PAIA Manual
This manual is published in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000 ("PAIA"), as read with the Protection of Personal Information Act, 4 of 2013 ("POPIA"). It explains what records DDM Technology (Pty) Ltd holds, and how you may ask for access to them.
1. Particulars of the private body
- Registered name: DDM Technology (Pty) Ltd
- Registration number: 2025/676074/07
- Physical and postal address: 20 Ridderspoor Avenue, Weltevredenpark, Roodepoort, Gauteng, 1709, South Africa
- Telephone: 067 128 8247
- Website: https://ddmflow.com
2. Information Officer
Requests under this manual must be addressed to the Information Officer. Under POPIA the head of a private body is its Information Officer, and this appointment is registered with the Information Regulator.
- Information Officer: Darius Isak Schutte, Managing Director
- Email: darius@ddmtech.co.za
- Telephone: 067 128 8247
- Information Regulator registration number: 2026-066525
- Deputy Information Officers: none currently appointed. POPIA permits a private body to designate deputies "if any", and none is necessary at our present size. This is reassessed as the business grows, and any appointment will be registered with the Regulator and reflected here.
3. The Guide published by the Information Regulator
The Information Regulator has published a guide, in terms of section 10 of PAIA, on how to use the Act. It is written for the public and is more general than this manual. The Regulator publishes it in each of South Africa's official languages, and in braille, free of charge, at https://inforegulator.org.za/paia-guidelines. Copies are also kept at our premises for inspection during business hours, and the Information Officer will supply one on request. The Regulator can be reached at:
- The Information Regulator (South Africa), Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
- P.O. Box 31533, Braamfontein, 2017
- General enquiries: the Regulator's iSupport helpdesk, at https://eservices.inforegulator.org.za
4. Records available without a formal request
No notice has been published in terms of section 52(2) of PAIA listing categories of records that are automatically available. The following are nonetheless available without a PAIA request, and asking for them formally is unnecessary:
- Our Privacy Policy, Terms of Service, Data Processing Agreement, Refund Policy and Security page, all published at https://ddmflow.com
- Product and pricing information published on our website
- A customer's own account data, which can be exported at any time from Settings → Account inside the product
- Invoices, statements and credit notes issued to the person or business they were addressed to
5. Records held in terms of other legislation
Records are also kept in accordance with, among others, the Companies Act 71 of 2008, the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991 (should we become a VAT vendor — we are not registered at present), the Tax Administration Act 28 of 2011, the Electronic Communications and Transactions Act 25 of 2002, POPIA and PAIA. The Basic Conditions of Employment Act 75 of 1997 and the Labour Relations Act 66 of 1995 will apply once we employ staff; we have no employees at the date of this manual.
Being listed here does not by itself make a record available, and a request under PAIA is decided under PAIA. Some of these Acts, however, give their own rights of access — the Companies Act, for example, entitles certain people to inspect certain company records — and PAIA does not displace them. If you are relying on another statute, say which one, and we will deal with the request under that Act rather than turning it away.
6. Records held, by subject and category
An important distinction before the list. DDM Technology operates DDM Flow, an invoicing and bookkeeping service. Most of the personal information on the platform is information about our customers' own clients, entered by those customers. For that information DDM Technology is an operator and the customer is the responsible party.
If you are the client of a business that uses DDM Flow, that business is ordinarily the right place to send your request: it controls the information, decides on access, and holds the relationship with you. That is a routing preference, not a refusal. Being an operator is not a ground of refusal under PAIA, and records in our possession or under our control remain subject to the Act. So if you address a request to us, we will assess it under the applicable law rather than turning it away — we will help you identify the right route, assist the customer in responding, protect other customers' information, and apply the consultation and refusal procedures in sections 7 to 9 where they arise.
The categories of records we hold, whether in our own right or as operator:
- Company records — Memorandum of Incorporation, CIPC filings, share register, director records, board and shareholder resolutions, licences and registrations.
- Financial records — accounting records, the general ledger, invoices, quotes, credit notes, payments, bank statements, asset registers, annual financial statements, tax returns and supporting records.
- Customer and subscriber records — account and contact details, business profile, subscription and plan history, billing and payment records, support correspondence, audit logs of actions taken in the product.
- Data processed on behalf of customers — the invoices, clients, expenses, documents and ledger entries our customers create. Held as operator, as explained above.
- Investor records — investor agreements, contribution and payment records, and related correspondence.
- Supplier and service-provider records — contracts, invoices and correspondence with the providers listed in section 10.
- Employment records — contracts, payroll and statutory employment records. DDM Technology has no employees at the date of this manual; the category is listed because it will apply when it does.
- Marketing and website records — enquiries, mailing list subscriptions, and website analytics.
7. How to request access to a record
- Complete Form 2 of the PAIA Regulations, 2021 ("Request for Access to Record of Private Body", prescribed under regulation 7). It is available free from the Information Regulator at https://inforegulator.org.za/paia-forms.
- Send the completed form to the Information Officer at the address or email in section 2.
- Identify the record clearly enough for us to find it, and give enough detail about yourself for us to reach you.
- State which right you are seeking to exercise or protect, and why the record is required to exercise or protect it. Section 50 of PAIA makes this a substantive requirement for requests to private bodies, not a formality. If your request does not address it, we will ask you to clarify before deciding — we will not simply refuse an incomplete request without giving you the chance to complete it.
- Say what form of access you want (a copy, an inspection, an electronic file) and how you would like to be told the outcome.
- If you are asking on someone else's behalf, attach proof that you are authorised to do so.
- Asking for your own personal information is different. A request for the personal information we hold about you is a POPIA request, made to the Information Officer, and is not subject to the section 50 test above or to a request fee. Customers can also export their own data at any time from Settings → Account.
