Back to Legal

PAIA manual

Ignis Labs (Pty) Ltd · Registration 2025/758623/07

Compiled: 8 October 2026
Last revised: 8 October 2026

Access contacts

Information Officer
Byron Rode
Telephone
086 999 0226
PAIA and general enquiries
support@ignislabs.io
Physical and postal address
28 Wesley Street, Observatory, Cape Town, 7806, South Africa
Deputy Information Officers
None appointed.
Fax
Not applicable.

Purpose and scope

This manual is prepared under section 51 of the Promotion of Access to Information Act 2 of 2000, as amended (PAIA). It explains how to identify and request records held by Ignis Labs and describes our processing of personal information under the Protection of Personal Information Act 4 of 2013 (POPIA).

It covers the company’s business records, websites, (my)cards, (my)loyalty, related APIs and support channels. Product privacy notices provide additional detail about the services you use. Records held independently by card issuers, merchants, app stores or other providers must be requested from the relevant body.

Help using PAIA

The Information Regulator’s section 10 guide explains access rights, how to make requests, available assistance, fees and remedies. It is available in the published official-language versions from the Regulator’s guide page. Contact our Information Officer for assistance obtaining the guide or identifying records.

The Information Regulator (South Africa) can be contacted at enquiries@inforegulator.org.za or 010 023 5200. PAIA complaints can be sent to PAIAComplaints@inforegulator.org.za.

Records available without a formal request

Published company and product information, blog articles and legal policies can be read on our websites without submitting a PAIA request. This manual is also freely available online. Availability of these documents does not make confidential company or customer records public.

Records under other legislation

Company incorporation and governance records are maintained under the Companies Act 71 of 2008. Accounting and tax records are maintained under applicable provisions of the Income Tax Act 58 of 1962, Value-Added Tax Act 89 of 1991 and Tax Administration Act 28 of 2011. Privacy and access-request records relate to PAIA and POPIA. Employment records, where held, are subject to applicable employment and payroll legislation.

Access under another law follows that law’s requirements. A record’s inclusion in this manual does not mean that it is automatically available for inspection or disclosure.

Subjects and record categories

The following categories help identify records for a request. Records depend on the activities and features used; a category does not imply that every possible record exists.

Company administration

Incorporation and governance documents, statutory registers and company correspondence.

Finance, tax and contracts

Accounting records, invoices, tax records, business agreements, supplier records and subscription or payment metadata where held.

Personnel

Employment, recruitment and payroll records where held.

(my)cards

Account/contact details, user-added card and wallet records, sync and recovery information, service metadata and authorised support or rights requests.

(my)loyalty

Merchant and customer account records, program membership, points, stamps, rewards, QR issuing/redemption events, transaction history and merchant reporting.

Website and communications

Contact enquiries, support conversations and attachments, newsletter subscriptions, blog memberships and related correspondence.

Technology, security and compliance

Operational documentation, analytics, diagnostics, security records and logs, privacy/access requests, decisions and complaints.

Personal-information processing

We process information to provide and administer services, manage accounts and contracts, respond to enquiries, operate loyalty programs, handle billing metadata, understand usage, improve reliability, protect services and meet legal obligations. In defined merchant arrangements, we process customer information on the business customer’s instructions.

Customers and product users

Contact and account information, card/sync records and loyalty membership, reward and redemption information relating to the services used.

Merchants, business representatives and suppliers

Business/contact details, roles, agreements, invoicing and transaction metadata where held.

Website visitors and correspondents

Technical and usage information, newsletter details, names, email addresses, messages, attachments and support correspondence.

Personnel and applicants

Recruitment, employment, contact and payroll information where held.

Recipients

Relevant hosting, infrastructure, storage, database, analytics, diagnostics, communications and support providers; app stores and billing platforms; merchants or business customers for loyalty operations; and advisers or authorities where legally required or reasonably necessary. Website services include Chatwoot, Supabase, Resend, Ghost and Mixpanel.

International processing

Hosting, analytics, communications, app-store and recovery providers may process relevant personal information outside South Africa. Website Mixpanel analytics uses its European service endpoint. Legacy iCloud/CloudKit or Google Drive recovery is subject to the selected provider’s processing arrangements. Where required, international processing is subject to appropriate contractual, organisational and technical safeguards.

Security measures

Controls include restricted access, encrypted connections, monitoring and secure development practices. Sensitive synced card fields use application-level encryption with controlled key access. This is not end-to-end encryption: authorised application processes and restricted administrators may decrypt records for permitted service, support, security or legal purposes. Retention and deletion are subject to legal duties and backup lifecycle constraints.

How to request a record

Complete the prescribed Form 2 and send it to the Information Officer using the contact details above. Identify the record, your contact details and preferred form of access. Explain the right you wish to exercise or protect and why the record is required. If you represent someone else, provide evidence of your authority. Identity and authority may need verification before disclosure.

The normal decision period is 30 days after receipt, subject to PAIA’s provisions, including third-party procedures. Where PAIA permits it, the period may be extended once by up to 30 further days with written notice. Decisions explain the result, applicable fees, reasons for refusal and available remedies. If a record cannot be found or does not exist, PAIA’s procedure for that situation applies.

Access may be limited to protect personal information, confidential commercial information, legal privilege, safety or other interests protected by PAIA, subject to its disclosure requirements. Listing a record is not a guarantee of access.

Fees

Applicable fees follow the current prescribed private-body schedule. The published schedule lists a R140 request fee and R2 per A4 photocopy or printed page. Other reproduction, search/preparation, delivery and deposit rules may apply. We provide the prescribed written notice of fees and access arrangements. Statutory exceptions and personal-information access rights remain applicable; not every privacy enquiry attracts a PAIA request fee.

Complaints and remedies

Private bodies do not have PAIA’s statutory internal appeal process for the specified public bodies. If a request is refused, receives no response within the applicable period, or you dispute a decision about fees, extension or access, you may complain to the Information Regulator using Form 5. The normal complaint period is 180 days; see the Regulator’s procedure for the relevant trigger and requirements. Court remedies remain available under PAIA, subject to the applicable procedures.

Availability and updates

This manual is freely available on ignislabs.io/paia and for public inspection at our principal place of business during normal business hours. Copies can be requested from the Information Officer, subject to any lawful copying charge, and are supplied to the Information Regulator on request. The head of the company updates the manual regularly as contacts, records, processing practices or legal requirements change.

Forms and guidance

(my)cards legal(my)loyalty legal

Issued by Byron Rode, Information Officer.