# PAIA MANUAL

**Kai Swarts, trading as Company Brain**

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended)

- **Date of compilation:** 2 August 2026
- **Date of last revision:** 2 August 2026
- **Version:** 1.0


---

## 1. List of acronyms and abbreviations

| Term | Meaning |
|---|---|
| **DIO** | Deputy Information Officer |
| **HPB** | Head of the Private Body |
| **IO** | Information Officer |
| **Minister** | Minister of Justice and Constitutional Development |
| **PAIA** | Promotion of Access to Information Act 2 of 2000 (as amended) |
| **POPIA** | Protection of Personal Information Act 4 of 2013 |
| **Regulations** | Regulations Relating to the Promotion of Access to Information, 2021 |
| **Regulator** | Information Regulator (South Africa) |
| **Republic** | Republic of South Africa |
| **the Body** | Kai Swarts, trading as Company Brain |

---

## 2. Purpose of this PAIA manual

This manual is provided so that a member of the public can —

2.1 check the categories of records held by the Body that are available without a person having to
submit a formal PAIA request;

2.2 have a sufficient understanding of how to make a request for access to a record of the Body, by
means of a description of the subjects on which the Body holds records and the categories of records
held on each subject;

2.3 know the description of the records of the Body that are available in accordance with any other
legislation;

2.4 access the contact details of the Information Officer, who will assist a person with the records
they intend to access;

2.5 know the description of the Guide on how to use PAIA, as updated by the Regulator, and how to
obtain access to it;

2.6 know that the Body processes personal information, the purpose of that processing, and the
description of the categories of data subjects and of the information relating to them;

2.7 know the recipients or categories of recipients to whom personal information may be supplied;

2.8 know whether the Body has planned transborder flows of personal information, and the recipients
or categories of recipients to whom personal information may be supplied; and

2.9 know whether the Body has appropriate security measures in place to ensure the confidentiality,
integrity and availability of the personal information it processes.

---

## 3. Key contact details for access to information

### 3.1 Head of the Private Body and Information Officer

The Body is a sole proprietorship. In terms of section 1 of PAIA read with section 1 of POPIA, the
head of the private body — and therefore the Information Officer — is the owner.

| | |
|---|---|
| **Name** | Kai Swarts |
| **Capacity** | Owner; Head of the Private Body; Information Officer |
| **Telephone** | 063 738 1166 (+27 63 738 1166) |
| **Email** | legal@companybrain.work |

### 3.2 Deputy Information Officer

No Deputy Information Officer has been designated. The Body is a sole proprietorship with no
employees, and the Information Officer performs all functions under PAIA and POPIA personally. If a
Deputy Information Officer is designated in future, this manual will be updated and the designation
registered with the Regulator.

### 3.3 General contact details for access to information

| | |
|---|---|
| **Access to information email** | legal@companybrain.work |
| **Privacy and data protection email** | privacy@companybrain.work |
| **General email** | hello@companybrain.work |

These are the same addresses published on the Body's website, so a person sees one consistent set of
contact details wherever they look.

### 3.4 Principal place of business

| | |
|---|---|
| **Trading name** | Company Brain |
| **Legal status** | Sole proprietorship — Kai Swarts, trading as Company Brain |
| **Registration number** | Not applicable (not a registered company or close corporation) |
| **Physical / street address** | 62/9 Milnerton Street, Kyalami, Johannesburg, Gauteng, 1684, South Africa |
| **Postal address** | As above |
| **Telephone** | 063 738 1166 (+27 63 738 1166) |
| **Email** | hello@companybrain.work |
| **Website** | https://companybrain.work |

---

## 4. The Guide on how to use PAIA, and how to obtain it

4.1 The Regulator has, in terms of section 10(1) of PAIA, updated and made available a Guide on how
to use PAIA ("the Guide"), in an easily comprehensible form and manner, as may reasonably be required
by a person who wishes to exercise any right contemplated in PAIA and POPIA.

