Access to information, South Africa.
The manual of Numata Business IT (Pty) Ltd prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, read with the Protection of Personal Information Act 4 of 2013.
- Section 51 of PAIA
- 7 June 2024
- 3 April 2025
- AM Koorts
- July 2026
On this page
- Purpose of this manual
- Terms used
- Key contact details
- The Regulator's Guide on how to use PAIA
- Categories of records available without a request
- Records held in accordance with other legislation
- Subjects and categories of records held
- Processing of personal information
- Recipients of personal information
- Security safeguards
- How to make a request
- Availability and updating of this manual
- Related policies
Applies to Numata Business IT (Pty) Ltd, South Africa.
Purpose of this manual
This manual is published so that any member of the public can understand what records Numata Business IT (Pty) Ltd holds and how to ask for access to them. It is prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended, and reflects our obligations under the Protection of Personal Information Act 4 of 2013.
It allows a requester to:
- Check which categories of records are available without a formal PAIA request.
- Understand how to make a request for access to a record, and on which subjects records are held.
- See which records are held in accordance with other legislation.
- Find the contact details of the Information Officer who will assist with a request.
- Locate the Regulator's Guide on how to use PAIA and how to obtain access to it.
- Understand whether personal information is processed, for what purpose, and which categories of data subjects and information are involved.
- See the recipients or categories of recipients to whom personal information may be supplied.
- See whether personal information is transferred or processed outside the Republic of South Africa.
- Confirm that appropriate security measures protect the confidentiality, integrity and availability of personal information processed.
Terms used
- IO: Information Officer.
- Minister: Minister of Justice and Correctional Services.
- PAIA: Promotion of Access to Information Act 2 of 2000, as amended.
- POPIA: Protection of Personal Information Act 4 of 2013.
- Regulator: the Information Regulator of South Africa.
- Republic: the Republic of South Africa.
Key contact details
Information Officer: AM Koorts. Telephone: +27 87 231 0311. Access to information general contact: compliance@numata.co.
National or head office, postal and physical address: Building C, Baobab Business Park, 86 John Vorster Road, Randpark Ridge, 2169, South Africa. Telephone: +27 87 231 0311. Website: numata.co.
The Regulator's Guide on how to use PAIA
In terms of section 10(1) of PAIA, the Regulator has compiled and made available an updated Guide on how to use PAIA, in an easily comprehensible form, for any person who wishes to exercise a right contemplated in PAIA or POPIA. The Guide is available in English.
The Guide describes the objectives of PAIA and POPIA; the contact details of the Information Officer and every Deputy Information Officer of public and private bodies; the manner and form of a request for access to a record of a public body under section 11 and of a private body under section 50; the assistance available from an Information Officer and from the Regulator; and all remedies in law available in respect of an act or failure to act under PAIA and POPIA, including how to lodge an internal appeal, a complaint to the Regulator and an application to court.
It also describes the obligation on public and private bodies to compile a manual under sections 14 and 51 respectively, the voluntary disclosure of categories of records under sections 15 and 52, the notices issued under sections 22 and 54 regarding fees payable in relation to requests for access, and the regulations made under section 92.
The Guide may be inspected or copied at the offices of public and private bodies, including the office of the Regulator, during normal working hours. It can also be obtained on request from the Information Officer, or from the Regulator's website at justice.gov.za/inforeg.
Categories of records available without a request
The company website is automatically available and need not be formally requested in terms of this manual. The following categories of records are automatically available for inspection, purchase or photocopying:
- Brochures.
- Marketing and promotional material.
