PAIA Manual
1. The private body and its head
| Private body | [TO CONFIRM: full legal name and status, e.g. "N Steyn trading as CuraPraxis" or company name and registration number] |
|---|---|
| Head of the private body | [TO CONFIRM: full name of the owner or designated head] |
| Postal and street address | [TO CONFIRM] |
| Telephone | [TO CONFIRM] |
| Email for PAIA requests | curapraxis@proton.me [TO CONFIRM: mailbox once the domain exists] |
| Website | curapraxis.co.za [TO CONFIRM: domain still to be registered] |
2. The section 10 Guide
The Information Regulator has published a Guide, in each official language, on how to use PAIA, as contemplated in section 10 of the Act. The Guide is available from the Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; enquiries@inforegulator.org.za; 010 023 5200; and on the Regulator's website at inforegulator.org.za.
3. Records available without a formal PAIA request
The following are freely available on this website: all public course information, the free Module 1, the Terms of Use, Privacy Notice, Disclaimer, the About page, this Manual, and the certificate verification service (which discloses, for a given certificate ID, the holder's name, the course and certificate name, the issue date and the status).
4. Records held by the private body
| Category | Records |
|---|---|
| Certificate records | Certificate ID, holder name, certificate type (Core or Advanced), course name, issue date, status, payment reference, claim token, email address where supplied |
| Financial records | Payment provider transaction records for tier purchases and upgrades, banking records, tax records |
| Correspondence | Email correspondence with course participants and third parties |
| Technical records | Hosting, deployment and security logs held by service providers |
| Business records | Contracts with service providers, domain registration, statutory records |
No records are automatically available under other legislation beyond those disclosed above; requests are assessed under PAIA.
5. How to request access to a record
- Use Form 2 (Request for Access to Record of Private Body), available from the Information Regulator's website, or write to us with the same particulars.
- Send it to the email or postal address in section 1, marked "PAIA request".
- Identify the record, the right you seek to exercise or protect and why the record is required for it, the form of access you want, and proof of identity.
- The prescribed request and access fees under the PAIA Regulations, where applicable, are payable; we will advise you of the amount before processing.
- We will respond within 30 days, as PAIA requires, subject to the Act's grounds of refusal (such as the mandatory protection of third party privacy and commercial information).
If your request is refused and you disagree, you may lodge a complaint with the Information Regulator (PAIAComplaints@inforegulator.org.za) or apply to court.
6. Processing of personal information (POPIA information)
Purposes
Personal information is processed to sell and deliver the course, issue and verify certificates, send certificate emails, keep financial records, and secure the service. There is no direct marketing.
Categories of data subjects and information
Course participants and certificate holders: name, email address where supplied, payment reference, certificate details. Website visitors: short-lived technical log data held by hosting providers. Course progress, assessment results and the participant's selected practitioner role are stored on the participant's own device and are never held by the private body.
Recipients
Service providers acting as operators (hosting, database, email delivery), the payment provider as an independent responsible party, and any person to whom a certificate holder gives their certificate ID (verification page disclosure). Otherwise, information is disclosed only where the law requires.
Cross-border flows
Hosting, database and email infrastructure is located outside South Africa, principally in the United States, under contractual protections, as described in the Privacy Notice.
Security measures
Encrypted transport, server-side restricted database credentials, cryptographically signed certificate IDs, column-level database protections preventing public access to claim tokens and email addresses, and least-data design (study data remains on the participant's device).
7. Availability of this manual
This manual is available on this website, from the address in section 1 during business hours, on request by email at no charge, and to the Information Regulator on request.