Legal
PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended)
DATE OF COMPILATION: 03/07/2026 DATE OF REVISION: 03/07/2026
1. LIST OF ACRONYMS AND ABBREVIATIONS
1.1 “CEO” Chief Executive Officer
1.2 “DIO” Deputy Information Officer;
1.3 “IO“ Information Officer;
1.4 “Minister” Minister of Justice and Correctional Services;
1.5 “PAIA” Promotion of Access to Information Act No. 2 of 2000( as Amended;
1.6 “POPIA” Protection of Personal Information Act No.4 of 2013;
1.7 “Regulator” Information Regulator; and
1.8 “Republic” Republic of South Africa
2. PURPOSE OF PAIA MANUAL
This PAIA Manual is useful for the public to-
2.1 check the categories of records held by a body which are available without a person having to submit a formal PAIA request;
2.2 have a sufficient understanding of how to make a request for access to a record of the body, by providing a description of the subjects on which the body holds records and the categories of records held on each subject;
2.3 know the description of the records of the body which are available in accordance with any other legislation;
2.4 access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;
2.5 know the description of the guide on how to use PAIA, as updated by the Regulator and how to obtain access to it;
2.6 know if the body will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;
2.7 know the description of the categories of data subjects and of the information or categories of information relating thereto;
2.8 know the recipients or categories of recipients to whom the personal information may be supplied;
2.9 know if the body has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and
2.10 know whether the body has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
3. KEY CONTACT DETAILS FOR ACCESS TO INFORMATION OF FREEBYTE
3.1. Chief Information Officer Name: FreeByte Proprietary Limited Tel: +27761423733 Email: info@free-byte.com
3.2 Access to information general contacts Email: info@free-byte.com
3.3 National or Head Office Postal Address: 27 Hartzenbergfontein Estate Hartzenbergfontein Walkerville Gauteng 1961 Physical Address: 27 Hartzenbergfontein Estate Hartzenbergfontein Walkerville Gauteng 1961 Telephone: +27761423733 Email: info@free-byte.com Website: www.free-byte.com
4. GUIDE ON HOW TO USE PAIA AND HOW TO OBTAIN ACCESS TO THE GUIDE
4.1. The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
4.2. The Guide is available in each of the official languages and in braille.
4.3. The aforesaid Guide contains the description of-
4.3.1. the objects of PAIA and POPIA;
4.3.2. the postal and street address, phone and fax number and, if available, electronic mail address of-
4.3.2.1. the Information Officer of every public body, and
4.3.2.2. every Deputy Information Officer of every public and private body designated in terms of section 17(1) of PAIA1 and section 56 of POPIA2;
4.3.3. the manner and form of a request for-
4.3.3.1. access to a record of a public body contemplated in section 113; and
4.3.3.2. access to a record of a private body contemplated in section 504;
4.3.4. the assistance available from the IO of a public body in terms of PAIA and POPIA;
4.3.5. the assistance available from the Regulator in terms of PAIA and POPIA;
4.3.6. all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging-
4.3.6.1. an internal appeal;
4.3.6.2. a complaint to the Regulator; and
4.3.6.3. an application with a court against a decision by the information officer of a public body, a decision on internal appeal or a decision by the Regulator or a decision of the head of a private body;
- the provisions of sections 145 and 516 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;
- the provisions of sections 157 and 528 providing for the voluntary disclosure of categories of records by a public body and private body, respectively;
- the notices issued in terms of sections 229 and 5410 regarding fees to be paid in relation to requests for access; and
- the regulations made in terms of section 9211.
- Section 17(1) of PAIA- For the purposes of PAIA, each public body must, subject to legislation governing the employment of personnel of the public body concerned, designate such number of persons as deputy information officers as are necessary to render the public body as accessible as reasonably possible for requesters of its records.
- Section 56(a) of POPIA- Each public and private body must make provision, in the manner prescribed in section 17 of the Promotion of Access to Information Act, with the necessary changes, for the designation of such a number of persons, if any, as deputy information officers as is necessary to perform the duties and responsibilities as set out in section 55(1) of POPIA.
- Section 11(1) of PAIA- A requester must be given access to a record of a public body if that requester complies with all the procedural requirements in PAIA relating to a request for access to that record; and access to that record is not refused in terms of any ground for refusal contemplated in Chapter 4 of this Part.
- Section 50(1) of PAIA- A requester must be given access to any record of a private body if-
- that record is required for the exercise or protection of any rights;
- that person complies with the procedural requirements in PAIA relating to a request for access to that record; and
- access to that record is not refused in terms of any ground for refusal contemplated in Chapter 4 of this Part.
