PAIA Manual

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended

Date of compilation: 20 September 2026 · Date of this revision: 20 September 2026

Download this manual as a PDF

This is the manual Synthro (Pty) Ltd is required to publish under section 51 of the Promotion of Access to Information Act 2 of 2000. It says what records we hold, which of them you may have without asking, and how to ask for the rest. It follows the order of the Information Regulator's own template for private bodies, so that the two can be read side by side.

1. List of acronyms and definitions

“the Company”Synthro (Pty) Ltd, registration number 2025/975079/07
“Head of the Private Body”The Chief Executive Officer of the Company, or a person duly authorised by hims 1 PAIA
“IO”Information Officers 1 PAIA
“PAIA”Promotion of Access to Information Act 2 of 2000, as amended
“POPIA”Protection of Personal Information Act 4 of 2013
“the Regulator”The Information Regulator (South Africa)
“the Republic”The Republic of South Africa
“the Platform”The Company’s human-resources software at app.synthro.io, including the NALA assistant

2. Purpose of this manual

This manual is for the public.It exists so that a person can, without approaching the Company first: see which categories of record are available without a formal request; understand well enough what the Company holds to be able to ask for a record; find the records available under other legislation; reach the Information Officer; find the Regulator's guide on how to use PAIA; and see what personal information the Company processes, why, who receives it, whether it leaves the Republic, and whether it is secured.

A right of access to a private body's record is not unconditional. Under section 50(1) of PAIA a requester must be given access only where the record is required for the exercise or protection of a right, the procedural requirements in PAIA are met, and no ground of refusal in Chapter 4 applies. This manual neither enlarges that right nor waives a ground of refusal.

The Company revises this manual as its records and its processing change, and the current version is always the one published on this page.

3. Key contact details for access to information

Head of the Private Body, and Information OfficerNaphtali Tsikada, Founder and Chief Executive Officers 51(1)(a)
Email for PAIA requestsprivacy@synthro.ios 53
Email for privacy and POPIA mattersprivacy@synthro.ios 55 POPIA
Registered and postal addressAnnette Street, Randburg, 2188, South Africa
Websitewww.synthro.io
Deputy Information OfficerNone designated. The Company is a small private body and the Information Officer discharges these duties personally. A deputy will be designated, and this manual updated, if that ceases to be practicable.s 17(1) PAIA

4. The Regulator's guide on how to use PAIA

The Regulator has, under section 10(1) of PAIA, compiled and updated a Guide on how to use PAIA, in an easily comprehensible form, for a person who wishes to exercise a right under PAIA or POPIA. It is available in each of the official languages and in braille.

The Guide describes: the objects of PAIA and POPIA; the contact particulars of the information officers and deputy information officers of public and private bodies; the manner and form of a request for access to a record of a public body under section 11 and of a private body under section 50; the assistance available from an information officer and from the Regulator; every remedy in law available in respect of an act or failure to act under PAIA and POPIA, including how to lodge an internal appeal, a complaint to the Regulator and an application to a court; the provisions of sections 14 and 51 requiring a manual; the provisions of sections 15 and 52 on voluntary disclosure; the notices on fees under sections 22 and 54; and the regulations made under section 92.

How to obtain the Guide. Download it from the Regulator at inforegulator.org.za, request it from the Information Officer at privacy@synthro.io, or inspect it at the Company's registered address during normal business hours.

5. Records available without a request

Made available voluntarily under section 52(1) of PAIA. No request, and no fee, is needed for any of these.

Terms of Servicewww.synthro.io/termsWebsite
Privacy Policy, including the full sub-processor registerwww.synthro.io/privacyWebsite
POPIA compliance statementwww.synthro.io/popiaWebsite
Vulnerability disclosure policywww.synthro.io/security/disclosureWebsite
This PAIA Manualwww.synthro.io/paiaWebsite
Product, pricing and security descriptionswww.synthro.ioWebsite

6. Records available under other legislation

Memorandum of Incorporation, share register, register of directorsCompanies Act 71 of 2008
Annual financial statements and accounting recordsCompanies Act 71 of 2008; Tax Administration Act 28 of 2011
VAT, PAYE and income-tax recordsIncome Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011
Employment records of the Company’s own staffBasic Conditions of Employment Act 75 of 1997; Employment Equity Act 55 of 1998; Labour Relations Act 66 of 1995
Records of processing operations, and this manualPOPIA; PAIA

