Not ready to publish. Company registration details, the physical address and the Information Officer are still unfilled. ECTA § 43(1) requires them, and a policy that names no responsible party is unenforceable and misleading. Fill in src/lib/legal/entity.ts before launch.

Draft pending legal review. These documents were drafted against POPIA, ECTA, the CPA and PAIA, but not by an admitted attorney. Enc0ded processes identity documents and special personal information, where the consequences of a defective notice fall on the data subject. Have them reviewed before they are relied on.

PAIA manual

Version 1.0 · Last updated 22 August 2026

Published under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA). It describes the records Enc0ded holds and how to request access to them. Private bodies are required to publish this manual and to make it available on request.

1 The body this manual belongs to

Legal name
[TO BE COMPLETED BEFORE LAUNCH]
Trading as
Enc0ded
Registration number
[TO BE COMPLETED BEFORE LAUNCH]
Physical address
[TO BE COMPLETED BEFORE LAUNCH]
Postal address
[TO BE COMPLETED BEFORE LAUNCH]
Website
https://www.enc0ded.com

2 Information Officer

Requests under PAIA are directed to the Information Officer, who is also the Information Officer for POPIA purposes:

Name
[TO BE COMPLETED BEFORE LAUNCH]
Email
[TO BE COMPLETED BEFORE LAUNCH]
Telephone
[TO BE COMPLETED BEFORE LAUNCH]
Regulator registration
[TO BE COMPLETED BEFORE LAUNCH]

3 The Regulator's guide

The Information Regulator has compiled a guide, in terms of PAIA § 10, explaining how to use the Act. It is available in each official language from the Regulator:

Authority
Information Regulator (South Africa)
Address
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Enquiries
enquiries.IR@justice.gov.za
Website
https://inforegulator.org.za

4 Records available without a formal request

These are published and need no PAIA request. Read them on this site:

  • Terms of service
  • Privacy policy
  • Cookie notice
  • This manual
  • Plan descriptions and pricing

If you are a customer, your own records — documents, audit trail, scores, alerts, payments, consent records — are available to you directly and immediately from your account's data page. You do not need PAIA, and you should not have to invoke a statute to see your own file.

5 Records held, by category

CategoryRecordsKept because
Customer recordsAccount details, uploaded documents, share links, access requests, security scores, breach alerts, data maps, erasure requestsProvision of the service
Encrypted recordsDigital Legacy credentials and wrapped keys, held as ciphertext we cannot decryptProvision of the service
Financial recordsInvoices, payment gateway references, refundsTax Administration Act, Companies Act
Security recordsAudit log of sign-ins, document access and share-link usePOPIA § 19
Company recordsRegistration documents, statutory registers, financial statementsCompanies Act 71 of 2008
Employment recordsContracts, payroll, leaveBasic Conditions of Employment Act, Labour Relations Act, tax law
Supplier recordsContracts with hosting, email and payment providers, including POPIA § 21 operator agreementsContract management and POPIA

6 How to request a record

  1. Complete the prescribed form (Form 2 of the PAIA Regulations), available from the Regulator's website.
  2. Send it to the Information Officer at the address in clause 2, providing enough detail to identify the record and enough information to reach you with the decision.
  3. If you are requesting a record in order to exercise or protect a right, say which right and how the record is required for it — PAIA § 50 makes this the test for access to a private body's records.
  4. Pay the prescribed request fee where one applies. We will tell you the amount before any work begins.

We will decide within 30 days and tell you in writing. That period may be extended by a further 30 days where the request covers a large number of records, and we will explain why if it is.

7 When access may be refused

PAIA obliges us to refuse access in certain cases, and permits it in others. The grounds most likely to apply here:

  • § 63 — another person's privacy.We will not disclose another customer's personal information. In practice this is the ground that will decide most requests to us.
  • § 64 and § 65 — commercial information and confidences. Third-party trade secrets, and information supplied in confidence.
  • § 66 — safety of individuals and property. Including records that would reveal how our security controls are configured.
  • § 67 — privileged records. Records privileged in legal proceedings.
  • § 68 — our own commercial information.

There is a category we cannot produce for a different reason: Digital Legacy credentials are encrypted under a password held only by the customer. A refusal there is not a decision we are making — we do not possess the means to read them, and no order can change that.

If we refuse, we will tell you which section we relied on and how to appeal: a complaint to the Information Regulator under § 77A, or an application to court under § 78.

8 Fees

Fees are those prescribed in the PAIA Regulations and are payable in advance. A personal requester seeking their own personal information pays no request fee, though a reproduction fee may apply. We will give you a written estimate before starting.

9 Processing of personal information

The categories of personal information we process, the recipients it is shared with, whether it leaves South Africa, and the security safeguards applied are set out in our privacy policy, which forms part of this manual for the purposes of PAIA § 51(1)(c)(iii).

10 Availability

This manual is available on this website, and on request from the Information Officer in any of the official languages we can reasonably provide. A copy is lodged with the Information Regulator.