- Members of the public can inspect or make copies of the Guide from the offices of the public and private bodies, including the office of the Regulator, during normal working hours.
- The Guide can also be obtained-
- upon request to the Information Officer;
- from the website of the Regulator (https://www.justice.gov.za/inforeg/).
4.6 A copy of the Guide is available in English, for public inspection during normal office hours.
- Section 14(1) of PAIA- The information officer of a public body must, in at least three official languages, make available a manual containing information listed in paragraph 4 above.
- Section 51(1) of PAIA- The head of a private body must make available a manual containing the description of the information listed in paragraph 4 above.
- Section 15(1) of PAIA- The information officer of a public body, must make available in the prescribed manner a description of the categories of records of the public body that are automatically available without a person having to request access
- Section 52(1) of PAIA- The head of a private body may, on a voluntary basis, make available in the prescribed manner a description of the categories of records of the private body that are automatically available without a person having to request access
- Section 22(1) of PAIA- The information officer of a public body to whom a request for access is made, must by notice require the requester to pay the prescribed request fee (if any), before further processing the request.
- Section 54(1) of PAIA- The head of a private body to whom a request for access is made must by notice require the requester to pay the prescribed request fee (if any), before further processing the request.
- Section 92(1) of PAIA provides that –“The Minister may, by notice in the Gazette, make regulations regarding- (a) any matter which is required or permitted by this Act to be prescribed;
- any matter relating to the fees contemplated in sections 22 and 54;
- any notice required by this Act;
- uniform criteria to be applied by the information officer of a public body when deciding which categories of records are to be made available in terms of section 15; and
- any administrative or procedural matter necessary to give effect to the provisions of this Act.”
5. CATEGORIES OF RECORDS OF THE FREEBYTE WHICH ARE AVAILABLE WITHOUT A PERSON HAVING TO REQUEST ACCESS
| Category of records | Types of the Record | Available on Website | Available upon request |
|---|---|---|---|
| Corporate & General Information | Company registration details, general contact information. | X | X |
| Policies & Terms | Privacy Policy, Terms of Use, Cookie Policy, Acceptable Use Policy. | X | X |
| Marketing & Public Relations | Product descriptions, service brochures, newsletters, press releases. | X | X |
| Customer Support Guides | Frequently Asked Questions (FAQs), public knowledge base, user manuals. | X | X |
6. DESCRIPTION OF THE RECORDS OF FREEBYTEWHICH ARE AVAILABLE IN ACCORDANCE WITH ANY OTHER LEGISLATION
| Category of Records | Applicable Legislation |
|---|---|
| Memorandum of incorporation | Companies Act 71 of 2008 |
| PAIA Manual | Promotion of Access to Information Act 2 of 2000 |
| Tax returns, financial statements, accounting records | Income Tax Act No. 58 of 1962 |
| VAT returns, invoices, export/import documentation | Value Added Tax Act No. 89 of 1991 |
| Electronic transaction logs, e-commerce compliance records, domain name registrations. | Electronic Communications and Transactions Act No. 25 of 2002 |
7. DESCRIPTION OF THE SUBJECTS ON WHICH THE BODY HOLDS RECORDS AND CATEGORIES OF RECORDS HELD ON EACH SUBJECT BY THE FREEBYTE
| Subjects on which the body holds records | Categories of records | |
|---|---|---|
| Strategic Documents, Plans, Proposals | Annual Reports, Strategic Plan, Performance Plan. | Annual |
| Human Resources | HR policies and procedures Advertised posts Employees records | |
| Information Technology (IT) & Security | System architecture documentation Network security policies Software licenses, access and authentication logs, incident response plans, data backup logs | |
| Sales, Marketing & PR | Marketing strategies, branding materials Press releases Market research data, campaign reports Vendor contract |
8. PROCESSING OF PERSONAL INFORMATION
8.1 Purpose of Processing Personal Information
FREEBYTE processes personal information only for specific, lawful, and legitimate business purposes. The primary purposes for which personal information is processed include, but are not limited to:
- Provision of Services: To deliver, operate, maintain, and improve our software applications, cloud platforms, and related technological services.
- Client and Account Management: To create and manage user accounts, authenticate users, verify identities, and provide ongoing customer support and troubleshooting.
- Administrative and Financial Purposes: To process transactions, issue invoices, manage billing, conduct financial reporting, and maintain commercial records.
- Security and IT Operations: To monitor system performance, detect, prevent, and mitigate fraud, unauthorized access, or cyber threats, and to ensure the overall security of our network and physical infrastructure.
- Communications and Marketing: To send administrative notices, technical alerts, updates, and (where legally permissible or with consent) marketing communications regarding our products and services.
