1. Introduction

The Promotion of Access to Information Act 2 of 2000 ("PAIA") gives effect to the constitutional right of access to information held by another person where that information is required for the exercise or protection of a right. Section 51 of PAIA requires every private body to publish a manual that tells the public what records it holds, how to ask for them, and on what grounds a request may be refused. Since the Protection of Personal Information Act 4 of 2013 ("POPIA") amended section 51, the manual must also describe how the body processes personal information.

This is that manual for Savvyly (Pty) Ltd. It covers the whole company and both of its platforms: KASI COIN, a rand-backed digital token that the company issues and the wallet app that holds it, and the Savvyly core-banking platform, software that cooperative financial institutions use to run their own business. It should be read with the company's Privacy Notice (SAV-PRV-001), which explains in more detail what personal information the company collects and why.

1.1 Purpose of this manual

This manual exists so that a person who wants a record from the company can find out, without having to ask first, whether the company is likely to hold it, how to ask for it, what it will cost, how long it will take, and what they can do if the request is refused. It also tells a person whose personal information the company processes what the company does with it and how to exercise their rights under POPIA.

1.5 Terms used in this manual

2. Company particulars

3. The Information Officer and Deputy Information Officer

Requests under PAIA, and requests and objections under POPIA, are addressed to the Information Officer. The Deputy Information Officer has been designated so that a request is never delayed by one person's absence, and may deal with any request in the same way as the Information Officer.

Please mark any request "For the attention of the Information Officer — PAIA request" (or "POPIA request"), so that it is routed correctly and the statutory period is counted from the day it arrives.

4. The Regulator's guide

Section 10 of PAIA requires the Information Regulator to publish, in each official language, a guide on how to use PAIA and POPIA to exercise a right. The guide explains the objects of the Acts, how to find the Information Officer of a body, the manner and form of a request, the assistance available from the Regulator, the remedies available, and the fees payable.

The guide is available from the Information Regulator's website, https://inforegulator.org.za, and from the Regulator on request; please see the website for the Regulator's current contact details. A copy of the guide may also be inspected at the company's head office during business hours, and the Information Officer will provide a copy on request.

5. Records available without a request

The company has not published a notice under section 52(2) of PAIA. The following records are nevertheless available without a formal request, free of charge, on the company's website or from the Information Officer:

Payments made with KASI COIN are recorded on the Stellar network, a public ledger that anyone may inspect without asking the company. The ledger carries wallet addresses and amounts and no names or identity numbers.

6. Records kept in accordance with other legislation

The company keeps records under the following laws. A record kept under one of them is not automatically available on request: access is still decided under PAIA, and the grounds of refusal in section 9 of this manual apply. The list is as complete as the company can make it and is not exhaustive; a law not listed may still require a record to be kept.

7. Subjects and categories of records held

The table lists the subjects on which the company holds records and the categories of record in each. The right-hand column is a guide to how a request is likely to be dealt with; every request is decided on its own merits under PAIA, and a record in a category marked "may be requested" may still be refused, in whole or part, on a ground in section 9.

8. How to request access to a record

8.1 The form

A request for access to a record of the company is made on Form 2 (Request for Access to Record) of the Regulations, which is available from the Information Regulator's website and from the Information Officer on request. Section 53 of PAIA requires the prescribed form; a request in a letter or email that does not contain the particulars the form asks for cannot be processed, and the Information Officer will help a requester to complete the form rather than turn the request away.

8.2 What the request must contain

8.3 Submitting the request

The completed form may be emailed to admin@savvyly.tech, delivered by hand to the head office, or posted to the postal address in section 2. A requester who cannot read or write, or who has a disability that prevents a written request, may make the request orally; the Information Officer will reduce it to writing on the form and give the requester a copy.

8.4 What happens next

9. Fees

PAIA provides for two kinds of fee, and the amounts are those prescribed in Annexure B of the Regulations, as amended from time to time. The Information Officer will tell a requester the amount before any fee is incurred.

