Neevo (Pty) Ltd · PAIA Manual
Manual on the Promotion of Access to Information
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended by the Protection of Personal Information Act 4 of 2013.
Contents
1. Purpose of this manual
Section 32 of the Constitution of the Republic of South Africa, 1996, gives everyone the right of access to information held by the State, and to information held by another person that is required for the exercise or protection of any right. The Promotion of Access to Information Act 2 of 2000 (“PAIA”) gives effect to that right.
Section 51 of PAIA requires every private body to compile a manual describing the records it holds and explaining how a person may request access to them. This document is the manual of Neevo (Pty) Ltd (“Neevo”, “the Company”, “we”, “us”).
Under section 50 of PAIA, a requester must be given access to a record of a private body if the record is required for the exercise or protection of any right, the procedural requirements set out in PAIA have been met, and no ground of refusal in PAIA applies.
This manual also sets out the particulars required by section 51(1)(c) of PAIA read with the Protection of Personal Information Act 4 of 2013 (“POPIA”) in relation to the personal information Neevo processes.
2. About Neevo
Neevo is a South African software studio. The Company designs, builds, hosts and maintains custom software, web applications and mobile applications for clients, and it develops and operates its own software products.
At the date of compilation of this manual, the Company operates the following products under its own name:
- GGFam — a family behaviour and chore-tracking application for South African households, available in English and Afrikaans.
- Triply — a trip and travel planning application.
- KinVault — a secure application for storing family documents and related information.
These products are operated by Neevo (Pty) Ltd and are not separate legal entities. Records relating to them are accordingly records of the Company and are covered by this manual.
At the date of compilation, the Company has one director and no employees.
3. Contact details
In terms of section 51(1)(a) of PAIA, and section 1 of PAIA read with section 55 of POPIA, the head of the Company is its sole director, who also acts as its Information Officer.
| Item | Detail |
|---|---|
| Registered name | Neevo (Pty) Ltd |
| Registration number | 2026/579962/07 |
| Legal status | Private company registered in terms of the Companies Act 71 of 2008 |
| Place of registration | Companies and Intellectual Property Commission (CIPC), South Africa |
| Financial year end | End February |
| VAT status | Not registered as a VAT vendor at the date of compilation |
| Head / Information Officer | Jacques Botha, Director |
| Physical address | 1 Ceretto, Woodhill Golf Estate, Garsfontein, Pretoria, 0081 |
| Postal address | 1 Ceretto, Woodhill Golf Estate, Garsfontein, Pretoria, 0081 |
| Telephone | 082 654 4955 |
| privacy@neevo.co.za | |
| Website | https://neevo.co.za |
The Information Officer has been registered with the Information Regulator. Requests for access to records, and enquiries about this manual, should be directed to the Information Officer by email at the address above.
The Company operates by appointment. Where a person wishes to inspect this manual at the Company’s premises, arrangements should be made in advance by email or telephone.
4. The Information Regulator’s guide on how to use PAIA
The Information Regulator has, in terms of section 10(1) of PAIA, published a guide containing information to assist any person who wishes to exercise a right under PAIA or POPIA. The guide is written in an easily comprehensible form and describes the objects of both Acts, the manner and form of a request, the assistance available from an information officer and from the Regulator, and the remedies available in law.
The guide is available in all official languages. It may be obtained from the Information Regulator website, on request from the Information Officer of the Company, and for inspection at the offices of the Information Regulator during normal working hours. No fee is charged for access to or inspection of the guide.
5. Records available without a request under PAIA
In terms of section 52(1) of PAIA, a private body may voluntarily make certain categories of records available without a person having to submit a formal request. The following categories of the Company’s records are made available on this basis, free of charge:
| Category of record | How to access |
|---|---|
| Descriptions of the Company’s services, and published pricing for its fixed-price services | On the website at neevo.co.za |
| Legal notices and policies, including the Privacy Policy, Terms of Service and Refund and Cancellation Policy | On the website at neevo.co.za |
| This PAIA Manual | On the website, and on request from the Information Officer |
| Company registration particulars | On request from the Information Officer, and from CIPC |
| Published information about the Company’s own products, including their descriptions and terms of use | On the website, and on the relevant product website or app store listing |
Making a record available in this way does not require the requester to show that the record is required for the exercise or protection of a right, and no request fee is payable.
