Access to Information

PAIA Manual · South Africa

Effective date: 3 October 2026.

Compiled under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), including the personal-information disclosures required by the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Purpose and terms

This manual explains the records Trackio holds, how to request access, and its personal-information processing. Trackio provides asset-tracking technology, operational visibility, reporting and related support.

PAIA means the Promotion of Access to Information Act; POPIA means the Protection of Personal Information Act; Information Officer means Trackio’s registered Information Officer. A Responsible Party determines processing purposes and means; an Operator processes information for a Responsible Party.

2. Company and contact details

Registered name: Trackio (Pty) Ltd | Trading name: Trackio

Company registration number: 2025/029176/07

Information Officer / head of the private body: Luke Osborne, CEO. The Information Officer retains final decision-making authority for PAIA matters.

Trackio has no Deputy Information Officer appointed at this time.

Primary PAIA, privacy and data-subject intake: support@trackiohub.com, addressed to the Information Officer.

Information Regulator registration: 2026-068235, completed on .

Registered and current principal business address for PAIA purposes; postal address and physical address for PAIA delivery and manual inspection: Unit 303, 1 Quendon Road, Cape Town, Western Cape, 8005, South Africa. Physical inspection is by prior arrangement during normal business hours. Contact the intake address or telephone number in this section to arrange inspection.

Telephone: +27 21 300 3839. Fax: None. Normal business hours: Monday to Friday, 09:00–17:00.

Current public website: https://www.trackiohub.com. The approved PAIA Manual will be published on trackiohub.com. No additional Trackio website needs to host the manual at this time.

3. The section 10 PAIA Guide and assistance

The Information Regulator’s Guide explains access rights, request procedures, fees and remedies. It is available in South African official languages through the Regulator’s PAIA page. Requests for assistance or a copy may also be directed to Trackio’s intake or the Regulator.

Official PAIA page and Guide downloads: https://inforegulator.org.za/paia/

English Guide: https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Guide-English_20210905.pdf

Regulator enquiries: enquiries@inforegulator.org.za | 010 023 5200 | toll free 0800 017 160. Current published address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. See https://inforegulator.org.za/contact-us/ for current channels.

Trackio will make the Information Regulator’s PAIA Guide available for inspection in English and Afrikaans at Trackio’s PAIA inspection address (section 2), by prior arrangement during normal business hours. Trackio may also direct requesters to the Information Regulator’s official online Guide and PAIA resources linked above.

4. Records available without a formal PAIA request

The public website provides product and service descriptions, public marketing material, articles, contact details and the published privacy notice. These may be viewed online without a PAIA application. Public pricing information is available where displayed.

Published privacy notice: https://www.trackiohub.com/privacy-policy

This PAIA Manual is made available as described in section 9. Trackio has not submitted a section 52 voluntary disclosure notice. No wider category of internal records is represented as automatically public.

5. Subjects and categories of records held

The following subjects and record categories describe Trackio’s company administration and technology services. Records may be electronic or paper. A category does not mean every possible record exists or that unrestricted disclosure is permitted; requests are assessed under section 7.

  • Company and governance: CIPC registration, incorporation and Memorandum of Incorporation documents; registered-office changes; director details; company particulars and regulatory-registration records.
  • Finance and commercial administration: financial models and summaries, budgets, pricing records, invoices, bank statements, VAT-registration and VAT-support records.
  • Customer and supplier relationships: service and consulting agreements, confidentiality agreements, supplier terms/documentation, business correspondence and customer assurance records.
  • People, recruitment and contractor administration: CVs and candidate records, contractor agreements and amendments, confidentiality records, remuneration/package/commission records and availability/leave tracking.
  • Platform, installations and operations: organisation and user-account records; roles and authentication records; device, asset and site records; tracking/telemetry events, locations and timestamps; installation/service activity; photographs and associated metadata; reports and exports.
  • Support and communications: customer/support emails, enquiries, messages, screenshots, attachments and diagnostic material supplied or generated for resolving cases.
  • Technology, security and continuity: software/source-code and development records, technical documentation, application/hosting/error and monitoring records, backup and restore evidence, operational alerts and compliance and incident-response records.
  • Marketing and public communications: published website content, public marketing material, sales-outreach materials and related business correspondence.

Requesters may identify records by subject, relevant dates and business or service context. Trackio searches the records it actually holds and applies the access process in section 7.

6. Records associated with other legislation

Companies Act 71 of 2008: incorporation and Memorandum of Incorporation documents, director and registered-office records, and company financial records.

Value-Added Tax Act 89 of 1991 and Tax Administration Act 28 of 2011: VAT registration, invoices and supporting accounting/bank records.