- Human Resources and Employment: To manage the recruitment process, administer employment contracts, process payroll, provide employee benefits, and evaluate performance.
- Legal and Regulatory Compliance: To fulfil statutory obligations under applicable South African laws (e.g., tax, labour, and company laws), enforce our terms of service, and cooperate with legal or regulatory authorities when required.
8.2 Description of the categories of Data Subjects and of the information or categories of information relating thereto
| Categories of Data Subjects | Personal Information that may be processed |
|---|---|
| Customers / Clients | Personal Details: Name and surname, gender. Contact Details: Physical and postal address, telephone number, email address. Account & Transactional Data: Username/passwords, billing information, payment records, service usage history, and support correspondence. |
| Service Providers, Suppliers, and Vendors | Corporate Details: Company registration numbers, VAT numbers, physical and postal addresses. Contact Person Data: Names, telephone numbers, and email addresses of account managers or representatives. Financial Data: Bank account details, invoices, and payment histories. |
| Employees, Directors, and Job Applicants | Identity & Background: Identity numbers, passport details, date of birth, CVs, educational qualifications, background checks. Employment Records: Employment contracts, payroll and remuneration details, bank account numbers, tax numbers, leave records, performance reviews, and disciplinary records. |
| Website Visitors and App Users | Technical & Usage Data: IP addresses, browser types, cookie identifiers, device information, and navigation patterns on the FREEBYTE platform. |
8.3 The recipients or categories of recipients to whom the personal information may be supplied
| Category of personal information | Recipients or Categories of Recipients to whom the personal information may be supplied |
|---|---|
| All Categories of Data (Hosted & Backed Up) | Cloud infrastructure and storage providers (e.g., Amazon Web Services - AWS), data center operators, and disaster recovery service providers. |
| Customer / Client Personal Details | Customer Relationship Management (CRM) platforms, helpdesk software providers, and marketing communication platforms (if consent is provided). |
| Financial and Billing Information | Payment gateways, commercial banks, financial institutions, debt collection agencies, and external financial auditors. |
| Employee Information | South African Revenue Service (SARS), Department of Employment and Labour, payroll administrators, pension/provident funds, and medical aid schemes. |
| Any applicable data subject to legal request | Law enforcement agencies, regulatory bodies (e.g., the Information Regulator), statutory bodies, and external legal advisors when required by law or for the protection of legal rights. |
8.4 Planned transborder flows of personal information
FREEBYTE transfers and stores certain personal information outside the Republic of South Africa for the purposes of cloud hosting, data backup, and system resilience. Specifically, personal information—listed under Article 8.2.—is transferred to and hosted on servers operated by Amazon Web Services (AWS)
located in the United States of America.
8.5 General description of Information Security Measures to be implemented by the responsible party to ensure the confidentiality, integrity and availability of the information
1. Technical and Organizational Measures FREEBYTE implements and maintains comprehensive technical and organizational measures to ensure the confidentiality, integrity, and availability of personal data processed within its managed cloud infrastructure. All personal data is hosted in a secure, serverless environment, supported by rigorous physical security and environmental hazard protections maintained by certified data center providers.
2. Encryption and Threat Protection To safeguard against unauthorized access and external threats, FREEBYTE enforces strict network security through a centralized API gateway, Content Delivery Network (CDN) routing, and Virtual Private Network (VPN) isolation. The infrastructure is actively protected against malicious activities utilizing Web Application Firewalls (WAF), automated Distributed Denial-of-Service (DDoS) mitigation, bot filtering, and rate-limiting controls. Furthermore, all personal data is encrypted both in transit via HTTPS/TLS protocols and at rest across database and storage layers, managed through secure, centralized cryptographic key and secret management systems.
3. Access Control and Data Minimization Access to system infrastructure, databases, and application deployments is strictly governed by Role-Based Access Control (RBAC) and continuously monitored through comprehensive access logging. In strict adherence to privacy-by-design principles, FREEBYTE actively enforces data minimization, applies data masking techniques where appropriate, and maintains encrypted, asynchronous backups to guarantee business continuity and secure data recovery.
9. AVAILABILITY OF THE MANUAL
9.1 A copy of the Manual is available-
9.1.1 on www.free-byte.com ;
9.1.2 head office of the FREEBYTE for public inspection during normal business hours;
9.1.3 to any person upon request and upon the payment of a reasonable prescribed fee; and
9.1.4 to the Information Regulator upon request.
9.2 A fee for a copy of the Manual, as contemplated in annexure B of the Regulations, shall be payable per each A4-size photocopy made.
10. UPDATING OF THE MANUAL
The head of a FREEBYTE will on a regular basis update this manual.
Issued by