PAIA s14 manual · POPIA s51
POPIA Information Manual
The PAIA section 14 / POPIA section 51 manual for {{LEGAL_ENTITY}}, covering the records we hold and how to request access. Draft for Legal Review — pending attorney sign-off.
Effective date: {{EFFECTIVE_DATE}}
This manual is effective from {{EFFECTIVE_DATE}} and is reviewed periodically.
1. About this manual
This manual is published in terms of section 14 of the Promotion of Access to Information Act 2 of 2000 (PAIA), as read with the Protection of Personal Information Act 4 of 2013 (POPIA). It describes the personal information and records held by {{LEGAL_ENTITY}} in connection with the Serve Station Job Card System, and how to request access to them.
2. Particulars of the body
- Legal entity
{{LEGAL_ENTITY}}- Registration number
{{REG_NUMBER}}- Registered address
{{REGISTERED_ADDRESS}}
3. Information Officer (POPIA s55 / PAIA contact)
- Information Officer
{{IO_NAME}}{{IO_EMAIL}}- Telephone
{{IO_PHONE}}- Postal / physical address
{{REGISTERED_ADDRESS}}
The Information Officer is (or will be) registered with the Information Regulator in terms of POPIA.
4. Records held
The following categories of records are processed through the Service:
- Organisation (tenant) and user account records — names, work emails, roles.
- Job-card records — job details, site addresses, customer name and contact details, technician notes and checklist results.
- Media — work photographs and captured customer signatures.
- Consent records — the immutable consent captured at sign-off.
- Security records — append-only audit logs (actor, IP address, user-agent, timestamp).
5. Operators & sub-operators (POPIA s20–21, s72)
Customer data is hosted in South Africa (af-south-1). The operators that process personal information on our behalf, and the cross-border basis where applicable, are:
| Operator | Service | Data location | Transfer basis |
|---|---|---|---|
| Supabase | Database, object storage, realtime | South Africa — af-south-1 (Cape Town) | In-country |
| Clerk | Authentication / session management | Offshore | POPIA s72 |
| Sentry | Error monitoring (PII scrubbed) | Offshore | POPIA s72 |
| Vercel | Application hosting / edge network | Offshore | POPIA s72 |
| GitHub | Source control / deployment pipeline | Offshore | POPIA s72 |
Offshore transfers are made under section 72 of POPIA on the basis of binding contractual terms. The DPA-signed status of each operator is tracked in the internal sub-operator register.
6. How to request access (PAIA)
- Complete the prescribed PAIA request form (Form 2 / the Regulator's current form).
- Send it to the Information Officer at
{{IO_EMAIL}}, with proof of identity. - Pay the prescribed request and access fees where applicable.
- We respond within the periods prescribed by PAIA (ordinarily 30 days), and may extend or refuse access only on the grounds permitted by PAIA.
Data-subject requests under POPIA (access, correction, deletion) are handled per our Privacy Policy within a 30-day service level.
7. Retention
Records are retained for an owner-justified retention period ({{owner-justified period}}) or as required by law, after which the record and any associated stored file are deleted while preserving the audit trail.
8. The Information Regulator
The Information Regulator (South Africa): JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. PAIA: PAIAComplaints@inforegulator.org.za · POPIA: POPIAComplaints@inforegulator.org.za.