PAIA
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended).
Date of compilation: 01/10/2021
Date of revision: 01/03/2025
List of acronyms and abbreviations
- “DPO” Deputy Privacy Officer;
- “IO” Information Officer;
- “Minister” Minister of Justice and Correctional Services;
- “PAIA” Promotion of Access to Information Act 2 of 2000 (as amended);
- “POPIA” Protection of Personal Information Act 4 of 2013;
- “Regulator” Information Regulator; and
- “Republic” Republic of South Africa.
Purpose of PAIA manual
This PAIA Manual is useful for the public to—
- check the categories of records held by a body which are available without a person having to submit a formal PAIA request;
- have a sufficient understanding of how to make a request for access to a record of the body, by providing a description of the subjects on which the body holds records and the categories of records held on each subject;
- know the description of the records of the body which are available in accordance with any other legislation;
- access all the relevant contact details of the Information Officer and Deputy Information Officer who will assist the public with the records they intend to access;
- know the description of the guide on how to use PAIA, as updated by the Regulator and how to obtain access to it;
- know if the body will process personal information, the purpose of processing of personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;
- know the recipients or categories of recipients to whom the personal information may be supplied;
- know if the body has planned to transfer or process personal information outside the Republic of South Africa and the recipients or categories of recipients to whom the personal information may be supplied; and
- know whether the body has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
Key contact details for access to information of Legal Interact
Deputy Privacy Officer
- Name: Raphael Segal
- Tel: +27 11 719 2000
- Email: privacy@avantedge.co.za
- Fax number: N/A
We have appointed our information officer to deal with all matters relating to PAIA so we can comply with our PAIA obligations. To request access to a record, please complete Form 2.
Access to information general contacts
Email: privacy@avantedge.co.za
National or head office
| Detail | Information |
|---|---|
| Postal address | Same as physical address |
| Physical address | 70 Melville Road, Illovo Central Building, 6th Floor |
| Telephone | +27 11 719 2000 |
| privacy@avantedge.co.za | |
| Website | www.legalinteract.com |
Guide on how to use PAIA and how to obtain access to the guide
- The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
- The Guide contains a description of the objects of PAIA and POPIA; the contact details of the Information Officer and every Deputy Information Officer of public and private bodies; the manner and form of a request for access to a record of a public or private body; the assistance available from the Information Officer of a public body and from the Regulator; all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including how to lodge an internal appeal, a complaint to the Regulator and an application to court; the provisions requiring public and private bodies to compile a manual and how to obtain access to a manual; the provisions providing for the voluntary disclosure of categories of records; the notices regarding fees to be paid in relation to requests for access; and the regulations made in terms of section 92 of PAIA.
- Members of the public can inspect or make copies of the Guide from the offices of the public and private bodies, including the office of the Regulator, during normal working hours.
- The Guide can also be obtained upon request to the Information Officer, or from the website of the Regulator (https://www.justice.gov.za/inforeg/).
- A copy of the Guide is also available in English for public inspection during normal office hours.
Categories of records available without a person having to request access
| Category of records | Type of record | On website | Upon request |
|---|---|---|---|
| Disclaimer | Disclaimer | Yes | Yes |
| Privacy Policy | Privacy Policy | Yes | Yes |
| Privacy document | Terms and Conditions | Yes | Yes |
| PAIA | PAIA Manual | Yes | Yes |
Records available in accordance with any other legislation
| Category of records | Applicable legislation |
|---|---|
| Memorandum of incorporation | Companies Act 71 of 2008 |
| PAIA Manual | Promotion of Access to Information Act 2 of 2000 |
Subjects on which Legal Interact holds records and the categories of records held
| Subject | Categories of records |
|---|---|
| Customers and their customers | First name, last name, organisation name, email, phone number, username, contact numbers, identity numbers in screenshots, environment information |
| Customers from a commercial perspective – such as through sales or customer servicing activities | Name, surname, email address, organisation details, and any personal details contained in uploaded data, relevant communication and/or documents used by the client |
| Debtors or creditors – such as through managing creditors’ books | Name, surname, organisation details, contact numbers, email address, and other personal information that may be contained in contracts |
| Prospective customers – such as through advertising or direct marketing activities | Name, surname, email address, organisation details, and any personal details contained in uploaded data |
| Employees – such as through monitoring, payroll or training activities | Email, names, phone numbers, financial details, banking details, and other personal information that may be contained in invoices |
| Employment candidates – such as through recruitment, interviewing or background checking activities | Name, surname, email address, organisation details |
| Vendors, contractors or other suppliers – such as through supply chain management | Name, surname, email address, password (encrypted) |
| IT users – such as through IT support, data processing or other IT-related activities | Name, surname, email address, organisation details, and any personal details contained in relevant communication and/or document templates used by the client |
| Directors or shareholders – such as through company administration activities | Names, ID numbers, contact details, qualifications, leave records, expenses, bank details, salary details, deductions (PAYE, UIF, SDL), bonuses, tax numbers, tax submissions, reimbursement details, demographic details, employment status, audit records |
| Clients (individuals and business representatives) | Name, surname, email address, organisation details, and any personal details contained in uploaded data, relevant communication and/or document templates used by the client |
| Suppliers (business representatives) | Name, surname, email address, organisation details, and any personal details contained in uploaded data, relevant communication and/or document templates used by the client |
| Employees, company financial records | Names, ID numbers, contact details, qualifications, leave records, expenses, bank details, salary details, deductions (PAYE, UIF, SDL), bonuses, tax numbers, tax submissions, reimbursement details, demographic details, employment status, audit records |
Processing of personal information
Purpose of processing personal information
- Manage the user functions to process their relevant activities on the system.
