1. Introduction
The Promotion of Access to Information Act 2 of 2000 ("PAIA") gives effect to the constitutional right of access to information held by another person where that information is required for the exercise or protection of a right. Section 51 of PAIA requires every private body to publish a manual that tells the public what records it holds, how to ask for them, and on what grounds a request may be refused. Since the Protection of Personal Information Act 4 of 2013 ("POPIA") amended section 51, the manual must also describe how the body processes personal information.
This is that manual for Savvyly (Pty) Ltd. It covers the whole company and both of its platforms: KASI COIN, a rand-backed digital token that the company issues and the wallet app that holds it, and the Savvyly core-banking platform, software that cooperative financial institutions use to run their own business. It should be read with the company's Privacy Notice (SAV-PRV-001), which explains in more detail what personal information the company collects and why.
1.1 Purpose of this manual
This manual exists so that a person who wants a record from the company can find out, without having to ask first, whether the company is likely to hold it, how to ask for it, what it will cost, how long it will take, and what they can do if the request is refused. It also tells a person whose personal information the company processes what the company does with it and how to exercise their rights under POPIA.
1.5 Terms used in this manual
| Term | Meaning |
|---|---|
| Company | Savvyly (Pty) Ltd, registration number 2020/858524/07 |
| Information Officer | The head of the company for the purposes of PAIA and POPIA — its Chief Executive Officer — or a person duly authorised by him |
| Deputy Information Officer | The person designated under section 56 of POPIA, read with section 17 of PAIA, to assist the Information Officer and act in his absence |
| Record | Recorded information in any form or medium, in the possession or under the control of the company, whether or not the company created it |
| Requester | A person who asks for access to a record, or a person acting on their behalf |
| Personal requester | A requester who seeks a record containing personal information about himself or herself |
| Regulator | The Information Regulator established under section 39 of POPIA, which oversees both PAIA and POPIA |
| Regulations | The Regulations relating to the Promotion of Access to Information, 2021, which prescribe the request form and the fees |
| Responsible party / operator | The POPIA terms for, respectively, the person who decides why and how personal information is processed, and a person who processes it on the responsible party's behalf |
2. Company particulars
| Item | Details |
|---|---|
| Registered name | Savvyly (Pty) Ltd |
| Trading names | Savvyly; KASI COIN |
| Registration number | 2020/858524/07 |
| Type of body | Private company incorporated in the Republic of South Africa |
| Head of the body | Nhlanhla Simelane, Chief Executive Officer |
| Physical address (head office and registered office) | Unit 14 Honey Rock, Van Vuren Road, Honey Road Ext 10, Gauteng, 2170, South Africa |
| Postal address | Unit 14 Honey Rock, Van Vuren Road, Honey Road Ext 10, Gauteng, 2170, South Africa |
| Telephone | 083 456 9947 (+27 83 456 9947) |
| admin@savvyly.tech | |
| Website | https://savvyly.tech |
| What the company does | It issues KASI COIN, a rand-backed digital token recorded on the Stellar public ledger, and operates the wallet app and merchant tools through which it is used; and it provides the Savvyly core-banking platform, a software service used by cooperative financial institutions to manage their members, deposits, loans and accounting |
3. The Information Officer and Deputy Information Officer
Requests under PAIA, and requests and objections under POPIA, are addressed to the Information Officer. The Deputy Information Officer has been designated so that a request is never delayed by one person's absence, and may deal with any request in the same way as the Information Officer.
| Information Officer | Deputy Information Officer | |
|---|---|---|
| Name | Nhlanhla Simelane | Mofihli McGregor Phofi |
| Position | Chief Executive Officer | Chief Operations Officer |
| admin@savvyly.tech | admin@savvyly.tech | |
| Physical address | Unit 14 Honey Rock, Van Vuren Road, Honey Road Ext 10, Gauteng, 2170 | As for the Information Officer |
Please mark any request "For the attention of the Information Officer — PAIA request" (or "POPIA request"), so that it is routed correctly and the statutory period is counted from the day it arrives.
4. The Regulator's guide
Section 10 of PAIA requires the Information Regulator to publish, in each official language, a guide on how to use PAIA and POPIA to exercise a right. The guide explains the objects of the Acts, how to find the Information Officer of a body, the manner and form of a request, the assistance available from the Regulator, the remedies available, and the fees payable.
The guide is available from the Information Regulator's website, https://inforegulator.org.za, and from the Regulator on request; please see the website for the Regulator's current contact details. A copy of the guide may also be inspected at the company's head office during business hours, and the Information Officer will provide a copy on request.