7. Subjects on which records are held, and the categories on each

Corporate and statutoryIncorporation documents, board and shareholder records, statutory registers, licences and registrations.
FinanceAccounting records, invoices, receipts, bank records, returns to SARS, insurance policies.
Customers and contractsSigned agreements, addenda, data-processing annexures, quotations, orders, correspondence, support tickets and billing records.
Human resources — the Company’s own peopleContracts of employment and engagement, confidentiality and intellectual-property assignments, payroll and leave records, performance and training records.
Suppliers and service providersSupplier contracts, data-processing terms, the sub-processor register, and the security and certification documentation received from providers.
Information technology and securityInformation-security policies, access-control records, audit logs, backup and disaster-recovery records, incident records.
MarketingWebsite content, campaign records, newsletter subscriptions and marketing-consent records.
Customer Data held on the PlatformEmployee records, documents, leave, performance, disciplinary and related records belonging to the Company's customers. The Company is the Operator of this information, not the Responsible Party — see section 8.

8. Processing of personal information

Purpose of processing, and two very different roles. The Company processes personal information for two purposes that must not be confused. First, as Responsible Party for its own business: to contract with and support its customers, to bill them, to employ and engage its own people, to market its services lawfully, and to meet its statutory obligations. Second, as Operatorfor the employee information its customers load onto the Platform. For that information the customer is the Responsible Party and decides what happens to it; the Company processes it only on the customer's authorisation, only to provide, operate and support the Platform for that customer and to comply with the law, and treats it as confidential.

A request about a customer's employee record is not the Company's to answer. Where a data subject approaches the Company about information held on the Platform on a customer's behalf, the Company will not respond substantively. It refers the request to that customer without undue delay and assists the customer in answering it. The employer, not the Company, decides that request.

The Company does not use Customer Data to train artificial intelligence.It is not used to train, fine-tune, retrain or otherwise improve any machine-learning or artificial-intelligence model, whether the Company's or a third party's, and no employee record is stored by any artificial-intelligence provider.

8.2 · Categories of data subjects, and the information processed

Customers, and the people at a customer who use the PlatformName, work email address, telephone number, job role, department, reporting line, account and authentication records, and records of use of the Platform.
Employees of a customer, whose records that customer loads onto the PlatformEmployment records: identifying particulars, contact details, employment history, remuneration and leave records, performance, disciplinary and grievance records, documents issued to them, and the special personal information a customer is permitted to load — race or ethnic origin and disability, for employment-equity reporting, and health information including medical certificates furnished in support of sick leave.
Prospective customers and website visitorsName, email address, company name, telephone number, the content of an enquiry, and website usage information.
The Company’s own employees, contributors and applicantsIdentifying and contact particulars, qualifications, employment and engagement records, remuneration and banking details, and performance records.
Suppliers and service providersCompany name and registration number, contact particulars of representatives, and banking details.

8.3 · Recipients to whom personal information may be supplied

Customer Data held on the PlatformThe sub-processors in the Company's published register at www.synthro.io/privacy — each engaged only to operate or support the Platform, and each bound by written data-protection and confidentiality obligations.
Billing and payment particularsThe Company’s payment processor, and its accountants and auditors.
Any categoryA court, the Regulator, SARS or another authority, where the Company is required by law to disclose it; and the Company’s legal advisers, under legal professional privilege.
No categoryThe Company does not supply personal information to any advertising network, data broker or information reseller, and does not sell, rent or otherwise monetise it.

8.4 · Planned transborder flows of personal information

United KingdomAll Customer Data held on the Platform — the primary database, authentication, stored documents, and the independent encrypted offsite backup. Held in the London region. The United Kingdom is subject to the UK General Data Protection Regulation and the Data Protection Act 2018, which uphold principles substantially similar to the conditions in POPIA.s 72(1)(a)
United StatesA narrow set of processing, none of which stores an employee record: the artificial-intelligence request that answers a question a user has actually asked, processed in transit only; transactional email, which carries the message but never an employee document; bot-protection signals on public forms; and delivery of the application front-end.s 72(1)(b)
Nigeria and South AfricaBilling contact and payment particulars, for payment processing. No employee records.s 72(1)(b)

