Legal
PAIA & POPIA Manual
Prepared in accordance with Section 51 of the Promotion of Access to Information Act, No. 2 of 2000 (“PAIA”) and the Protection of Personal Information Act, No. 4 of 2013 (“POPIA”).
Document Version: 1.3 (July 2026) · First issued April 2026
Introduction
This Manual is published in terms of Section 51 of the Promotion of Access to Information Act, 2000 (PAIA) and addresses the requirements of the Protection of Personal Information Act, 2013 (POPIA). AGILEGYPSY LABS (PTY) LTD (“the Company”) is a software studio providing engineering services — AI development, custom AI solutions, Web2/3 development, and cloud architecture — and operating its own software products under registered trading names.
This Manual applies to the Company as the private body, including all of its trading names, brands, products, and websites, whether existing now or introduced in the future. Where a brand publishes its own product-specific privacy policy, that policy supplements — and does not replace — this Manual.
Company Contact Details
The Company also holds additional registered domains (including designedbio.co.za and jobzi.co.za, among others) that are currently unutilised or in development. This Manual applies to any service the Company operates on those domains from time to time.
The PAIA Guide and Information Regulator
The Guide on how to use PAIA (Section 10 of the Act) is developed, updated, and made available by the Information Regulator, which took over the PAIA functions previously performed by the South African Human Rights Commission with effect from 30 June 2021. The Guide is available in all official languages (and braille) from the Regulator's website.
Contact the Information Regulator
Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Website: inforegulator.org.za
Email: inforeg@inforegulator.org.za
Records Available Without Request (Section 51(1)(c))
The following records are available on our website without having to request access in terms of PAIA:
- Terms of Service
- Privacy Policy
- Pricing and engagement information
- Marketing and promotional materials
Records Kept in Terms of Other Legislation (Section 51(1)(d))
The Company retains records in accordance with the following legislation (where applicable):
- Basic Conditions of Employment Act No. 75 of 1997
- Companies Act No. 71 of 2008
- Compensation for Occupational Injuries and Diseases Act No. 130 of 1993
- Consumer Protection Act No. 68 of 2008
- Electronic Communications and Transactions Act No. 25 of 2002
- Employment Equity Act No. 55 of 1998
- Income Tax Act No. 58 of 1962
- Labour Relations Act No. 66 of 1995
- Tax Administration Act No. 28 of 2011
- Value Added Tax Act No. 89 of 1991
Categories of Records Held by the Company (Section 51(1)(e))
Access to the following records must be requested according to the access procedures set out in PAIA. Please note that recording a category does not imply that a request for access will be granted. Access is subject to the grounds of refusal listed in PAIA.
6.1 Corporate & Governance
Memorandum of Incorporation; director's register; shareholder agreements; minutes of meetings.
6.2 Financial & Tax
Annual financial statements; tax returns and assessments; accounting records, invoices, and receipts; banking records.
6.3 Human Resources
Employment contracts; payroll records; disciplinary records.
6.4 Information Technology
Software licensing agreements; system security policies; data architecture documentation.
6.5 Client & Customer Data (all brands)
Client account details; project briefs, statements of work, and contracts; engagement deliverables and correspondence; product account and usage records; support tickets and correspondence.
6.6 Product Records by Brand
Kointel (kointel.co.za): user account details; cryptocurrency transaction histories and CSV uploads; tax calculation reports and AI classifications. KTHULHU (kthulhu.co) and Art of Zeta (artofzeta.com): user account details, application content, and usage records for the respective applications. Equivalent categories apply to any product the Company launches under a new brand.
Processing of Personal Information (POPIA)
7.1 Purpose of Processing
We process personal information to provide our engineering services and AI products, process payments, verify identities, improve our services, and comply with legal obligations.
7.2 Categories of Data Subjects and Information
- Clients/Users (all brands): Name, email address, IP address, project and engagement materials, product account details, and usage data. For Kointel users this additionally includes cryptocurrency transaction histories and wallet addresses uploaded for tax-calculation purposes.
- Employees/Contractors: ID numbers, banking details, contact info.
- Service Providers/Vendors: Company details, banking data, contact personnel.
7.3 Recipients to Whom Information May Be Supplied
In accordance with POPIA Section 18(1)(e), recipients are disclosed by category. Because the Company is a studio that launches new products and takes on new client engagements from time to time, the named operators within each category change; the current named list is maintained by the Information Officer and is available on request. The categories are:
- Hosting, cloud, and database providers (currently Cloudflare, Inc. — all brands; Neon, Inc. — KTHULHU database)
- AI / machine-learning service providers (currently Google — Gemini via Cloudflare AI Gateway; Anthropic — Claude; OpenAI; Voyage AI; Cloudflare Workers AI)
- Payment gateways (currently PayFast (Pty) Ltd — Kointel; Stitch Money (Pty) Ltd — agilegypsy.com)
- Communication and email service providers (currently Forward Email LLC)
- Clients for whom we develop or host — only where we process their end-users' data as operator under a data processing agreement, and only that client's own data
- Law enforcement or regulatory bodies (only when legally compelled)
7.4 Cross-Border Transfers
We use global cloud infrastructure (Cloudflare, Google). As such, data is transferred across borders, but only to operators subject to binding corporate rules or data protection laws that provide an adequate level of protection (such as the GDPR).
7.5 Information Security Measures
We employ edge encryption (TLS), database encryption at rest, secure JWT authentication, PBKDF2-SHA256 password hashing, role-based access control, and strict cloud environment isolation.
Procedure for Requesting Access to Records
- 1.Form of Request: Use the prescribed PAIA Form 2 (available from the Information Regulator at inforegulator.org.za) and submit it to the Information Officer by email.
- 2.Information Required: The form must identify the record requested, confirm your identity, specify the form of access required, and include your postal or email address.
- 3.Right to Access: State the right you seek to exercise or protect, and provide a clear explanation of why the requested record is required for the exercise or protection of that right.
- 4.Fees: A request fee (currently R140 for private bodies as prescribed under the PAIA Regulations, 2021) must be paid before the request is processed. If access is granted, an additional access fee is payable for reproduction, search, and preparation. Fee waivers are available in terms of PAIA.
Submit requests to: john@agilegypsy.com with subject line: “PAIA Access Request”.
Prescribed POPIA forms (downloadable)
The following prescribed forms are available for download below, from the Information Officer on request, and from the Information Regulator's website:
- Form 1 — Objection to processing of personal information (POPIA Section 11(3), Regulation 2). [PDF]
- Form 2 — Request for correction or deletion of personal information (POPIA Section 24(1), Regulation 3). [PDF]
- Form 4 — Application for consent to direct marketing (POPIA Section 69(2), Regulation 6). [PDF]
Grounds of Refusal
Access to records may be refused on the grounds set out in PAIA Chapters 4 and 5, including but not limited to:
- Records containing personal information of a third party who has not consented to disclosure (Section 63).
- Records that are privileged from production in legal proceedings (Section 67).
- Records containing trade secrets or commercially sensitive information (Section 64).
- Records requested for purposes not relating to the exercise or protection of rights (Section 9).
Availability of this Manual
This Manual is available for inspection free of charge at the Company's physical address (125 Benoni Road, Rynfield AH, Benoni, 1501), upon request from the Information Officer at john@agilegypsy.com, and on this website at agilegypsy.com/legal/paia-manual.
Download this Manual (PDF)