Promotion of Access to Information Act

PAIA Manual

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended). This Manual explains which records Clidash holds, how to request access to them, and how Clidash processes personal information.

  • Clidash (Pty) Ltd
  • Registration no.2025/499646/07
  • Compiled25 August 2026
  • Revised25 August 2026
On this page
01

List of acronyms and abbreviations

AbbreviationMeaning
“CEO”Chief Executive Officer
“Clidash”Clidash (Pty) Ltd, registration number 2025/499646/07
“DIO”Deputy Information Officer
“IO”Information Officer
“Minister”Minister of Justice and Correctional Services
“PAIA”Promotion of Access to Information Act No. 2 of 2000 (as amended)
“POPIA”Protection of Personal Information Act No. 4 of 2013
“Regulator”Information Regulator
“Republic”Republic of South Africa
02

Purpose of this PAIA Manual

This PAIA Manual is useful for the public to:

2.1check the categories of records held by Clidash which are available without a person having to submit a formal PAIA request;

2.2have a sufficient understanding of how to make a request for access to a record of Clidash, by providing a description of the subjects on which Clidash holds records and the categories of records held on each subject;

2.3know the description of the records of Clidash which are available in accordance with any other legislation;

2.4access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;

2.5know the description of the guide on how to use PAIA, as updated by the Regulator, and how to obtain access to it;

2.6know if Clidash will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;

2.7know the description of the categories of data subjects and of the information or categories of information relating thereto;

2.8know the recipients or categories of recipients to whom the personal information may be supplied;

2.9know if Clidash has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and

2.10know whether Clidash has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.

03

About Clidash and the scope of this Manual

Clidash (Pty) Ltd is a private company incorporated in the Republic of South Africa under registration number 2025/499646/07. Clidash develops and operates a cloud-based customer relationship management platform used by independent financial advisory firms.

Clidash's role in relation to personal information falls into two distinct categories, and this distinction determines where a request for access should be directed:

3.1Clidash as responsible party. Clidash determines the purpose and means of processing in respect of its own records: its employees, its own customers (advisory firms) and their staff users, its suppliers, its prospective customers and visitors to its website. This Manual describes those records.

3.2Clidash as operator. Clidash processes personal information relating to the clients of advisory firms solely on behalf of, and on the documented instruction of, those firms. In respect of that information the advisory firm is the responsible party and Clidash is an operator as defined in POPIA.

Are you a client of a financial advisory firm?

A request for access to the records of a client of an advisory firm must be directed to that advisory firm and not to Clidash. Clidash will refer any such request received to the relevant firm and will assist that firm in responding.

04

Key contact details for access to information

4.2 Deputy Information Officer

Clidash has not designated a Deputy Information Officer. All requests should be directed to the Information Officer.

4.3 Access to information general contacts

Email
info@clidash.com

4.4 Head office

Physical address
23 Kreupelboom, Cape Town, 7530
Postal address
As per physical address
Telephone
+27 71 222 0845
Email
info@clidash.com
Website
https://clidash.com
05

Guide on how to use PAIA and how to obtain access to the Guide

5.1The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.

5.2The Guide is available in each of the official languages and in braille.

5.3The Guide contains a description of:

5.3.1the objects of PAIA and POPIA;

5.3.2the postal and street address, phone and fax number and, if available, electronic mail address of the Information Officer of every public body, and every Deputy Information Officer of every public and private body designated in terms of section 17(1) of PAIA and section 56 of POPIA;

5.3.3the manner and form of a request for access to a record of a public body contemplated in section 11, and access to a record of a private body contemplated in section 50;

5.3.4the assistance available from the Information Officer of a public body in terms of PAIA and POPIA;

5.3.5the assistance available from the Regulator in terms of PAIA and POPIA;

5.3.6all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court against a decision by the information officer of a public body, a decision on internal appeal, a decision by the Regulator or a decision of the head of a private body;

5.3.7the provisions of sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;

5.3.8the provisions of sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively;

5.3.9the notices issued in terms of sections 22 and 54 regarding fees to be paid in relation to requests for access; and

5.3.10the regulations made in terms of section 92.