9. Security safeguards

A general description, as the Regulator's template requires.The Company maintains appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of the personal information in its care, as sections 19 and 21 of POPIA require. These include: encryption in transit and at rest; database-level row security, so that each customer's data is logically isolated and inaccessible to any other customer; authenticated, role-based access control, with multi-factor authentication available on accounts and required for administrative access; access by Company personnel strictly on a need-to-know basis under a binding duty of confidentiality; audit logging of administrative access; regular encrypted backups, together with an independent encrypted offsite copy held with a separate provider for disaster recovery; and a documented incident-response procedure.

This description is deliberately general. The Act asks for the nature of the safeguards, not their configuration. The Company will not publish detail that would assist a person seeking to defeat them. A customer conducting a governance or procurement review may request fuller detail under confidentiality.

If safeguards are compromised. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the Company notifies the affected customer in writing immediately and in any event within twenty-four hours, notifies the Regulator and the data subjects as section 22 of POPIA requires, and contains, investigates and remediates the incident.

10. How to request access to a record

Use the prescribed form. A request for access to a record of a private body must be made on the form prescribed by the PAIA Regulations, being Form 2 under the Regulations published in 2021. Download the current form from the Regulator at inforegulator.org.za, or ask us for a copy at privacy@synthro.io.

Send it to the Information Officer at privacy@synthro.io, or by post or delivery to the address in section 3. Give enough particulars for the Company to identify the record and to identify you; state the form of access you want; give an address in the Republic for the reply; and — this is the part most often left out, and the Company cannot decide a request without it — state the right you are seeking to exercise or protect, and explain why the record is required for that.

If you are asking on someone else's behalf, submit proof of your authority in a form satisfactory to the Information Officer. If you cannot read or write, or a disability prevents you completing the form, you may make the request orally, and the Information Officer will reduce it to writing and give you a copy.

Fees. A request fee, and where access is granted an access fee, are prescribed by Annexure B to the PAIA Regulations. The Company charges what is prescribed and nothing more; it levies no fee of its own. Because those amounts are set and changed by Gazette they are not reproduced here: the Information Officer will notify you in writing of the amount payable before the request is processed further, as section 54 requires. A request by a data subject for their own personal information carries no request fee.

Decision and time. The Company will decide within thirty days of receiving a compliant request, and will notify you in writing of the decision and, where access is refused, of adequate reasons and the provisions relied on. That period may be extended by a further thirty days in the circumstances PAIA permits, and you will be told if it is.

Grounds of refusal. The Company may be obliged or entitled to refuse access under Chapter 4 of Part 3 of PAIA, including to protect the privacy of a third party, the commercial information of a third party or of the Company, information held in confidence, and records privileged from production in legal proceedings. A customer's Customer Data is the commercial and confidential information of that customer, and the Company will not disclose it to a third party without that customer's authorisation or a lawful obligation to do so.

If you are dissatisfied. There is no internal appeal against a decision of the head of a private body. You may lodge a complaint with the Regulator under section 77A of PAIA, on the prescribed complaint form, at PAIAComplaints@inforegulator.org.za; or apply to a court under section 78. Nothing in this manual limits either remedy.

11. Availability of this manual, and how to reach the Regulator

Where to find this manual. It is published on this page and downloadable as a PDF; it is available for public inspection at the Company's registered address during normal business hours; it will be sent to any person on request, a reasonable prescribed fee per A4 photocopy applying to a paper copy and no fee to the electronic copy; and it is available to the Regulator on request.

The Company updates this manual whenever its records or its processing change materially, and reviews it at least annually. The date of compilation and the date of the current revision appear at the top of this page.

Information Regulator (South Africa)

Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone 010 023 5200 · Toll free 0800 017 160
General enquiries enquiries@inforegulator.org.za
PAIA complaints PAIAComplaints@inforegulator.org.za
POPIA complaints POPIAComplaints@inforegulator.org.za
inforegulator.org.za

12. Issued by

NameNaphtali Tsikada
CapacityFounder and Chief Executive Officer — Head of the Private Body and Information Officer
ForSynthro (Pty) Ltd, registration number 2025/975079/07
Date of compilation20 September 2026
Date of this revision20 September 2026