List of acronyms and abbreviations
| Abbreviation | Meaning |
|---|---|
| “CEO” | Chief Executive Officer |
| “Clidash” | Clidash (Pty) Ltd, registration number 2025/499646/07 |
| “DIO” | Deputy Information Officer |
| “IO” | Information Officer |
| “Minister” | Minister of Justice and Correctional Services |
| “PAIA” | Promotion of Access to Information Act No. 2 of 2000 (as amended) |
| “POPIA” | Protection of Personal Information Act No. 4 of 2013 |
| “Regulator” | Information Regulator |
| “Republic” | Republic of South Africa |
Purpose of this PAIA Manual
This PAIA Manual is useful for the public to:
2.1check the categories of records held by Clidash which are available without a person having to submit a formal PAIA request;
2.2have a sufficient understanding of how to make a request for access to a record of Clidash, by providing a description of the subjects on which Clidash holds records and the categories of records held on each subject;
2.3know the description of the records of Clidash which are available in accordance with any other legislation;
2.4access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;
2.5know the description of the guide on how to use PAIA, as updated by the Regulator, and how to obtain access to it;
2.6know if Clidash will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;
2.7know the description of the categories of data subjects and of the information or categories of information relating thereto;
2.8know the recipients or categories of recipients to whom the personal information may be supplied;
2.9know if Clidash has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and
2.10know whether Clidash has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
About Clidash and the scope of this Manual
Clidash (Pty) Ltd is a private company incorporated in the Republic of South Africa under registration number 2025/499646/07. Clidash develops and operates a cloud-based customer relationship management platform used by independent financial advisory firms.
Clidash's role in relation to personal information falls into two distinct categories, and this distinction determines where a request for access should be directed:
3.1Clidash as responsible party. Clidash determines the purpose and means of processing in respect of its own records: its employees, its own customers (advisory firms) and their staff users, its suppliers, its prospective customers and visitors to its website. This Manual describes those records.
3.2Clidash as operator. Clidash processes personal information relating to the clients of advisory firms solely on behalf of, and on the documented instruction of, those firms. In respect of that information the advisory firm is the responsible party and Clidash is an operator as defined in POPIA.
Are you a client of a financial advisory firm?
A request for access to the records of a client of an advisory firm must be directed to that advisory firm and not to Clidash. Clidash will refer any such request received to the relevant firm and will assist that firm in responding.
Key contact details for access to information
4.1 Information Officer
Gerhard Arnold Hattingh
Chief Executive Officer
- Date of appointment
- 24 June 2025
- Registration with the Regulator
- Registration number 2026-006374
- arnold@clidash.com
- Telephone
- +27 71 222 0845
4.2 Deputy Information Officer
4.3 Access to information general contacts
- info@clidash.com
4.4 Head office
- Physical address
- 23 Kreupelboom, Cape Town, 7530
- Postal address
- As per physical address
- Telephone
- +27 71 222 0845
- info@clidash.com
- Website
- https://clidash.com
Guide on how to use PAIA and how to obtain access to the Guide
5.1The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
5.2The Guide is available in each of the official languages and in braille.
5.3The Guide contains a description of:
5.3.1the objects of PAIA and POPIA;
5.3.2the postal and street address, phone and fax number and, if available, electronic mail address of the Information Officer of every public body, and every Deputy Information Officer of every public and private body designated in terms of section 17(1) of PAIA and section 56 of POPIA;
5.3.3the manner and form of a request for access to a record of a public body contemplated in section 11, and access to a record of a private body contemplated in section 50;
5.3.4the assistance available from the Information Officer of a public body in terms of PAIA and POPIA;
5.3.5the assistance available from the Regulator in terms of PAIA and POPIA;
5.3.6all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court against a decision by the information officer of a public body, a decision on internal appeal, a decision by the Regulator or a decision of the head of a private body;
5.3.7the provisions of sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;
5.3.8the provisions of sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively;
5.3.9the notices issued in terms of sections 22 and 54 regarding fees to be paid in relation to requests for access; and
5.3.10the regulations made in terms of section 92.
