PAIA Manual
PAIA MANUAL — SETHALA (PTY) LTD
Registration Number: 2012/163091/07
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended.
| Date of compilation | 14 May 2026 |
| Date of latest revision | 20 August 2026 |
| Version | Regulator-template aligned final website version 2026.2 |
Table of Contents
| Section | Heading |
|---|---|
| 1 | List of acronyms and abbreviations |
| 2 | Purpose of PAIA Manual |
| 3 | Key contact details for access to information of Sethala (Pty) Ltd |
| 4 | Guide on how to use PAIA and how to obtain access to the Guide |
| 5 | Categories of records available without a formal PAIA request |
| 6 | Description of records available in accordance with any other legislation |
| 7 | Description of subjects on which Sethala holds records and categories of records held on each subject |
| 8 | Processing of personal information |
| 8.1 | Purpose of processing personal information |
| 8.2 | Categories of data subjects and personal information |
| 8.3 | Recipients or categories of recipients to whom personal information may be supplied |
| 8.4 | Planned transborder flows of personal information |
| 8.5 | General description of information security measures |
| 9 | Availability of the Manual |
| 10 | Updating of the Manual |
1. List of Acronyms and Abbreviations
| Acronym / abbreviation | Meaning |
|---|---|
| CEO | Chief Executive Officer |
| DIO | Deputy Information Officer |
| IO | Information Officer |
| Minister | Minister of Justice and Correctional Services |
| PAIA | Promotion of Access to Information Act 2 of 2000, as amended |
| POPIA | Protection of Personal Information Act 4 of 2013 |
| Regulator | Information Regulator established under POPIA |
| Republic | Republic of South Africa |
| SARS | South African Revenue Service |
| Sethala | Sethala (Pty) Ltd, registration number 2012/163091/07 |
| UIF | Unemployment Insurance Fund |
| VAT | Value-Added Tax |
2. Purpose of PAIA Manual
This PAIA Manual is intended to assist members of the public, data subjects, customers, employees, contractors, service providers and other interested persons to:
check the categories of records held by Sethala that are available without a person having to submit a formal PAIA request;
obtain a sufficient understanding of how to make a request for access to a record of Sethala by providing a description of the subjects on which Sethala holds records and the categories of records held on each subject;
know the description of records of Sethala that are available in accordance with other South African legislation;
access the relevant contact details of Sethala’s Information Officer and any Deputy Information Officer who may assist the public with access to records;
know the description of the Guide on how to use PAIA, as updated by the Regulator, and how to obtain access to the Guide;
understand whether Sethala processes personal information, the purposes for which personal information is processed and the categories of data subjects concerned;
understand the categories of personal information processed by Sethala;
understand the recipients or categories of recipients to whom personal information may be supplied;
understand whether Sethala has planned to transfer or process personal information outside the Republic and the categories of recipients to whom such information may be supplied; and
understand the general security measures implemented or under implementation to protect the confidentiality, integrity and availability of personal information processed by Sethala.
This Manual should be read together with Sethala’s Privacy, Data Protection & Cookies Notice, applicable contractual terms, internal POPIA policies, Acceptable Use of IT Policy and other applicable Sethala policies or agreements.
3. Key Contact Details for Access to Information of Sethala (Pty) Ltd
3.1. Information Officer / Head of Private Body
| Item | Details |
|---|---|
| Name | Rolf Schurink |
| Telephone | 012 942 4000 |
| [email protected] | |
| Fax number | Not used / not applicable |
3.2. Deputy Information Officer
The Deputy Information Officer designated for Sethala is Berdina Schurink. Contact details are set out below.
| Item | Details |
|---|---|
| Name | Berdina Schurink |
| Telephone | 012 942 4000 |
| [email protected] | |
| Fax number | Not used / not applicable |
3.3. Access to Information General Contact
| Item | Details |
|---|---|
| General PAIA / POPIA email | [email protected] |
| Purpose | PAIA access requests, POPIA requests, privacy queries and Information Regulator-related correspondence |
3.4. National / Head Office
| Item | Details |
|---|---|
| Name of private body | Sethala (Pty) Ltd |
| Registration number | 2012/163091/07 |
| Postal address | Same as physical address |
| Physical address | 4th Floor, Menlyn Corner, 87 Frikkie de Beer Street, Menlyn, Pretoria, 0181, South Africa |
| Telephone | 012 942 4000 |
| [email protected] | |
| Website | www.sethala.com |
4. Guide on How to Use PAIA and How to Obtain Access to the Guide
The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”) in an easily comprehensible form and manner as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
The Guide is available in each of the official languages and in braille.