4.2 The Guide is available in each of the official languages and in braille.

4.3 The Guide contains a description of, among other things: the objects of PAIA and POPIA; the
contact details of the Information Officer of every public body and the head of every private body;
the manner and form of a request for access to a record; the assistance available from an information
officer and from the Regulator; the remedies available in law if a right conferred by PAIA or POPIA
is infringed; and the provisions of PAIA and POPIA dealing with notices, fees and access.

4.4 Members of the public may inspect or make copies of the Guide at the offices of public and
private bodies, including the offices of the Regulator, during normal working hours.

4.5 The Guide may also be obtained —

- 4.5.1 on request to the Information Officer of the Body, at the contact details in section 3;
- 4.5.2 from the website of the Regulator at **https://inforegulator.org.za**; and
- 4.5.3 on request to the Regulator, at the contact details in section 11.

4.6 A copy of the Guide is available in the following two official languages for public inspection
at the Body's principal place of business during normal office hours: **English** and **isiZulu**.

---

## 5. Categories of records available without a person having to request access

The Body has not published a notice in terms of section 52(2) of PAIA. The following categories of
records are nevertheless made available voluntarily and may be accessed without a formal PAIA request.

| Category of records | Types of record | On the website | On request |
|---|---|---|---|
| Legal and policy notices | Privacy Policy; Cookie and Analytics Notice; Terms of Use; legal and supplier information | X | X |
| This PAIA manual | The current version of this manual | X | X |
| Product and service information | Public product descriptions, deployment and security overview, published rate information | X | X |
| Commercial scope material | The Company Brain scope summary describing the published package, allowances and boundaries | | X |
| Published research | Publicly available research authored by the owner, and links to it | X | X |
| Marketing material | Published articles, presentations and public briefing material | X | X |

Records in the "on request" column are supplied at the Body's discretion without a formal PAIA
request, subject to any confidentiality obligation owed to a third party. Where a record cannot be
supplied informally, a request may be made under section 8 of this manual.

---

## 6. Records available in accordance with other legislation

The following categories of records are created and held in accordance with other legislation. This
list does not mean that those records are automatically available to a requester; it identifies the
legislation under which they are created or retained.

| Category of records | Applicable legislation |
|---|---|
| This PAIA manual; records of requests received and processed; annual PAIA reports | Promotion of Access to Information Act 2 of 2000 |
| Records of processing operations; consent records; data-subject request records; security-compromise records | Protection of Personal Information Act 4 of 2013 |
| Tax returns, supporting schedules, invoices and financial records | Tax Administration Act 28 of 2011; Income Tax Act 58 of 1962 |
| VAT records — **not currently applicable**: the Body is not registered for VAT. This row applies from the date of any VAT registration. | Value-Added Tax Act 89 of 1991 |
| Electronic transaction and supplier-disclosure records; data messages | Electronic Communications and Transactions Act 25 of 2002 |
| Software, documentation and other works in which copyright subsists | Copyright Act 98 of 1978 |
| Customer-facing agreements and marketing records, to the extent the Act applies | Consumer Protection Act 68 of 2008 |
| Employment records | Basic Conditions of Employment Act 75 of 1997; Labour Relations Act 66 of 1995 — **not currently applicable**: the Body has no employees |

---

## 7. Subjects on which the Body holds records, and categories of records held on each subject

| Subject | Categories of records |
|---|---|
| Commercial and contractual | Order forms, proposals, commercial scope sheets, quotations, statements of work, non-disclosure agreements, partner and reseller arrangements, correspondence relating to negotiations |
| Customers and prospective customers | Business contact details, enquiry and meeting records, requirements and scoping notes, references and correspondence |
| Product, engineering and technical | Source code, architecture and design documentation, technical specifications, test results and test reports, defect registers, build, release and deployment records, technical evaluations |
| Deployment, service delivery and support | Environment configuration records, connector and integration configuration, support tickets and correspondence, incident records, service-review notes, monthly usage statements, go-live acceptance records |
| Information security and data protection | This manual, the Privacy Policy and Cookie Notice, records of processing operations, consent records, data-subject requests and responses, security-compromise records, security assessments and remediation records |
| Marketing and website | Website content and design assets, published articles and briefing material, website analytics reports, brand and image assets |
| Finance and tax | Invoices issued and received, bank records, accounting records, tax returns and supporting documents |
| Suppliers and service providers | Service agreements, subscription and licence records, invoices, supplier correspondence |
| Owner and administration | The owner's own business records, registrations, licences and professional records |
| Employment and human resources | **Not currently applicable** — the Body has no employees. Records of independent contractors, where engaged, are held under "Suppliers and service providers". |

---

## 8. How to request access to a record of the Body

This section is included to help a requester. It summarises PAIA; PAIA itself prevails if there is
any difference.