5.4Members of the public can inspect or make copies of the Guide from the offices of public and private bodies, including the office of the Regulator, during normal working hours.
5.5The Guide can also be obtained:
5.5.1upon request to the Information Officer; and
5.5.2from the website of the Regulator at https://inforegulator.org.za.
5.6A copy of the Guide is also available in the following two official languages, for public inspection during normal office hours at the head office of Clidash:
5.6.1English; and
5.6.2Afrikaans.
Categories of records available without a person having to request access
| Category of records | Types of record | Available on website | Available upon request |
|---|---|---|---|
| Corporate information | Company overview, product descriptions, contact details | ||
| Information governance | This PAIA Manual, Privacy Notice | ||
| Contractual terms | Standard Service Agreement terms, Data Processing Agreement, Data Security and Compliance Overview | ||
| Marketing material | Product information, published articles, pricing information |
Records available in accordance with other legislation
| Category of records | Applicable legislation |
|---|---|
| Memorandum of Incorporation, share register, director and shareholder records, annual returns | Companies Act 71 of 2008 |
| PAIA Manual | Promotion of Access to Information Act 2 of 2000 |
| Records relating to the processing of personal information, records of data subject requests and of security compromises | Protection of Personal Information Act 4 of 2013 |
| Income tax, VAT and PAYE records | Income Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011 |
| Employment contracts, payroll records, leave records, employment equity records | Basic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995; Employment Equity Act 55 of 1998 |
| Unemployment insurance records | Unemployment Insurance Act 63 of 2001 |
| Skills development levy records | Skills Development Levies Act 9 of 1999 |
| Occupational health and safety records | Occupational Health and Safety Act 85 of 1993 |
| Compensation fund records | Compensation for Occupational Injuries and Diseases Act 130 of 1993 |
| Financial statements and accounting records | Companies Act 71 of 2008 |
| Records relating to electronic communications and transactions | Electronic Communications and Transactions Act 25 of 2002 |
Subjects on which Clidash holds records and categories of records held
| Subject | Categories of records |
|---|---|
| Corporate and statutory | Memorandum of Incorporation; CIPC registration documents and annual returns; share register; director and shareholder records; board and shareholder resolutions |
| Finance | Management accounts and annual financial statements; invoices and statements; bank records; tax returns and assessments; budgets and forecasts; subscription and billing records |
| Human resources | Employment contracts and addenda; personnel files; payroll and remuneration records; leave records; recruitment and job applicant records; HR policies and procedures; training and awareness records |
| Customers and contracts | Service Agreements; Data Processing Agreements; onboarding and implementation records; support and service correspondence; data migration records; billing and subscription records |
| Prospective customers | Enquiries and correspondence; proposals and quotations; demonstration and trial records |
| Suppliers and service providers | Supplier contracts and Data Processing Agreements; supplier invoices and payment records; sub-processor records |
| Product, technical and security | Source code and technical architecture documentation; access control and role-based access records; system and application audit logs; backup and recovery records; availability monitoring records; incident and security compromise records; information security policies |
| Information governance and compliance | This PAIA Manual; POPIA policies and procedures; Information Officer registration records; records of data subject requests; records of security compromises and notifications; consent and processing records |
| Marketing | Website content and analytics; marketing campaign records; published material |
| Insurance and legal | Insurance policies and claims records; legal correspondence and advice; litigation records (where applicable) |
Processing of personal information
9.1 Purpose of processing personal information
Clidash processes personal information for the following purposes:
9.1.1to provide, operate, support and maintain the Clidash platform for its customers in accordance with the Service Agreement and Data Processing Agreement concluded with each customer;
9.1.2to administer customer accounts, including onboarding, user provisioning, subscription management, billing and collection of fees;
9.1.3to provide customer support and to respond to enquiries and service requests;
9.1.4to communicate with customers and prospective customers about the products and services of Clidash;
9.1.5to recruit, employ and administer the employment of its personnel, and to comply with its obligations as an employer;
9.1.6to procure goods and services from suppliers and to administer those relationships;
9.1.7to maintain the security, integrity and availability of its systems, including access control, audit logging, monitoring and incident investigation;
9.1.8to comply with its legal, regulatory, accounting and tax obligations; and
9.1.9to establish, exercise or defend legal claims.