The Guide contains a description of:
the objects of PAIA and POPIA;
the postal and street address, telephone number and, where available, electronic mail address of the Information Officer of every public body and every Deputy Information Officer of every public and private body designated in terms of PAIA and POPIA;
the manner and form of a request for access to a record of a public body and a private body;
the assistance available from Information Officers in terms of PAIA and POPIA;
the assistance available from the Regulator in terms of PAIA and POPIA;
all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal where applicable, a complaint to the Regulator, or an application to court;
the requirements for public and private bodies to compile PAIA manuals and how to obtain access to a manual;
the provisions for voluntary disclosure of categories of records by public and private bodies;
notices regarding fees to be paid in relation to requests for access; and
the regulations made under PAIA.
Members of the public may inspect or make copies of the Guide from the offices of public and private bodies, including the office of the Regulator, during normal working hours.
The Guide may also be obtained:
upon request to Sethala’s Information Officer at [email protected]; and
from the website of the Information Regulator at https://inforegulator.org.za/paia/.
A copy of the Guide is available in the following two official languages for public inspection during normal office hours: English and Afrikaans.
4.7. Practical Notes on Requests for Access to Records
A person who wishes to request access to a record held by Sethala must use the prescribed PAIA request form, being Form 2: Request for Access to Record. The request must be submitted to the Information Officer at [email protected] and should include sufficient detail to identify the requested record, proof of identity, proof of authority where the request is made on behalf of another person, the form of access required, the right the requester seeks to exercise or protect, and why the record is required for that purpose.
Access to a record of a private body may be granted where the record is required for the exercise or protection of a right, the requester has complied with the procedural requirements of PAIA and access is not refused under any ground for refusal in PAIA. Sethala may refuse access where PAIA permits or requires refusal, including where access would involve the unreasonable disclosure of personal information, confidential information, trade secrets, commercial information, privileged information, security-related information or information belonging to a third party.
Private bodies do not have the same internal appeal procedure as public bodies under PAIA. Where a requester is dissatisfied with a decision by Sethala, the requester may consider the complaint and court remedies available under PAIA.
5. Categories of Records of Sethala Which Are Available Without a Person Having to Request Access
Certain records may be available without a person having to submit a formal PAIA request. Availability may depend on the nature of the record, whether the record is already publicly available, whether the record contains personal or confidential information and Sethala’s operational requirements.
| Category of records | Types of record | Available on website | Available upon request |
|---|---|---|---|
| Company information | General company profile and general business information | Yes, where published | Yes |
| Website information | Website terms, notices, privacy notices or policies | Yes, where published | Yes |
| PAIA and POPIA documents | PAIA Manual, Privacy, Data Protection & Cookies Notice and related public compliance documents | Yes, where published | Yes |
| Contact information | General business contact details | Yes | Yes |
| Product or service information | General product, platform or service descriptions | Yes, where published | Yes |
| Complaints information | Complaints procedure or customer support process | Yes, where published | Yes |
| Public marketing information | Brochures, presentations or publicly released marketing material | Yes, where published | Yes |
Sethala may require a formal PAIA request where a record is not publicly available, relates to a third party, contains confidential information, contains personal information or requires assessment under PAIA.
