PAIA Manual

PAIA MANUAL — SETHALA (PTY) LTD

Registration Number: 2012/163091/07

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended.

Date of compilation14 May 2026
Date of latest revision20 August 2026
VersionRegulator-template aligned final website version 2026.2

Table of Contents

SectionHeading
1List of acronyms and abbreviations
2Purpose of PAIA Manual
3Key contact details for access to information of Sethala (Pty) Ltd
4Guide on how to use PAIA and how to obtain access to the Guide
5Categories of records available without a formal PAIA request
6Description of records available in accordance with any other legislation
7Description of subjects on which Sethala holds records and categories of records held on each subject
8Processing of personal information
8.1Purpose of processing personal information
8.2Categories of data subjects and personal information
8.3Recipients or categories of recipients to whom personal information may be supplied
8.4Planned transborder flows of personal information
8.5General description of information security measures
9Availability of the Manual
10Updating of the Manual

1. List of Acronyms and Abbreviations

Acronym / abbreviationMeaning
CEOChief Executive Officer
DIODeputy Information Officer
IOInformation Officer
MinisterMinister of Justice and Correctional Services
PAIAPromotion of Access to Information Act 2 of 2000, as amended
POPIAProtection of Personal Information Act 4 of 2013
RegulatorInformation Regulator established under POPIA
RepublicRepublic of South Africa
SARSSouth African Revenue Service
SethalaSethala (Pty) Ltd, registration number 2012/163091/07
UIFUnemployment Insurance Fund
VATValue-Added Tax

2. Purpose of PAIA Manual

This PAIA Manual is intended to assist members of the public, data subjects, customers, employees, contractors, service providers and other interested persons to:

  1. check the categories of records held by Sethala that are available without a person having to submit a formal PAIA request;

  2. obtain a sufficient understanding of how to make a request for access to a record of Sethala by providing a description of the subjects on which Sethala holds records and the categories of records held on each subject;

  3. know the description of records of Sethala that are available in accordance with other South African legislation;

  4. access the relevant contact details of Sethala’s Information Officer and any Deputy Information Officer who may assist the public with access to records;

  5. know the description of the Guide on how to use PAIA, as updated by the Regulator, and how to obtain access to the Guide;

  6. understand whether Sethala processes personal information, the purposes for which personal information is processed and the categories of data subjects concerned;

  7. understand the categories of personal information processed by Sethala;

  8. understand the recipients or categories of recipients to whom personal information may be supplied;

  9. understand whether Sethala has planned to transfer or process personal information outside the Republic and the categories of recipients to whom such information may be supplied; and

  10. understand the general security measures implemented or under implementation to protect the confidentiality, integrity and availability of personal information processed by Sethala.

This Manual should be read together with Sethala’s Privacy, Data Protection & Cookies Notice, applicable contractual terms, internal POPIA policies, Acceptable Use of IT Policy and other applicable Sethala policies or agreements.

3. Key Contact Details for Access to Information of Sethala (Pty) Ltd

3.1. Information Officer / Head of Private Body

ItemDetails
NameRolf Schurink
Telephone012 942 4000
Email[email protected]
Fax numberNot used / not applicable

3.2. Deputy Information Officer

The Deputy Information Officer designated for Sethala is Berdina Schurink. Contact details are set out below.

ItemDetails
NameBerdina Schurink
Telephone012 942 4000
Email[email protected]
Fax numberNot used / not applicable

3.3. Access to Information General Contact

ItemDetails
General PAIA / POPIA email[email protected]
PurposePAIA access requests, POPIA requests, privacy queries and Information Regulator-related correspondence

3.4. National / Head Office

ItemDetails
Name of private bodySethala (Pty) Ltd
Registration number2012/163091/07
Postal addressSame as physical address
Physical address4th Floor, Menlyn Corner, 87 Frikkie de Beer Street, Menlyn, Pretoria, 0181, South Africa
Telephone012 942 4000
Email[email protected]
Websitewww.sethala.com

4. Guide on How to Use PAIA and How to Obtain Access to the Guide

The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”) in an easily comprehensible form and manner as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.

