PAIA · Section 51 Manual

PAIA Manual

Manual in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 ("PAIA"), read with the Protection of Personal Information Act 4 of 2013 ("POPIA") · Version 1 · [TO CONFIRM: date] · Reviewed annually

1. The private body and its head

Private body[TO CONFIRM: full legal name and status, e.g. "N Steyn trading as CuraPraxis" or company name and registration number]
Head of the private body[TO CONFIRM: full name of the owner or designated head]
Postal and street address[TO CONFIRM]
Telephone[TO CONFIRM]
Email for PAIA requestscurapraxis@proton.me [TO CONFIRM: mailbox once the domain exists]
Websitecurapraxis.co.za [TO CONFIRM: domain still to be registered]

2. The section 10 Guide

The Information Regulator has published a Guide, in each official language, on how to use PAIA, as contemplated in section 10 of the Act. The Guide is available from the Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; enquiries@inforegulator.org.za; 010 023 5200; and on the Regulator's website at inforegulator.org.za.

3. Records available without a formal PAIA request

The following are freely available on this website: all public course information, the free Module 1, the Terms of Use, Privacy Notice, Disclaimer, the About page, this Manual, and the certificate verification service (which discloses, for a given certificate ID, the holder's name, the course and certificate name, the issue date and the status).

4. Records held by the private body

CategoryRecords
Certificate recordsCertificate ID, holder name, certificate type (Core or Advanced), course name, issue date, status, payment reference, claim token, email address where supplied
Financial recordsPayment provider transaction records for tier purchases and upgrades, banking records, tax records
CorrespondenceEmail correspondence with course participants and third parties
Technical recordsHosting, deployment and security logs held by service providers
Business recordsContracts with service providers, domain registration, statutory records

No records are automatically available under other legislation beyond those disclosed above; requests are assessed under PAIA.

5. How to request access to a record

  1. Use Form 2 (Request for Access to Record of Private Body), available from the Information Regulator's website, or write to us with the same particulars.
  2. Send it to the email or postal address in section 1, marked "PAIA request".
  3. Identify the record, the right you seek to exercise or protect and why the record is required for it, the form of access you want, and proof of identity.
  4. The prescribed request and access fees under the PAIA Regulations, where applicable, are payable; we will advise you of the amount before processing.
  5. We will respond within 30 days, as PAIA requires, subject to the Act's grounds of refusal (such as the mandatory protection of third party privacy and commercial information).

If your request is refused and you disagree, you may lodge a complaint with the Information Regulator (PAIAComplaints@inforegulator.org.za) or apply to court.

6. Processing of personal information (POPIA information)

Purposes

Personal information is processed to sell and deliver the course, issue and verify certificates, send certificate emails, keep financial records, and secure the service. There is no direct marketing.

Categories of data subjects and information

Course participants and certificate holders: name, email address where supplied, payment reference, certificate details. Website visitors: short-lived technical log data held by hosting providers. Course progress, assessment results and the participant's selected practitioner role are stored on the participant's own device and are never held by the private body.

Recipients

Service providers acting as operators (hosting, database, email delivery), the payment provider as an independent responsible party, and any person to whom a certificate holder gives their certificate ID (verification page disclosure). Otherwise, information is disclosed only where the law requires.

Cross-border flows

Hosting, database and email infrastructure is located outside South Africa, principally in the United States, under contractual protections, as described in the Privacy Notice.

Security measures

Encrypted transport, server-side restricted database credentials, cryptographically signed certificate IDs, column-level database protections preventing public access to claim tokens and email addresses, and least-data design (study data remains on the participant's device).

7. Availability of this manual

This manual is available on this website, from the address in section 1 during business hours, on request by email at no charge, and to the Information Regulator on request.