Paia Manual
01LIST OF ACRONYMS AND ABBREVIATIONS
"CEO" Chief Executive Officer
"DIO" Deputy Information Officer
"IO" Information Officer
"ISMS" Information Security Management System
"Minister" Minister of Justice and Correctional Services
"PAIA" Promotion of Access to Information Act No. 2 of 2000 (as amended)
"POPIA" Protection of Personal Information Act No. 4 of 2013
"Regulator" Information Regulator
"Republic" Republic of South Africa
02PURPOSE OF PAIA MANUAL
This PAIA Manual is useful for the public to-
- check the categories of records held by a body which are available without a person having to submit a formal PAIA request;
- have a sufficient understanding of how to make a request for access to a record of the body, by providing a description of the subjects on which the body holds records and the categories of records held on each subject;
- know the description of the records of the body which are available in accordance with any other legislation;
- access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;
- know the description of the guide on how to use PAIA, as updated by the Regulator and how to obtain access to it;
- know if the body will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;
- know the description of the categories of data subjects and of the information or categories of information relating thereto;
- know the recipients or categories of recipients to whom the personal information may be supplied;
- know if the body has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and
- know whether the body has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
03KEY CONTACT DETAILS FOR ACCESS TO INFORMATION OF ARCAIDEA (PTY) LTD
3.1 Registered company details
Registered name: Arcaidea (Pty) Ltd
Company registration number: 2022/611739/07
Country of incorporation: Republic of South Africa
3.2 Information Officer
Name: Jacques van Niekerk (Chief Executive Officer)
Tel: 084 606 1990
Email: jacques@arcaidea.ai
Note: Under section 1(1)(v) and section 17 of PAIA, the head of a private body (the CEO) is the Information Officer by default. PAIA uses the term "Information Officer" rather than "Chief Information Officer".
3.3 Deputy Information Officer
Name: Frikan Erwee (Appointed Data Officer)
Tel: 082 640 5323
Email: frikan@arcaidea.ai
3.4 Access to information general contacts
Email: info@arcaidea.ai
3.5 National or Head Office
Postal Address: 81 Pomegranate Street, Monaghan Farm, Lanseria, Gauteng, 1739
Physical Address: 81 Pomegranate Street, Monaghan Farm, Lanseria, Gauteng, 1739
Telephone: 084 606 1990
Email: info@arcaidea.ai
Website: www.arcaidea.ai
04GUIDE ON HOW TO USE PAIA AND HOW TO OBTAIN ACCESS TO THE GUIDE
- The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA ("Guide"), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
- The Guide is available in English.
- The aforesaid Guide contains the description of-
- the objects of PAIA and POPIA;
- the postal and street address, phone number and electronic mail address of the Information Officer of every public body and every Deputy Information Officer of every public and private body designated in terms of section 17(1) of PAIA and section 56 of POPIA;
- the manner and form of a request for access to a record of a public body contemplated in section 11, and access to a record of a private body contemplated in section 50;
- the assistance available from the Information Officer of a public body in terms of PAIA and POPIA;
- the assistance available from the Regulator in terms of PAIA and POPIA;
- all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court;
- the provisions of sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;
- the provisions of sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively;
- the notices issued in terms of sections 22 and 54 regarding fees to be paid in relation to requests for access; and
- the regulations made in terms of section 92.
- Members of the public can inspect or make copies of the Guide from the offices of the public and private bodies, including the office of the Regulator, during normal working hours.
- The Guide can also be obtained-
- upon request to the Information Officer;
- from the website of the Regulator (https://inforegulator.org.za/).
- A copy of the Guide is also available in the following official languages, for public inspection at the physical address, during normal office hours: English.
05CATEGORIES OF RECORDS OF ARCAIDEA (PTY) LTD WHICH ARE AVAILABLE WITHOUT A PERSON HAVING TO REQUEST ACCESS
- Marketing and product information published on www.arcaidea.ai;
- General company information published on the company's LinkedIn and other public-facing channels;
- Employment status;
- Employee, client and service provider personal information is only available to the individual directly, or the registered contact person.