Records held in accordance with other legislation
Records are held in accordance with, among others, the Basic Conditions of Employment Act 75 of 1997; Companies Act 71 of 2008 and applicable regulations; Compensation for Occupational Injuries and Diseases Act 130 of 1993; Competition Act 89 of 1998; Consumer Protection Act 68 of 2008; Copyright Act 98 of 1978; Electronic Communications Act 36 of 2005; Electronic Communications and Transactions Act 25 of 2002; Employment Equity Act 55 of 1998; Exchange Control Amnesty and Amendment of Taxation Laws Act of 2003; Financial Advisory and Intermediary Services Act 37 of 2002; Financial Intelligence Centre Act 38 of 2001; Financial Sector Regulation Act 9 of 2017; Income Tax Act 58 of 1962; Intellectual Property Laws Amendment Act 38 of 1997; Labour Relations Act 66 of 1995; Occupational Health and Safety Act 85 of 1993; Pension Funds Act 24 of 1956; Prevention and Combating of Corrupt Activities Act 12 of 2004; Prevention of Organised Crime Act 121 of 1998; Promotion of Access to Information Act 2 of 2000; Promotion of Equality and Prevention of Unfair Discrimination Act 4 of 2000; Protected Disclosures Act 26 of 2000; Protection of Personal Information Act 4 of 2013; South African Reserve Bank Act 90 of 1989; Unemployment Insurance Act 63 of 2001; Unemployment Insurance Contributions Act 4 of 2002; and Value Added Tax Act 89 of 1991.
Subjects and categories of records held
- Companies Act records: documents of incorporation and records relating to the appointment of directors, prescribed officers, public officers and the company secretary.
- Personal documents and records for clients: employee records, address lists, employment contracts, leave records, payroll reports and wage registers, and salary records.
- Financial records: annual financial records and statements, asset registers, bank statements, banking details and accounts, banking records, debtor and creditor statements and invoices, general and subsidiary ledgers, general reconciliations, invoices and tax returns.
- Income tax records: PAYE records, documents issued to employees for income tax purposes, records of payments made to SARS on behalf of employees, and other statutory records including UIF.
Processing of personal information
Personal information is processed to support sales and marketing activities, the recruitment and management of staff, engagement with suppliers and the general public, and the fulfilment of agreements with vendors and customers.
Categories of data subjects and the personal information that may be processed are: customers and clients, being name, title and contact details, postal or street address, contact numbers and email addresses, FICA documentation and pay slips; and service providers, being name and contact details, identity or company information, banking and financial information, VAT numbers, and contractor, client and supplier agreements.
Recipients of personal information
Personal information may be supplied to:
- Any organisation or person that provides Numata Business IT (Pty) Ltd with products or services.
- Any payment system used by Numata Business IT (Pty) Ltd.
- Regulatory and governmental authorities, ombudsmen or other authorities, including tax authorities, where there is a duty to share information.
- Operators appointed under written agreement to process personal information on our instruction, subject to additional security controls.
Security safeguards
We identify all reasonably foreseeable internal and external risks to personal information in our possession or under our control, establish and maintain appropriate safeguards against those risks, regularly verify that the safeguards are effectively implemented, and update them in response to new risks or deficiencies. Measures include, among others:
- Access control.
- Data encryption.
- Defensive measures.
- Robust monitoring, auditing and reporting capabilities.
- Data backups.
- Endpoint detection, anti-virus and anti-malware solutions.
- Staff awareness and training.
- Policies and procedures.
- Agreements concluded with operators to implement additional security controls.
How to make a request
A requester must be given access to a record of a private body where the record is required for the exercise or protection of a right, the requester complies with the procedural requirements of PAIA, and access is not refused on a ground in Chapter 4 of Part 3 of the Act.
Requests must be made on the prescribed PAIA request form, identify the record sought, state the right the requester seeks to exercise or protect and why the record is required for that purpose, and give the postal address or electronic address of the requester. Where a request is made on behalf of another person, proof of capacity must be attached. Requests are directed to the Information Officer at compliance@numata.co or through the contact page.
The prescribed request fee must be paid before the request is processed further, as required by section 54 of PAIA. Where access is granted, an access fee calculated in terms of the fees notice may also be payable. A decision is made within 30 days of receipt, and that period may be extended once by a further 30 days in the circumstances set out in the Act. Reasons are given in writing where a request is refused, together with the remedies available, being a complaint to the Regulator or an application to court.
Availability and updating of this manual
A copy of this manual is available for download at numata.co, at the head office of Numata Business IT (Pty) Ltd for public inspection during normal business hours, to any person on request against payment of a reasonable prescribed fee, and to the Information Regulator on request. A fee as contemplated in Annexure B of the Regulations is payable for each A4-size photocopy made.
The Information Officer updates this manual on a regular basis. It was compiled on 7 June 2024 and last revised on 3 April 2025. Issued by AM Koorts, Information Officer.