### 8.1 The form of the request

8.1.1 A request must be made on **Form 2 — Request for Access to Record [Regulation 7]**, or on a
form that corresponds substantially with it. Form 2 is available from the Regulator at
**https://inforegulator.org.za/paia-forms/**, and from the Information Officer on request.

8.1.2 The completed form must be submitted to the Information Officer at the email or physical
address in section 3.

8.1.3 The request must —

- provide sufficient particulars to enable the Information Officer to identify the record and the
  requester;
- indicate the form of access required;
- specify a postal address or email address of the requester in the Republic;
- **identify the right the requester is seeking to exercise or protect, and explain why the record
  requested is required for the exercise or protection of that right** (section 53(2)(d) — this is a
  requirement specific to requests to a private body);
- state whether the requester wishes to be informed of the decision in any manner other than in
  writing, and if so, the manner and the particulars; and
- if the request is made on behalf of another person, include proof of the capacity in which the
  requester is making the request, to the satisfaction of the Information Officer.

8.1.4 A requester who is unable to read or write, or who has a disability, may make the request
orally, and the Information Officer will reduce it to writing on Form 2 and provide the requester
with a copy.

### 8.2 Fees

8.2.1 **Request fee.** A request fee of **R140.00** is payable before the request is processed. A
**personal requester** — a requester seeking access to a record containing personal information about
that requester — is **not** required to pay the request fee.

8.2.2 **Access fee.** Where access is granted, an access fee is payable to reimburse the Body for
the cost of searching for, reproducing and preparing the record for delivery. The fees below are
those prescribed in Annexure B to the Regulations for a private body, and were verified against the
Regulator's published fee structure on 2 August 2026.

| # | Item | Fee |
|---|---|---|
| 1 | Request fee, payable by every requester other than a personal requester | R140.00 |
| 2 | Black-and-white photocopy of an A4-size page, or part thereof | R2.00 per page |
| 3 | Printed copy of an A4-size page, or part thereof | R2.00 per page |
| 4 | Copy in computer-readable form — flash drive (provided by the requester) | R40.00 |
| | Copy in computer-readable form — compact disc (provided by the requester) | R40.00 |
| | Copy in computer-readable form — compact disc (provided to the requester) | R60.00 |
| 5 | Transcription of visual images, per A4-size page | Outsourced; charged at the service provider's quotation |
| 6 | Copy of visual images | Outsourced; charged at the service provider's quotation |
| 7 | Transcription of an audio record, per A4-size page | R24.00 |
| 8 | Copy of an audio record — flash drive (provided by the requester) | R40.00 |
| | Copy of an audio record — compact disc (provided by the requester) | R40.00 |
| | Copy of an audio record — compact disc (provided to the requester) | R60.00 |
| 9 | Search for and preparation of the record for disclosure, for each hour or part of an hour reasonably required, **excluding the first hour** | R145.00 per hour, to a maximum of R435.00 |
| 10 | Deposit, where the Information Officer estimates that the search and preparation will exceed six hours | One third of the total of the access fees in items 2 to 8 |
| 11 | Postage, email or other electronic transfer | The actual cost incurred |

8.2.3 The Information Officer will notify the requester of the fees payable on **Form 3 — Outcome of
Request and of Fees Payable [Regulation 8]** before further processing the request. A requester may
lodge a complaint with the Regulator or apply to a court against a decision on fees or on a deposit.

8.2.4 A fee is payable for a copy of this manual, as contemplated in Annexure B to the Regulations,
per A4-size photocopy. No fee is payable for viewing this manual on the Body's website or inspecting
it at the Body's principal place of business.