06DESCRIPTION OF THE RECORDS OF ARCAIDEA (PTY) LTD WHICH ARE AVAILABLE IN ACCORDANCE WITH ANY OTHER LEGISLATION
Category of Records
Applicable Legislation
Memorandum of Incorporation
Companies Act 71 of 2008
PAIA Manual
Promotion of Access to Information Act 2 of 2000
Personal information processing records, consent records, breach register
Protection of Personal Information Act 4 of 2013 (POPIA)
Employment records, contracts, payroll
Basic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995; Employment Equity Act 55 of 1998; Skills Development Act 97 of 1998
Tax records, VAT returns, PAYE/SDL/UIF
Income Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011; Unemployment Insurance Act 63 of 2001
Annual financial statements, accounting records
Companies Act 71 of 2008
B-BBEE verification records
Broad-Based Black Economic Empowerment Act 53 of 2003
Information Security Management System (ISMS) records, Statement of Applicability, risk assessments, audit logs
ISO/IEC 27001:2022 (voluntary certification framework); POPIA s19 (security safeguards)
07DESCRIPTION OF THE SUBJECTS ON WHICH THE BODY HOLDS RECORDS AND CATEGORIES OF RECORDS HELD ON EACH SUBJECT BY ARCAIDEA (PTY) LTD
Category of records
Types of the Record
Available on Website
Available upon request
Information
Debtor details; creditor details; employee policies; employee personal details
No
Yes
Financial
Annual financial statements; monthly financial records; tax compliance status
No
Yes
Business
Strategic plans; operational policies; meeting minutes; statutory reports; annual reports
No
Yes
Human Resources
HR policies and procedures; advertised positions; employee records
No
Yes
Technical and product records
Source code; software design documents; architecture diagrams; product roadmaps; technical documentation for the Arcaidea SaaS platform
No
No (commercially confidential / IP)
Customer (tenant) and contract records
Customer master subscription agreements; statements of work; data processing agreements; NDAs; customer onboarding records; service delivery and support records
No
On legitimate request only (subject to NDA / DPA)
Platform operational records
Tenant configuration; role and permission assignments; audit logs; system event logs; usage and billing metrics; incident and support tickets
No
Tenant-specific records on request from authorised tenant contact
Information security records
ISMS policies; Statement of Applicability; risk register; access logs; audit logs; incident register; vulnerability scan reports; backup logs; security awareness training records
No
No (security-sensitive)
Data protection records
POPIA processing register; data subject request log; breach register; consent records; data processing agreements with sub-processors
No
Subject access requests only
Vendor and sub-processor records
Cloud service provider agreements (e.g. AWS, GitHub, Sentry); software licence records; supplier due diligence records
No
No
Statutory and governance records
Memorandum of Incorporation; CIPC filings; share register; director resolutions; board minutes
No
Yes (subject to Companies Act)
08HOW TO SUBMIT A REQUEST FOR ACCESS
This section describes how a requester may request access to a record held by Arcaidea (Pty) Ltd. A request is made to the Information Officer, whose contact details appear in paragraph 3.
8.1 Form of request
A requester must complete the prescribed form (Form 2: Request for Access to Record of a Private Body) under the PAIA Regulations and submit it to the Information Officer. A request must:
- provide sufficient detail to enable the Information Officer to identify both the record(s) requested and the requester;
- identify the right that the requester seeks to exercise or protect, and explain why the requested record is required for the exercise or protection of that right, as contemplated in section 50 of PAIA;
- specify the form of access required and the manner in which the requester wishes to be notified of the decision;
- where the request is made on behalf of another person, be accompanied by proof of the capacity in which the requester is acting, to the satisfaction of the Information Officer.
8.2 Fees
- A personal requester (a person requesting a record that contains their own personal information) is not required to pay a request fee.
- Any other requester must pay the prescribed request fee before the request is processed. The Information Officer will notify the requester in writing of the amount payable.
- Where access is granted, an access fee is payable for the reproduction of the record and for the search and preparation time that exceeds the prescribed free hours.
- The applicable request and access fees are those prescribed by the Minister from time to time in the PAIA Regulations. The Information Officer will provide the requester with the current fees on request.
8.3 Decision period
The Information Officer will decide on a request within 30 days of receipt of a compliant request, unless that period is lawfully extended in terms of PAIA. The requester will be notified of the decision and, where access is refused, of the grounds for the refusal and of the remedies available.