6. Records held in terms of other legislation
In terms of section 51(1)(d) of PAIA, the following is a description of the categories of records the Company holds in accordance with other legislation. This list is not exhaustive, and the mention of legislation here does not mean that the records concerned are automatically available.
| Category of record | Legislation |
|---|---|
| Memorandum of incorporation, registers, resolutions and other statutory company records | Companies Act 71 of 2008 |
| Accounting records, invoices, financial statements and supporting documents | Companies Act 71 of 2008; Tax Administration Act 28 of 2011 |
| Income tax records and returns | Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011 |
| Value-added tax records, if and when the Company becomes a registered vendor | Value-Added Tax Act 89 of 1991 |
| Records of processing personal information, and data subject requests | Protection of Personal Information Act 4 of 2013 |
| This manual and records of access requests | Promotion of Access to Information Act 2 of 2000 |
| Records relating to electronic transactions concluded through the website | Electronic Communications and Transactions Act 25 of 2002 |
| Records relating to agreements with clients who are consumers | Consumer Protection Act 68 of 2008 |
| Records relating to software, source code and other copyrighted works | Copyright Act 98 of 1978 |
The Company has no employees at the date of compilation of this manual. Records required by employment legislation, including the Basic Conditions of Employment Act 75 of 1997 and related statutes, will be held and this manual updated accordingly should the Company employ staff.
7. Subjects and categories of records held by the Company
| Subject | Categories of records |
|---|---|
| Company and statutory | Incorporation documents, memorandum of incorporation, director and share registers, resolutions, correspondence with CIPC and other regulators, licences and registrations |
| Finance and accounting | Quotations, invoices, statements, proof of payment, bank statements, accounting records, tax returns and assessments, payment gateway transaction records |
| Client engagements | Service agreements, statements of work, project specifications, Blueprint and Efficiency Audit deliverables, prototypes, designs, correspondence, meeting notes, change requests and sign-offs |
| Software and technical | Source code, repositories, architecture and design documentation, technical specifications, test records, deployment and release records, credentials and access records |
| Client data processed on behalf of clients | Databases, files and records containing information belonging to clients and to their customers, staff or users, held by the Company in its capacity as an operator under written agreement |
| Products operated by the Company | User account records, subscription and billing records, application data and usage records for GGFam, Triply and KinVault, and related support correspondence |
| Suppliers and service providers | Contracts and terms of service, contact details, invoices, payment records |
| Marketing and enquiries | Website enquiry submissions, contact details, consent and subscription records, marketing correspondence, website analytics |
| Information technology and infrastructure | Hosting and infrastructure configuration, server and application logs, security and audit logs, backup records, incident records |
| Insurance and risk | Policies, schedules and claims correspondence, where applicable |
8. Processing of personal information
This section sets out the particulars contemplated in section 51(1)(c) of PAIA read with POPIA. Fuller detail is set out in the Company’s Privacy Policy, which should be read together with this manual.
8.1 Purposes of processing
- Respond to enquiries received through its website and by other means.
- Conclude and perform agreements with clients, and deliver its services.
- Host, maintain, support and secure software built for clients.
- Operate, support and bill for its own products.
- Invoice clients, receive payment and maintain accounting records.
- Send updates and other communications to persons who have consented to receive them.
- Operate, secure and improve its website.
- Comply with its obligations in law.
8.2 Categories of data subjects and personal information
| Category of data subject | Personal information that may be processed |
|---|---|
| Prospective clients and enquirers | Name, email address, telephone or WhatsApp number, business name, and the content of the enquiry |
| Clients and representatives | Name, contact details, company and registration details, billing address, correspondence, project information and payment records |
| Users of the Company’s own products | Name, email address, account credentials in encrypted form, household or group membership, application usage data, subscription and payment records, and support correspondence |
| Children whose information is processed through GGFam | First name or nickname, age or date of birth, household membership, and activity records within the application, processed with the consent of a parent or competent person |
| Data subjects whose information is processed for clients | Personal information determined by the client, processed only on the client’s documented instructions as operator |
| Suppliers and service providers | Name, contact details, registration and tax numbers, banking details |
| Subscribers | Name, email address, and consent/withdrawal records |
| Website visitors | IP address, browser and device information, pages visited, and referral information |
| The director | Identity and contact details, banking details, and records required by company and tax legislation |
The Company does not seek special personal information, as defined in POPIA, through its website. Where the Company processes the personal information of children through GGFam, it does so on the basis of the consent of a parent or other competent person, in accordance with section 35 of POPIA.
