PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended · Date of compilation/revision: 9 September 2026 · Version 10
On this page
1. Acronyms and definitions
CIPC — Companies and Intellectual Property Commission.
CPA — Consumer Protection Act 68 of 2008.
ECTA — Electronic Communications and Transactions Act 25 of
2002.
HPCSA — Health Professions Council of South Africa.
IO — Information Officer.
PAIA — Promotion of Access to Information Act 2 of 2000, as
amended.
POPIA — Protection of Personal Information Act 4 of 2013.
Regulator — Information Regulator of South Africa.
2. Purpose of this manual
This manual is published by IndunAI (by In-House IT) as a private body for purposes of section 51 of PAIA. It is intended to help members of the public understand the categories of records we hold, the records available without a formal request, records available under other legislation, how we process personal information, and how a person may request access to a record.
Under section 50 of PAIA, access to a record of a private body may be required where the record is needed for the exercise or protection of a right, the requester complies with the procedural requirements, and no ground of refusal applies. A person seeking access to their own personal information may also have rights under section 23 of POPIA.
3. Details of the private body and Information Officer
Private body: In House It (Pty) Ltd
(registration number 2024/456850/07), trading as IndunAI, a
private company incorporated in the Republic of South Africa and registered
with the Companies and Intellectual Property Commission (CIPC).
Head of the private body / Information Officer:
Angus Baumgardt.
Deputy Information Officer: none currently designated.
Physical and postal address: 47 Moss Road, Ocean View, Durban, KwaZulu-Natal, 4052.
Telephone / WhatsApp: +27 76 786 4417.
Email for PAIA and POPIA requests:
angus@indunai.co.za.
Website: indunai.co.za.
4. The Information Regulator's PAIA Guide
The Information Regulator has published a Guide in terms of section 10 of PAIA explaining how to exercise rights under PAIA and POPIA, the forms and procedures used for requests, available assistance, applicable fees and remedies.
The Guide is available from the Information Regulator at inforegulator.org.za/paia and through the Regulator's offices. At the date of this manual the Regulator's principal contact details are Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, South Africa, telephone 010 023 5200 and enquiries@inforegulator.org.za.
A requester may also ask the Information Officer for reasonable assistance in locating the Guide or the prescribed forms.
5. Records available without a formal PAIA request
No formal section 52 notice is relied on for this manual unless one is separately published. The following records are nevertheless voluntarily available without a formal PAIA request, subject to reasonable website availability:
- Our privacy policy.
- The platform's client terms of service.
- This PAIA manual.
- Public website content, published product information and public marketing material.
- Public social-media content we have published.
- Your own upcoming booking details, which the assistant can confirm in the same conversation channel you booked on, subject to the ordinary checks that you are the person who made the booking.
6. Records available in accordance with other legislation
Where applicable to us, records may be created, retained, disclosed or accessed under legislation including the following. This list is not exhaustive, and inclusion does not mean that every record is automatically available to every requester.
| Legislation | Examples of relevant records |
|---|---|
| Companies Act 71 of 2008 | Company incorporation, statutory and corporate records |
| Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011 | Tax, accounting and supporting financial records |
| Value-Added Tax Act 89 of 1991 | VAT records and tax invoices, where applicable |
| Electronic Communications and Transactions Act 25 of 2002 | Electronic transaction, supplier and service records |
| Consumer Protection Act 68 of 2008 | Consumer, complaint and direct-marketing compliance records, where applicable |
| Protection of Personal Information Act 4 of 2013 | Privacy, data-subject, operator, security and Information Officer records |
| Promotion of Access to Information Act 2 of 2000 | PAIA requests, decisions, fees and related correspondence |
| Basic Conditions of Employment Act 75 of 1997 | Employment records, where applicable |
| Labour Relations Act 66 of 1995 | Employment and labour-relations records, where applicable |
| Unemployment Insurance Act 63 of 2001 and related legislation | UIF records, where applicable |
| Compensation for Occupational Injuries and Diseases Act 130 of 1993 | Employment and compensation records, where applicable |
7. Subjects on which we hold records, and categories of records
- Corporate and governance: CIPC and incorporation records, the Memorandum of Incorporation and company statutory records, policies, registers and governance records, Information Officer and compliance records.
- Clients and commercial relationships: proposals, quotations, orders and contracts, subscription and account records, Client contact and onboarding information, configuration, implementation and support records, usage, billing, invoicing and payment records.
- Platform and service operations: Instance configuration and system settings, audit, access, security and operational logs, support tickets and troubleshooting records, backup and disaster-recovery records, incident and security-compromise records, integration and API configuration records.
- Client-controlled customer and patient data processed as operator: names and contact details, webchat, WhatsApp and email conversations, voice notes and transcriptions, images and files supplied during conversations, appointment, rescheduling and cancellation records, calendar information, qualification or intake answers, addresses supplied for appointments or dispatch, quotes, invoices and payment confirmations, and CRM synchronisation records where a Client enables an integration.
