DATASEKA PAIA MANUAL

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended
Read together with the Protection of Personal Information Act 4 of 2013

Publication date: 04 August 2026
Last reviewed: 04 August 2026

1. Introduction

Dataseka (Pty) Limited (Dataseka) is a South African data analytics and visualisation company that provides the Dataseka platform, Seeka artificial-intelligence features, cloud hosting, customer-managed deployment licences, support and related professional services.

This Manual is published under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA) and includes information required by the Protection of Personal Information Act 4 of 2013 (POPIA).

PAIA gives a person a right to request access to a record held by a private body where the record is required for the exercise or protection of a right, subject to PAIA’s procedural requirements and grounds for refusal.

This Manual is intended to help a requester:

  • understand the categories of records held by Dataseka;
  • identify records that are available without a formal PAIA request;
  • understand how to submit a request for access to a record;
  • obtain the contact details of Dataseka’s Information Officer;
  • understand the categories and purposes of Personal Information processed by Dataseka;
  • understand Dataseka’s general approach to recipients, international transfers and security safeguards; and
  • obtain information about the remedies available if a request is refused or not answered.

This Manual does not mean that every listed record exists, that a listed record will be disclosed, or that access will be granted contrary to PAIA, POPIA, confidentiality obligations, legal privilege, intellectual-property rights or the rights of another person.

2. Details of the private body

  • Legal name: Dataseka (Pty) Limited
  • Registration number: 2026/292616/07
  • Trading name: Dataseka
  • Registered or principal physical address: V & A Waterfront, Cape Town, South Africa
  • Postal address: Same as the registered or principal physical address
  • Telephone: +27 72 177 9935
  • General email: hello@dataseka.com
  • Website: https://dataseka.com

3. Information Officer and access contacts

The head of a private body is the Information Officer by virtue of office under PAIA and POPIA, subject to registration with the Information Regulator.

3.1 Information Officer

  • Name: Chantel Boris
  • Title: Compliance Officer
  • Telephone: +27 72 177 9935
  • Email for PAIA and privacy requests: hello@dataseka.com
  • Physical address: V & A Waterfront, Cape Town, South Africa

3.2 Deputy Information Officer

  • Status: None designated

3.3 General access-to-information contact

4. The Information Regulator’s PAIA Guide

The Information Regulator has published a guide explaining how to use PAIA, the rights of requesters, the procedures for requesting records, the applicable forms, the fees that may be charged and the remedies available.

The Guide and prescribed forms are available from the Information Regulator:

A copy of the Guide may also be requested from Dataseka’s Information Officer.

5. Records available without a formal PAIA request

The following records may be accessed without submitting Form 2, subject to website availability, applicable terms and reasonable administrative requirements:

Category Examples Method of access
Corporate and contact information Company name, contact information and public business profile Dataseka website or on request
Product information Product descriptions, supported deployment models, public documentation and feature information Dataseka website
Pricing information Public subscription, licence, AI-task and add-on pricing https://dataseka.com/pricing
Legal notices Terms of Service, Privacy Notice, cookie information and this PAIA Manual Dataseka website
Data-protection information Public Subprocessor List and public privacy information Dataseka website
Security information Public Security or Trust page and responsible-disclosure contact Dataseka website
Marketing material Public articles, videos, case studies, press releases and social-media posts Dataseka website and public channels
Statutory records expressly made public Records that legislation requires Dataseka to make publicly available Website or on request

Records not listed above are not automatically available and may require a formal request.

