PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended
Date of compilation: 20 September 2026 · Date of this revision: 20 September 2026
This is the manual Synthro (Pty) Ltd is required to publish under section 51 of the Promotion of Access to Information Act 2 of 2000. It says what records we hold, which of them you may have without asking, and how to ask for the rest. It follows the order of the Information Regulator's own template for private bodies, so that the two can be read side by side.
1. List of acronyms and definitions
| “the Company” | Synthro (Pty) Ltd, registration number 2025/975079/07 | |
| “Head of the Private Body” | The Chief Executive Officer of the Company, or a person duly authorised by him | s 1 PAIA |
| “IO” | Information Officer | s 1 PAIA |
| “PAIA” | Promotion of Access to Information Act 2 of 2000, as amended | |
| “POPIA” | Protection of Personal Information Act 4 of 2013 | |
| “the Regulator” | The Information Regulator (South Africa) | |
| “the Republic” | The Republic of South Africa | |
| “the Platform” | The Company’s human-resources software at app.synthro.io, including the NALA assistant |
2. Purpose of this manual
This manual is for the public.It exists so that a person can, without approaching the Company first: see which categories of record are available without a formal request; understand well enough what the Company holds to be able to ask for a record; find the records available under other legislation; reach the Information Officer; find the Regulator's guide on how to use PAIA; and see what personal information the Company processes, why, who receives it, whether it leaves the Republic, and whether it is secured.
A right of access to a private body's record is not unconditional. Under section 50(1) of PAIA a requester must be given access only where the record is required for the exercise or protection of a right, the procedural requirements in PAIA are met, and no ground of refusal in Chapter 4 applies. This manual neither enlarges that right nor waives a ground of refusal.
The Company revises this manual as its records and its processing change, and the current version is always the one published on this page.
3. Key contact details for access to information
| Head of the Private Body, and Information Officer | Naphtali Tsikada, Founder and Chief Executive Officer | s 51(1)(a) |
| Email for PAIA requests | privacy@synthro.io | s 53 |
| Email for privacy and POPIA matters | privacy@synthro.io | s 55 POPIA |
| Registered and postal address | Annette Street, Randburg, 2188, South Africa | |
| Website | www.synthro.io | |
| Deputy Information Officer | None designated. The Company is a small private body and the Information Officer discharges these duties personally. A deputy will be designated, and this manual updated, if that ceases to be practicable. | s 17(1) PAIA |
4. The Regulator's guide on how to use PAIA
The Regulator has, under section 10(1) of PAIA, compiled and updated a Guide on how to use PAIA, in an easily comprehensible form, for a person who wishes to exercise a right under PAIA or POPIA. It is available in each of the official languages and in braille.
The Guide describes: the objects of PAIA and POPIA; the contact particulars of the information officers and deputy information officers of public and private bodies; the manner and form of a request for access to a record of a public body under section 11 and of a private body under section 50; the assistance available from an information officer and from the Regulator; every remedy in law available in respect of an act or failure to act under PAIA and POPIA, including how to lodge an internal appeal, a complaint to the Regulator and an application to a court; the provisions of sections 14 and 51 requiring a manual; the provisions of sections 15 and 52 on voluntary disclosure; the notices on fees under sections 22 and 54; and the regulations made under section 92.
How to obtain the Guide. Download it from the Regulator at inforegulator.org.za, request it from the Information Officer at privacy@synthro.io, or inspect it at the Company's registered address during normal business hours.
5. Records available without a request
Made available voluntarily under section 52(1) of PAIA. No request, and no fee, is needed for any of these.