5. Records available without a request
The company has not published a notice under section 52(2) of PAIA. The following records are nevertheless available without a formal request, free of charge, on the company's website or from the Information Officer:
- this manual and the Privacy Notice (SAV-PRV-001);
- the terms and conditions, refunds and cancellation policy, and company information published on the website;
- the KASI COIN terms of use, fee schedule and client disclosures, which are shown in the app before an account is opened;
- the complaints procedure, and how to escalate a complaint;
- marketing and product information published on the website; and
- the company's public records at the Companies and Intellectual Property Commission, which may also be obtained from the Commission.
Payments made with KASI COIN are recorded on the Stellar network, a public ledger that anyone may inspect without asking the company. The ledger carries wallet addresses and amounts and no names or identity numbers.
6. Records kept in accordance with other legislation
The company keeps records under the following laws. A record kept under one of them is not automatically available on request: access is still decided under PAIA, and the grounds of refusal in section 9 of this manual apply. The list is as complete as the company can make it and is not exhaustive; a law not listed may still require a record to be kept.
| Legislation | Records kept |
|---|---|
| Companies Act 71 of 2008 | Memorandum of Incorporation, register of directors, securities register, minutes and resolutions, annual financial statements, accounting records |
| Financial Intelligence Centre Act 38 of 2001 | Client identification and verification records, transaction records, the Risk Management and Compliance Programme, screening and monitoring records, reports to the Financial Intelligence Centre and their supporting records |
| Financial Advisory and Intermediary Services Act 37 of 2002, and its codes of conduct | Records of financial services rendered in relation to KASI COIN, client disclosures, complaints, fit-and-proper records of key individuals and representatives, conflicts of interest |
| Financial Sector Regulation Act 9 of 2017 | Records required by the Financial Sector Conduct Authority, including regulatory returns and correspondence |
| Protection of Constitutional Democracy against Terrorist and Related Activities Act 33 of 2004 | Records of screening against, and reports concerning, persons and entities subject to sanctions |
| Protection of Personal Information Act 4 of 2013 | Records of processing, requests from data subjects, security compromises and notifications, operator agreements, records of cross-border transfers |
| Promotion of Access to Information Act 2 of 2000 | This manual; requests for access and their outcome |
| Electronic Communications and Transactions Act 25 of 2002 | Records of electronic transactions and communications |
| Consumer Protection Act 68 of 2008 | Records relating to the supply of goods and services to consumers, where the Act applies |
| Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011 | Tax returns, assessments, supporting accounting records, employees' tax records |
| Value-Added Tax Act 89 of 1991 | VAT records, if and while the company is registered for VAT |
| Basic Conditions of Employment Act 75 of 1997 | Employment contracts, time and remuneration records |
| Labour Relations Act 66 of 1995 | Records of disciplinary proceedings, disputes and collective agreements, where applicable |
| Employment Equity Act 55 of 1998 | Employment-equity records, where the Act applies to the company |
| Unemployment Insurance Act 63 of 2001; Unemployment Insurance Contributions Act 4 of 2002 | Records of employees and contributions |
| Skills Development Levies Act 9 of 1999 | Records of levies paid |
| Compensation for Occupational Injuries and Diseases Act 130 of 1993 | Records of employees, earnings and incidents |
| Occupational Health and Safety Act 85 of 1993 | Health and safety records |
7. Subjects and categories of records held
The table lists the subjects on which the company holds records and the categories of record in each. The right-hand column is a guide to how a request is likely to be dealt with; every request is decided on its own merits under PAIA, and a record in a category marked "may be requested" may still be refused, in whole or part, on a ground in section 9.
