  • Professional advisors where necessary
  • Third parties with your consent or at your instruction

Some of our service providers may process or store information outside South Africa. Where personal information is transferred across borders, we take reasonable steps to ensure it receives a level of protection consistent with POPIA.

7. Data Security

We take appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information in our possession and to protect it against loss, damage, unauthorised access and unlawful processing. These measures include restricting access to personal information to those who need it, hosting and processing information with reputable service providers, and requiring our staff to keep information confidential. No method of transmission or storage is completely secure, and while we strive to protect your information we cannot guarantee absolute security.

8. Your Rights Under POPIA

You have the right to:

  • Request access to the personal information we hold about you
  • Request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained
  • Object, on reasonable grounds, to the processing of your personal information
  • Withdraw consent where processing is based on consent (subject to legal or contractual restrictions)
  • Lodge a complaint with the Information Regulator

To exercise any of these rights, contact us using the details in section 11. Some information may be subject to retention obligations that limit our ability to delete it (see section 9).

9. Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Certain records are subject to statutory minimum retention periods — for example, accounting and company records under the Companies Act 71 of 2008, and records required under the Tax Administration Act 28 of 2011 — which we observe. When information is no longer required, we securely destroy or de-identify it.

10. Cookies

Our website uses cookies. Strictly necessary cookies are required for the site to function. We may also use analytics or performance cookies to understand how visitors use the site. Non-essential cookies are only set with your consent, which you can give or decline through the cookie banner when you first visit, and change at any time through your browser settings.

11. Information Officer and Contact

The Information Officer for Brown and Ferguson Advisory (Pty) Ltd is Taryn Brown.

You may contact us regarding this policy, your personal information, or to exercise your rights, at:

Email: info@brownandferguson.co.za
Telephone: +27 (0)10 590 1058
Address: Block B, 1st Floor, Infinity Office Park, 4 Pieter Wenning Road, Fourways, Johannesburg

You also have the right to lodge a complaint with the Information Regulator:

Information Regulator (South Africa)
Email: POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za

12. Changes to This Policy

We may update this policy from time to time. The current version, with its "last updated" date, is always available on our website.