We will decide within 30 days of receiving the request and notify you in writing. That period may be extended by a further 30 days where the request is for a large number of records or a search through many records is needed, in which case we will tell you why. If access is refused, the notice will give reasons and explain how to challenge the decision.
8. Fees
PAIA provides for two fees: a request fee, payable before the request is processed, and an access feecovering the search for, preparation and reproduction of the record. Where the search and preparation are expected to exceed the prescribed threshold of hours, we may require a deposit before work begins.
The amounts are those prescribed in Annexure B to the PAIA Regulations, 2021 (GN R.757, Government Gazette 45057 of 27 August 2021), as amended or replaced. The current schedule is published by the Information Regulator at https://inforegulator.org.za/paia-forms, and we will notify you in writing of the fee or deposit payable, using the prescribed notification, before any work is done. DDM Technology is not a VAT vendor, so no VAT is added.
Exemptions from the request fee apply in the circumstances prescribed by the Regulations. You may also dispute the fee or deposit we require — by complaining to the Information Regulator or applying to a court, as set out in section 12 below.
Requests for your own personal information are different. Exercising a right under POPIA — access to your own information, correction, deletion or objection — is not an ordinary PAIA request and does not attract a PAIA request fee.
9. Grounds on which access may be refused
PAIA obliges us to refuse access in some circumstances and permits it in others. The grounds in Chapter 4 of Part 3 include:
- the unreasonable disclosure of personal information about a third party;
- commercial information of a third party — trade secrets, financial or commercial information that could harm them, or information supplied in confidence during contract negotiations;
- certain confidential information of a third party, where disclosure would constitute an actionable breach of a duty of confidence owed to them under an agreement — confidentiality alone is not a universal veto, and the statutory test must be met;
- information that could endanger a person's life or physical safety, or prejudice the security of property;
- privileged records that could not be produced in legal proceedings;
- our own commercial information — trade secrets, information whose disclosure would harm our commercial or financial interests, and computer-program source code;
- research information of a third party or of our own, where disclosure would expose the researcher or the subject matter to serious disadvantage.
A ground of refusal rarely swallows a whole record. Where only part of a record may be withheld, we will disclose the rest with the protected parts redacted, and tell you what was removed and why. Where a record contains information about a third party, we will consult that third party before deciding, as PAIA requires, so they can make representations or consent.
Access must nonetheless be granted where section 70 applies — the public-interest override for private bodies. Despite any ground above, a record must be disclosed where it would reveal a substantial contravention of, or failure to comply with, the law, or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm. (Section 46 is the equivalent provision for public bodies and does not apply to us.)
10. Processing of personal information under POPIA
Purpose. We process personal information to provide and support the DDM Flow service, to administer accounts, subscriptions and billing, to communicate with customers, to meet our accounting and tax obligations, to detect and prevent fraud and abuse, and to comply with the law.
Categories of data subjects and their information.
- Customers and their users — name, email address, telephone number, business details, account and subscription records, payment records.
- Our customers' clients — name, contact details, billing address and transaction history, entered by the customer and held by us as operator.
- Suppliers and service providers — contact and contract details.
- Investors — identity, contact and payment details.
- Enquirers and website visitors — contact details submitted to us and technical usage information.
- Employees — none at present; statutory employment records when applicable.
Recipients. Personal information may be shared with the service providers we use to run the platform — cloud hosting and database providers, payment providers, email delivery providers, error and product-analytics providers, our support-chat provider, and artificial-intelligence providers used to power product features — and with our accountants, auditors and legal advisers, and with authorities where the law requires it. The current list of providers is set out in our Privacy Policy and Data Processing Agreement.
Cross-border transfers. Some of these providers process information outside South Africa. Where that happens we rely on the safeguards permitted by section 72 of POPIA, including binding contractual terms offering an adequate level of protection.
Security safeguards. Personal information is protected by measures appropriate to its sensitivity, including encryption in transit and at rest, database-level access controls that separate each customer's data from every other customer's, role-based access within accounts, authentication controls including rejection of passwords known to have been breached, audit logging of actions taken on records, and contractual obligations on our operators. No system is perfectly secure, and we do not claim otherwise.
11. Your rights over your personal information
- Access — to know what we hold about you, and to ask for a copy.
- Correction or deletion — to have inaccurate, irrelevant, excessive, misleading or unlawfully obtained information corrected or deleted, using Form 2 of the POPIA Regulations, 2018. Note that this is a different form from Form 2 of the PAIA Regulations mentioned in section 7 — the numbering collides, the statutes do not.
- Objection — to object to processing on reasonable grounds, using Form 1 of the POPIA Regulations, 2018.
- Direct marketing — to require us to stop, at any time.
- Complaint — to complain to the Information Regulator, or to apply to a court.
Send any of these to the Information Officer at the details in section 2. Customers can also export or delete their own account data directly from Settings → Account in the product.
12. Remedies if we refuse
There is no internal appeal against a decision of a private body under PAIA. If we refuse access, or you are unhappy with how the request was handled, you may:
- Lodge a complaint with the Information Regulator in terms of section 77A of PAIA, using the prescribed Form 5 ("Complaint to the Information Regulator"), available from https://inforegulator.org.za/paia-forms. A complaint must ordinarily be lodged within 180 days; or
- Apply to a court for appropriate relief in terms of section 78 of PAIA.
Complaints may be emailed to PAIAComplaints@inforegulator.org.za, submitted through the eServices portal at https://eservices.inforegulator.org.za, or sent to the addresses in section 3.
13. Availability of this manual
This manual is available free of charge on this website, at our principal place of business during business hours, from the Information Regulator, and by email on request to the Information Officer. It is also lodged with the Information Regulator. It will be updated whenever our particulars, the records we hold, or the law change materially; the effective date at the top of this page shows when it was last revised.