6. Description of the Records of Sethala Which Are Available in Accordance with Any Other Legislation
Sethala may hold records in accordance with the following South African legislation, where applicable:
| Category of records | Applicable legislation |
|---|---|
| Memorandum of incorporation, company registration documents, company records, share records, resolutions and governance records | Companies Act 71 of 2008 |
| Tax records, invoices, accounting records and related financial records | Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011; Value-Added Tax Act 89 of 1991 |
| Employment records, payroll records, leave records and employment contracts | Basic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995 |
| Employee tax records and PAYE records | Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011 |
| UIF records | Unemployment Insurance Act 63 of 2001; Unemployment Insurance Contributions Act 4 of 2002 |
| Occupational health and safety records, where applicable | Occupational Health and Safety Act 85 of 1993 |
| Compensation for occupational injury or disease records, where applicable | Compensation for Occupational Injuries and Diseases Act 130 of 1993 |
| PAIA Manual and access request records | Promotion of Access to Information Act 2 of 2000 |
| Privacy, data subject request and personal information processing records | Protection of Personal Information Act 4 of 2013 and applicable regulations, including the Regulations relating to the Processing of Data Subjects’ Health or Sex Life by Certain Responsible Parties, 2026, where applicable |
| Electronic communications, website, online transaction and electronic records, where applicable | Electronic Communications and Transactions Act 25 of 2002 |
| Consumer complaints and customer service records, where applicable | Consumer Protection Act 68 of 2008 |
| Contract, supplier and customer records | Common law, Companies Act 71 of 2008 and applicable commercial legislation |
| Financial intelligence and anti-money laundering records, where applicable to Sethala’s activities | Financial Intelligence Centre Act 38 of 2001 |
| Intellectual property records | Copyright Act 98 of 1978; Trade Marks Act 194 of 1993; Patents Act 57 of 1978, where applicable |
This list is not exhaustive. Sethala may hold records under other laws depending on its business activities, customer requirements, contractual obligations and statutory obligations.
7. Description of the Subjects on Which Sethala Holds Records and Categories of Records Held on Each Subject by Sethala
| Subjects on which Sethala holds records | Categories of records |
|---|---|
| Corporate governance | Company registration documents, company secretarial records, shareholder records, resolutions, director records, governance policies, statutory registers and company correspondence |
| Finance and accounting | Invoices, statements, accounting records, bank records, supplier invoices, customer billing information, tax records, VAT records, payment records and financial reports |
| Customers and contracts | Customer agreements, service agreements, subscription records, support records, onboarding records, customer correspondence, commercial proposals and account administration records |
| Platform users | User account records, names, surnames, work email addresses, user roles, branch information, division information, access permissions, login records, audit records and support interactions |
| Customer-controlled platform data | Records uploaded, managed or processed by customers or end-users through Sethala’s platform, subject to customer control, applicable agreement terms and access permissions |
| Machine and device data | Machine data, device data, operational telemetry, status information, encrypted technical data, usage records and other non-personal technical information processed for operational, technical, monitoring or system-related purposes |
| Suppliers and service providers | Supplier agreements, service provider records, due diligence records, invoices, contact details, support agreements, hosting records and correspondence |
| Employees and contractors | Employment contracts, contractor agreements, payroll records, leave records, disciplinary records, training records, performance records, policies, acknowledgements and HR correspondence |
| Interns and applicants | CVs, applications, interview notes, reference checks, qualification information, correspondence and onboarding records |
| IT and information security | Access control records, user permissions, system logs, audit trails, device records, incident reports, backup records, security policies and technical documentation |
| Product and development | Technical specifications, software development records, product documentation, release records, change logs, internal workflows, project plans and intellectual property records |
| Legal and compliance | Policies, procedures, POPIA records, PAIA requests, data subject requests, complaints, legal correspondence, regulatory correspondence and risk records |
| Marketing and communications | Website content, enquiry records, marketing material, customer communications, campaign records and consent records, where applicable |
| Complaints and support | Customer complaints, support tickets, escalation records, resolution records and service feedback |
8. Processing of Personal Information
8.1. Purpose of Processing Personal Information
Sethala processes personal information for purposes connected with its business operations, customer relationships, platform administration, platform security, support, billing, employment and compliance obligations.
Where Sethala’s customers or end-users use Sethala’s platform to Process their own client or operational Personal Information, the organisation that determines the purpose and means of that Processing is generally the Responsible Party. Sethala may act as that Responsible Party’s direct Operator where it is directly appointed under a contract or mandate. Where Sethala Processes Personal Information downstream on behalf of a Reseller, Hosted Partner or other Operator, Sethala Processes within the Responsible Party’s knowledge or authorisation and the applicable Processing chain contemplated by section 20 of POPIA.