| Subject | Categories of record | Availability |
|---|---|---|
| Company secretarial | Memorandum of Incorporation, registration documents, share register, register of directors, minutes and resolutions of the board and shareholders, statutory returns | Public records: freely available. Minutes and resolutions: may be requested |
| Governance and policy | Governing frameworks, policies and standards, risk and compliance registers, board reports, internal audit records | May be requested; commercially sensitive and security-related content may be withheld (sections 68 and 66 of PAIA) |
| Financial and tax | Annual financial statements, management accounts, general ledger, bank statements, budgets and forecasts, tax and VAT records, asset register | May be requested; commercial information may be withheld (section 68) |
| Reserve and treasury | Records of the trust account holding the rand reserve that backs KASI COIN, reconciliations of reserve to issued supply, mint and redemption records | Aggregate information may be requested; client-level detail is personal information of third parties (section 63) |
| KASI COIN clients and merchants | Applications, identification and verification records, wallet and account records, transaction history, statements, correspondence, complaints | Available to the client concerned as a personal requester; to others only with consent or on a ground in PAIA |
| Financial-crime compliance | The Risk Management and Compliance Programme, screening results, risk ratings, monitoring alerts, investigation records, freezes, and reports to the Financial Intelligence Centre | The programme may be requested. Records of investigations and reports are not available: the Financial Intelligence Centre Act prohibits disclosing that a report has been or may be made |
| Core-banking platform (records held for cooperative institutions) | The data of each institution that uses the platform: its members, accounts, deposits, loans, transactions and staff users; the institution's configuration; audit trails of use | The institution is the responsible party and holds these records for its own purposes. Requests must be made to the institution. A request made to the company is referred to the institution |
| Core-banking customers (institutions) | Contracts, service levels, invoices, support tickets and correspondence with each institution | Available to the institution concerned; commercial terms may be withheld as third-party commercial information (section 64) |
| Personnel | Employment and service contracts, remuneration and tax records, leave, training, performance and disciplinary records, pre-employment and fit-and-proper checks, declarations, access records | Available to the person concerned as a personal requester; to others only with consent or on a ground in PAIA |
| Directors | Appointment records, fit-and-proper and honesty-and-integrity declarations, disclosures of interest | Available to the director concerned; public records freely available |
| Service providers and suppliers | Contracts, due-diligence records, provider personnel vetting records, performance reviews, invoices | May be requested; commercial and personal information of the provider may be withheld (sections 63 and 64) |
| Information technology and security | System architecture, security configurations, access logs, incident records, continuity and recovery plans, key-management records | Generally withheld: disclosure could prejudice the security of the platform and of the information on it (section 66) |
| Regulatory | Licence application and correspondence with the Financial Sector Conduct Authority, the Financial Intelligence Centre, the Information Regulator and other authorities; regulatory returns | May be requested, subject to any restriction imposed by the authority or by law |
| Legal | Legal opinions, litigation files, agreements | Records privileged from production in legal proceedings are withheld (section 67) |
| Marketing and communications | Website content, published materials, marketing consents and opt-outs | Published material freely available; consents available to the person concerned |
8. How to request access to a record
8.1 The form
A request for access to a record of the company is made on Form 2 (Request for Access to Record) of the Regulations, which is available from the Information Regulator's website and from the Information Officer on request. Section 53 of PAIA requires the prescribed form; a request in a letter or email that does not contain the particulars the form asks for cannot be processed, and the Information Officer will help a requester to complete the form rather than turn the request away.
8.2 What the request must contain
- enough particulars to allow the Information Officer to identify the record or records requested, and the requester;
- the form of access required — for example a copy, an inspection, or a transcription;
- the postal address, email address or other means by which the requester wishes to be told of the decision;
- the right the requester is seeking to exercise or protect, and an explanation of why the record is required for that purpose — section 53(2)(d) of PAIA (a person asking only whether the company holds personal information about him or her, and for that information, may instead rely on section 23 of POPIA, which does not require this);
- if the requester wishes to be told of the decision in a particular manner, that manner; and
- if the request is made on behalf of another person, proof of the capacity in which it is made.
8.3 Submitting the request
The completed form may be emailed to admin@savvyly.tech, delivered by hand to the head office, or posted to the postal address in section 2. A requester who cannot read or write, or who has a disability that prevents a written request, may make the request orally; the Information Officer will reduce it to writing on the form and give the requester a copy.
8.4 What happens next
- The Information Officer decides the request as soon as reasonably possible, and in any event within 30 days of receiving it (section 56 of PAIA), and tells the requester the decision in the manner requested.
- The period may be extended once, by no more than a further 30 days, where the request is for a large number of records, requires a search through records held elsewhere, or requires consultation — the requester is told of the extension, the reasons for it, and the right to complain to the Regulator about it (section 57).
- Where a record contains information about a third party, the Information Officer takes reasonable steps to inform that third party and gives it the opportunity to make representations before the decision (sections 71 to 73).
- If the Information Officer does not decide the request within the period, the request is regarded as refused (section 58), and the requester may use the remedies in section 10 of this manual.
- If access is granted, the requester is told of any access fee payable and the form in which access will be given; access is given once the fee is paid. If access is refused, the requester is given adequate reasons, the provision of PAIA relied on, and the remedies available.
- If a record cannot be found or does not exist, the requester is told so by affidavit or affirmation, with the steps taken to find it (section 55).
