Skip to main content
Bibeno

Bibeno product

Everything your team needs to run each sale.

Explore Bibeno’s point-of-sale, product, stock and reporting tools.

Software overviewSee what Bibeno includes.Point of saleTake orders and complete sales at the counter.Products & menusManage products, prices and selling options.Inventory managementTrack stock movement and complete stock takes.Backoffice & reportingManage access and review business performance.Download for WindowsInstall Bibeno on a supported device.
Bibeno product catalog interface.Inside BibenoSee the full Bibeno product.Explore

Made for independent businesses

Software that fits the way your business works.

See how Bibeno supports food-service and specialty retail teams.

Industries overviewSee which businesses Bibeno is built for.CafésManage orders, products, stock and daily reporting.Takeaways and quick-serviceKeep service fast and every order organised.Boutiques and specialty retailManage checkout, products and stock together.
A café team serving a customer at the counter.Find the right fitTell us how your business operates.Explore
Pricing

About Bibeno

A South African team focused on independent business.

Learn about Bibeno, how we help businesses get started and how to contact us.

About BibenoOur story, purpose and product principles.How we workSee what to expect from setup and rollout.Contact usSpeak to sales, support or our general team.Get startedTell us about your business and what you need.
A team of independent bakery operators working together.Meet BibenoBuilt locally. Supported by real people.Explore
Sign inBook a demo
Legal/Data Processing Agreement

Data Processing Agreement

The operator agreement governing customer-controlled personal information processed through Bibeno, including instructions, confidentiality, security, sub-operators, international transfers, data-subject assistance, security compromises, audit evidence, retention, return, and deletion.

Status: Effective 14 August 2026Version: 1.0.0Content hash: 9864b2dde6c994e8c476553e7c6e08c8f51f59415887842a91a146e6550b2fc5
1. Parties, scope, and priority0% read

On this page

Data Processing Agreement

  1. 1. Parties, scope, and priority
  2. 2. Definitions and legal roles
  3. 3. Customer instructions
  4. 4. Processing description
  5. 5. Customer obligations
  6. 6. Bibeno personnel and confidentiality
  7. 7. Security measures
  8. 8. Sub-operators
  9. 9. International processing and transfers
  10. 10. Data-subject and PAIA assistance
  11. 11. Security compromises
  12. 12. Risk assessment, prior authorisation, and consultation
  13. 13. Audit and compliance evidence
  14. 14. Government and third-party requests
  15. 15. Return, retention, legal holds, and deletion
  16. 16. Liability and term
  17. 17. Changes and contact

1. Parties, scope, and priority

In plain language: the customer decides the lawful purpose and instructions for personal information in its business records. Bibeno processes that information to provide and secure the service, must follow lawful documented instructions, and remains responsible for the operator duties described here. The customer cannot instruct Bibeno to do something unlawful, and neither party can transfer its own legal duties to the other by contract.

This Data Processing Agreement forms part of the Terms of Service or signed customer agreement whenever Bibeno processes personal information on behalf of the customer. The customer is the contracting business and Bibeno is the verified legal entity identified below.

BIBENO (PTY) LTD

2026/355321/07

If this agreement conflicts with a general service term about operator processing, this agreement controls. A signed order may add stricter lawful processing instructions. A commercial term does not override a mandatory POPIA safeguard or authorise processing that the customer itself may not lawfully instruct.

2. Definitions and legal roles

Personal information, processing, data subject, responsible party, operator, special personal information, child, competent person, record, and Information Regulator have the meanings given by POPIA and PAIA where those laws apply.

The customer is the responsible party for customer-controlled customer, loyalty, employee, supplier, transaction, product, marketing, support, merchant-storefront, online-order, fulfilment, and operational information because the customer determines the business purpose and essential means of that processing. Bibeno is the operator for that processing except where the approved processing schedule identifies an independent Bibeno purpose.