The Guide is available in each of the official languages and in braille.

The Guide contains a description of:

  1. the objects of PAIA and POPIA;

  2. the postal and street address, telephone number and, where available, electronic mail address of the Information Officer of every public body and every Deputy Information Officer of every public and private body designated in terms of PAIA and POPIA;

  3. the manner and form of a request for access to a record of a public body and a private body;

  4. the assistance available from Information Officers in terms of PAIA and POPIA;

  5. the assistance available from the Regulator in terms of PAIA and POPIA;

  6. all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal where applicable, a complaint to the Regulator, or an application to court;

  7. the requirements for public and private bodies to compile PAIA manuals and how to obtain access to a manual;

  8. the provisions for voluntary disclosure of categories of records by public and private bodies;

  9. notices regarding fees to be paid in relation to requests for access; and

  10. the regulations made under PAIA.

Members of the public may inspect or make copies of the Guide from the offices of public and private bodies, including the office of the Regulator, during normal working hours.

The Guide may also be obtained:

  1. upon request to Sethala’s Information Officer at [email protected]; and

  2. from the website of the Information Regulator at https://inforegulator.org.za/paia/.

A copy of the Guide is available in the following two official languages for public inspection during normal office hours: English and Afrikaans.

4.7. Practical Notes on Requests for Access to Records

A person who wishes to request access to a record held by Sethala must use the prescribed PAIA request form, being Form 2: Request for Access to Record. The request must be submitted to the Information Officer at [email protected] and should include sufficient detail to identify the requested record, proof of identity, proof of authority where the request is made on behalf of another person, the form of access required, the right the requester seeks to exercise or protect, and why the record is required for that purpose.

Access to a record of a private body may be granted where the record is required for the exercise or protection of a right, the requester has complied with the procedural requirements of PAIA and access is not refused under any ground for refusal in PAIA. Sethala may refuse access where PAIA permits or requires refusal, including where access would involve the unreasonable disclosure of personal information, confidential information, trade secrets, commercial information, privileged information, security-related information or information belonging to a third party.

Private bodies do not have the same internal appeal procedure as public bodies under PAIA. Where a requester is dissatisfied with a decision by Sethala, the requester may consider the complaint and court remedies available under PAIA.

5. Categories of Records of Sethala Which Are Available Without a Person Having to Request Access

Certain records may be available without a person having to submit a formal PAIA request. Availability may depend on the nature of the record, whether the record is already publicly available, whether the record contains personal or confidential information and Sethala’s operational requirements.

Category of recordsTypes of recordAvailable on websiteAvailable upon request
Company informationGeneral company profile and general business informationYes, where publishedYes
Website informationWebsite terms, notices, privacy notices or policiesYes, where publishedYes
PAIA and POPIA documentsPAIA Manual, Privacy, Data Protection & Cookies Notice and related public compliance documentsYes, where publishedYes
Contact informationGeneral business contact detailsYesYes
Product or service informationGeneral product, platform or service descriptionsYes, where publishedYes
Complaints informationComplaints procedure or customer support processYes, where publishedYes
Public marketing informationBrochures, presentations or publicly released marketing materialYes, where publishedYes

Sethala may require a formal PAIA request where a record is not publicly available, relates to a third party, contains confidential information, contains personal information or requires assessment under PAIA.

6. Description of the Records of Sethala Which Are Available in Accordance with Any Other Legislation

Sethala may hold records in accordance with the following South African legislation, where applicable:

Category of recordsApplicable legislation
Memorandum of incorporation, company registration documents, company records, share records, resolutions and governance recordsCompanies Act 71 of 2008
Tax records, invoices, accounting records and related financial recordsIncome Tax Act 58 of 1962; Tax Administration Act 28 of 2011; Value-Added Tax Act 89 of 1991
Employment records, payroll records, leave records and employment contractsBasic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995
Employee tax records and PAYE recordsIncome Tax Act 58 of 1962; Tax Administration Act 28 of 2011
UIF recordsUnemployment Insurance Act 63 of 2001; Unemployment Insurance Contributions Act 4 of 2002
Occupational health and safety records, where applicableOccupational Health and Safety Act 85 of 1993
Compensation for occupational injury or disease records, where applicableCompensation for Occupational Injuries and Diseases Act 130 of 1993
PAIA Manual and access request recordsPromotion of Access to Information Act 2 of 2000
Privacy, data subject request and personal information processing recordsProtection of Personal Information Act 4 of 2013 and applicable regulations, including the Regulations relating to the Processing of Data Subjects’ Health or Sex Life by Certain Responsible Parties, 2026, where applicable
Electronic communications, website, online transaction and electronic records, where applicableElectronic Communications and Transactions Act 25 of 2002
Consumer complaints and customer service records, where applicableConsumer Protection Act 68 of 2008
Contract, supplier and customer recordsCommon law, Companies Act 71 of 2008 and applicable commercial legislation
Financial intelligence and anti-money laundering records, where applicable to Sethala’s activitiesFinancial Intelligence Centre Act 38 of 2001
Intellectual property recordsCopyright Act 98 of 1978; Trade Marks Act 194 of 1993; Patents Act 57 of 1978, where applicable

This list is not exhaustive. Sethala may hold records under other laws depending on its business activities, customer requirements, contractual obligations and statutory obligations.

7. Description of the Subjects on Which Sethala Holds Records and Categories of Records Held on Each Subject by Sethala

Subjects on which Sethala holds recordsCategories of records
Corporate governanceCompany registration documents, company secretarial records, shareholder records, resolutions, director records, governance policies, statutory registers and company correspondence
Finance and accountingInvoices, statements, accounting records, bank records, supplier invoices, customer billing information, tax records, VAT records, payment records and financial reports
Customers and contractsCustomer agreements, service agreements, subscription records, support records, onboarding records, customer correspondence, commercial proposals and account administration records
Platform usersUser account records, names, surnames, work email addresses, user roles, branch information, division information, access permissions, login records, audit records and support interactions
Customer-controlled platform dataRecords uploaded, managed or processed by customers or end-users through Sethala’s platform, subject to customer control, applicable agreement terms and access permissions
Machine and device dataMachine data, device data, operational telemetry, status information, encrypted technical data, usage records and other non-personal technical information processed for operational, technical, monitoring or system-related purposes
Suppliers and service providersSupplier agreements, service provider records, due diligence records, invoices, contact details, support agreements, hosting records and correspondence
Employees and contractorsEmployment contracts, contractor agreements, payroll records, leave records, disciplinary records, training records, performance records, policies, acknowledgements and HR correspondence
Interns and applicantsCVs, applications, interview notes, reference checks, qualification information, correspondence and onboarding records
IT and information securityAccess control records, user permissions, system logs, audit trails, device records, incident reports, backup records, security policies and technical documentation
Product and developmentTechnical specifications, software development records, product documentation, release records, change logs, internal workflows, project plans and intellectual property records
Legal and compliancePolicies, procedures, POPIA records, PAIA requests, data subject requests, complaints, legal correspondence, regulatory correspondence and risk records
Marketing and communicationsWebsite content, enquiry records, marketing material, customer communications, campaign records and consent records, where applicable
Complaints and supportCustomer complaints, support tickets, escalation records, resolution records and service feedback

8. Processing of Personal Information

8.1. Purpose of Processing Personal Information

Sethala processes personal information for purposes connected with its business operations, customer relationships, platform administration, platform security, support, billing, employment and compliance obligations.

Where Sethala’s customers or end-users use Sethala’s platform to Process their own client or operational Personal Information, the organisation that determines the purpose and means of that Processing is generally the Responsible Party. Sethala may act as that Responsible Party’s direct Operator where it is directly appointed under a contract or mandate. Where Sethala Processes Personal Information downstream on behalf of a Reseller, Hosted Partner or other Operator, Sethala Processes within the Responsible Party’s knowledge or authorisation and the applicable Processing chain contemplated by section 20 of POPIA.