9. Fees
PAIA provides for two kinds of fee, and the amounts are those prescribed in Annexure B of the Regulations, as amended from time to time. The Information Officer will tell a requester the amount before any fee is incurred.
- A request fee, payable when a request is submitted by a requester other than a personal requester (section 54(1)). A personal requester asking for his or her own personal information pays no request fee.
- An access fee, payable before access is given, covering the cost of reproducing the record, of searching for and preparing it for disclosure where the time involved exceeds that allowed in the Regulations, and of postage (section 54).
- A deposit of part of the access fee may be required where the search and preparation will take longer than the time prescribed in the Regulations (section 54); if access is then refused, the deposit is repaid.
A requester may be exempted from a fee where the Regulations provide for it, and a requester may complain to the Regulator, or apply to court, about the amount of a fee or a deposit. The company does not charge for providing a person with confirmation of whether it holds personal information about them (section 23(1)(a) of POPIA).
10. Grounds for refusing access
Chapter 4 of Part 3 of PAIA sets out the only grounds on which a private body may refuse access. Some are mandatory — the company must refuse — and some are discretionary. The company may refuse only on one of these grounds, and where only part of a record is protected it discloses the rest (section 59).
| Section of PAIA | Ground |
|---|---|
| 63 | Unreasonable disclosure of personal information about a third party who is a natural person, including a deceased individual |
| 64 | Commercial information of a third party: trade secrets, financial, commercial, scientific or technical information whose disclosure would be likely to cause harm to the third party's commercial or financial interests, or information supplied in confidence whose disclosure would put the third party at a disadvantage in negotiations or competition |
| 65 | Disclosure that would breach a duty of confidence owed to a third party under an agreement |
| 66 | Disclosure that could reasonably be expected to endanger the life or physical safety of an individual, or to prejudice the security of a building, structure, system, means of transport or other property — which includes the security of the platform and of the personal information it holds |
| 67 | Records privileged from production in legal proceedings, unless the privilege has been waived |
| 68 | Commercial information of the company: trade secrets, financial, commercial, scientific or technical information whose disclosure would be likely to cause harm to its commercial or financial interests, information whose disclosure would put it at a disadvantage in negotiations or competition, and computer programs owned by it |
| 69 | Research information of the company or a third party, where disclosure would expose the researcher or the subject of the research to serious disadvantage |
The public-interest override. Despite any of these grounds, the company must grant access where disclosure would reveal evidence of a substantial contravention of, or failure to comply with, the law, or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm the ground is intended to prevent (section 70).
Records the law forbids the company to disclose. The Financial Intelligence Centre Act prohibits the company from disclosing that a report has been, or may be, made to the Financial Intelligence Centre, or any information from which that could be inferred. A request that would require such a disclosure is refused, and the refusal will not confirm or deny whether any such record exists.
11. Remedies
The company is a private body and has no internal appeal procedure. A requester, or a third party, who is dissatisfied with a decision of the Information Officer — a refusal, a fee, an extension, or the form of access — may:
- lodge a complaint with the Information Regulator under section 77A of PAIA, in the manner and within the period (180 days of the decision) that Part 4A of PAIA prescribes; or
- apply to a court with jurisdiction for appropriate relief under section 78, within 180 days of the decision.
The Information Regulator's website is https://inforegulator.org.za; please see the website for its current contact details and the complaint forms.
12. Processing of personal information under POPIA
Section 51(1)(c) of PAIA, as amended by POPIA, requires this manual to describe the company's processing of personal information. The full description, written for the people concerned, is the Privacy Notice (SAV-PRV-001); the particulars the Act requires are summarised here.
12.1 The purposes of processing
- identifying and verifying KASI COIN clients and merchants, and operating their wallets and accounts — sending and receiving payments, deposits, cash-outs and fees;
- meeting the company's obligations under the Financial Intelligence Centre Act and related laws: screening, monitoring, investigating, freezing where required, record keeping and reporting;
- meeting its obligations under the financial-sector conduct laws in relation to KASI COIN, including disclosures, complaints and fit-and-proper requirements;
- securing the platform and preventing fraud;
- providing the core-banking software service to cooperative institutions, as their operator and on their instructions;
- recruiting, employing and engaging staff and contractors, and managing service providers;
- keeping accounting, tax and statutory records; and
- communicating with clients, prospective clients, website visitors and others who contact the company, including direct marketing where the law allows.