6. Records available under other legislation

Dataseka may create, hold or retain records under the following South African legislation, to the extent applicable to its operations:

Category of record Applicable legislation
Incorporation documents, securities records, director records, resolutions and statutory registers Companies Act 71 of 2008 and Companies Regulations
Accounting, tax, VAT, payroll and supporting records Companies Act 71 of 2008; Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011; Value-Added Tax Act 89 of 1991
Electronic contracts, communications, website disclosures and transaction records Electronic Communications and Transactions Act 25 of 2002
Consumer-related transaction and complaint records, where applicable Consumer Protection Act 68 of 2008
Personal Information, data-subject request and privacy-compliance records Protection of Personal Information Act 4 of 2013
Access-to-information records, this Manual and PAIA request records Promotion of Access to Information Act 2 of 2000
Employment contracts, leave, remuneration and working-time records, where applicable Basic Conditions of Employment Act 75 of 1997
Employment-relations and disciplinary records, where applicable Labour Relations Act 66 of 1995
Employment-equity records, where applicable Employment Equity Act 55 of 1998
Skills-development and levy records, where applicable Skills Development Act 97 of 1998 and Skills Development Levies Act 9 of 1999
Unemployment-insurance and occupational-injury records, where applicable Unemployment Insurance Act 63 of 2001; Unemployment Insurance Contributions Act 4 of 2002; Compensation for Occupational Injuries and Diseases Act 130 of 1993
Copyright, trade-mark, software-licensing and other intellectual-property records Copyright Act 98 of 1978; Trade Marks Act 194 of 1993; applicable common law
Security-incident, cybercrime and law-enforcement records, where applicable Cybercrimes Act 19 of 2020 and other applicable law

This list is not exhaustive. Legislation may be amended, replaced or become applicable as Dataseka’s operations change.

7. Subjects on which Dataseka holds records

Dataseka may hold the following categories of records. Access remains subject to PAIA and other applicable law.

Subject Categories of records
Corporate governance Incorporation documents, Memorandum of Incorporation, director and shareholder records, resolutions, governance policies, business plans and statutory registers
Finance and tax Budgets, management accounts, invoices, payment records, bank records, tax returns, supporting documents, expense records and financial statements
Customers and commercial agreements Customer details, Orders, subscriptions, Enterprise licences, quotations, statements of work, service-level agreements, data-processing agreements, support arrangements and correspondence
Product and technology Product requirements, roadmaps, source and object code, architecture, configurations, technical documentation, connectors, APIs, deployment artefacts, testing records and release records
Customer Data and service operations Workspace metadata, connection metadata, schemas, queries, refresh logs, dashboard records, support diagnostics, access records and operational records processed for customers
AI Features and AI Tasks AI Inputs and Outputs, task type, task confirmation, model-routing information, safety and validation records, retry and error records, task charges, feedback and corrections, subject to customer agreements and access restrictions
Security and continuity Access-control records, authentication logs, security alerts, vulnerability and patching records, incident-response records, backup records, recovery records, risk assessments and vendor-security reviews
Privacy and information governance Privacy notices, data-processing records, impact assessments, data-subject requests, PAIA requests, consent and objection records, retention records, transfer safeguards, subprocessor assessments and incident notifications
Sales and marketing Enquiries, prospect records, campaign records, marketing preferences, event records, proposals, public content, referral records and customer case-study permissions
Support and Professional Services Support tickets, implementation plans, meeting notes, training materials, migration records, configuration records, test results, acceptance records and project correspondence
Personnel and recruitment Applications, contracts, remuneration, leave, performance, training, disciplinary, benefits and statutory employment records, where applicable
Suppliers and partners Supplier and partner due diligence, contracts, invoices, security assessments, referral arrangements and correspondence
Intellectual property Trade marks, copyrights, licences, inventions, know-how, product designs, domain names, confidential methods and third-party software records
Legal, compliance and disputes Legal advice, privileged communications, claims, complaints, investigations, litigation, regulatory correspondence and compliance records
Communications Business emails, meeting records, support communications, customer-approved chat channels and other business correspondence

Customer Data may contain records belonging to a Dataseka customer. Where Dataseka acts only as an operator or processor, a requester should ordinarily direct a request to the relevant customer as the responsible party or controller. Dataseka will assist the customer as required by the applicable Data Processing Addendum and law.