8.4 Grounds for refusal
Access to a record may be refused only on the grounds set out in Chapter 4 of Part 3 of PAIA. These include the mandatory protection of the privacy of third parties who are natural persons, the commercial information of third parties, information disclosed in confidence, and records that are privileged from production in legal proceedings.
8.5 Remedies
Arcaidea (Pty) Ltd is a private body. PAIA does not provide for an internal appeal against a decision of a private body. A requester who is dissatisfied with a decision may:
- lodge a complaint with the Information Regulator using the prescribed form (Form 5: Complaint to the Information Regulator); or
- apply to a court for appropriate relief in terms of PAIA.
09PROCESSING OF PERSONAL INFORMATION
9.1 Purpose of Processing Personal Information
- Confirmation of details of employees, clients and service providers vital to the prevention of fraud, as well as for communicative purposes.
- Performance of contractual obligations under customer subscription agreements and data processing agreements, including the licensing, hosting, support and ongoing development of the Arcaidea SaaS platform;
- Authentication and access control for the Arcaidea platform (including multi-tenant role-based access control, multi-factor authentication, and session management);
- Compliance with statutory and regulatory obligations including POPIA, the Companies Act, the Basic Conditions of Employment Act, and tax legislation;
- Recruitment, selection, onboarding, payroll, performance management and ongoing employment administration of staff;
- Information security and incident response, including the operation of an Information Security Management System aligned to ISO/IEC 27001:2022;
- Internal management, reporting and audit purposes.
9.2 Description of the categories of Data Subjects and of the information or categories of information relating thereto
Categories of Data Subjects
Personal Information that may be processed
Customers (subscribing tenant organisations)
Name, address, registration numbers or identity numbers, employment status and bank details
Service Providers
Names, registration number, VAT numbers, address, trade secrets and bank details
Employees and contractors
Full name, ID/passport number, date of birth, contact details, residential and postal address, banking details, tax reference number, salary and payroll data, employment contract terms, qualifications, certifications, performance records, leave records, next of kin, beneficiary details, disciplinary records, training and development records
Arcaidea platform end-users (tenant-side users)
Username, email address, hashed credentials (bcrypt), authentication tokens (JWT/OTP), role and permission assignments, IP address, session metadata, audit-log activity, and any further data captured under the relevant customer's data processing agreement
Job applicants
CV, contact details, qualifications, references, interview notes, right-to-work documentation
Directors and shareholders
Full name, ID number, contact details, share register entries, director declarations
Website visitors and marketing prospects
IP address, browser metadata, cookie identifiers, contact details voluntarily submitted via web forms
9.3 The recipients or categories of recipients to whom the personal information may be supplied
Category of personal information
Recipients or Categories of Recipients
Identity number and names, for criminal checks
South African Police Services
Qualifications, for qualification verifications
South African Qualifications Authority (SAQA)
Credit and payment history
Registered credit bureaus
Employee tax, payroll and statutory data
South African Revenue Service (SARS); Department of Employment and Labour (UIF); Compensation Fund; relevant SETA; medical aid and provident fund administrators
Personal information processed on behalf of Arcaidea (operators / sub-processors)
Cloud hosting and infrastructure providers (Amazon Web Services, Microsoft Azure, Google Cloud Platform); source code hosting (GitHub); productivity and collaboration tools; vulnerability monitoring and observability tools (e.g. Snyk, Sentry); accounting and payroll service providers; recruitment platforms — each governed by a written operator / data processing agreement
Arcaidea platform end-user personal information
Processed strictly on behalf of and on documented instructions from the subscribing customer (who is the responsible party for its own tenant data), in accordance with the applicable data processing agreement and POPIA section 21
Statutory and regulatory recipients
Companies and Intellectual Property Commission (CIPC); Information Regulator (South Africa); auditors and legal advisors under professional duty of confidentiality
Banking and financial recipients
Authorised commercial banks for payment processing and salary disbursement
9.4 Planned transborder flows of personal information
Arcaidea may transfer personal information outside the Republic of South Africa in the following circumstances:
- Transfers to cloud infrastructure providers (Amazon Web Services, Microsoft Azure, Google Cloud Platform) which may host data in regions outside South Africa, subject to the relevant provider's standard contractual safeguards;
- Transfers to source-code hosting, observability and security-scanning tools (e.g. GitHub, Sentry, Snyk) used by the engineering teams;
- Transfers to Thentic Labs B.V. (Netherlands), the intra-group entity that holds the platform intellectual property and from which Arcaidea licenses the platform, where personnel based in the Netherlands process limited personal information (including staff, contractor and platform operational data) for development, support and maintenance purposes. The Netherlands provides a level of data protection substantially similar to that required under POPIA;
- Transfers to or from subscribing customers located outside South Africa in the course of providing the Arcaidea SaaS platform, subject to the relevant subscription agreement and data processing agreement.