PAIA 2 of 2000 and POPIA 4 of 2013: this manual and the Information Officer registration certificate; privacy/compliance records and processing records.

Access to records under other legislation is subject to that legislation’s conditions. Inclusion in this manual does not make a record automatically public.

7. Making a PAIA request

7.1 Submit the request

Use the Regulator’s current Form 2 — Request for Access to Record — and send it to support@trackiohub.com for Luke Osborne, Information Officer. Postal and hand-delivery requests use the Quendon Road address in section 2. A suggested subject is “PAIA request — Trackio”.

Form 2: https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-PAIA-Form02-Reg7.pdf

Identify yourself and the record sufficiently to locate it; give relevant dates, references or customer/asset context where known. State the right to be exercised or protected and why the record is needed. Specify the requested access format, delivery/correspondence method and contact details. Attach proof of identity and, if acting for someone else, proof of authority. Sign the form and any additional pages; state any fee-exemption grounds. Contact intake if assistance or an accessible submission arrangement is needed.

7.2 Assessment, outcome and timing

Request administration includes coordinating intake, logging receipt, organising searches and keeping request correspondence and administration records. The Information Officer retains final decision-making authority for access, fees, extensions and any lawful refusal. Identity/authority checks and customer coordination must not create a blanket restriction on statutory access.

Ordinarily, a decision is due as soon as reasonably possible and within 30 calendar days of receipt or receipt of the required particulars. PAIA provides specific third-party procedures. One extension of up to 30 further days is permitted on statutory grounds, with timely written notice explaining the period, reasons and challenge rights. Failure to decide within the applicable period is a deemed refusal.

The Information Officer assesses applicable privacy, confidentiality, commercial and privilege grounds, any required third-party notice, severable disclosure and the public-interest override. A category marked internal is not itself a lawful refusal ground. Where records cannot be found or do not exist after reasonable searches, PAIA requires an affidavit or affirmation describing the search.

Written outcomes use Form 3 and state the decision, access arrangements/fees or adequate refusal reasons and remedies. Access may be by inspection or an available copy/electronic format, subject to PAIA and applicable payment.

Form 3: https://inforegulator.org.za/wp-content/uploads/2020/07/Form-3-PAIA.pdf

7.3 Fees

The current published private-body request fee is R140, subject to applicable exemptions and the law governing the request. Prescribed reproduction, search/preparation and delivery fees may also apply. The current search/preparation rate is R145 per hour or part after the first hour, capped at R435; a prescribed deposit may apply when searching exceeds six hours. Inspection itself is free; copies may attract fees.

Trackio gives the required written fee/deposit notice and payment instructions, including challenge rights. If access is refused after a deposit, the deposit must be repaid. Apply the current prescribed schedule and any applicable exemption; the PAIA request fee does not apply to POPIA’s free confirmation of whether personal information is held.

Official fee schedule: https://inforegulator.org.za/paia-fees-structure-2/

7.4 Complaints and court remedies

Trackio is a private body: PAIA’s public-body internal-appeal procedure does not apply. An aggrieved requester may complain to the Information Regulator using PAIA Form 5, ordinarily within 180 days of the relevant decision, including a deemed refusal. PAIA also provides court remedies and applicable time limits. The written outcome/extension/fee notice must identify the relevant remedy and deadline.

PAIA Form 5: https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-PAIA-Form05-Reg10-1.pdf

PAIA complaints: PAIAComplaints@inforegulator.org.za. Attach the request, response (if any), relevant correspondence and representative authority. Current complaint channels: https://inforegulator.org.za/contact-us/

8. Personal-information processing under POPIA

8.1 Roles and purposes

For customer-directed tracking services, the standard model is customer as Responsible Party and Trackio as Operator. Trackio separately determines purposes for its own business administration, contacts, billing and security. Processing is subject to the applicable POPIA requirements and, where Trackio is Operator, the customer’s lawful instructions.

Processing supports account/access administration; customer-directed tracking, reporting and alerts; installation/service coordination; support and privacy requests; security, diagnostics and reliability; recruitment and contractor administration; invoicing, finance, tax and company obligations; and business enquiries and communications. Public marketing and sales-outreach records are described in section 5.