Client data processed as operator
Where Clidash processes personal information relating to the clients of an advisory firm, it does so solely as an operator, on the documented instruction of that firm, and for no purpose of its own. Clidash does not use that information to train artificial intelligence models and does not disclose it other than as instructed by the firm or as required by law.
9.2 Categories of data subjects and of the information relating thereto
| Category of data subject | Personal information that may be processed |
|---|---|
| Customers (advisory firms) and their authorised users | Name and surname; job title and role; work contact details (email address, telephone number); business address; company registration number and VAT number; authentication and account records; system usage and audit log records; billing and payment records |
| Prospective customers | Name and surname; job title; work contact details; business name; correspondence and enquiry records |
| Employees and job applicants | Name and surname; contact details; residential address; identity number; date of birth; qualifications and employment history; remuneration and banking details; tax reference number; leave and performance records; emergency contact details; recruitment correspondence |
| Suppliers and service providers | Names of contact persons; name of the legal entity; registration and VAT numbers; physical and postal address; contact details; banking details; contractual and commercial information |
| Website visitors | Technical and usage information collected through the website, including device and browser information and pages visited |
| Clients of advisory firms (processed as operator only) | Name and surname; contact details; identity number; date of birth; residential and postal address; marital and dependant information; financial product, policy and investment information; correspondence, notes and documents uploaded by the advisory firm; and any other personal information the advisory firm elects to record in the platform, which may include special personal information such as health information where relevant to a financial product |
9.3 Recipients or categories of recipients to whom personal information may be supplied
| Category of personal information | Recipients or categories of recipients |
|---|---|
| Customer and client data hosted in the platform | Cloud infrastructure providers engaged as sub-operators, namely Google Cloud Platform (data hosted in Johannesburg, South Africa) and Microsoft Azure (artificial intelligence processing) |
| Transactional and notification email content | Email delivery service provider engaged as sub-operator |
| Billing and payment information | Payment processing service provider engaged as sub-operator |
| Client data processed as operator | The relevant advisory firm, being the responsible party, and any third party the firm instructs Clidash to transmit to |
| Employee information | South African Revenue Service; Unemployment Insurance Fund; Compensation Fund; retirement fund and medical scheme administrators (where applicable); payroll service providers |
| Employee and supplier banking information | Clidash's banking service providers |
| Financial and corporate records | External accountants and auditors; attorneys and other professional advisers; Companies and Intellectual Property Commission; South African Revenue Service |
| Any category of personal information | Law enforcement authorities, regulators and courts, where required by law or a valid legal process |
A current register of the sub-operators engaged by Clidash is available on request and is included in the Data Security and Compliance Overview supplied to customers.
9.4 Planned transborder flows of personal information
Clidash hosts its primary database and file storage within the Republic of South Africa, in Google Cloud's Johannesburg region. The following processing takes place outside the Republic:
| Processing activity | Country or region | Categories of personal information |
|---|---|---|
| Artificial intelligence processing (document extraction, summarisation, transcription) | Sweden (Microsoft Azure, EU Data Zone) | Content of documents, notes and communications submitted for processing, which may include names, contact details, identity numbers, financial product information and other personal information contained in that content |
| Serverless application functions | Belgium (Google Cloud) | Data transiting the platform in the course of processing requests |
| Outbound transactional email delivery | United States | Recipient name and email address, and the content of the email |
| Payment processing | Republic of South Africa | Billing contact details and payment information |
Transfers outside the Republic are made in accordance with section 72 of POPIA, on the basis of contractual arrangements with each recipient that require the recipient to uphold principles for the reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information under POPIA, and on the basis that the transfer is necessary for the performance of the contract between Clidash and the customer. Content submitted for artificial intelligence processing is not retained by the model provider and is not used to train models.
