Access to information
PAIA manual
Prepared under section 51 of the Promotion of Access to Information Act 2 of 2000, as amended. This manual explains what records Kouga Digital holds and how to request access to them.
Private body and Information Officer
Private body: Michael Herbst, a sole proprietor trading as Kouga Digital.
Registration number: not applicable to the sole proprietorship.
Head and Information Officer: Michael Herbst. No Deputy Information Officer has been designated.
Kouga DigitalPhysical and postal address: 63 Da Gama Road, Jeffreys Bay, Eastern Cape, 6330, South Africa
Phone: 064 676 5276
Email and PAIA requests: hello@kougadigital.co.za
Website: kougadigital.co.za
Fax: not applicable
PAIA Guide and request procedure
The Information Regulator's section 10 Guide on how to use PAIA explains the Act, requests, fees and remedies. The Regulator provides the Guide in South Africa's official languages and in accessible formats through its PAIA resource page. Electronic copies in English and Afrikaans are kept for public inspection at the business address during normal business hours.
- Complete the prescribed Form 2: Request for Access to Record.
- Describe the record, identify the right to be exercised or protected, and explain why the record is required for that right.
- Attach proof of identity and, when acting for someone else, proof of authority.
- Send the signed form to the Information Officer by email, post or delivery using the details above.
Prescribed request, search, reproduction and access fees may apply. Kouga Digital will use the prescribed outcome notice to explain any amount before access is provided. A decision is ordinarily made within 30 days, subject to PAIA's permitted extensions and third-party procedures.
Access is not automatic. A request may or must be refused on a ground in PAIA, including protection of another person's privacy, confidential commercial information, safety, legally privileged material or records connected to litigation already under way.
Records available without a formal request
Kouga Digital does not rely on a separate voluntary notice under section 52(2) of PAIA. The following public records are nevertheless available without a formal PAIA request:
| Category | Records | Access |
|---|---|---|
| Business information | Contact details, service areas, opening hours and public profiles | Website |
| Services and prices | Service descriptions, published prices and promotion terms | Website |
| Policies and manuals | Privacy policy and this PAIA manual | Website and downloadable PDF |
This voluntary list does not make private client, financial or third-party records publicly available.
Subjects and categories of records held
| Subject | Categories of records |
|---|---|
| Enquiries and clients | Contact details, messages, quotations, agreed scope, client communications and service records |
| Jobs and technical support | Job notes, device or account details supplied for the work, remote-access consent, handover notes, warranties and support history |
| Projects and deliverables | Client-supplied documents, CV source material, images, logos, website copy, working files and completed deliverables |
| Finance and tax | Invoices, receipts, payment records, debit-order mandates where applicable, and accounting or tax records |
| Communications | Business email and WhatsApp Business correspondence |
| Website and administration | Website content and configuration, form submissions, security records and business administration records |
| PAIA and POPIA | Manuals, policies, requests, decisions, complaints and records of privacy-related enquiries |
Kouga Digital has no employees and keeps no employee or contractor personnel records. A record appearing in this list is not necessarily disclosable: PAIA's grounds for refusal and other legal duties still apply.
Records maintained under other legislation
Where applicable to this sole-proprietor practice, records are created or retained under the following legislation:
| Legislation | Relevant records |
|---|---|
| Promotion of Access to Information Act 2 of 2000 | PAIA manual, requests and decisions |
| Protection of Personal Information Act 4 of 2013 | Privacy, data-subject request and information-security records |
| Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011 | Invoices, receipts, payment, accounting and tax records |
| Consumer Protection Act 68 of 2008 | Quotes, service terms, invoices and client communications |
| Electronic Communications and Transactions Act 25 of 2002 | Electronic transactions, communications and website information |
Listing legislation does not make every record automatically available and does not imply that every provision applies to every transaction.
Processing of personal information
Purposes
Personal information is used to deliver and secure the website; respond to enquiries; prepare quotations; agree, create, perform, document, invoice and support work; arrange authorised providers and payments; maintain accounting and tax records; handle PAIA or privacy requests; and meet legal obligations.
Data subjects and information
| Data subjects | Information that may be processed |
|---|---|
| Site visitors | IP address, browser or device information, requested page and timestamp processed by Netlify for delivery, security and troubleshooting |
| Enquirers and prospective clients | Name, contact details, enquiry content, selected service and form technical details |
| Clients and their authorised contacts | Contact, quotation, agreement, billing or debit-order information where applicable, payment references, client-supplied project content, working files, deliverables, and job, device, account, support and consent information; personal information incidentally encountered during authorised support |
| PAIA or privacy requesters | Identity, contact details, authority to act, requested record, relevant right and request correspondence |
Recipients
Information is handled by Michael Herbst and may be supplied only as needed to Netlify for website delivery, security and forms; Google Workspace and Google Drive for business email and backups; WhatsApp/Meta for WhatsApp Business messages; banks or debit-order operators for payments; domain registrars, hosting or email providers, hardware suppliers and another service provider authorised for a client's work; and professional advisers, the Information Regulator, SARS, law-enforcement bodies or courts where authorised or required by law.
Cross-border processing and security
Cross-border processing
Visitor, client, enquiry and communications data may be processed outside South Africa by Netlify, Google and WhatsApp/Meta, and by an authorised provider needed for a job. No Google data region is currently selected. Europe is the preferred option only if a supported Workspace edition and service are confirmed; that setting may not cover a WhatsApp chat backup stored in Google Drive, whose location must be confirmed separately. Other operational, backup or service data may still be processed in countries where those providers or their subprocessors operate. Primary working copies of quotes, invoices and job records are stored locally on protected computers or removable backup drives in South Africa; copies sent by email or included in a cloud backup may also be processed by the providers above.
Kouga Digital uses established providers and their contractual and technical safeguards, limits transferred information to what is needed for the service, and remains responsible for handling personal information in accordance with POPIA.
General security safeguards
- BitLocker or equivalent device encryption and protected local or removable storage.
- Unique passwords managed with Bitwarden and two-factor authentication using Bitwarden or Aegis.
- A separate managed Chrome Enterprise work profile with advanced security controls.
- Antivirus and anti-malware protection, security updates and backups.
- Separate work email, work number and WhatsApp Business account, with access limited to the proprietor.
- Client-device, account and third-party information is accessed only as necessary and authorised, and is not copied or retained unless needed and agreed.
- HTTPS, restricted website permissions, form spam protection and provider security controls.
Availability, remedies and updates
This manual is available free of charge on this page, as a downloadable PDF, and for public inspection during normal business hours at 63 Da Gama Road (please arrange a time). A printed copy may attract prescribed reproduction or postage fees. It will be supplied to the Information Regulator on request.
A private-body request has no internal appeal. If a request is refused or not answered within the applicable period, the requester may lodge a complaint using the Regulator's prescribed Form 5 or apply to a competent court, subject to PAIA's requirements and time limits. Current forms and guidance are available from the Information Regulator's PAIA page.
Michael Herbst will review and update this manual regularly and when material business, legal or processing arrangements change.
Issued by: Michael Herbst, Owner and Information Officer
Date of compilation: 10 August 2026
Latest revision: 10 August 2026