PAIA Manual
This manual explains how to request access to records held by DataRights in terms of the Promotion of Access to Information Act, 2 of 2000.
1. Company Details
| Entity | DataRights |
|---|---|
| Country | South Africa |
| Service address | South Africa |
| Information Officer | DataRights Information Officer |
| privacy@datarights.co.za | |
| Support | support@datarights.co.za |
2. Purpose of This Manual
This PAIA Manual helps data subjects, customers, regulators, and other requesters understand what categories of records DataRights may hold and how a formal access request can be submitted.
3. Records DataRights May Hold
- Company administration, governance, accounting, and operational records.
- Customer account, consent, subscription, payment, and support records.
- POPIA request workflow records, broker response records, and audit records.
- Supplier, infrastructure, security, and service provider records.
- Operator agreements, data processing addenda, acceptance evidence, and service-provider compliance records.
4. How to Request Access
Send a written PAIA request to privacy@datarights.co.za. Include enough detail to identify the record requested, your contact details, proof of identity where required, and the right you are seeking to exercise.
5. Grounds for Refusal
DataRights may refuse access where PAIA or another law allows or requires refusal, including where records contain another person's personal information, confidential commercial information, legally privileged material, security-sensitive information, or records not held by DataRights.
6. Fees
PAIA request fees, access fees, or reproduction fees may apply where allowed by law. DataRights will explain any applicable fee before processing where required.
7. Information Regulator and Regulatory Resources
You may contact the Information Regulator of South Africa for PAIA or POPIA complaints if you are not satisfied with the response to a lawful request. DataRights keeps official links and forms on a separate Regulatory Resources page.
8. Service Providers and Cross-Border Records
Records may be processed through service providers used by DataRights. Resend processes transactional email recipient details, metadata, and message content, with primary processing operations in the United States. A request for access to DataRights records should still be submitted to DataRights. Where necessary and legally permitted, DataRights may seek assistance from the relevant service provider.
Supabase-hosted customer and operational records may be stored or processed according to the selected project region and the locations used by Supabase and its authorised sub-processors. Requests for access to these DataRights records must be submitted to DataRights, which remains responsible for responding and may use Supabase tools or assistance where necessary.
Cloudflare-processed traffic, request, security, and operational records may be handled through Cloudflare's global infrastructure. Requests for DataRights records must be submitted to DataRights, which remains responsible for responding and may seek Cloudflare assistance where necessary and legally permitted.
HIBP-derived breach alert records held by DataRights may include breach source, date, exposed-data categories, severity, and customer action context. Requests for DataRights-held HIBP-derived records must be submitted to DataRights. HIBP-specific opt-out or visibility requests should use HIBP's own opt-out process.
9. Service Disclaimer
DataRights provides administrative support and automation for requests made under POPIA, including Sections 11 and 24 where applicable. DataRights submits requests and tracks responses, but third-party organisations remain responsible for their own compliance and response decisions.