Access to information

PAIA manual

Prepared under section 51 of the Promotion of Access to Information Act 2 of 2000, as amended. This manual explains what records Kouga Digital holds and how to request access to them.

Private body and Information Officer

Private body: Michael Herbst, a sole proprietor trading as Kouga Digital.

Registration number: not applicable to the sole proprietorship.

Head and Information Officer: Michael Herbst. No Deputy Information Officer has been designated.

Kouga Digital
Physical and postal address: 63 Da Gama Road, Jeffreys Bay, Eastern Cape, 6330, South Africa
Phone: 064 676 5276
Email and PAIA requests: hello@kougadigital.co.za
Website: kougadigital.co.za
Fax: not applicable

PAIA Guide and request procedure

The Information Regulator's section 10 Guide on how to use PAIA explains the Act, requests, fees and remedies. The Regulator provides the Guide in South Africa's official languages and in accessible formats through its PAIA resource page. Electronic copies in English and Afrikaans are kept for public inspection at the business address during normal business hours.

  1. Complete the prescribed Form 2: Request for Access to Record.
  2. Describe the record, identify the right to be exercised or protected, and explain why the record is required for that right.
  3. Attach proof of identity and, when acting for someone else, proof of authority.
  4. Send the signed form to the Information Officer by email, post or delivery using the details above.

Prescribed request, search, reproduction and access fees may apply. Kouga Digital will use the prescribed outcome notice to explain any amount before access is provided. A decision is ordinarily made within 30 days, subject to PAIA's permitted extensions and third-party procedures.

Access is not automatic. A request may or must be refused on a ground in PAIA, including protection of another person's privacy, confidential commercial information, safety, legally privileged material or records connected to litigation already under way.

Records available without a formal request

Kouga Digital does not rely on a separate voluntary notice under section 52(2) of PAIA. The following public records are nevertheless available without a formal PAIA request:

CategoryRecordsAccess
Business informationContact details, service areas, opening hours and public profilesWebsite
Services and pricesService descriptions, published prices and promotion termsWebsite
Policies and manualsPrivacy policy and this PAIA manualWebsite and downloadable PDF

This voluntary list does not make private client, financial or third-party records publicly available.

Subjects and categories of records held

SubjectCategories of records
Enquiries and clientsContact details, messages, quotations, agreed scope, client communications and service records
Jobs and technical supportJob notes, device or account details supplied for the work, remote-access consent, handover notes, warranties and support history
Projects and deliverablesClient-supplied documents, CV source material, images, logos, website copy, working files and completed deliverables
Finance and taxInvoices, receipts, payment records, debit-order mandates where applicable, and accounting or tax records
CommunicationsBusiness email and WhatsApp Business correspondence
Website and administrationWebsite content and configuration, form submissions, security records and business administration records
PAIA and POPIAManuals, policies, requests, decisions, complaints and records of privacy-related enquiries

Kouga Digital has no employees and keeps no employee or contractor personnel records. A record appearing in this list is not necessarily disclosable: PAIA's grounds for refusal and other legal duties still apply.

Records maintained under other legislation

Where applicable to this sole-proprietor practice, records are created or retained under the following legislation:

LegislationRelevant records
Promotion of Access to Information Act 2 of 2000PAIA manual, requests and decisions
Protection of Personal Information Act 4 of 2013Privacy, data-subject request and information-security records
Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011Invoices, receipts, payment, accounting and tax records
Consumer Protection Act 68 of 2008Quotes, service terms, invoices and client communications
Electronic Communications and Transactions Act 25 of 2002Electronic transactions, communications and website information

Listing legislation does not make every record automatically available and does not imply that every provision applies to every transaction.

Processing of personal information

Purposes

Personal information is used to deliver and secure the website; respond to enquiries; prepare quotations; agree, create, perform, document, invoice and support work; arrange authorised providers and payments; maintain accounting and tax records; handle PAIA or privacy requests; and meet legal obligations.

Data subjects and information

Data subjectsInformation that may be processed
Site visitorsIP address, browser or device information, requested page and timestamp processed by Netlify for delivery, security and troubleshooting
Enquirers and prospective clientsName, contact details, enquiry content, selected service and form technical details
Clients and their authorised contactsContact, quotation, agreement, billing or debit-order information where applicable, payment references, client-supplied project content, working files, deliverables, and job, device, account, support and consent information; personal information incidentally encountered during authorised support
PAIA or privacy requestersIdentity, contact details, authority to act, requested record, relevant right and request correspondence

Recipients

Information is handled by Michael Herbst and may be supplied only as needed to Netlify for website delivery, security and forms; Google Workspace and Google Drive for business email and backups; WhatsApp/Meta for WhatsApp Business messages; banks or debit-order operators for payments; domain registrars, hosting or email providers, hardware suppliers and another service provider authorised for a client's work; and professional advisers, the Information Regulator, SARS, law-enforcement bodies or courts where authorised or required by law.

Cross-border processing and security

Cross-border processing

Visitor, client, enquiry and communications data may be processed outside South Africa by Netlify, Google and WhatsApp/Meta, and by an authorised provider needed for a job. No Google data region is currently selected. Europe is the preferred option only if a supported Workspace edition and service are confirmed; that setting may not cover a WhatsApp chat backup stored in Google Drive, whose location must be confirmed separately. Other operational, backup or service data may still be processed in countries where those providers or their subprocessors operate. Primary working copies of quotes, invoices and job records are stored locally on protected computers or removable backup drives in South Africa; copies sent by email or included in a cloud backup may also be processed by the providers above.

Kouga Digital uses established providers and their contractual and technical safeguards, limits transferred information to what is needed for the service, and remains responsible for handling personal information in accordance with POPIA.

General security safeguards

  • BitLocker or equivalent device encryption and protected local or removable storage.
  • Unique passwords managed with Bitwarden and two-factor authentication using Bitwarden or Aegis.
  • A separate managed Chrome Enterprise work profile with advanced security controls.
  • Antivirus and anti-malware protection, security updates and backups.
  • Separate work email, work number and WhatsApp Business account, with access limited to the proprietor.
  • Client-device, account and third-party information is accessed only as necessary and authorised, and is not copied or retained unless needed and agreed.
  • HTTPS, restricted website permissions, form spam protection and provider security controls.

Availability, remedies and updates

This manual is available free of charge on this page, as a downloadable PDF, and for public inspection during normal business hours at 63 Da Gama Road (please arrange a time). A printed copy may attract prescribed reproduction or postage fees. It will be supplied to the Information Regulator on request.

A private-body request has no internal appeal. If a request is refused or not answered within the applicable period, the requester may lodge a complaint using the Regulator's prescribed Form 5 or apply to a competent court, subject to PAIA's requirements and time limits. Current forms and guidance are available from the Information Regulator's PAIA page.

Michael Herbst will review and update this manual regularly and when material business, legal or processing arrangements change.

Issued by: Michael Herbst, Owner and Information Officer
Date of compilation: 10 August 2026
Latest revision: 10 August 2026