### 8.3 The decision

8.3.1 The Information Officer will decide the request and notify the requester in writing within
**30 days** of receipt, and will state the outcome, the fees payable, the form of access, and — where
access is refused — adequate reasons and the right to lodge a complaint or apply to a court.

8.3.2 That period may be extended by a further period of not more than **30 days** in the
circumstances set out in section 57 of PAIA, in which case the requester will be notified in writing
of the extension and the reasons for it.

8.3.3 Where access is granted, the record will be made available in the form requested, unless doing
so would unreasonably interfere with the running of the Body's operations, damage the record, or
infringe copyright not owned by the Body.

### 8.4 Grounds on which access may or must be refused

Access to a record may or must be refused on the grounds set out in Chapter 4 of Part 3 of PAIA,
which include —

- the mandatory protection of the privacy of a third party who is a natural person (section 63);
- the mandatory protection of the commercial information of a third party, including trade secrets,
  financial, commercial, scientific or technical information (section 64);
- the mandatory protection of information supplied in confidence, where disclosure would constitute a
  breach of a duty of confidence owed to a third party (section 65);
- the mandatory protection of the safety of individuals and the protection of property (section 66);
- records privileged from production in legal proceedings (section 67);
- the commercial information of the Body, including trade secrets, information whose disclosure would
  be likely to cause harm to its commercial or financial interests, and information whose disclosure
  could put the Body at a disadvantage in negotiations or commercial competition (section 68); and
- research information of the Body or of a third party, where disclosure would be likely to expose
  the researcher, the subject matter or the research to serious disadvantage (section 69).

Access may also be refused where a request is manifestly frivolous or vexatious, or where the work
involved in processing it would substantially and unreasonably divert the Body's resources
(section 45). Where a ground of refusal applies only to part of a record, access will be given to the
remainder (section 28 read with section 65).

Some of these grounds are directly relevant to the Body's records: source code, technical design
documentation, security assessments, defect registers and commercial scope material are commercial
and technical information of the Body, and customer environment configuration and support records are
frequently supplied in confidence by a customer.

### 8.5 Remedies available to a requester

8.5.1 The internal-appeal procedure in section 74 of PAIA applies to public bodies only. It does not
apply to a private body.

8.5.2 A requester who is dissatisfied with a decision of the Body may —

- lodge a complaint with the Regulator on **Form 5 — Complaint Form [Regulation 10]**, within
  180 days of the decision (section 77A); or
- apply to a court for appropriate relief within 180 days (section 78).

---

## 9. Processing of personal information

### 9.1 Purpose of processing

The Body processes personal information for the following purposes:

- responding to business enquiries and managing relationships with customers, prospective customers,
  partners and suppliers;
- concluding and performing agreements, including deploying, configuring, maintaining and supporting
  the Company Brain software in a customer's environment;
- providing support, service reviews and usage reporting to customers;
- understanding which pages of the Body's website are useful, using analytics, **and only where the
  visitor has given consent**;
- invoicing, payment, accounting and tax;
- complying with legal and regulatory obligations, and establishing, exercising or defending legal
  claims; and
- protecting the security and integrity of the Body's systems and information, and preventing
  fraud and abuse.

The Body does not sell personal information, does not process personal information for advertising or
remarketing, and does not carry out automated decision-making that produces legal effects for a data
subject or similarly significantly affects them.

**Position on customer content.** Where the Body deploys Company Brain into infrastructure provided
and controlled by a customer, the customer determines the purpose and means of processing the content
in that environment and is the responsible party for it. The Body acts as an operator in relation to
that content, under a written agreement, and only to the extent needed to deploy, configure, maintain
and support the software. In the standard configuration, document content, evidence and derived
knowledge remain inside the customer's infrastructure.