- Manage the users and permissions within the systems and integrations.
- Audit user activity for client use, manage and respond to issues and measure throughput of the systems.
- Manage permissions and limit or expand functions for specific users.
- Enable functionality throughout the systems without replicating functionality (master data).
- Follow internal policies, or policies of clients depending on industry or individual clients.
- Allow users to capture unstructured notes or text that is stored and displayed by the system.
- Comply with data protection requirements by automating the removal or anonymisation of personal data once retention periods are met.
- Manage customer contract obligations and the end-to-end management of a legal matter, contract lifecycle or contract review.
- Enable notifications and communications from the system to users.
- Enable contract, document and legal process functionality such as key data points, summarisation, clause extraction and comparison.
- Enable invoice extraction and management.
- Enable authorisation and authentication to already configured user profiles in a client’s environment.
- Manage situations of lost data and restore points for retrieval after any event of data loss.
- Facilitate search features and data processing pipelines (Elastic Search).
- Facilitate payment features via PayPal, MCB (Mauritius Commercial Bank) and Microsoft Marketplace as payment solution providers.
- Billing and revenue collection to ensure timely payments for services provided.
- Payment processing for goods and services received from suppliers.
- Salary payments, employee benefits administration, tax compliance and leave tracking.
- Employee data management, leave tracking, payroll integration and system maintenance.
- Calculation and submission of employee tax (PAYE, UIF, etc.) to SARS.
- BEE certificate maintenance for certain companies in the group.
- Annual financial audits, provisional and income tax submissions, and client-requested reports.
- Direct marketing of goods or services; entering into a contract; providing goods or services; historical, statistical or research purposes; paying employees; law enforcement; credit reporting; and profiling.
Categories of data subjects and the information relating thereto
| Category of data subjects | Personal information that may be processed |
|---|---|
| Customers / clients | Name, address, registration numbers or identity numbers, employment status and bank details |
| Service providers | Names, registration number, VAT numbers, address, trade secrets and bank details |
| Employees | Address, qualifications, gender and race |
Recipients to whom the personal information may be supplied
| Category of personal information | Recipients or categories of recipients |
|---|---|
| Identity number and names, for criminal checks | South African Police Service |
| Qualifications, for qualification verifications | South African Qualifications Authority |
| Credit and payment history, for credit information | Credit bureaus |
Planned transborder flows of personal information
- Adequacy – transfer to Israel.
- Where suppliers are international, transfers occur under standard banking regulations.
- Limited to payment information through standard integrations with payment providers.
- Azure (hosting) – Azure services in the South Africa region; others in their default regions.
General description of information security measures
Measures implemented by the responsible party to ensure the confidentiality, integrity and availability of the information include:
- Role-based access controls and segmented access control, including for Azure DevOps and Azure SQL Server.
- Multi-factor authentication, network authentication, Entra ID authentication and user password management.
- User access management, need-to-know restrictions and access control lists for subcontractors and third parties.
- Annual penetration testing, code vulnerability scanning and a code review system.
- Encryption, encrypted data transfer, TLS, API keys and secure key storage in Key Vault.
- Anonymisation, pseudonymisation, minimisation of personal data in bug tracking and secure disposal.
- Firewalls, intrusion detection tools, breach detection tools, anti-virus protection and email scanning.
- Data backups, audit logs and system activity logging.
- Regular software updates, mobile device management tools and vendor risk management.
- Secure premises, internal policies and plans, and internal awareness and training for staff.
Availability of the manual
- A copy of the manual is available on legalinteract.com;
- at the head office of Legal Interact for public inspection during normal business hours;
- to any person upon request and upon payment of a reasonable prescribed fee; and
- to the Information Regulator upon request.
A fee for a copy of the manual, as contemplated in annexure B of the Regulations, shall be payable per each A4-size photocopy made.
Updating of the manual
The head of Legal Interact will update this manual on a regular basis.
Ready to improve your practice health?
See exactly where your firm is losing time, revenue and opportunities — then book a working session with our team.