Bibeno is separately the responsible party for its own contracting, account administration, billing, supplier, platform security, fraud prevention, legal compliance, service communications, and direct relationship records. That separate processing is governed by the Privacy Notice rather than treated as an instruction under this agreement.

3. Customer instructions

The Terms, accepted order, enabled features, documented administrator configuration, support request, lawful API action, approved import, and written instruction together form the customer's documented instructions. Bibeno processes customer-controlled information only to provide, secure, maintain, support, back up, transmit, return, delete, or lawfully improve the instructed service.

Bibeno informs the customer if an instruction appears to violate applicable data-protection law and may pause only the affected processing while the parties clarify it. Bibeno may process without the customer's instruction where law requires it, but will notify the customer before doing so unless law prohibits notice.

The customer may not instruct Bibeno to process unsupported high-risk data, special personal information, children's information, payment-card data, criminal-allegation records, biometric templates, or data in an unapproved territory until the relevant feature, lawful ground, safeguards, prior authorisation, and contract schedule are approved.

4. Processing description

The subject matter is the hosted POS, Backoffice, device, support, billing-adjacent, merchant storefront, online catalogue, quote, order, fulfilment, payment-reference, refund, import, export, reporting, workforce, loyalty, marketing, inventory, and related functionality selected by the customer. Processing continues for the service term and the approved return, suspension, retention, legal-hold, backup, and deletion periods.

  • Data subjects may include customer owners, administrators, employees, applicants, users, storefront visitors, online-order customers and recipients, consumers, loyalty members, suppliers, contacts, support requesters, and people named in customer records.
  • Information may include identity and contact data, collection or delivery details, addresses where enabled, order items and options, requested fulfilment time, order notes, limited allergy or safety information where lawfully configured, account and role data, employee and attendance data, customer and loyalty data, product and supplier data, sales and payment references, messages and preferences, device and location context, support content, files, audit logs, and technical identifiers.
  • Operations may include collection, receipt, validation, import, organisation, storage, access, retrieval, display, calculation, transmission, export, restriction, reconciliation, backup, restoration, correction, aggregation, de-identification, legal hold, deletion, and destruction.
  • Purposes are limited to delivering the configured service, customer support, security, resilience, compliance assistance, transaction integrity, authorised reporting, and the other specific instructions in the accepted order.

5. Customer obligations

The customer remains accountable for the lawfulness, fairness, transparency, necessity, accuracy, and retention of its processing; the notices and choices provided to data subjects; the authority of its users; and the legality of each instruction.

  • Use only approved features and collect only information reasonably needed for a stated business purpose.
  • Maintain an appropriate lawful processing ground and any required consent, employee policy, direct-marketing evidence, competent-person authorisation, or prior authorisation.
  • Configure roles, branches, devices, integrations, exports, retention, messages, and administrator access appropriately and review them regularly.
  • Respond as responsible party to data subjects and regulators and promptly relay requests or incidents requiring Bibeno's assistance.
  • For a public storefront, publish the customer's own accurate supplier, privacy, consumer-term, price, fulfilment, cancellation, refund, complaint, and contact disclosures before live collection, and bind the active branch and policy version to the order evidence.
  • Do not invite end customers to place health histories, identity documents, card details, or other unnecessary high-risk information in free-text order, delivery, support, or profile fields.
  • Do not give Bibeno unlawful, contradictory, deceptive, or technically unsafe instructions.

6. Bibeno personnel and confidentiality

Bibeno permits customer-controlled information to be processed only by authorised personnel and approved sub-operators who need access for the instructed purpose. They are bound by enforceable confidentiality, acceptable-use, security, and post-access obligations and receive training proportionate to their role.

Production and support access is individually attributable, least-privilege, time- or purpose-scoped where practicable, authenticated, logged, reviewed, and revoked when no longer required. Personnel may not use customer-controlled information for personal purposes, undisclosed profiling, unrelated product development, marketing, or another customer's benefit.

7. Security measures

Bibeno establishes and maintains appropriate, reasonable technical and organisational measures to protect the integrity and confidentiality of customer-controlled information; identify reasonably foreseeable internal and external risks; establish safeguards; verify their effective implementation; and update them as risks or deficiencies change.

