Section 51 private-body manual
PAIA manual
Section 51 manual for the VettedSaaSBlueprint private body, prepared under the Promotion of Access to Information Act 2 of 2000.
- Effective
- Next review
1. Identity and contact details
- Body name
- VettedSaaSBlueprint
- Nature of body
- South African sole proprietorship and private body
- Head designation
- Sole Proprietor, VettedSaaSBlueprint
- Information Officer display name
- Information Officer, VettedSaaSBlueprint
- Street and submission address
- 3 Wagner Lane, Sagewood, Johannesburg, Gauteng, South Africa
No company registration number, public telephone, or fax number applies. Information Officer registration confirmation is a production release prerequisite and is not self-attested by this manual.
2. Purpose, status, and availability
This manual helps a person identify records held by VettedSaaSBlueprint and use PAIA to request a record required for the exercise or protection of a right. It also describes personal-information processing required by section 51 of PAIA as amended by POPIA.
The manual is available without charge on this website and may be requested by email for inspection. It is effective on and scheduled for review by . It will be updated when material recordkeeping, processing, or legal requirements change.
3. PAIA guide, forms, and help
The South African Information Regulator publishes the PAIA guide, the private-body manual template, Form 2, fee information, complaint Form 5, and guides in South African official languages. Obtain the current guide and official forms from https://inforegulator.org.za/paia/ before submitting a request.
4. Records automatically available
The following public records are automatically available without a PAIA request, subject to normal website availability:
- Published review pages and visible publication dates.
- Privacy, terms, affiliate disclosure, editorial, accessibility, contact, and this PAIA manual.
- Public navigation, robots instructions, and sitemap entries for approved public pages.
Internal drafts, audit records, security information, credentials, and unpublished evidence are not automatically available.
5. Applicable legislation
Records may be held under applicable legislation, including:
- Promotion of Access to Information Act 2 of 2000.
- Protection of Personal Information Act 4 of 2013.
- Electronic Communications and Transactions Act 25 of 2002.
- Copyright Act 98 of 1978.
- Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011, to the extent applicable.
- Consumer Protection Act 68 of 2008, to the extent applicable to published representations.
This list is indicative and does not imply that every statute creates every category of record for this sole proprietorship.
6. Subjects and categories of records
- Editorial and research: evidence sources, product notes, structured drafts, review versions, limitations, corrections, and approval records.
- Affiliate operations: approved destination links, network records, offer evidence, click aggregates, and commission statements.
- Website operations: source code, deployment records, security and error logs, configuration records, and accessibility checks.
- Governance and compliance: policies, PAIA requests and outcomes, POPIA requests, audit logs, retention records, and Information Officer administration.
- Communications: editorial corrections, privacy enquiries, accessibility feedback, PAIA correspondence, and vendor correspondence.
- Financial and tax: lawful income, expense, banking, invoice, affiliate-payment, and tax-supporting records.
- Service providers: hosting, database, domain, software, and professional-service agreements and correspondence.
7. POPIA processing description
Purposes
Personal information may be processed to operate and secure the publication, respond to enquiries and rights requests, maintain reliable affiliate links, improve content in aggregate, administer service-provider and affiliate relationships, keep lawful financial and tax records, and meet legal obligations.
Categories of data subjects
- Public website visitors.
- People who send editorial, privacy, accessibility, or PAIA enquiries.
- Vendor, affiliate-network, hosting, database, and professional-service contacts.
- The sole proprietor and authorised administrators.
Personal-information categories
- Names, business roles, email addresses, correspondence, and request records.
- Limited first-party event data if analytics are enabled, including page URL, referrer, user agent, event type, link identifier, and time. The application stores no raw IP address or IP hash.
- Account, security, audit, financial, tax, and affiliate-payment records where lawfully required.
Recipient categories
Information may be supplied only as necessary to hosting and infrastructure providers such as Vercel, Oracle storage and worker services, affiliate networks such as PartnerStack, destination vendors after a visitor chooses to click, professional advisers, regulators, or lawful authorities.
Cross-border flows
Cloud hosting, storage, affiliate networks, and destination vendors may process information outside South Africa. Transfers are limited to necessary data and are managed with contractual, technical, and organisational safeguards intended to support applicable POPIA requirements.
Security safeguards
Safeguards include access restriction, owner authentication, secret separation, audited publication controls, data minimisation, privacy-signal suppression, retention limits, dependency and deployment checks, encryption provided by service platforms, backups where appropriate, and incident review. Safeguards are reviewed as risks and services change.
8. Form 2 request procedure
- Download the current Form 2 from the Information Regulator PAIA page.
- Identify the record with enough detail for it to be located and state the right you seek to exercise or protect, why the record is required, your preferred form of access, and contact details.
- Provide proof of identity. A representative must also provide proof of authority to act for the requester.
- Email the completed request and supporting documents to vettedsaasblueprint@proton.me, or deliver them to 3 Wagner Lane, Sagewood, Johannesburg, Gauteng, South Africa.
Do not send unnecessary identity information. VettedSaaSBlueprint may ask for proportionate verification before disclosing a record.
9. Fees and timing
Prescribed fees may apply under PAIA before access is provided, including a request fee where permitted and access or reproduction fees. Any required fee and payment method will be communicated using the prescribed process.
A decision is ordinarily communicated within 30 calendar days after a valid request is received, subject to a lawful extension under PAIA. The outcome will state whether access is granted or refused, any fees, the form of access, and available remedies.
10. Grounds for refusal
Access may be refused only on a ground permitted by PAIA. Examples include mandatory protection of another person's privacy, commercial information or confidential information of a third party, safety, legally privileged material, research information, or records whose disclosure would prejudice security or lawful operations. Mandatory disclosure provisions remain applicable where the Act requires them.
11. Remedies
A requester dissatisfied with a private-body decision generally has no internal appeal. Subject to PAIA procedures and time limits, the requester may submit a complaint to the Information Regulator using the current complaint form or apply to a court with jurisdiction. The official PAIA page explains the complaint and court routes.
12. Manual availability and Update history
The current manual is available as this printable HTML page, by email request, and for inspection at the listed address by prior arrangement. No fee applies to inspect the manual itself.
| Date | Version | Change |
|---|---|---|
| 2026-07-21 | 1.0 | First public Section 51 manual. |
Use your browser's print command to save or print a clean copy of this manual.