5.4Members of the public can inspect or make copies of the Guide from the offices of public and private bodies, including the office of the Regulator, during normal working hours.

5.5The Guide can also be obtained:

5.5.1upon request to the Information Officer; and

5.5.2from the website of the Regulator at https://inforegulator.org.za.

5.6A copy of the Guide is also available in the following two official languages, for public inspection during normal office hours at the head office of Clidash:

5.6.1English; and

5.6.2Afrikaans.

06

Categories of records available without a person having to request access

Category of records Types of record Available on website Available upon request
Corporate information Company overview, product descriptions, contact details
Information governance This PAIA Manual, Privacy Notice
Contractual terms Standard Service Agreement terms, Data Processing Agreement, Data Security and Compliance Overview
Marketing material Product information, published articles, pricing information
07

Records available in accordance with other legislation

Category of recordsApplicable legislation
Memorandum of Incorporation, share register, director and shareholder records, annual returnsCompanies Act 71 of 2008
PAIA ManualPromotion of Access to Information Act 2 of 2000
Records relating to the processing of personal information, records of data subject requests and of security compromisesProtection of Personal Information Act 4 of 2013
Income tax, VAT and PAYE recordsIncome Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011
Employment contracts, payroll records, leave records, employment equity recordsBasic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995; Employment Equity Act 55 of 1998
Unemployment insurance recordsUnemployment Insurance Act 63 of 2001
Skills development levy recordsSkills Development Levies Act 9 of 1999
Occupational health and safety recordsOccupational Health and Safety Act 85 of 1993
Compensation fund recordsCompensation for Occupational Injuries and Diseases Act 130 of 1993
Financial statements and accounting recordsCompanies Act 71 of 2008
Records relating to electronic communications and transactionsElectronic Communications and Transactions Act 25 of 2002
08

Subjects on which Clidash holds records and categories of records held

SubjectCategories of records
Corporate and statutoryMemorandum of Incorporation; CIPC registration documents and annual returns; share register; director and shareholder records; board and shareholder resolutions
FinanceManagement accounts and annual financial statements; invoices and statements; bank records; tax returns and assessments; budgets and forecasts; subscription and billing records
Human resourcesEmployment contracts and addenda; personnel files; payroll and remuneration records; leave records; recruitment and job applicant records; HR policies and procedures; training and awareness records
Customers and contractsService Agreements; Data Processing Agreements; onboarding and implementation records; support and service correspondence; data migration records; billing and subscription records
Prospective customersEnquiries and correspondence; proposals and quotations; demonstration and trial records
Suppliers and service providersSupplier contracts and Data Processing Agreements; supplier invoices and payment records; sub-processor records
Product, technical and securitySource code and technical architecture documentation; access control and role-based access records; system and application audit logs; backup and recovery records; availability monitoring records; incident and security compromise records; information security policies
Information governance and complianceThis PAIA Manual; POPIA policies and procedures; Information Officer registration records; records of data subject requests; records of security compromises and notifications; consent and processing records
MarketingWebsite content and analytics; marketing campaign records; published material
Insurance and legalInsurance policies and claims records; legal correspondence and advice; litigation records (where applicable)
09

Processing of personal information

9.1 Purpose of processing personal information

Clidash processes personal information for the following purposes:

9.1.1to provide, operate, support and maintain the Clidash platform for its customers in accordance with the Service Agreement and Data Processing Agreement concluded with each customer;

9.1.2to administer customer accounts, including onboarding, user provisioning, subscription management, billing and collection of fees;

9.1.3to provide customer support and to respond to enquiries and service requests;

9.1.4to communicate with customers and prospective customers about the products and services of Clidash;

9.1.5to recruit, employ and administer the employment of its personnel, and to comply with its obligations as an employer;

9.1.6to procure goods and services from suppliers and to administer those relationships;

9.1.7to maintain the security, integrity and availability of its systems, including access control, audit logging, monitoring and incident investigation;

9.1.8to comply with its legal, regulatory, accounting and tax obligations; and

9.1.9to establish, exercise or defend legal claims.