### 9.2 Categories of data subjects, and the personal information processed

| Categories of data subjects | Personal information that may be processed |
|---|---|
| Website visitors | Technical request data processed by the hosting provider in delivering the website (including IP address, request time, page requested, browser user-agent, referring page); and, **only with consent**, analytics data about pages viewed and journeys through the site. The analytics provider does not store the IP address; it uses it transiently to estimate an approximate location and then discards it. |
| Customers and prospective customers, and their personnel | Name, job title, employer, business email address, business telephone number, correspondence, meeting notes, requirements and scoping information |
| Named reviewers, administrators and technical contacts within a customer environment | Name, business email address, role, the review, approval and publication decisions they take within the software, and the audit record of those decisions |
| Partners and their personnel | Name, job title, employer, business contact details, correspondence, commercial and partnership records |
| Suppliers, service providers and independent contractors | Name, business contact details, contractual and payment details, invoices, banking details where required for payment |
| Professional advisers | Name, business contact details, correspondence |
| The owner | The owner's own identity, tax, banking, registration and business records |

The Body does not knowingly process the personal information of children, and does not process
special personal information as contemplated in section 26 of POPIA, except where a data subject
volunteers it in unsolicited correspondence.

### 9.3 Recipients or categories of recipients to whom personal information may be supplied

| Category of personal information | Recipients or categories of recipients |
|---|---|
| Website technical request data | The website hosting and edge-delivery provider, as operator |
| Website analytics data, where the visitor has consented | Google, as the provider of Google Analytics 4 |
| Business correspondence and contact details | The email, collaboration and professional-network providers used by the Body, as operators |
| Invoicing, accounting and tax records | The Body's accountant or bookkeeper; the South African Revenue Service |
| Records relevant to a legal claim, dispute or regulatory process | The Body's attorneys; courts, tribunals and regulators, where required |
| Records of processing, requests and security compromises | The Information Regulator, where required by POPIA or PAIA |
| Content and personal information within a customer environment | The customer itself. Content is disclosed to a hosted model provider **only** where that customer expressly opts into a premium hosted model; the default configuration uses a self-hosted model inside the customer's own environment. |

The Body does not supply personal information to any other recipient, other than where required by
law or with the data subject's consent.

### 9.4 Planned transborder flows of personal information

The Body has planned transborder flows of personal information. The website hosting and
edge-delivery provider, the analytics provider, and the email and collaboration providers used by the
Body all operate globally, and personal information in the categories described in section 9.2 may be
processed outside the Republic, principally in the United States and the European Union.

The Body relies on the following bases in section 72 of POPIA, as applicable to each transfer: that
the recipient is subject to a law, binding corporate rules or a binding agreement providing an
adequate level of protection substantially similar to POPIA; that the data subject has consented, in
the case of website analytics; and that the transfer is necessary for the performance of a contract
between the data subject and the Body, or for the conclusion or performance of a contract concluded
in the data subject's interest.

**Customer content is not part of this.** In the standard configuration, document content in a
Company Brain deployment stays inside the customer's own infrastructure and is not transferred out of
it by the Body. Where a customer opts into a premium hosted model, prompt content is transmitted to
that provider on that customer's instruction, under that customer's own arrangements.

The providers in use as at the date of this manual, and the processing each carries out, are —

| Provider | Processing | Where |
|---|---|---|
| Cloudflare, Inc. (edge hosting for the Body's website, provided through the platform on which the site is published) | Delivery of the website and the technical request data necessary for it | Global edge network |
| Google LLC — Google Analytics 4 | Website analytics, **only where the visitor has consented** | United States and other locations |
| Google LLC — email and productivity | Business correspondence and the documents attached to it | United States and other locations |
| Microsoft Corporation — GitHub | Source-code and technical-documentation hosting; may contain the names and contact details of contributors and correspondents | United States |
| LinkedIn Corporation | Business contact and correspondence initiated through the professional network | United States |
| The premium hosted model provider (currently Anthropic) | Prompt content, **only where a customer expressly opts into a premium hosted model**. Not used in the standard configuration. | United States |

### 9.5 General description of information security measures

The Body applies the following measures to secure the personal information it processes. Measures
marked "product" are implemented in the Company Brain software and have been verified in the source
code; measures marked "operational" are applied to the Body's own business systems.