8.3 Recipients of personal information
Personal information may be supplied, where necessary and lawful, to:
- hosting and infrastructure providers, who store website, application and client data;
- email delivery providers, who transmit correspondence and notifications;
- the Company’s payment gateway, which processes payments and handles payment card details directly;
- application distribution platforms, where the Company’s products or a client’s application is published;
- the Company’s bank, accountant and professional advisors;
- clients, in respect of personal information the Company processes on their behalf;
- regulatory and revenue authorities, including SARS and CIPC, where required; and
- any person to whom disclosure is required by law, or is necessary to establish, exercise or defend a right in law.
Service providers who process personal information on the Company’s behalf do so under written agreement and only on the Company’s instructions.
8.4 Transborder flows of personal information
The Company hosts its website, its own products and the applications it maintains for clients on South African infrastructure.
Certain supporting services used by the Company may involve the processing or storage of personal information outside the Republic of South Africa. Where personal information is transferred across a border, the Company does so only in accordance with section 72 of POPIA, on the basis that the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, or on another basis permitted by that section. Current particulars are set out in the Company’s Privacy Policy.
8.5 Security safeguards
The Company takes reasonably practicable technical and organisational measures to secure the integrity and confidentiality of personal information in its possession or under its control, and to prevent its loss, damage, unauthorised destruction or unlawful access. These measures include encrypted connections, encryption of data at rest where appropriate, access control and least-privilege permissions, multi-factor authentication on administrative accounts, patching and updating of systems, logging and monitoring, regular backups, and periodic review of safeguards.
Where the Company acts as an operator for a client, it processes personal information only with the knowledge and authorisation of that client, treats it as confidential, and notifies the client immediately where there are reasonable grounds to believe that the personal information has been accessed or acquired by an unauthorised person.
9. How to request access to a record
A person who wishes to request access to a record of the Company that is not listed in section 5 above must:
- Complete Form 2 (Request for Access to Record of a Private Body), prescribed under the PAIA Regulations and available from the Information Regulator.
- Submit the completed form to the Information Officer at privacy@neevo.co.za, or deliver it to the address in section 3.
- Provide sufficient particulars to identify the record and the requester.
- State which right the requester seeks to exercise or protect, and explain why the requested record is required.
- State the form of access required and preferred notification method.
- Provide proof of identity and, where relevant, proof of authority to act for another person.
- Pay the prescribed request fee when notified to do so.
The Information Officer will decide on the request within 30 days of receipt and will notify the requester of the decision in the manner requested. This period may be extended once, by a further period of not more than 30 days, in the circumstances set out in section 57 of PAIA. Where the request concerns a record containing information about a third party, the notification procedures in PAIA apply and may affect the time taken.
If the request is granted, the Information Officer will notify the requester of the access fee payable, the form in which access will be given, and the right to lodge a complaint against the tender or payment of the fee. If the request is refused, the Information Officer will give written reasons and will identify the provision of PAIA relied on.
Where a requester is unable to make a written request because of illiteracy or disability, the request may be made orally to the Information Officer, who will reduce it to writing and provide a copy to the requester.
10. Fees
Two types of fee may be payable under PAIA in respect of a request to a private body. A request fee is payable before the request is processed. An access fee is payable where the request is granted and covers the cost of searching for, preparing and reproducing the record.
| Item | Fee |
|---|---|
| Request fee, payable by every requester | R140,00 |
| Photocopy or printed copy of an A4 page or part thereof | R2,00 |
| Search for and preparation of the record, for each hour or part thereof reasonably required, excluding the first hour | R145,00 per hour, to a maximum of R435,00 |
| Deposit where search and preparation is expected to take more than six hours | Not more than one third of the access fee that would be payable if granted |
| Postage, email or other electronic transmission | Actual expense, if any |
| Computer-readable copies, transcriptions and other reproduction | As prescribed in Annexure B to the PAIA Regulations, 2021 |
The Company is not a registered VAT vendor at the date of compilation of this manual, and no value-added tax is added to the fees above.