Sethala may process personal information for the following purposes:
to provide, operate, maintain and support Sethala’s platform and related services;
to create, administer and manage user accounts, roles, permissions, branches, divisions and access controls;
to authenticate users and protect platform, system and network security;
to maintain audit logs, security logs, access records and support records;
to provide customer support and respond to queries;
to manage customer relationships, contractual obligations, onboarding and account administration;
to issue invoices, manage accounts, perform accounting and financial administration and process payments;
to use approved business email, document management, productivity, communications and business administration systems;
to use approved internal business assistance, workflow support and related operational systems;
to manage supplier and service provider relationships;
to comply with tax, company, employment, access to information, privacy and other legal obligations;
to recruit, employ, manage and pay employees, interns and contractors;
to manage IT security, acceptable use, monitoring and incident response;
to investigate complaints, support issues, suspected misuse or security incidents;
to protect Sethala’s rights, property, systems, personnel, customers, users and legal interests;
to respond to lawful requests from regulators, courts, law enforcement or other competent authorities;
to communicate with customers, users, employees, suppliers and business contacts;
to perform internal reporting, planning, risk management and governance functions; and
to perform any other lawful business purpose reasonably connected to Sethala’s operations.
Sethala also processes non-personal machine data and encrypted technical data for operational, technical, monitoring, redundancy, processing or system-related purposes. Sethala does not intend such machine data to identify a natural or juristic person.
8.2. Description of the Categories of Data Subjects and of the Information or Categories of Information Relating Thereto
| Categories of data subjects | Personal information that may be processed |
|---|---|
| Customer representatives | Name, surname, job title, employer, department, branch, division, work email address, work telephone number, account information, correspondence, contract records and support history |
| Platform users | Name, surname, username, work email address, role, permissions, branch, division, access logs, system activity, audit trails, support interactions and security-related records |
| Customer-controlled data subjects | Personal information uploaded, captured or processed by customers or end-users through the platform, subject to the customer’s instructions, applicable agreements and access controls |
| Suppliers and service providers | Name, surname, business contact details, company name, registration number, VAT number, banking details, invoices, contractual information, correspondence and service records |
| Employees | Name, surname, ID number, contact details, home address, banking details, payroll information, tax information, employment records, leave records, performance records, disciplinary records, training records, emergency contact details and benefit information |
| Contractors and consultants | Name, surname, contact details, company information, identity or registration details, tax information, payment information, contract records, work output, access records and correspondence |
| Interns and job applicants | Name, surname, CV, contact details, qualifications, reference information, interview notes, background information, application records and correspondence |
| Website visitors and enquirers | Name, surname, email address, telephone number, company details, enquiry details, website usage information, IP address and communication records |
| Business contacts | Name, surname, company, role, email address, telephone number, communication history and meeting records |
| Complainants | Name, surname, contact details, complaint details, supporting information, correspondence, investigation records and outcome records |
| Regulators and authorities | Contact details, correspondence, request records, reporting records and compliance-related records |
Sethala does not intentionally process special personal information unless it is necessary, lawful and relevant to a specific employment, legal, security, contractual or compliance purpose.
