PAIA Manual

Prepared in terms of section 51 of the Promotion of Access to Information Act, 2000 (as amended)

Date of compilation: 7 January 2026
Date of last revision: 28 July 2026

1 Company details

1.1 Private Body: TriplicityID Pty Ltd

1.2 Company registration number: 2025/774082/07

1.3 Registered Office: Unit A2, 10 Niblick Way, Somerset West, 7130

2 Information Officer

TriplicityID's Information Officer is Takudzwa Tanyaradzwa Hove. The Information Officer was appointed on 1 July 2026 and TriplicityID's registration was confirmed with the Information Regulator on 21 July 2026.

Privacy, POPIA, and PAIA-related requests may be directed to the Information Officer using the contact details below.

3 Information Regulator

The Information Regulator (South Africa) is the supervisory authority responsible for monitoring and enforcing compliance with POPIA and PAIA. A data subject or requester may lodge a complaint with the Information Regulator, or obtain guidance on the exercise of their rights, using the details below. TriplicityID's Information Officer registration can be verified via the Information Regulator's eServices portal.

4 List of Acronyms and Abbreviations

5 Purpose of this PAIA Manual

This PAIA Manual is prepared in accordance with section 51 of PAIA and serves to provide members of the public with information on how to request access to records held by the Company, the types of records held, and the processing of personal information in line with POPIA.

6 Guide on how to use PAIA

The Information Regulator has published a guide on how to use PAIA. The guide is available from the Information Regulator at https://www.inforegulator.org.za.

7 How to request access to records

A requester who wishes to access a record held by the Company should follow the process set out below.

  1. Requests must be submitted to the Information Officer in writing, using the contact details set out in section 2 of this manual.
  2. The request must provide sufficient detail to enable the Company to identify the record requested, to identify and verify the requester, and to establish the requester's capacity or the interest on which the request is based.
  3. Where prescribed, the relevant PAIA request form for private bodies must be used, together with any supporting identification or proof of authority required.
  4. Applicable request, search, reproduction, or access fees may apply in accordance with PAIA and the applicable regulations.
  5. The Company will assess the request and respond within the time period prescribed by PAIA, subject to any lawful extension of that period where permitted.
  6. Access may be refused where PAIA permits refusal, including where records contain protected third-party personal information, confidential commercial information, privileged material, or security-sensitive information. Where a request is refused, the requester will be informed of the grounds for refusal and of the remedies available to them.

8 Categories of Records Automatically Available

9 Records Available in Terms of Legislation

10 Subjects and Categories of Records Held

11 Purpose for Processing of Personal Information

The Company processes personal information for business operations, relationship management, compliance with legal obligations, website administration and provision of products and services. This includes employment and corporate administration, customer and supplier management, fraud prevention, identity verification, and the provision of API-based risk signal services.

In relation to its API-based services, the Company processes submitted identifiers and related technical data in order to generate risk or trust signals for the customer. The Company typically acts as operator on the documented instruction of the customer, who acts as responsible party for the relevant end-user personal information.

12 Categories of Data Subjects

13 Categories of Recipients

14 POPIA transparency and data subject rights

14.1 The capacity in which the Company processes personal information. The Company processes personal information in different capacities depending on the context. For its own business operations, the Company processes personal information as responsible party. For certain product services delivered to customers, the Company generally processes personal information as operator on the instruction of the relevant customer, who remains the responsible party for that end-user processing.

14.2 Automated risk and trust signals. The Company's products may support fraud prevention, identity verification, and related risk intelligence workflows. Certain services generate automated risk or trust signals based on submitted identifiers or related technical data. The Company does not itself make customer-facing decisions regarding the onboarding, decline, restriction, or other treatment of an individual. Customers remain responsible for those decisions and for their own lawful basis, privacy notices, and procedures for objections and human review.

14.3 Rights of data subjects. Depending on the context and subject to applicable law, data subjects may have the right to request access to their personal information, to request correction or deletion where applicable, to object to certain processing, and to lodge a complaint with the Information Regulator. These requests may be directed to the Information Officer using the contact details in section 2 of this manual.

14.4 Requests relating to customer-submitted data. Where a request relates to personal information submitted to the Company by a customer through the Company's services, the relevant customer may need to handle the request as responsible party, with the Company assisting where appropriate. In these cases the Company will, where lawful and practical, direct the data subject to the relevant customer.

14.5 Voluntary and mandatory information. Some personal information is required by law, by contract, or as a matter of operational necessity, while other information is provided voluntarily. Where required information is not provided, the Company may be unable to onboard a person, respond to a request, enter into a contract, or deliver a service.

15 Cross-border transfers of Personal Information

The Company may transfer personal information outside the Republic of South Africa where this is necessary for its operations or services and where such transfer is permitted by applicable law.

Depending on the service involved, such transfers may include service providers or sub-operators located in jurisdictions such as the United Kingdom, member states of the European Union, and the United States.

The Company applies contractual and other appropriate safeguards to protect personal information in connection with cross-border transfers, in accordance with POPIA, so as to ensure a level of protection substantially similar to that provided under POPIA.

16 Information Security Measures

The Company implements appropriate technical and organisational measures to ensure the confidentiality, integrity, and availability of personal information under its control. These measures include access controls and authentication mechanisms, role-based access on a need-to-know basis, data encryption where appropriate, secure system and network configurations, anti-malware and security monitoring solutions, and ongoing review of security practices to address risks and vulnerabilities.

17 Availability of this Manual

This manual is available on the Company website and upon request to the Information Officer.

18 Updating of this Manual

This PAIA Manual will be reviewed and updated on a regular basis, and whenever there is a material change to the information it contains. The version published on the Company website is the current version, and the date of last revision is shown at the top of this manual.

19 Contact Us

PAIA access requests, POPIA complaints, correction requests, deletion requests, and other privacy-related queries should be directed to the Information Officer using the contact details set out in section 2 of this manual.

If you have any other questions about this PAIA Manual or our data protection practices, please contact info@triplicityid.com.