12.2 Categories of data subjects and of personal information
| Data subjects | Categories of personal information |
|---|---|
| KASI COIN clients and applicants | Identity (name, identity or passport number, date of birth, nationality, identity-document image); contact details; biometric verification (face image and liveness check); wallet public key and device information; account, tier, limits and transactions; bank account for cash-out; sign-in and network information; screening, risk and monitoring records; correspondence and complaints |
| Merchants and business clients, and their owners, directors and authorised people | Business name, registration number, address and bank account; identity and contact details of the people concerned; screening and court-record search results |
| People referred by clients | Name and contact details |
| Website visitors and enquirers | IP address and server-log information; name, email address and message where the contact form is used |
| Members, clients and staff users of cooperative institutions (processed as operator) | Whatever the institution records on the core-banking platform: typically identity and contact details, membership, deposit and loan accounts, repayments, transactions and documents, and staff user accounts |
| Staff, contractors, job applicants and directors | Identity and contact details; qualifications, employment history and references; tax and bank details; remuneration; identity, sanctions, court-record and, where required, criminal and credit checks; fit-and-proper and honesty-and-integrity declarations; training and access records |
| Personnel of service providers | Identity and contact details, vetting and training attestations, and records of access to the company's systems |
| Suppliers and their contact people | Names, contact details, bank details and contract records |
The company processes two kinds of special personal information: biometric information, for identity verification required by the Financial Intelligence Centre Act, and information about alleged offences, arising from sanctions screening and fit-and-proper checks. The company does not knowingly process personal information about children.
12.3 Recipients
Personal information may be supplied, only as needed, to: the company's operators — identity verification, cloud hosting, network security, SMS, email and push-notification delivery, IP intelligence, court-records data, and outsourced support and engineering personnel — each under a written contract meeting sections 20 and 21 of POPIA; the bank and payment gateway that process deposits and cash-outs; a client's cooperative institution, where the client uses KASI COIN through it; professional advisers and auditors; and regulators, the Financial Intelligence Centre, the South African Revenue Service, courts and law-enforcement agencies where the law requires or permits it. No artificial-intelligence provider receives personal information. The company does not sell personal information.
12.4 Planned transfers outside South Africa
The platform and its database are hosted in South Africa. Some operators are, or process information, outside South Africa, including in the European Union, the United States and India, and backup copies may be kept in a second hosting region. A transfer is made only on a ground in section 72 of POPIA — principally a recipient bound by a law, binding corporate rules or a binding agreement giving protection substantially similar to POPIA — and the ground is recorded before the transfer begins.
12.5 Security measures
The company protects personal information under an information security programme approved by its directors and aligned to ISO/IEC 27001, which requires, among other measures: encryption in transit and at rest; hosting in South Africa; client private keys that never leave the client's device and company signing keys held in a managed key service; role-based access with multi-factor authentication for staff; masking of restricted fields such as identity numbers, with every reveal recorded with a reason; an audit trail of access to client records; no production client data on developer computers and reviewed software changes; vulnerability testing; screening, confidentiality undertakings and training for people with access; written operator agreements; and a procedure for notifying the Regulator and affected persons of a security compromise under section 22 of POPIA.
12.6 Data subjects' rights, and the forms to use
| What you want to do | How |
|---|---|
| Find out whether the company holds personal information about you, or obtain a copy | Ask the Information Officer (section 23 of POPIA). Confirmation is free. A copy of the record is requested on Form 2 of the PAIA Regulations, 2021, as a personal requester, with no request fee |
| Object to the processing of your personal information | Form 1 of the POPIA Regulations, 2018 (section 11(3) of POPIA) |
| Ask for correction or deletion of your personal information, or destruction of a record | Form 2 of the POPIA Regulations, 2018 (section 24 of POPIA) |
| Opt out of direct marketing | The opt-out in any marketing message, or by email to the Information Officer (section 69) |
| Make representations about an automated decision | By email, as described in the Privacy Notice (SAV-PRV-001) section 5 (section 71) |
| Complain about the company's processing | To the Information Officer first; and to the Information Regulator at any time (section 74) |
If you are a member of a cooperative institution that uses the core-banking platform, the institution is the responsible party for your information, and your request should be made to it; a request made to the company is referred to the institution.
13. Availability and updating of this manual
This manual is available on the company's website at https://savvyly.tech/paia-manual.html, and for inspection at the head office during business hours, free of charge. A printed copy is provided on request for the fee prescribed in the Regulations for a copy of a manual. It is provided to the Information Regulator on request.
The Information Officer reviews this manual at least once a year, and updates it whenever the company's particulars, its Information Officer or Deputy, the records it holds or the way it processes personal information change. The version on the website is always the current one, and carries its date.