8.3. The Recipients or Categories of Recipients to Whom Personal Information May Be Supplied
| Category of personal information | Recipients or categories of recipients to whom the personal information may be supplied |
|---|---|
| Customer and platform user information | Authorised Sethala personnel, customer administrators, support personnel, approved hosting providers, software service providers and authorised technical service providers |
| Business email, documents and operational records | Authorised Sethala personnel, approved cloud productivity and document-management service providers, approved IT administrators, security service providers and authorised support providers |
| Internal workflow, business support or assistant-related information | Authorised Sethala personnel, approved workflow or business-support system providers and approved system administrators, subject to applicable access controls and permissions |
| Accounting and billing information | Approved accounting or financial administration service providers, auditors, accountants, tax practitioners, banks, payment service providers and SARS |
| Employee payroll and tax information | Payroll administrators, SARS, UIF, banks, accountants, auditors and relevant statutory bodies |
| Employee and contractor information | Authorised managers, HR personnel, payroll providers, legal advisers, insurers, benefit providers and relevant statutory bodies |
| Supplier and service provider information | Authorised Sethala personnel, accountants, auditors, banks, legal advisers and relevant operational service providers |
| IT and security records | Hosting providers, IT service providers, cybersecurity service providers, auditors, legal advisers and law enforcement where required |
| Complaint and support records | Customer support personnel, senior management, technical teams, legal advisers and relevant service providers |
| Legal and compliance information | Legal advisers, auditors, regulators, courts, law enforcement agencies and other competent authorities |
| Website enquiry and communication records | Authorised sales, support, administrative and management personnel |
Sethala will not sell personal information. Sethala will only disclose personal information where there is a lawful basis to do so, including where disclosure is necessary for a contract, required by law, required for legitimate operational purposes, authorised by the data subject or necessary to protect Sethala’s rights, systems, personnel, customers or users.
8.4. Planned Transborder Flows of Personal Information
Sethala uses approved hosting, cloud, accounting, productivity, document-management, support and workflow service providers for business and operational purposes. As a public-facing Manual, supplier names and provider-specific infrastructure details are not published here. These details are managed internally and contractually where appropriate.
| Country / region | Purpose or context | Categories of information |
|---|---|---|
| South Africa | Ordinary business, operational and compliance processing | Business contact information, customer and supplier information, employee information, platform administration information and related operational records, as applicable. |
| Other jurisdictions, where applicable | International customer relationships, approved service-provider processing, support, communications, business administration or other lawful cross-border activities | Only categories of personal information reasonably necessary for the relevant purpose. Sethala applies section 72 of POPIA and other applicable safeguards where personal information is transferred outside South Africa. |
Where Sethala Processes customer-controlled Personal Information as a direct Operator or as an authorised person Processing on behalf of an Operator in a reseller, Hosted Partner or other Processing chain, cross-border Processing will be governed by the applicable Responsible Party authority, contractual terms, section 72 of POPIA where applicable and any relevant data-protection addendum.
8.5. General Description of Information Security Measures to Be Implemented by Sethala to Ensure the Confidentiality, Integrity and Availability of the Information
Sethala takes reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, unauthorised disclosure, unlawful processing, accidental destruction and misuse. Sethala’s general safeguards may include:
local or approved infrastructure hosting arrangements;
approved business systems, infrastructure providers and service providers;
access control and user permissions;
role-based access controls;
password requirements and secure authentication practices;
audit logs and system activity records;
limitation of access to authorised personnel;
confidentiality obligations for employees and contractors;
acceptable use and IT security policies;
secure backup practices;
anti-virus and anti-malware controls, where applicable;
software patching and system maintenance;
monitoring of system use where lawful and appropriate;
incident reporting and escalation procedures;
supplier and service provider controls;
physical security controls at office premises, where applicable;
secure disposal or deletion of records where appropriate; and
reasonable measures to ensure confidentiality, integrity and availability of information.
Where information is routed or processed across borders, Sethala applies reasonable technical and organisational safeguards to reduce the risk of unauthorised access, disclosure, alteration or misuse.
9. Availability of the Manual
A copy of this Manual is available:
on Sethala’s website at www.sethala.com, where published;
at Sethala’s head office for public inspection during normal business hours;
to any person upon request to [email protected] and upon payment of any reasonable prescribed fee, where applicable; and
to the Information Regulator upon request.
A fee for a copy of the Manual, as contemplated in Annexure B of the PAIA Regulations, shall be payable per each A4-size photocopy made, where applicable.
10. Updating of the Manual
Sethala will review and update this Manual from time to time where necessary. This may occur where Sethala’s business operations, processing activities, legal requirements, regulatory guidance, Information Officer or Deputy Information Officer, contact details, service arrangements or other relevant circumstances change.
Issued by: Information Officer
Rolf Schurink — Chief Executive Officer / Information Officer
