Documents and Downloads

Compliance documentation.

Standard compliance documents for due diligence, procurement and vendor assessment. Released under NDA on request through your Numata contact.

Policies
23 available
Release
Under NDA
Owner
GRC and CISO
Cadence
Continuous review
Document library

Every policy and plan, and how to get it.

  • PAIA Manual (Section 51)

    Numata South Africa's manual under the Promotion of Access to Information Act, covering the Information Officer, records held, request procedure, prescribed forms and fees, and POPIA obligations as a responsible party. Published, as required by PAIA.

  • Privacy Policy

    What personal information Numata collects, why we hold it, who we share it with, how long we keep it, and the rights a data subject can exercise across POPIA, GDPR and UK GDPR. Published.

  • Business Conduct and Ethics

    Numata's Anti-Corruption and Bribery Policy and Anti-Modern Slavery and Prevention and Combating of Trafficking in Persons Policy: zero tolerance for bribery and corruption, rules on gifts and hospitality, facilitation payments and kickbacks, record keeping, supply chain expectations, and the protected route for raising concerns. Published.

  • Data Processing Agreement (DPA)

    Standard DPA covering data processing terms, sub-processor obligations, security measures and data subject rights under GDPR and POPIA.

  • Security Questionnaire

    Pre-completed SIG Lite / CAIQ security questionnaire covering governance, risk management, access control, encryption and incident response.

  • Sub-Processor List

    Current list of sub-processors used in service delivery, including name, purpose, data processed and geographic location.

  • Security Policy

    The overarching information security policy that anchors Numata's programme, aligned to CIS Controls.

  • Acceptable Use Policy

    Terms governing acceptable use of Numata-managed systems, applications and infrastructure.

  • Artificial Intelligence Usage Policy

    Policy governing the use of AI tools and services within Numata-managed environments, including data classification and approved platforms.

  • Incident Management and Response Plan

    Documented plan led by the CISO covering detection, containment, eradication, recovery and post-incident review.

  • Risk Management Policy

    Numata's approach to identifying, prioritising and mitigating risk across the organisation.

  • Data Governance Policy

    How data is classified, owned and governed throughout its lifecycle.

  • Encryption Policy

    Standards for encryption of data at rest and in transit across managed environments.

  • Vulnerability Management Policy

    Governance of vulnerability scanning, triage, remediation and reporting.

  • Patch Management Policy

    Standards and cadence for security and functional patching across managed estates.

  • Change Management Policy

    Governance for planned changes across managed environments, including advisory board review.

  • Asset Management Policy

    How managed assets are inventoried, tracked and retired.

  • Electronic Data Disposal Policy

    Requirements for secure disposal and destruction of electronic data and media.

  • Third-Party Risk Management Policy

    How vendors and suppliers are assessed, onboarded and continuously monitored.

  • Software Development Lifecycle Policy

    Secure development practices across the software delivery lifecycle.

  • Physical Security Policy

    Controls that protect Numata premises, equipment and physical media.

  • Business Continuity Plan

    Framework for maintaining critical business services through disruption.

  • Disaster Recovery Plan

    Recovery procedures for managed infrastructure, applications and data, aligned to defined RTO and RPO targets.

Need a specific document?

If you require documentation not listed above, such as a custom security questionnaire or specific compliance attestation, contact our team.

Request documentation