- Marketing and communications: campaign records, consent and lawful-basis records, opt-out, unsubscribe and suppression records, and published marketing content and its performance.
- Suppliers and service providers: supplier contracts and data-processing agreements, cloud, hosting, AI, messaging, calendar, email, payment, backup and integration provider records, supplier invoices and payment records.
- PAIA, POPIA and regulatory: access, correction, deletion and objection requests, PAIA request forms and decisions, Regulator correspondence, risk assessments, security reviews and compliance documentation.
- Intellectual property: software, source code and technical documentation, designs, artwork, brands, trademarks and domain records.
8. Processing of personal information
8.1 Purposes of processing
Answering enquiries and support requests; operating the AI assistant; managing appointments, reminders, administrative workflows and connected services; providing quotes, invoices, account administration and payment reconciliation; securing systems, preventing abuse, investigating incidents and maintaining backups; complying with legal, tax, regulatory and contractual obligations; managing suppliers, contractors and business relationships; conducting lawful direct marketing and maintaining opt-out records; and improving service reliability and quality in a manner consistent with POPIA and applicable professional duties.
8.2 Categories of data subjects and information
| Category of data subject | Personal Information that may be processed |
|---|---|
| IndunAI Clients and authorised users | Names, contact details, business details, account identifiers, subscription, support, billing and payment records |
| Prospective Clients | Names, contact details, business information, enquiries, demo and proposal records |
| Customers and prospective customers | Names, telephone numbers, email addresses, conversation content, files, addresses, appointments, service enquiries, quotes and related records |
| Website visitors and chat users | Network (IP) information, session identifiers, messages, approximate network-derived location and technical/security information |
| Suppliers and service providers | Names, business details, registration/tax information, contact details, bank/payment information and contracts |
| Employees, contractors and applicants, where applicable | Identity/contact information, qualifications, employment and payroll information, statutory employment records |
| Direct-marketing recipients | Contact details, consent/lawful-basis records, campaign records, opt-outs and suppression information |
| Regulators, complainants and requesters | Identity/contact information and records relevant to PAIA, POPIA, complaints or regulatory correspondence |
Conversation content, appointment details.
8.3 Recipients or categories of recipients
Personal information may be supplied to the following where necessary, lawful and appropriate: our own authorised team and contractors; In House It (Pty) Ltd as our POPIA operator (hosting, in Johannesburg); the AI provider that generates the assistant's replies, our own account with OpenAI (message content and voice notes, to generate replies and transcribe); Meta Platforms in the United States and Ireland where WhatsApp is used (WhatsApp also carries the alerts our own team receives about enquiries and bookings, whichever channel the customer used); Google, where bookings are placed in our calendar; ipwho.is (a web-chat visitor's network address alone); OpenStreetMap's Nominatim service in Germany (street addresses only, for call-out dispatch); PayFast (Pty) Ltd where a customer pays an invoice online; encrypted backup and disaster-recovery providers; professional advisers, insurers, auditors, banks and accountants where reasonably necessary; and courts, law-enforcement bodies, regulators or public authorities where disclosure is required or permitted by law.
8.4 Planned transborder flows of personal information
Some processing occurs outside South Africa. The planned or possible flows are:
| Provider category | Information that may flow | Possible locations / basis |
|---|---|---|
| AI providers | Message content, relevant conversation context, voice-note audio/transcriptions and permitted files | May include the United States or other provider locations; transfer governed by section 72 of POPIA and applicable contractual safeguards |
| Meta / WhatsApp | WhatsApp identifiers and message content | May include Ireland, the United States and other Meta processing locations |
| Calendar provider | Booking, contact and message information where connected | May be processed in provider cloud regions outside South Africa |
| Encrypted backup providers | Encrypted backup copies | May be stored outside South Africa; access is restricted and encryption is applied |
| Approximate-location and geocoding services | A web-chat visitor's network address alone, or a street address alone for call-out dispatch | Processed outside South Africa; no name or contact details accompany either |
Transfers outside South Africa are assessed under section 72 of POPIA, on the basis of each provider's data-processing terms read with the necessity of the transfer to perform what the data subject asked for. For health information, children's information or other special processing, prior authorisation from the Regulator may be required in specific circumstances. Our privacy policy sets this out in full.
8.5 General description of information-security measures
Isolated environment and credential separation; encrypted network transport; role-based and need-to-know access restrictions; authentication and credential controls; logging and security monitoring; nightly backups encrypted before they leave the server, with an encrypted copy held off-site (Microsoft OneDrive) that cannot be read without our key; software maintenance and security updates; incident-response and breach-notification procedures; confidentiality obligations for authorised personnel and operators; and risk-based review of service providers and data flows. Security measures are adjusted according to the nature, volume and sensitivity of the personal information and the reasonably foreseeable risks.