Client data processed as operator

Where Clidash processes personal information relating to the clients of an advisory firm, it does so solely as an operator, on the documented instruction of that firm, and for no purpose of its own. Clidash does not use that information to train artificial intelligence models and does not disclose it other than as instructed by the firm or as required by law.

9.2 Categories of data subjects and of the information relating thereto

Category of data subjectPersonal information that may be processed
Customers (advisory firms) and their authorised usersName and surname; job title and role; work contact details (email address, telephone number); business address; company registration number and VAT number; authentication and account records; system usage and audit log records; billing and payment records
Prospective customersName and surname; job title; work contact details; business name; correspondence and enquiry records
Employees and job applicantsName and surname; contact details; residential address; identity number; date of birth; qualifications and employment history; remuneration and banking details; tax reference number; leave and performance records; emergency contact details; recruitment correspondence
Suppliers and service providersNames of contact persons; name of the legal entity; registration and VAT numbers; physical and postal address; contact details; banking details; contractual and commercial information
Website visitorsTechnical and usage information collected through the website, including device and browser information and pages visited
Clients of advisory firms (processed as operator only)Name and surname; contact details; identity number; date of birth; residential and postal address; marital and dependant information; financial product, policy and investment information; correspondence, notes and documents uploaded by the advisory firm; and any other personal information the advisory firm elects to record in the platform, which may include special personal information such as health information where relevant to a financial product

9.3 Recipients or categories of recipients to whom personal information may be supplied

Category of personal informationRecipients or categories of recipients
Customer and client data hosted in the platformCloud infrastructure providers engaged as sub-operators, namely Google Cloud Platform (data hosted in Johannesburg, South Africa) and Microsoft Azure (artificial intelligence processing)
Transactional and notification email contentEmail delivery service provider engaged as sub-operator
Billing and payment informationPayment processing service provider engaged as sub-operator
Client data processed as operatorThe relevant advisory firm, being the responsible party, and any third party the firm instructs Clidash to transmit to
Employee informationSouth African Revenue Service; Unemployment Insurance Fund; Compensation Fund; retirement fund and medical scheme administrators (where applicable); payroll service providers
Employee and supplier banking informationClidash's banking service providers
Financial and corporate recordsExternal accountants and auditors; attorneys and other professional advisers; Companies and Intellectual Property Commission; South African Revenue Service
Any category of personal informationLaw enforcement authorities, regulators and courts, where required by law or a valid legal process

A current register of the sub-operators engaged by Clidash is available on request and is included in the Data Security and Compliance Overview supplied to customers.

9.4 Planned transborder flows of personal information

Clidash hosts its primary database and file storage within the Republic of South Africa, in Google Cloud's Johannesburg region. The following processing takes place outside the Republic:

Processing activityCountry or regionCategories of personal information
Artificial intelligence processing (document extraction, summarisation, transcription)Sweden (Microsoft Azure, EU Data Zone)Content of documents, notes and communications submitted for processing, which may include names, contact details, identity numbers, financial product information and other personal information contained in that content
Serverless application functionsBelgium (Google Cloud)Data transiting the platform in the course of processing requests
Outbound transactional email deliveryUnited StatesRecipient name and email address, and the content of the email
Payment processingRepublic of South AfricaBilling contact details and payment information

Transfers outside the Republic are made in accordance with section 72 of POPIA, on the basis of contractual arrangements with each recipient that require the recipient to uphold principles for the reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information under POPIA, and on the basis that the transfer is necessary for the performance of the contract between Clidash and the customer. Content submitted for artificial intelligence processing is not retained by the model provider and is not used to train models.