| Terms of Service | www.synthro.io/terms | Website |
| Privacy Policy, including the full sub-processor register | www.synthro.io/privacy | Website |
| POPIA compliance statement | www.synthro.io/popia | Website |
| Vulnerability disclosure policy | www.synthro.io/security/disclosure | Website |
| This PAIA Manual | www.synthro.io/paia | Website |
| Product, pricing and security descriptions | www.synthro.io | Website |
6. Records available under other legislation
| Memorandum of Incorporation, share register, register of directors | Companies Act 71 of 2008 |
| Annual financial statements and accounting records | Companies Act 71 of 2008; Tax Administration Act 28 of 2011 |
| VAT, PAYE and income-tax records | Income Tax Act 58 of 1962; Value-Added Tax Act 89 of 1991; Tax Administration Act 28 of 2011 |
| Employment records of the Company’s own staff | Basic Conditions of Employment Act 75 of 1997; Employment Equity Act 55 of 1998; Labour Relations Act 66 of 1995 |
| Records of processing operations, and this manual | POPIA; PAIA |
7. Subjects on which records are held, and the categories on each
| Corporate and statutory | Incorporation documents, board and shareholder records, statutory registers, licences and registrations. |
| Finance | Accounting records, invoices, receipts, bank records, returns to SARS, insurance policies. |
| Customers and contracts | Signed agreements, addenda, data-processing annexures, quotations, orders, correspondence, support tickets and billing records. |
| Human resources — the Company’s own people | Contracts of employment and engagement, confidentiality and intellectual-property assignments, payroll and leave records, performance and training records. |
| Suppliers and service providers | Supplier contracts, data-processing terms, the sub-processor register, and the security and certification documentation received from providers. |
| Information technology and security | Information-security policies, access-control records, audit logs, backup and disaster-recovery records, incident records. |
| Marketing | Website content, campaign records, newsletter subscriptions and marketing-consent records. |
| Customer Data held on the Platform | Employee records, documents, leave, performance, disciplinary and related records belonging to the Company's customers. The Company is the Operator of this information, not the Responsible Party — see section 8. |
8. Processing of personal information
Purpose of processing, and two very different roles. The Company processes personal information for two purposes that must not be confused. First, as Responsible Party for its own business: to contract with and support its customers, to bill them, to employ and engage its own people, to market its services lawfully, and to meet its statutory obligations. Second, as Operatorfor the employee information its customers load onto the Platform. For that information the customer is the Responsible Party and decides what happens to it; the Company processes it only on the customer's authorisation, only to provide, operate and support the Platform for that customer and to comply with the law, and treats it as confidential.
A request about a customer's employee record is not the Company's to answer. Where a data subject approaches the Company about information held on the Platform on a customer's behalf, the Company will not respond substantively. It refers the request to that customer without undue delay and assists the customer in answering it. The employer, not the Company, decides that request.
The Company does not use Customer Data to train artificial intelligence.It is not used to train, fine-tune, retrain or otherwise improve any machine-learning or artificial-intelligence model, whether the Company's or a third party's, and no employee record is stored by any artificial-intelligence provider.
8.2 · Categories of data subjects, and the information processed
| Customers, and the people at a customer who use the Platform | Name, work email address, telephone number, job role, department, reporting line, account and authentication records, and records of use of the Platform. |
| Employees of a customer, whose records that customer loads onto the Platform | Employment records: identifying particulars, contact details, employment history, remuneration and leave records, performance, disciplinary and grievance records, documents issued to them, and the special personal information a customer is permitted to load — race or ethnic origin and disability, for employment-equity reporting, and health information including medical certificates furnished in support of sick leave. |
| Prospective customers and website visitors | Name, email address, company name, telephone number, the content of an enquiry, and website usage information. |
| The Company’s own employees, contributors and applicants | Identifying and contact particulars, qualifications, employment and engagement records, remuneration and banking details, and performance records. |
| Suppliers and service providers | Company name and registration number, contact particulars of representatives, and banking details. |
8.3 · Recipients to whom personal information may be supplied
| Customer Data held on the Platform | The sub-processors in the Company's published register at www.synthro.io/privacy — each engaged only to operate or support the Platform, and each bound by written data-protection and confidentiality obligations. |
| Billing and payment particulars | The Company’s payment processor, and its accountants and auditors. |
| Any category | A court, the Regulator, SARS or another authority, where the Company is required by law to disclose it; and the Company’s legal advisers, under legal professional privilege. |
| No category | The Company does not supply personal information to any advertising network, data broker or information reseller, and does not sell, rent or otherwise monetise it. |
8.4 · Planned transborder flows of personal information
| United Kingdom | All Customer Data held on the Platform — the primary database, authentication, stored documents, and the independent encrypted offsite backup. Held in the London region. The United Kingdom is subject to the UK General Data Protection Regulation and the Data Protection Act 2018, which uphold principles substantially similar to the conditions in POPIA. | s 72(1)(a) |
| United States | A narrow set of processing, none of which stores an employee record: the artificial-intelligence request that answers a question a user has actually asked, processed in transit only; transactional email, which carries the message but never an employee document; bot-protection signals on public forms; and delivery of the application front-end. | s 72(1)(b) |
| Nigeria and South Africa | Billing contact and payment particulars, for payment processing. No employee records. | s 72(1)(b) |
9. Security safeguards
A general description, as the Regulator's template requires.The Company maintains appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of the personal information in its care, as sections 19 and 21 of POPIA require. These include: encryption in transit and at rest; database-level row security, so that each customer's data is logically isolated and inaccessible to any other customer; authenticated, role-based access control, with multi-factor authentication available on accounts and required for administrative access; access by Company personnel strictly on a need-to-know basis under a binding duty of confidentiality; audit logging of administrative access; regular encrypted backups, together with an independent encrypted offsite copy held with a separate provider for disaster recovery; and a documented incident-response procedure.