Sethala may process personal information for the following purposes:

  1. to provide, operate, maintain and support Sethala’s platform and related services;

  2. to create, administer and manage user accounts, roles, permissions, branches, divisions and access controls;

  3. to authenticate users and protect platform, system and network security;

  4. to maintain audit logs, security logs, access records and support records;

  5. to provide customer support and respond to queries;

  6. to manage customer relationships, contractual obligations, onboarding and account administration;

  7. to issue invoices, manage accounts, perform accounting and financial administration and process payments;

  8. to use approved business email, document management, productivity, communications and business administration systems;

  9. to use approved internal business assistance, workflow support and related operational systems;

  10. to manage supplier and service provider relationships;

  11. to comply with tax, company, employment, access to information, privacy and other legal obligations;

  12. to recruit, employ, manage and pay employees, interns and contractors;

  13. to manage IT security, acceptable use, monitoring and incident response;

  14. to investigate complaints, support issues, suspected misuse or security incidents;

  15. to protect Sethala’s rights, property, systems, personnel, customers, users and legal interests;

  16. to respond to lawful requests from regulators, courts, law enforcement or other competent authorities;

  17. to communicate with customers, users, employees, suppliers and business contacts;

  18. to perform internal reporting, planning, risk management and governance functions; and

  19. to perform any other lawful business purpose reasonably connected to Sethala’s operations.

Sethala also processes non-personal machine data and encrypted technical data for operational, technical, monitoring, redundancy, processing or system-related purposes. Sethala does not intend such machine data to identify a natural or juristic person.

8.2. Description of the Categories of Data Subjects and of the Information or Categories of Information Relating Thereto

Categories of data subjectsPersonal information that may be processed
Customer representativesName, surname, job title, employer, department, branch, division, work email address, work telephone number, account information, correspondence, contract records and support history
Platform usersName, surname, username, work email address, role, permissions, branch, division, access logs, system activity, audit trails, support interactions and security-related records
Customer-controlled data subjectsPersonal information uploaded, captured or processed by customers or end-users through the platform, subject to the customer’s instructions, applicable agreements and access controls
Suppliers and service providersName, surname, business contact details, company name, registration number, VAT number, banking details, invoices, contractual information, correspondence and service records
EmployeesName, surname, ID number, contact details, home address, banking details, payroll information, tax information, employment records, leave records, performance records, disciplinary records, training records, emergency contact details and benefit information
Contractors and consultantsName, surname, contact details, company information, identity or registration details, tax information, payment information, contract records, work output, access records and correspondence
Interns and job applicantsName, surname, CV, contact details, qualifications, reference information, interview notes, background information, application records and correspondence
Website visitors and enquirersName, surname, email address, telephone number, company details, enquiry details, website usage information, IP address and communication records
Business contactsName, surname, company, role, email address, telephone number, communication history and meeting records
ComplainantsName, surname, contact details, complaint details, supporting information, correspondence, investigation records and outcome records
Regulators and authoritiesContact details, correspondence, request records, reporting records and compliance-related records

Sethala does not intentionally process special personal information unless it is necessary, lawful and relevant to a specific employment, legal, security, contractual or compliance purpose.

8.3. The Recipients or Categories of Recipients to Whom Personal Information May Be Supplied

Category of personal informationRecipients or categories of recipients to whom the personal information may be supplied
Customer and platform user informationAuthorised Sethala personnel, customer administrators, support personnel, approved hosting providers, software service providers and authorised technical service providers
Business email, documents and operational recordsAuthorised Sethala personnel, approved cloud productivity and document-management service providers, approved IT administrators, security service providers and authorised support providers
Internal workflow, business support or assistant-related informationAuthorised Sethala personnel, approved workflow or business-support system providers and approved system administrators, subject to applicable access controls and permissions
Accounting and billing informationApproved accounting or financial administration service providers, auditors, accountants, tax practitioners, banks, payment service providers and SARS
Employee payroll and tax informationPayroll administrators, SARS, UIF, banks, accountants, auditors and relevant statutory bodies
Employee and contractor informationAuthorised managers, HR personnel, payroll providers, legal advisers, insurers, benefit providers and relevant statutory bodies
Supplier and service provider informationAuthorised Sethala personnel, accountants, auditors, banks, legal advisers and relevant operational service providers
IT and security recordsHosting providers, IT service providers, cybersecurity service providers, auditors, legal advisers and law enforcement where required
Complaint and support recordsCustomer support personnel, senior management, technical teams, legal advisers and relevant service providers
Legal and compliance informationLegal advisers, auditors, regulators, courts, law enforcement agencies and other competent authorities
Website enquiry and communication recordsAuthorised sales, support, administrative and management personnel