The published Security Measures Schedule describes the customer-facing baseline. It includes identity and access management, tenant and branch isolation, secure development, vulnerability and dependency management, encryption and secret handling, logging and evidence, malware and upload controls, backups and recovery, incident response, personnel controls, provider assurance, retention, secure deletion, change control, and continuity.

Bibeno may improve or replace a measure without customer consent if the change does not materially reduce overall protection. A material reduction requires advance notice, a documented risk decision, and any re-acceptance or termination right required by the service agreement or law.

8. Sub-operators

The customer gives general authorisation for Bibeno to use only the sub-operators listed in the approved Subprocessor List for the documented purpose and locations. Bibeno remains responsible for selecting, contracting, instructing, monitoring, and exiting each sub-operator and imposes data-protection obligations no less protective for the relevant processing.

Bibeno gives reasonable advance notice of a new or replacement sub-operator where the change materially affects customer-controlled information. The customer may raise a reasoned data-protection objection during the stated notice period. The parties will seek a reasonable alternative; if none is available, the customer may stop the affected optional feature or exercise any termination right in the accepted order.

Customer-selected email, messaging, payment, storage, identity, or integration providers are not Bibeno sub-operators merely because Bibeno supports a connection. The customer is responsible for selecting and contracting with them, while Bibeno remains responsible for the security and accuracy of its supported integration boundary.

9. International processing and transfers

Bibeno and an approved sub-operator may process customer-controlled information outside South Africa only after the recipient, purpose, information, data subjects, processing and support locations, onward transfers, security, retention, contract, and a safeguard permitted by section 72 of POPIA have been verified.

Bibeno will provide the customer with the approved location and transfer information reasonably needed for its transparency and risk assessment. The customer must not direct an unsupported foreign transfer or activate a non-South-African customer context while the applicable legal feature gate is blocked.

10. Data-subject and PAIA assistance

Taking into account the nature of processing and information available to Bibeno, Bibeno assists the customer with access, correction, deletion, objection, restriction, consent withdrawal, marketing suppression, PAIA, complaint, and other valid requests relating to customer-controlled information.

If Bibeno receives a request directly, it verifies enough context to identify the likely responsible party, does not disclose customer-controlled information without authority, and forwards the request to the customer unless prohibited by law. Bibeno does not decide the customer's lawful exemptions or refusal grounds but records and implements the customer's lawful instruction.

Ordinary self-service search, correction, export, and deletion support is included in the service. Material custom work may be charged only where the accepted order permits it, the request is not caused by Bibeno's breach, and the charge does not obstruct a statutory right.

11. Security compromises

Bibeno notifies the customer immediately after discovering a compromise affecting customer-controlled information and does not wait for a complete investigation. Initial and supplemental notices provide the known or reasonably available incident time, discovery, systems, tenants, data, data subjects, likely consequences, containment, preservation, sub-operator involvement, and recommended action.

Bibeno supports containment, investigation, recovery, evidence preservation, root-cause analysis, regulator and data-subject notification, and remediation. The customer remains responsible for notifications in its responsible-party role; Bibeno will not notify on the customer's behalf unless specifically authorised and lawful.

Neither party may make a misleading statement about the other or delay a mandatory notice for reputational convenience. Communications are coordinated where reasonably possible without preventing either party from meeting its own legal duty.

12. Risk assessment, prior authorisation, and consultation

Bibeno provides reasonable information about the service, measures, providers, locations, retention, incidents, and processing needed for the customer's privacy impact assessment, prior-authorisation analysis, regulator consultation, or sector review.

The customer must not begin a processing activity requiring Information Regulator prior authorisation until it is obtained. The relevant feature remains disabled where Bibeno cannot verify the required lawful approval.