8.2 Data subjects and information categories

  • Customer organisations, users and business contacts: names, contact details, organisation/role, account status, communications and billing/business details. Relevant juristic-person information is also considered under POPIA.
  • Installers and people identifiable through customer asset/device associations: user/device/asset/site identifiers, location, timestamps, telemetry/activity records, service assignments and installation photographs/metadata. A device reading alone is not necessarily personal information; linkage can make it identifiable.
  • Support correspondents and people included in submissions: contact details, correspondence, screenshots, photos and diagnostic attachments.
  • Users and technical/administrative personnel: account/authentication records, IP and device/app/browser identifiers, event/error/log context and monitored interactions.
  • Directors, contractor/supplier contacts and applicants: company/governance identity and contact particulars, CV/application information, engagement/confidentiality records, remuneration/invoices and relevant financial or tax details. Information varies by role and engagement.

8.3 Recipients

Authorised customer users receive the relevant customer’s operational records and reports. Necessary Trackio staff and authorised contractors receive information for support, operations, technical work and administration.

Service-provider categories include hosting/database and cloud storage/messaging, which may handle account, operational, telemetry and backup records; email/document collaboration, which may handle contacts, correspondence and attachments; diagnostics/monitoring, which may handle technical identifiers and event/request context; and reporting and device/OEM services, which may handle customer service and telemetry records. Maps/address services may receive relevant queries and browser/network metadata where enabled. Operational collaboration/development services may handle business communications and contributor metadata. The information supplied depends on the service and purpose; these categories do not imply that every provider receives every information category.

Banks and finance/tax advisers may receive relevant payment, accounting and business-contact information where needed for finance or tax administration. CIPC, SARS, courts, regulators or other legally entitled authorities may receive relevant records where required or lawfully authorised. Disclosures remain subject to authority, purpose and applicable law.

8.4 Cross-border flows

Germany: Render hosting in Germany is disclosed in Trackio’s service agreements. Production database backups are stored in Google Cloud’s Frankfurt region. These flows can include account, tracking and service information held in the hosted database or its backup.

Overseas development/support access may arise through contractor engagements, including an India-based engagement. Any access depends on the authorised task and permissions.

Other cloud, email/document collaboration, monitoring, reporting, OEM, mapping and supplier-support services may process information outside South Africa. Depending on the service, these flows can involve business contacts, correspondence, user/device identifiers, diagnostic context and person-linked service information. Locations vary by provider and service; no exclusive South African or European residency is stated.

Cross-border processing is subject to the applicable requirements of section 72 of POPIA and customer instructions where Trackio acts as Operator. Questions about a particular information category or processing arrangement may be directed to the intake in section 2.

8.5 General security measures

Trackio’s application code implements role/organisation access controls and password hashing. Contractual confidentiality obligations, monitoring/logging integrations and independent production database backups with a tested isolated restore support confidentiality, integrity and availability. Documented hosting and backup paths include provider-supported transport protection; provider documentation also describes encryption at rest for hosting/database and cloud storage. This summary does not assert complete encryption or control coverage across every system.

Approved management requirements: privileged-access reviews quarterly and on joiner/mover/leaver changes; privacy/security training at onboarding and annually; and material-subprocessor review before onboarding/material change and annually.

This is a general description of security measures, not a certification or security guarantee.

8.6 Privacy requests and retention

Authorised access, correction, objection and deletion enquiries use support@trackiohub.com. Identity/authority must be verified. Where Trackio is Operator, requests are coordinated with the customer Responsible Party, with assistance under the applicable agreement and law. Requests about Trackio’s own records are assessed by its Information Officer.

Under POPIA, confirmation of whether Trackio as Responsible Party holds your personal information is free on adequate proof of identity. Access/correction/deletion rights are subject to POPIA’s conditions; any applicable access fee is estimated in writing. Current POPIA objection and correction/deletion forms are linked on https://inforegulator.org.za/popia/. POPIA complaints may be sent to POPIAComplaints@inforegulator.org.za.

Information is retained according to its service or business purpose and applicable legal, contractual, dispute and backup-retention requirements. Periods vary by information category and system. The approved active-system data deletion target is within 30 calendar days, subject to legal, contractual and backup-retention requirements. It is a management target, not an automatic statutory deadline or a guarantee of immediate deletion from every backup or retained copy. Deletion requests are assessed through the intake in section 2, with customer coordination where Trackio acts as Operator. The separate PAIA response period in section 7 continues to apply.

9. Availability and updating of the manual

The approved manual will be published on trackiohub.com and made available at Trackio’s current principal business address for PAIA purposes in section 2. Physical inspection is by prior arrangement during normal business hours. A copy may be requested through the intake, subject to an applicable reasonable copying charge; a copy is also available to the Information Regulator on request. Inspection arrangements must facilitate access and must not be used to restrict statutory rights.

The Information Officer is responsible for maintaining the manual. Review takes place annually and after a material change or incident. Contact, service or processing changes are reflected promptly.