Sethala will not sell personal information. Sethala will only disclose personal information where there is a lawful basis to do so, including where disclosure is necessary for a contract, required by law, required for legitimate operational purposes, authorised by the data subject or necessary to protect Sethala’s rights, systems, personnel, customers or users.

8.4. Planned Transborder Flows of Personal Information

Sethala uses approved hosting, cloud, accounting, productivity, document-management, support and workflow service providers for business and operational purposes. As a public-facing Manual, supplier names and provider-specific infrastructure details are not published here. These details are managed internally and contractually where appropriate.

Country / regionPurpose or contextCategories of information
South AfricaOrdinary business, operational and compliance processingBusiness contact information, customer and supplier information, employee information, platform administration information and related operational records, as applicable.
Other jurisdictions, where applicableInternational customer relationships, approved service-provider processing, support, communications, business administration or other lawful cross-border activitiesOnly categories of personal information reasonably necessary for the relevant purpose. Sethala applies section 72 of POPIA and other applicable safeguards where personal information is transferred outside South Africa.

Where Sethala Processes customer-controlled Personal Information as a direct Operator or as an authorised person Processing on behalf of an Operator in a reseller, Hosted Partner or other Processing chain, cross-border Processing will be governed by the applicable Responsible Party authority, contractual terms, section 72 of POPIA where applicable and any relevant data-protection addendum.

8.5. General Description of Information Security Measures to Be Implemented by Sethala to Ensure the Confidentiality, Integrity and Availability of the Information

Sethala takes reasonable technical and organisational measures to protect personal information against loss, damage, unauthorised access, unauthorised disclosure, unlawful processing, accidental destruction and misuse. Sethala’s general safeguards may include:

  1. local or approved infrastructure hosting arrangements;

  2. approved business systems, infrastructure providers and service providers;

  3. access control and user permissions;

  4. role-based access controls;

  5. password requirements and secure authentication practices;

  6. audit logs and system activity records;

  7. limitation of access to authorised personnel;

  8. confidentiality obligations for employees and contractors;

  9. acceptable use and IT security policies;

  10. secure backup practices;

  11. anti-virus and anti-malware controls, where applicable;

  12. software patching and system maintenance;

  13. monitoring of system use where lawful and appropriate;

  14. incident reporting and escalation procedures;

  15. supplier and service provider controls;

  16. physical security controls at office premises, where applicable;

  17. secure disposal or deletion of records where appropriate; and

  18. reasonable measures to ensure confidentiality, integrity and availability of information.

Where information is routed or processed across borders, Sethala applies reasonable technical and organisational safeguards to reduce the risk of unauthorised access, disclosure, alteration or misuse.

9. Availability of the Manual

A copy of this Manual is available:

  1. on Sethala’s website at www.sethala.com, where published;

  2. at Sethala’s head office for public inspection during normal business hours;

  3. to any person upon request to [email protected] and upon payment of any reasonable prescribed fee, where applicable; and

  4. to the Information Regulator upon request.

A fee for a copy of the Manual, as contemplated in Annexure B of the PAIA Regulations, shall be payable per each A4-size photocopy made, where applicable.

10. Updating of the Manual

Sethala will review and update this Manual from time to time where necessary. This may occur where Sethala’s business operations, processing activities, legal requirements, regulatory guidance, Information Officer or Deputy Information Officer, contact details, service arrangements or other relevant circumstances change.


Issued by: Information Officer

Rolf Schurink — Chief Executive Officer / Information Officer