This description is deliberately general. The Act asks for the nature of the safeguards, not their configuration. The Company will not publish detail that would assist a person seeking to defeat them. A customer conducting a governance or procurement review may request fuller detail under confidentiality.
If safeguards are compromised. Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the Company notifies the affected customer in writing immediately and in any event within twenty-four hours, notifies the Regulator and the data subjects as section 22 of POPIA requires, and contains, investigates and remediates the incident.
10. How to request access to a record
Use the prescribed form. A request for access to a record of a private body must be made on the form prescribed by the PAIA Regulations, being Form 2 under the Regulations published in 2021. Download the current form from the Regulator at inforegulator.org.za, or ask us for a copy at privacy@synthro.io.
Send it to the Information Officer at privacy@synthro.io, or by post or delivery to the address in section 3. Give enough particulars for the Company to identify the record and to identify you; state the form of access you want; give an address in the Republic for the reply; and — this is the part most often left out, and the Company cannot decide a request without it — state the right you are seeking to exercise or protect, and explain why the record is required for that.
If you are asking on someone else's behalf, submit proof of your authority in a form satisfactory to the Information Officer. If you cannot read or write, or a disability prevents you completing the form, you may make the request orally, and the Information Officer will reduce it to writing and give you a copy.
Fees. A request fee, and where access is granted an access fee, are prescribed by Annexure B to the PAIA Regulations. The Company charges what is prescribed and nothing more; it levies no fee of its own. Because those amounts are set and changed by Gazette they are not reproduced here: the Information Officer will notify you in writing of the amount payable before the request is processed further, as section 54 requires. A request by a data subject for their own personal information carries no request fee.
Decision and time. The Company will decide within thirty days of receiving a compliant request, and will notify you in writing of the decision and, where access is refused, of adequate reasons and the provisions relied on. That period may be extended by a further thirty days in the circumstances PAIA permits, and you will be told if it is.
Grounds of refusal. The Company may be obliged or entitled to refuse access under Chapter 4 of Part 3 of PAIA, including to protect the privacy of a third party, the commercial information of a third party or of the Company, information held in confidence, and records privileged from production in legal proceedings. A customer's Customer Data is the commercial and confidential information of that customer, and the Company will not disclose it to a third party without that customer's authorisation or a lawful obligation to do so.
If you are dissatisfied. There is no internal appeal against a decision of the head of a private body. You may lodge a complaint with the Regulator under section 77A of PAIA, on the prescribed complaint form, at PAIAComplaints@inforegulator.org.za; or apply to a court under section 78. Nothing in this manual limits either remedy.
11. Availability of this manual, and how to reach the Regulator
Where to find this manual. It is published on this page and downloadable as a PDF; it is available for public inspection at the Company's registered address during normal business hours; it will be sent to any person on request, a reasonable prescribed fee per A4 photocopy applying to a paper copy and no fee to the electronic copy; and it is available to the Regulator on request.
The Company updates this manual whenever its records or its processing change materially, and reviews it at least annually. The date of compilation and the date of the current revision appear at the top of this page.
Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Telephone 010 023 5200 · Toll free 0800 017 160
General enquiries enquiries@inforegulator.org.za
PAIA complaints PAIAComplaints@inforegulator.org.za
POPIA complaints POPIAComplaints@inforegulator.org.za
inforegulator.org.za
12. Issued by
| Name | Naphtali Tsikada |
| Capacity | Founder and Chief Executive Officer — Head of the Private Body and Information Officer |
| For | Synthro (Pty) Ltd, registration number 2025/975079/07 |
| Date of compilation | 20 September 2026 |
| Date of this revision | 20 September 2026 |