WEBGIANT · LEGAL & COMPLIANCE
PAIA Manual
South African PAIA section 51 manual · Draft becomes effective on publication.
1. Introduction
This manual is prepared for WebGiant (Pty) Ltd in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (“PAIA”), as amended, and includes information relevant to the Protection of Personal Information Act 4 of 2013 (“POPIA”). Its purpose is to explain the categories of records held by WebGiant and how a person may request access to records in accordance with law.
2. Company details
| Item | Details |
|---|---|
| Name | WebGiant (Pty) Ltd |
| Registration number | Contact WebGiant for this information. |
| Head / principal officer | Contact WebGiant for this information. |
| Information Officer | Contact WebGiant for this information. |
| Postal address | Contact WebGiant for this information. |
| Physical address | Contact WebGiant for this information. |
| Telephone | +27 66 322 5322 |
| Email for PAIA requests | privacy@webgiant.co.za |
| Website | https://webgiant.co.za/ |
3. PAIA Guide
The Information Regulator has published a guide explaining how PAIA may be used. The guide and prescribed forms are available from the Information Regulator. Requesters should consult the current guide and forms when making a formal PAIA request.
4. Records available without a formal PAIA request
- Public website content and published service information.
- Public privacy, cookie, website terms and acceptable-use policies.
- Information that WebGiant voluntarily makes publicly available from time to time.
5. Records held by WebGiant
| Category | Examples |
|---|---|
| Corporate and governance | Company registration records, statutory records, governance documents, policies and resolutions where applicable. |
| Finance and tax | Invoices, statements, accounting records, tax records, banking/payment records and supporting documents. |
| Clients and services | Quotations, contracts, SOWs, project records, support tickets, hosting/domain records and service correspondence. |
| Human resources / contractors | Employment/contractor records, payroll-related records, performance/disciplinary/training records where applicable. |
| Suppliers and service providers | Vendor contracts, invoices, due-diligence and service records. |
| IT and security | System inventories, access records, security logs, incident records, backups and configuration records subject to security/confidentiality restrictions. |
| Marketing | Campaign records, consent/opt-out records and business contact information. |
| Legal and compliance | Policies, complaints, requests, regulator correspondence, legal opinions and privileged records. |
6. Processing of personal information
WebGiant processes personal information to provide web development, hosting, domains, support and related services; manage clients and suppliers; bill and account; secure systems; respond to enquiries; market services lawfully; comply with legal obligations; and establish, exercise or defend legal rights.
7. Categories of data subjects and personal information
| Data subject | Information categories |
|---|---|
| Prospective and current clients | Identity, contact, business, project, billing, support and account information. |
| Client end-users / customers | Data held in client-controlled websites, databases, mailboxes or systems where WebGiant acts as operator. |
| Employees / contractors | Identity, contact, employment/contract, payroll, access and performance records where applicable. |
| Suppliers | Contact, registration, tax, banking and contractual records. |
| Website visitors | Technical/log data, cookie choices, forms and communications. |
8. Recipients / categories of recipients
- Hosting/cloud and backup providers
- Domain registries/registrars
- Email and communications providers
- Payment/accounting providers
- Security and support providers
- Professional advisers and authorities where lawful
- Client-authorised subprocessors
9. Planned transborder flows
WebGiant may transfer or make personal information accessible across borders in connection with international clients, cloud services, domains, hosting, support, email, analytics, payment or other approved providers. Such transfers are assessed against POPIA and other applicable transfer rules and are subject to appropriate contractual, technical or legal safeguards.
10. Security measures
WebGiant uses risk-based safeguards such as access controls, authentication, system updates, endpoint protection, secure remote administration, backups, logging, confidentiality obligations, vendor controls and incident-response procedures. Specific controls vary by system and sensitivity.
11. Request procedure
A person requesting access to a record must use the current prescribed PAIA form and submit it to the Information Officer at the contact details above. Fees prescribed by law may apply. WebGiant may refuse access on grounds permitted by PAIA, including privacy, confidentiality, legal privilege, safety/security, commercial information and other statutory grounds.
12. Availability
This manual will be made available through WebGiant’s website and at its office in the manner required by applicable law and the Information Regulator’s current guidance.