8. Processing of Personal Information

8.1 Purposes of processing

Dataseka may process Personal Information to:

  • operate, administer, secure and support the Dataseka platform;
  • create and manage accounts, workspaces, permissions and authentication;
  • provide data connections, analytics, visualisations, dashboards and exports;
  • provide Seeka and other AI Features, including orchestration, validation and task billing;
  • deliver Professional Services, support, training, migration and deployment services;
  • manage subscriptions, Enterprise licences, invoices, payments and accounting;
  • communicate service, security, product and contractual information;
  • respond to enquiries and conduct lawful business-to-business marketing;
  • prevent fraud, misuse, security incidents and unauthorised access;
  • evaluate and improve product performance using appropriate Usage Data, feedback and de-identified information;
  • comply with legal, tax, regulatory, audit and law-enforcement obligations; and
  • establish, exercise or defend legal rights.

More detail is provided in Dataseka’s Privacy Notice.

8.2 Categories of data subjects and Personal Information

Data-subject category Personal Information that may be processed
Website visitors and prospects Name, business contact details, employer, role, interests, communications, cookie identifiers, IP address, device and website-usage information
Customers and customer representatives Contact, company, contractual, billing, payment-reference, subscription, licence, support and relationship information
Authorised Users and administrators Identity, business contact, account, authentication, role, permission, workspace, usage, query, dashboard, AI-task, audit and support information
Individuals represented in Customer Data Any Personal Information lawfully supplied or connected by the customer, which may include financial, employment, client, supplier, special or sensitive information
Job applicants and personnel Identity, contact, employment, qualification, remuneration, performance, leave, disciplinary, tax and statutory information, where applicable
Suppliers, contractors and partners Identity, contact, company, tax, banking, due-diligence, contract, performance and invoice information
Professional advisers and public authorities Identity, contact, professional, regulatory, claim, investigation and correspondence information
Event, training and support participants Registration, attendance, communication, support, feedback and recording information where disclosed and lawful

8.3 Recipients or categories of recipients

Personal Information may be supplied, where necessary and lawful, to:

  • Dataseka personnel and authorised contractors subject to confidentiality and access controls;
  • customers and their authorised administrators where the information relates to the customer’s workspace or instructions;
  • cloud-hosting, database, storage, networking and monitoring providers;
  • enterprise AI and model providers used to provide Seeka or other AI Features;
  • authentication, communications, support, email and collaboration providers;
  • payment, accounting, tax and fraud-prevention providers;
  • professional advisers, auditors, insurers and financial institutions;
  • regulators, courts, law-enforcement agencies and other public authorities where required or permitted by law;
  • parties involved in a proposed or completed financing, restructuring, merger, acquisition or sale, subject to appropriate confidentiality and legal safeguards; and
  • other recipients authorised by the data subject or customer.

Dataseka’s current direct subprocessors are published in the Subprocessors section of the Trust page.

8.4 Planned transborder flows

Dataseka is established in South Africa and uses cloud and technology providers that may process Personal Information in South Africa and other countries.

Depending on the selected deployment, cloud region, support route, AI provider and customer configuration, information may be processed in countries where Google Cloud, approved service providers or customer-selected providers operate. Current provider, purpose and location information is maintained in the Subprocessors section of the Trust page.

Dataseka uses contractual, organisational and technical safeguards appropriate to the transfer, which may include:

  • section 72 of POPIA;
  • adequacy decisions or recognised jurisdictions;
  • the European Commission’s Standard Contractual Clauses;
  • the United Kingdom International Data Transfer Addendum or other approved UK mechanism;
  • contractual commitments with operators and subprocessors; and
  • access, encryption, minimisation and transfer-risk controls.

For a Customer-Managed Environment, the customer ordinarily selects and controls the hosting region, infrastructure providers and customer-managed AI account, subject to the customer agreement.