13. Audit and compliance evidence

Bibeno makes available proportionate current evidence such as this agreement, the Security Measures Schedule, Subprocessor List, relevant certifications or assessment summaries if any, penetration or vulnerability remediation summaries, incident and continuity evidence, and responses to a reasonable security questionnaire.

If that evidence is insufficient for a material, specific risk, the customer may request a scoped audit no more than once annually unless a compromise, regulator, or credible material deficiency justifies more. An audit must protect other customers, security, secrets, privilege, and availability; use an independent qualified reviewer; occur on reasonable notice; and avoid production disruption.

Bibeno bears the cost of correcting its confirmed material non-compliance. The customer bears reasonable external cost of an elective audit not caused by such non-compliance, unless a signed order says otherwise.

14. Government and third-party requests

Bibeno reviews a subpoena, warrant, court order, regulator demand, or other compulsory request for validity, scope, authority, and prohibited disclosure. Where lawful, Bibeno notifies the customer before disclosure and gives the customer a reasonable opportunity to seek protection.

Bibeno discloses only the minimum information lawfully required, records the request and response, and challenges an overbroad or unlawful demand where reasonable. Nothing requires Bibeno to disclose another customer's information, security secrets, or privileged material.

15. Return, retention, legal holds, and deletion

During the service and applicable exit period, the customer may use available export tools to retrieve supported customer-controlled information. At the end of service, Bibeno returns, deletes, destroys, or irreversibly de-identifies information according to the customer's lawful instruction and the published retention schedule.

Bibeno may retain a restricted copy only where law, tax, accounting, transaction integrity, security, dispute, backup, or a valid legal hold requires it. Retained information is isolated from ordinary use, remains protected by this agreement, and is deleted when the basis ends.

Deletion uses the controlled dry-run, approval, execution, item-outcome, and completion-hash workflow. Backups expire through their lifecycle and are not restored to ordinary processing after valid deletion except for a documented recovery need followed by reapplication of the deletion instruction.

16. Liability and term

This agreement begins when the customer accepts the service contract and continues while Bibeno processes customer-controlled information. Duties concerning confidentiality, security, incident evidence, retained information, audit records, and deletion survive for as long as the relevant information or obligation remains.

Liability is allocated under the Terms of Service or signed customer agreement, subject to any different mandatory liability that applies to personal-information processing. Neither party is excused from its own POPIA accountability merely because the other party has a related duty.

17. Changes and contact

A material change to roles, purposes, categories, sub-operator authorisation, international processing, safeguards, assistance, retention, or deletion follows the legal change-classification process and requires notice and re-acceptance where applicable. Published versions remain immutable.

Data-processing questions and instructions may be sent through the authenticated support route or to support@bibeno.co.za. Security compromises must use the urgent incident route identified in the Security Measures Schedule. Do not send secrets, passwords, full card data, or unnecessary personal information by email.

Book a demo
Bibeno

Point of sale and business management software for South African food-service and independent retail businesses.

Book a demo

Product

Software overviewIndustriesPricingDownload for WindowsBook a demoGet started

Company

AboutContact usSign in

Legal

Legal centreTermsPrivacyData processing agreementRefunds and cancellation
BIBENO (PTY) LTD · Reg. 2026/355321/07© 2026 Bibeno POSsupport@bibeno.co.za+27 60 659 1848

Choose your cookie preferences

Essential storage is always active. Optional analytics and marketing tools remain off unless you allow them. Read more.

Cookie preferences

Control optional website technologies

Necessary technology is always active. Optional categories remain off until you enable them. You can change these choices from the website footer.

Strictly necessary

Remembers your consent choice and supports essential website security and forms. This category cannot be switched off.

Currently used: Bibeno consent storage; Cloudflare Turnstile on protected demo forms.

Functional

Would remember optional site preferences that are not needed for core features.

Not currently used.

Analytics

Would help us understand website use and improve performance through approved measurement tools.

Not currently used.

Marketing

Would support approved advertising, campaign measurement or personalised marketing.

Not currently used.

Your browser is sending a Global Privacy Control signal. Optional categories remain off unless you actively change them here.