9.5 General description of information security measures
Clidash implements appropriate, reasonable technical and organisational measures in terms of section 19 of POPIA to secure the integrity and confidentiality of personal information in its possession or under its control. These include:
Technical measures
- Encryption of personal information in transit using TLS, and encryption at rest
- Logical separation of each customer's data, with access enforced by server-side security rules that are verified by an automated test suite executed on every deployment
- Role-based access control governing which users and which Clidash personnel may access which data, enforced at both the application and server layers
- Multi-factor authentication on all administrative and infrastructure accounts
- Application-level audit logging of privileged actions, including any access by Clidash personnel to a customer environment, recorded and visible to the affected customer
- Infrastructure-level audit logging of data access
- Continuous availability monitoring with automated alerting
- Automated backups with point-in-time recovery, and periodic testing of restoration
- Full disk encryption on all endpoint devices used by personnel
- Segregation of production, development and demonstration environments, with production data not used outside the production environment
Organisational measures
- A designated Information Officer registered with the Regulator
- Written information security, access control and incident response policies
- Contractual confidentiality obligations binding on all personnel
- Documented onboarding and offboarding procedures governing the granting and withdrawal of system access
- Written agreements with all sub-operators requiring them to establish and maintain appropriate security measures
- Notification of the affected customer and, where applicable, the Regulator and affected data subjects, in the event of a security compromise
How to request access to a record
-
10.1
A requester must complete Form 2 (Request for Access to Record of Private Body), prescribed in Regulation 7 of the PAIA Regulations, 2021, and submit it to the Information Officer at the contact details in paragraph 4 above. The form is available from the Information Officer and from the website of the Regulator.
-
10.2
The requester must provide sufficient particulars to enable the Information Officer to identify the record and the requester, must indicate the form of access required, and must specify a postal address or email address in the Republic.
-
10.3
The requester must identify the right that he or she is seeking to exercise or protect and explain why the record requested is required for the exercise or protection of that right.
-
10.4
The prescribed request fee must be paid before the request is processed. Where access is granted, a further access fee is payable for the search, reproduction and preparation of the record.
-
10.5
The Information Officer will decide on the request and notify the requester of the decision within 30 days of receipt of the request, which period may be extended in the circumstances contemplated in PAIA.
-
10.6
Access to a record may be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, which include the mandatory protection of the privacy of a third party who is a natural person, the mandatory protection of the commercial information of a third party, and the mandatory protection of records privileged from production in legal proceedings.
10.7 Prescribed fees
The fees prescribed in Annexure B to the PAIA Regulations, 2021 (published in Regulation Gazette No. 11329, Government Gazette No. 45057 of 27 August 2021) in respect of private bodies are:
| Item | Amount |
|---|---|
| Request fee payable by every requester | R140.00 |
| Photocopy of an A4-size page | R2.00 per page or part thereof |
| Printed copy of an A4-size page | R2.00 per page or part thereof |
| Copy in computer-readable form on a flash drive provided by the requester | R40.00 |
| Copy in computer-readable form on a compact disc provided by the requester | R40.00 |
| Copy in computer-readable form on a compact disc provided to the requester | R60.00 |
| Transcription of visual images, per A4-size page | To be outsourced; charged in accordance with a quotation obtained from the service provider |
Fees for the search and preparation of records, and any deposit payable, are as prescribed in Annexure B to the PAIA Regulations, 2021. These amounts may be amended by the Minister from time to time, and the current fee structure published by the Regulator applies.
Availability of this Manual
11.1A copy of this Manual is available:
11.1.1on the website of Clidash at https://clidash.com/doc-manual;
11.1.2at the head office of Clidash for public inspection during normal business hours;
11.1.3to any person upon request and upon payment of a reasonable prescribed fee; and
11.1.4to the Information Regulator upon request.
11.2A fee for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made.
Updating of this Manual
The head of Clidash (Pty) Ltd will update this Manual on a regular basis and whenever a material change occurs in the information it contains.
Issued by
Gerhard Arnold Hattingh
Chief Executive Officer and Information Officer
Clidash (Pty) Ltd