No fee is payable in respect of the records listed in section 5 of this manual, or in respect of the Information Regulator’s guide referred to in section 4.
Fees are payable by electronic funds transfer to the Company’s bank account. Details will be provided in the notice requiring payment. A record will be made available once payment has been received.
11. Grounds on which access may be refused
Chapter 4 of Part 3 of PAIA, being sections 62 to 70, sets out the grounds on which the head of a private body must or may refuse a request for access. Where a ground of refusal applies to only part of a record, that part is severed and access is given to the remainder, in accordance with section 28 read with section 57 of PAIA.
The grounds most likely to be relevant to records held by the Company are:
| Section | Ground of refusal |
|---|---|
| 63 | Mandatory protection of the privacy of a third party who is a natural person, where disclosure would involve the unreasonable disclosure of personal information about that person |
| 64 | Mandatory protection of the commercial information of a third party, including trade secrets, financial, commercial, scientific or technical information the disclosure of which would be likely to cause harm |
| 65 | Mandatory protection of information supplied in confidence by a third party, where disclosure would put the Company in breach of a duty of confidence |
| 66 | Mandatory protection of the safety of individuals, and protection of property |
| 67 | Mandatory protection of records privileged from production in legal proceedings |
| 68 | Protection of the commercial information of the Company itself, including trade secrets, and financial, commercial, scientific or technical information the disclosure of which would be likely to cause harm to its commercial or financial interests |
| 69 | Mandatory protection of research information of a third party, and protection of research information of the Company |
Section 68 is particularly relevant to Neevo. Source code, technical architecture, methodologies, tooling and pricing information are commercial information of the Company, the disclosure of which would be likely to cause harm to its commercial and financial interests.
Section 70 of PAIA nonetheless requires disclosure, despite any of the grounds above, where disclosure would reveal a substantial contravention of or failure to comply with the law, or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm contemplated.
A request may also be refused where it does not meet the requirements of PAIA, including where the requester has not shown that the record is required for the exercise or protection of a right, or where the record cannot be found or does not exist. In the latter case the Information Officer will notify the requester by way of an affidavit or affirmation, as required by section 55 of PAIA.
12. Remedies available if a request is refused
There is no internal appeal against a decision of the head of a private body.
A requester or third party who is dissatisfied with a decision of the Information Officer, or who has received no response within the prescribed period, may:
- lodge a complaint with the Information Regulator within 180 days of the decision, on the prescribed form; or
- apply to a court with jurisdiction for appropriate relief, in terms of section 78 of PAIA.
A complaint to the Information Regulator is lodged through the Regulator’s eServices portal, for which the complainant must first register a user profile. The Regulator’s contact details are:
| Information Regulator (South Africa) | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| Telephone | 010 023 5200 |
| Toll free | 0800 017 160 |
| General enquiries | enquiries@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Website | https://inforegulator.org.za |
A data subject who is dissatisfied with the way the Company has processed personal information is asked to raise the matter with the Information Officer first. That does not limit the right to complain to the Information Regulator at any time.
13. Availability of this manual
A copy of this manual is available:
- On the Company’s website at https://neevo.co.za, free of charge.
- At the Company’s premises, for inspection during normal business hours, by prior arrangement, free of charge.
- To any person on request to the Information Officer, on payment of the prescribed fee for reproduction, if any.
- To the Information Regulator on request, free of charge.
14. Updating of this manual
The Information Officer will review this manual at least annually, and will update it whenever there is a material change to the Company’s structure, its operations, the records it holds or the way it processes personal information.
The Company will submit its annual report on requests for access to records to the Information Regulator within the period determined by the Regulator, in accordance with section 83(4) of PAIA.
The version number and dates at the top of this manual reflect the current version.
Issued by Jacques Botha
Director and Information Officer, Neevo (Pty) Ltd
Date: 14 August 2026