9.5 General description of information security measures

Clidash implements appropriate, reasonable technical and organisational measures in terms of section 19 of POPIA to secure the integrity and confidentiality of personal information in its possession or under its control. These include:

Technical measures

  • Encryption of personal information in transit using TLS, and encryption at rest
  • Logical separation of each customer's data, with access enforced by server-side security rules that are verified by an automated test suite executed on every deployment
  • Role-based access control governing which users and which Clidash personnel may access which data, enforced at both the application and server layers
  • Multi-factor authentication on all administrative and infrastructure accounts
  • Application-level audit logging of privileged actions, including any access by Clidash personnel to a customer environment, recorded and visible to the affected customer
  • Infrastructure-level audit logging of data access
  • Continuous availability monitoring with automated alerting
  • Automated backups with point-in-time recovery, and periodic testing of restoration
  • Full disk encryption on all endpoint devices used by personnel
  • Segregation of production, development and demonstration environments, with production data not used outside the production environment

Organisational measures

  • A designated Information Officer registered with the Regulator
  • Written information security, access control and incident response policies
  • Contractual confidentiality obligations binding on all personnel
  • Documented onboarding and offboarding procedures governing the granting and withdrawal of system access
  • Written agreements with all sub-operators requiring them to establish and maintain appropriate security measures
  • Notification of the affected customer and, where applicable, the Regulator and affected data subjects, in the event of a security compromise
10

How to request access to a record

  1. 10.1

    A requester must complete Form 2 (Request for Access to Record of Private Body), prescribed in Regulation 7 of the PAIA Regulations, 2021, and submit it to the Information Officer at the contact details in paragraph 4 above. The form is available from the Information Officer and from the website of the Regulator.

  2. 10.2

    The requester must provide sufficient particulars to enable the Information Officer to identify the record and the requester, must indicate the form of access required, and must specify a postal address or email address in the Republic.

  3. 10.3

    The requester must identify the right that he or she is seeking to exercise or protect and explain why the record requested is required for the exercise or protection of that right.

  4. 10.4

    The prescribed request fee must be paid before the request is processed. Where access is granted, a further access fee is payable for the search, reproduction and preparation of the record.

  5. 10.5

    The Information Officer will decide on the request and notify the requester of the decision within 30 days of receipt of the request, which period may be extended in the circumstances contemplated in PAIA.

  6. 10.6

    Access to a record may be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, which include the mandatory protection of the privacy of a third party who is a natural person, the mandatory protection of the commercial information of a third party, and the mandatory protection of records privileged from production in legal proceedings.

10.7 Prescribed fees

The fees prescribed in Annexure B to the PAIA Regulations, 2021 (published in Regulation Gazette No. 11329, Government Gazette No. 45057 of 27 August 2021) in respect of private bodies are:

ItemAmount
Request fee payable by every requesterR140.00
Photocopy of an A4-size pageR2.00 per page or part thereof
Printed copy of an A4-size pageR2.00 per page or part thereof
Copy in computer-readable form on a flash drive provided by the requesterR40.00
Copy in computer-readable form on a compact disc provided by the requesterR40.00
Copy in computer-readable form on a compact disc provided to the requesterR60.00
Transcription of visual images, per A4-size pageTo be outsourced; charged in accordance with a quotation obtained from the service provider

Fees for the search and preparation of records, and any deposit payable, are as prescribed in Annexure B to the PAIA Regulations, 2021. These amounts may be amended by the Minister from time to time, and the current fee structure published by the Regulator applies.

11

Availability of this Manual

11.1A copy of this Manual is available:

11.1.1on the website of Clidash at https://clidash.com/doc-manual;

11.1.2at the head office of Clidash for public inspection during normal business hours;

11.1.3to any person upon request and upon payment of a reasonable prescribed fee; and

11.1.4to the Information Regulator upon request.

11.2A fee for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made.

12

Updating of this Manual

The head of Clidash (Pty) Ltd will update this Manual on a regular basis and whenever a material change occurs in the information it contains.

Issued by

Gerhard Arnold Hattingh

Chief Executive Officer and Information Officer
Clidash (Pty) Ltd