**Product measures**

- Source-system credentials are encrypted before they are written to storage, using platform data
  protection with cryptographic separation per source, so one source's credentials cannot be
  decrypted by another component.
- A deployment will not start in production on an ephemeral encryption key ring, so credentials
  cannot silently become unrecoverable.
- Every application programming interface route requires authentication and carries an authorisation
  policy; access is role-based, and keys are issued per principal.
- Application programming interface keys are verified using constant-time comparison, and failed
  attempts are logged without recording the key.
- Request rate limiting is applied, with separate limits for partner traffic.
- Governance-critical changes are written to an append-only, hash-chained record using SHA-256, which
  can be verified on demand; any alteration to a record breaks the chain and is reported.
- Personal information detected during ingestion can be redacted, with the original value recoverable
  only by an administrator through an encrypted pointer, or not stored at all under a pointer-only
  policy.
- Standard security response headers are applied to every response, and transport encryption is
  terminated at the ingress layer.
- In the standard configuration, inference runs on a self-hosted model inside the customer's own
  environment, so content is not transmitted to an external model provider.

**Operational measures**

- Multi-factor authentication on email, code hosting, cloud and administrative accounts.
- Unique, randomly generated passwords held in a password manager.
- Full-disk encryption on devices used to conduct the Body's business.
- Least-privilege access to customer environments, granted for the purpose and period required.
- Secrets held in a managed secret store rather than in configuration files, source code or messages.
- Regular backups of business records, and retention of records only for as long as necessary.
- A process for identifying, containing and recording a security compromise, and for notifying the
  Regulator and affected data subjects as required by section 22 of POPIA.

**Statement of limits.** The Body holds no security certification, and no independent penetration
test has been performed. These measures are described so that a person can understand what is in
place; they are not represented as a guarantee against every possible compromise.


---

## 10. Availability of this manual

10.1 A copy of this manual is available —

- 10.1.1 on the Body's website at https://companybrain.work/paia;
- 10.1.2 at the Body's principal place of business, for public inspection during normal business
  hours;
- 10.1.3 to any person on request, on payment of the prescribed fee for a photocopy; and
- 10.1.4 to the Information Regulator on request.

10.2 A fee for a copy of this manual, as contemplated in Annexure B to the Regulations, is payable
per A4-size photocopy made. No fee is payable for viewing it on the website or inspecting it at the
principal place of business.

---

## 11. Contact details of the Information Regulator

| | |
|---|---|
| **Information Regulator (South Africa)** | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| **Telephone** | 010 023 5200 |
| **Toll free** | 0800 017 160 |
| **General enquiries** | enquiries@inforegulator.org.za |
| **PAIA complaints** | PAIAComplaints@inforegulator.org.za |
| **POPIA complaints** | POPIAComplaints@inforegulator.org.za |
| **Website** | https://inforegulator.org.za |

These details were taken from the Regulator's own contact page on 2 August 2026. The Regulator has
moved offices — the address "JD House, 27 Stiemens Street, Braamfontein" still appears on older
Regulator forms and on many other bodies' PAIA manuals, and should not be relied on. Re-check the
contact page at each annual review.

---

## 12. Updating of this manual

The Information Officer will review this manual at least annually, and will update it whenever there
is a material change to the Body's records, its processing of personal information, its contact
details or the applicable law. Each revision will carry a new revision date.

A revision will be made in particular if the Body registers for VAT, engages employees, designates a
Deputy Information Officer, changes the providers listed in section 9.4, or changes any contact
detail in section 3.

---

## 13. Approval

Issued by:

**Kai Swarts**
Owner; Head of the Private Body; Information Officer
Kai Swarts, trading as Company Brain

Date of issue: **2 August 2026**

Signature: _______________________________________


---

### Annexure — Prescribed forms

The following prescribed forms are referred to in this manual and are available from the Regulator at
https://inforegulator.org.za/paia-forms/ :

| Form | Title | Regulation |
|---|---|---|
| Form 1 | Request for a copy of the Guide from an Information Officer | Regulation 3 |
| Form 2 | Request for Access to Record | Regulation 7 |
| Form 3 | Outcome of request and of fees payable | Regulation 8 |
| Form 5 | Complaint Form | Regulation 10 |