8.5 General description of information-security measures

Dataseka applies security measures appropriate to the nature, context and risk of the processing. Subject to the selected service and deployment model, these measures may include:

  • encryption of information in transit and at rest where supported;
  • identity and access management, role-based permissions and least-privilege access;
  • multifactor authentication for privileged or supported access;
  • logical tenant isolation for shared cloud environments;
  • secrets and credential management;
  • logging, monitoring and security-alerting controls;
  • secure software-development, code-review and change-management practices;
  • vulnerability identification, dependency management, patching and remediation;
  • backups, recovery procedures and continuity planning;
  • incident-response and notification procedures;
  • personnel confidentiality and access restrictions;
  • vendor due diligence and contractual data-protection requirements; and
  • periodic review and testing of safeguards.

Customers remain responsible for their user permissions, credentials, connected data sources, endpoints and lawful use of the Services. Customers operating Customer-Managed Environments are also responsible for the infrastructure, networks, operating systems, backups and security controls assigned to them under the applicable Order and Documentation.

Public security information is available on Dataseka’s Trust page. Detailed or sensitive security materials may be made available under appropriate confidentiality restrictions.

9. How to request access to a record

9.1 Prescribed form

A requester must complete PAIA Form 2 — Request for Access to Record and submit it to Dataseka’s Information Officer using the contact details in section 3.

The requester should provide enough information to identify:

  • the requester and, where applicable, the person on whose behalf the request is made;
  • the specific record or category of records requested;
  • the preferred form and manner of access;
  • the right the requester seeks to exercise or protect;
  • why the requested record is required for that right; and
  • any reasonable accommodation required because of disability or illiteracy.

Proof of identity and, where acting for another person, proof of authority may be required.

9.2 Assistance

Dataseka will provide reasonable assistance required by PAIA to a person who cannot complete the prescribed form because of illiteracy, disability or another legitimate difficulty.

9.3 Fees

Dataseka may charge the request, search, preparation, reproduction, deposit and delivery fees prescribed under PAIA, subject to any applicable exemption.

The current official fee schedule is published by the Information Regulator at https://inforegulator.org.za/wp-content/uploads/2026/03/PAIA-Fees-structure.pdf.

No fee will be charged merely to confirm whether Dataseka holds Personal Information about a requester where POPIA requires that confirmation to be free of charge.

9.4 Decision period

Dataseka will decide a valid request as soon as reasonably possible and ordinarily within 30 days after receipt, subject to any extension permitted by PAIA. Dataseka will notify the requester of the decision, applicable fees and the available remedies.

10. Grounds on which access may be refused

Dataseka may or must refuse access where PAIA permits or requires refusal, including where disclosure would unreasonably affect:

  • another person’s privacy;
  • confidential commercial information or trade secrets of Dataseka or a third party;
  • information supplied in confidence;
  • the safety of a person or security of property or systems;
  • legally privileged information;
  • research information;
  • intellectual-property rights;
  • law-enforcement, regulatory or legal proceedings; or
  • another protected interest recognised by PAIA.

Dataseka may sever protected information and provide access to the remainder where PAIA requires this. The public-interest override in PAIA applies where its statutory requirements are met.

11. Remedies and complaints

A private body does not have an internal appeal procedure under PAIA.

A requester or affected third party may, subject to PAIA’s requirements and time limits:

  • lodge a complaint with the Information Regulator using the prescribed complaint process; or
  • apply to a competent court for appropriate relief.

Information Regulator complaint details:

12. Availability of this Manual

This Manual is available:

  • on Dataseka’s website at dataseka.com/paia-manual;
  • for inspection at Dataseka’s principal office during normal business hours by prior appointment;
  • by email request to Dataseka’s Information Officer;
  • to the Information Regulator upon request; and
  • in another accessible form where reasonably required by law.

A fee for a physical copy may be charged in accordance with the prescribed PAIA fee schedule.

13. Updating this Manual

Dataseka will review this Manual regularly and update it when there is a material change to its records, processing activities, contact details, legislation or regulatory guidance. Dataseka intends to perform a formal review at least annually.

14. Issued by

  • Information Officer: Chantel Boris
  • Title: Compliance Officer
  • Date: 04 August 2026