PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act No. 2 of 2000 ("PAIA"), as amended. This manual explains what records Strategix Application Solutions (Pty) Ltd holds, how to request access to them, and how personal information is processed in connection with the XGRC® platform.
Purpose of this Manual
- Check the categories of records held by the body that are available without submitting a formal PAIA request.
- Understand the process of requesting access to a record of the body.
- Know the records available in accordance with other legislation.
- Access contact details of the Information Officer and Deputy Information Officers.
- Find out how to obtain the PAIA Guide compiled by the Information Regulator.
- Understand if and how personal information is processed, the purpose thereof, and related data subject categories.
- Know to whom personal information may be supplied, including transborder disclosures.
- Understand the body’s security measures to ensure confidentiality, integrity, and availability of personal information.
Key Contact Details for Access to Information
| Role | Name | Contact |
|---|---|---|
| Information Officer | Jacob O’Brien | [email protected] · +27 87 802 0179 |
| Deputy Information Officer | Deneys Minne | [email protected] · +27 87 802 0179 |
| Deputy Information Officer | Stan O’Brien | [email protected] · +27 87 802 0179 |
General Contact & Head Office
General access to information requests: [email protected]. Head office — Physical: York House Block A Unit 5, Tybalt Place, Waterfall Office Park, Midrand. Postal: PO Box 11208, Aston Manor, 1630. Telephone: +27 87 802 0179. Website: www.strategix.co.za.
Guide on How to Use PAIA
The Information Regulator has compiled a PAIA Guide, available in all official languages and in braille, explaining how to exercise any right contemplated in PAIA and POPIA. It is accessible on the Information Regulator’s website at justice.gov.za/inforeg, or on request.
Categories of Records Automatically Available
- Marketing brochures and company profiles.
- Privacy Policy, End User Licence Agreement, Cybersecurity & Data Protection Policy, and Release Notes.
- This approved PAIA Manual.
Records Available in Terms of Other Legislation
- Memorandum of Incorporation — Companies Act 71 of 2008.
- PAIA Manual — Promotion of Access to Information Act 2 of 2000.
- Data Processing Records, Consent Logs — POPIA 4 of 2013.
- ISMS Documentation — ISO/IEC 27001:2022.
Subjects and Categories of Records Held
- Employee and contractor records, training logs, access rights, and related records.
- Compliance and legal requirement information.
- Stakeholder master data: community, partner, supplier, customer, government, shareholder, and union.
Purpose of Processing Personal Information
Personal information is processed to enable secure delivery of cloud-based GRC services, facilitate user access and support, conduct audits and incident response, and ensure legal and contractual compliance under ISO 27001, GDPR, and POPIA.
Categories of Data Subjects and Information Processed
- Clients/Customers — name, contact details, organisation information, access logs, encrypted data.
- Employees — name, race, gender, job title, access rights, training and audit records.
- Vendors/Service Providers — company details, regulatory compliance status, audit data.
Recipients of Personal Information
- Client/user information — Support Team, Microsoft Azure (data hosting).
- Platform/system events — Security Operations Centre (SOC), Internal Audit, ISO auditors.
- ISMS documents — Information Regulator (upon request), Executive Management.
- Vendor details and qualifications — Internal Finance Team, External Auditors.
Transborder Data Flows
Strategix stores and processes data within Microsoft Azure’s Europe-West (Netherlands) region. This includes user platform data, backups, access logs, and encrypted personal information. All data is protected under international security and compliance frameworks.
Information Security Safeguards
The organisation implements a certified ISO 27001:2022 Information Security Management System (ISMS), including 256-bit Rijndael encryption, 24/7 SOC monitoring, daily vulnerability assessments, SIEM/SOAR systems, quarterly disaster recovery testing, multi-factor authentication, and the least-access principle for all user roles.
Availability of this Manual
- On the XGRC® Software website (this page).
- By formal request to the Information Officer or a Deputy Information Officer.
Updating of the Manual
This manual is reviewed and updated regularly by the Information Officer to ensure ongoing compliance with internal policies, ISO 27001, PAIA and POPIA.
Declaration
This PAIA Manual has been compiled and authorised by Jacob O’Brien (Information Officer, Chief Executive Officer), Deneys Minne (Deputy Information Officer) and Stan O’Brien (Deputy Information Officer) of Strategix Application Solutions (Pty) Ltd.
Questions about this document, or need a signed copy for procurement? Contact us.
Contact us