All transborder flows are subject to the conditions set out in section 72 of POPIA. Transfers are made on the basis that the recipient is bound by binding corporate rules, standard contractual clauses, or the consent of the data subject, and that the recipient is subject to a level of protection that is substantially similar to that provided under POPIA.
9.5 General description of Information Security Measures to ensure the confidentiality, integrity and availability of personal information
Arcaidea operates an Information Security Management System aligned to ISO/IEC 27001:2022. A Statement of Applicability is maintained which records the Annex A controls implemented across organisational, people, physical and technological domains. The security measures described below are kept under continuous review and are summarised here in general terms only, in accordance with section 51(1)(d) of PAIA and section 19 of POPIA.
Organisational controls:
- Documented information security, data handling, access management, password, remote work, and AI tooling policies, reviewed periodically;
- Designated Information Officer and Deputy Information Officer / Data Officer;
- Confidentiality and acceptable-use undertakings in all employment and contractor agreements;
- Documented incident response and breach notification procedures;
- Documented data processing agreements with clients (as operator) and sub-processors (as responsible party);
- Periodic supplier due-diligence and tooling approval (CIO sign-off required for new tools).
People controls:
- Background and reference checks at appointment;
- Mandatory security awareness training and acknowledgement of the data handling policy;
- Internal initiatives such as the "Night Watchman" rotational security focus and the CBT Academy training programme;
- Formal joiner / mover / leaver process including timely revocation of access on termination.
Physical controls:
- Office access controls at the registered head office;
- Clear-desk and clear-screen policy;
- Production infrastructure is cloud-hosted; physical server controls are provided by the underlying cloud service providers under their own certified security programmes;
- Hard-copy records, where retained, are stored in secure locations with restricted access.
Technological controls:
- Role-based access control (RBAC) on all production systems, with least-privilege as the default;
- Multi-factor authentication on administrative and privileged accounts;
- Secure software development lifecycle, including peer code review (branch protection with mandatory approvals), automated linting, secret-scanning, and dependency vulnerability monitoring (e.g. Snyk, Dependabot);
- Encryption of credentials at rest using bcrypt; session and sensitive-action security using JWT and OTP mechanisms;
- Encryption of production databases at rest and TLS for data in transit;
- Segregation of development, UAT and production environments and segregation of duties on production releases;
- Centralised logging, monitoring and alerting on security-relevant events;
- Endpoint protection, anti-malware and patch management across user devices;
- Backups, with documented retention, restoration testing and geo-redundancy considerations;
- Data masking and anonymisation in non-production environments where personal information would otherwise be exposed.
Arcaidea will, at the request of a data subject and to the extent permitted under PAIA and POPIA, provide further information about the technical and organisational measures applied to the processing of that data subject's personal information.
10AVAILABILITY OF THE MANUAL
A copy of the Manual is available-
- Upon written request emailed to info@arcaidea.ai;
- At the head office of Arcaidea (Pty) Ltd for public inspection during normal business hours;
- To any person upon request and upon the payment of a reasonable prescribed fee;
- To the Information Regulator upon request;
- On the Arcaidea website at www.arcaidea.ai, as a downloadable PDF.
A fee for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made.
11UPDATING OF THE MANUAL
The head of Arcaidea (Pty) Ltd will review this Manual at least annually, and additionally upon any material change to the business, its processing activities, or the regulatory environment. The reviewed Manual will be published on the company website and made available for public inspection as set out in section 10 above. This Manual is not required to be submitted to the Information Regulator; it must be kept current and publicly accessible. Separately, and as a distinct obligation, the head of the private body (or a duly designated Deputy Information Officer registered with the Information Regulator) submits an annual report to the Information Regulator, in terms of section 83(4) of PAIA, on the access to information requests received and processed by Arcaidea (Pty) Ltd during each reporting period (1 April to 31 March), through the Regulator’s eServices portal.