8.6 How long records are kept
Conversation and booking records are kept for as long as we are using them to run this service and to keep an ordinary record of our dealings with you. We have not set an automatic deletion date for them, so they are removed when we no longer need them, when this service ends, or when you ask us to delete them. Invoices and payment records are kept for the period tax and company law requires, generally five years. Full detail is in our privacy policy.
9. Responsible-party and operator roles
For our own website visitors, leads, Clients, billing and support records, In House It (Pty) Ltd ordinarily acts as the responsible party.
Where a Client uses IndunAI to communicate with that Client's own customers or patients, the Client ordinarily acts as the responsible party and In House It (Pty) Ltd acts as that Client's operator. In those circumstances the Client determines the lawful purpose and legal basis for the processing, and we process the information under the Client's lawful instructions, subject to POPIA and the applicable contract. A request about information we hold only as an operator may be referred to, or coordinated with, that Client.
10. How to request access to a record
A requester seeking a record under PAIA should use the prescribed Form 02, Request for Access to Record (Annexure A to the PAIA Regulations, 2021), available from inforegulator.org.za/paia. The completed form may be sent to angus@indunai.co.za.
The requester should provide enough information to enable the Information Officer to identify the requester and, where applicable, the person on whose behalf the request is made; identify the requested record with reasonable specificity; understand the right the requester seeks to exercise or protect and why the record is required for that purpose, unless a different statutory access right applies; identify the preferred form of access; contact the requester; and verify authority where the requester acts on behalf of another person.
Where a requester cannot complete the prescribed form because of disability, illiteracy or another genuine difficulty, the requester should contact the Information Officer for reasonable assistance.
11. Requests for your own personal information under POPIA
A data subject may request confirmation of whether we hold personal information about them, and may request access to it, in accordance with section 23 of POPIA, subject to the applicable provisions of PAIA.
Confirmation under section 23(1)(a) is free of charge. Access to a record or description under section 23(1)(b) is subject to any prescribed fee, if applicable; where a fee is payable the requester will be informed in accordance with law. Where the requested personal information is held by us only as the operator for a Client, we may refer or coordinate the request with that Client, because the Client is ordinarily the responsible party.
12. Fees
The fees prescribed in Annexure B to the PAIA Regulations, 2021, as amended from time to time, apply to PAIA requests where legally payable. The Information Officer will give the required notice of the request fee, access fee, reproduction fee, deposit or other prescribed amount before requiring payment.
The request fee (currently R140) is payable by every requester of a private body's record, plus reproduction fees. If you are asking for your own personal information, you can instead use your separate right of access under section 23 of POPIA: confirmation that we hold information about you is free of charge, and no fee is prescribed for access to your own information.
The current prescribed forms and fee schedule should be obtained from the Information Regulator at inforegulator.org.za/paia.
13. Time periods, extensions and third-party notices
The Information Officer will ordinarily decide a PAIA request within 30 days after receipt of a valid request, subject to any lawful extension.
The period may be extended once, by not more than 30 additional days, in circumstances permitted by PAIA, including where a large number of records is involved, records must be searched for at another location, consultation is reasonably necessary, or the requester agrees to an extension.
Where a requested record concerns a third party, PAIA's third-party notification and representation procedures may apply before a decision is made. Where applicable, the outcome and any fees payable will be communicated using the prescribed Form 03 or another legally accepted notice.
14. Grounds for refusal and severability
Access may be refused where PAIA requires or permits refusal, including where disclosure would unlawfully invade another person's privacy, reveal protected confidential or commercial information, compromise safety or security, disclose legally privileged material, or fall within another statutory ground of refusal.
Where only part of a record is protected, any part of it that can reasonably be severed from the protected part, and is not itself protected, must be disclosed (section 59).
15. Remedies
A private body does not have the same internal-appeal process that applies to certain public bodies. If a request is refused, deemed refused or otherwise not handled lawfully, a requester may use the remedies available under PAIA.
A requester may lodge a complaint with the Information Regulator using the prescribed Form 05 of the PAIA Regulations, 2021, generally within 180 days (section 77A). Once that complaints procedure has been exhausted, section 78 allows a requester to apply to a court with jurisdiction. Regulator resources, complaint channels and current forms are available at inforegulator.org.za/paia.
16. Availability of this manual
This manual is available electronically at this address and may be requested from angus@indunai.co.za. A printed copy may be inspected by prior arrangement with the Information Officer during reasonable business hours. Copies may be supplied subject to any prescribed or reasonable reproduction fee permitted by PAIA and the Regulations. A copy will be supplied to the Information Regulator where legally required or requested.
17. Updating this manual
The Information Officer will review and update this manual when material facts, processing activities, service providers, legislation or regulatory requirements change.
18. Issued by
Angus Baumgardt
Information Officer
In House It (Pty) Ltd
Requests and questions: angus@indunai.co.za
Telephone / WhatsApp: +27 76 786 4417