A requester may be exempted from a fee where the Regulations provide for it, and a requester may complain to the Regulator, or apply to court, about the amount of a fee or a deposit. The company does not charge for providing a person with confirmation of whether it holds personal information about them (section 23(1)(a) of POPIA).

10. Grounds for refusing access

Chapter 4 of Part 3 of PAIA sets out the only grounds on which a private body may refuse access. Some are mandatory — the company must refuse — and some are discretionary. The company may refuse only on one of these grounds, and where only part of a record is protected it discloses the rest (section 59).

The public-interest override. Despite any of these grounds, the company must grant access where disclosure would reveal evidence of a substantial contravention of, or failure to comply with, the law, or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm the ground is intended to prevent (section 70).

Records the law forbids the company to disclose. The Financial Intelligence Centre Act prohibits the company from disclosing that a report has been, or may be, made to the Financial Intelligence Centre, or any information from which that could be inferred. A request that would require such a disclosure is refused, and the refusal will not confirm or deny whether any such record exists.

11. Remedies

The company is a private body and has no internal appeal procedure. A requester, or a third party, who is dissatisfied with a decision of the Information Officer — a refusal, a fee, an extension, or the form of access — may:

The Information Regulator's website is https://inforegulator.org.za; please see the website for its current contact details and the complaint forms.

12. Processing of personal information under POPIA

Section 51(1)(c) of PAIA, as amended by POPIA, requires this manual to describe the company's processing of personal information. The full description, written for the people concerned, is the Privacy Notice (SAV-PRV-001); the particulars the Act requires are summarised here.

12.1 The purposes of processing

12.2 Categories of data subjects and of personal information

The company processes two kinds of special personal information: biometric information, for identity verification required by the Financial Intelligence Centre Act, and information about alleged offences, arising from sanctions screening and fit-and-proper checks. The company does not knowingly process personal information about children.

12.3 Recipients

Personal information may be supplied, only as needed, to: the company's operators — identity verification, cloud hosting, network security, SMS, email and push-notification delivery, IP intelligence, court-records data, and outsourced support and engineering personnel — each under a written contract meeting sections 20 and 21 of POPIA; the bank and payment gateway that process deposits and cash-outs; a client's cooperative institution, where the client uses KASI COIN through it; professional advisers and auditors; and regulators, the Financial Intelligence Centre, the South African Revenue Service, courts and law-enforcement agencies where the law requires or permits it. No artificial-intelligence provider receives personal information. The company does not sell personal information.

12.4 Planned transfers outside South Africa

The platform and its database are hosted in South Africa. Some operators are, or process information, outside South Africa, including in the European Union, the United States and India, and backup copies may be kept in a second hosting region. A transfer is made only on a ground in section 72 of POPIA — principally a recipient bound by a law, binding corporate rules or a binding agreement giving protection substantially similar to POPIA — and the ground is recorded before the transfer begins.

12.5 Security measures

The company protects personal information under an information security programme approved by its directors and aligned to ISO/IEC 27001, which requires, among other measures: encryption in transit and at rest; hosting in South Africa; client private keys that never leave the client's device and company signing keys held in a managed key service; role-based access with multi-factor authentication for staff; masking of restricted fields such as identity numbers, with every reveal recorded with a reason; an audit trail of access to client records; no production client data on developer computers and reviewed software changes; vulnerability testing; screening, confidentiality undertakings and training for people with access; written operator agreements; and a procedure for notifying the Regulator and affected persons of a security compromise under section 22 of POPIA.

12.6 Data subjects' rights, and the forms to use

If you are a member of a cooperative institution that uses the core-banking platform, the institution is the responsible party for your information, and your request should be made to it; a request made to the company is referred to the institution.

13. Availability and updating of this manual

This manual is available on the company's website at https://savvyly.tech/paia-manual.html, and for inspection at the head office during business hours, free of charge. A printed copy is provided on request for the fee prescribed in the Regulations for a copy of a manual. It is provided to the Information Regulator on request.

The Information Officer reviews this manual at least once a year, and updates it whenever the company's particulars, its Information Officer or Deputy, the records it holds or the way it processes personal information change. The version on the website is always the current one, and carries its date.