PAIA Manual
Manual in terms of section 51 of the Promotion of Access to Information Act, 2000 (PAIA), read with the Protection of Personal Information Act, 2013 (POPIA)
Last Updated: 11 August 2026
1. Introduction
This manual is published for MRM Tech (Pty) Ltd (Registration No. 2016/289127/07), trading as Resonancy ("we", "us"), a private body as defined in PAIA. It explains how to request access to records we hold and describes how we process personal information. It is available on this website, at our offices, and from the Information Regulator on request.
2. Contact details
Information Officer: Gerrie van Wyk
Email: privacy@resonancy.io
Address: 15 Northcliff Office Park, 203 Beyers Naudé Drive, Northcliff, Johannesburg, Gauteng, South Africa
Website: https://resonancy.io
3. The Regulator's Guide (section 10 of PAIA)
The Information Regulator has published a Guide on how to use PAIA, in all official languages, containing the information a person needs to exercise their rights under PAIA and POPIA. The Guide is available from the Information Regulator: website https://inforegulator.org.za, email enquiries@inforegulator.org.za, telephone 010 023 5200, or at Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg.
4. Records that are automatically available
- Content published on this website, including marketing material, articles and case studies
- Our Privacy Policy and this PAIA Manual
5. Records available on request under PAIA
Subject to the grounds of refusal in PAIA, we hold records in these categories:
- Statutory and corporate records (incorporation documents, share register, minutes)
- Financial and tax records (annual financial statements, SARS records)
- Human resources records (employment contracts, policies, payroll)
- Operational and client records (agreements, work orders, correspondence)
- Information technology records (system documentation, licences)
- Personal information records (as described in section 8 below)
Records may also be held in terms of other legislation, including the Companies Act 71 of 2008, the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991, the Basic Conditions of Employment Act 75 of 1997, the Labour Relations Act 66 of 1995, the Unemployment Insurance Act 63 of 2001, and the Compensation for Occupational Injuries and Diseases Act 130 of 1993.
6. How to request access to a record
- Complete the prescribed request form (Form 2 of the PAIA Regulations, 2021), available from the Information Regulator's website, and send it to the Information Officer at the contact details above.
- Provide sufficient particulars to identify the record and the right you seek to exercise or protect, and proof of identity.
- The prescribed request fee and access fees (PAIA Regulations fee schedule) apply, unless you are requesting your own personal information.
- We will respond within 30 days as required by PAIA.
- If your request is refused and you are not satisfied, you may lodge a complaint with the Information Regulator or apply to court.
7. Requests about your personal information (POPIA)
You may request confirmation of whether we hold personal information about you, request access to it, and request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (sections 23–24 of POPIA). Correction or deletion requests may be made on Form 2 of the POPIA Regulations or a substantially similar form, sent to the Information Officer. We verify the identity of requesters before acting on a request.
8. Processing of personal information (POPIA description)
- Purposes: providing software development and managed application services to business clients; operating client CRM and customer-experience systems as an operator on our clients' behalf; responding to enquiries; employment administration.
- Categories of data subjects and personal information: client business contacts (names, business contact details, job titles); users of client systems we operate; website visitors who submit forms (name, email, company); employees and job applicants (HR records).
- Recipients: service providers who process on our behalf under data processing terms, including Vercel, Amazon Web Services, MongoDB Atlas, Google Workspace, SendGrid, Sentry and Intercom; no personal information is sold.
- Cross-border transfers: primary processing occurs in South Africa; encrypted backups are replicated to other regions (including the EU) and some service providers process in the US/EU, in each case subject to section 72 of POPIA.
- Security measures: encryption of data in transit (TLS) and at rest (AES-256), role-based least-privilege access control, multi-factor authentication on administrative systems, audit logging, managed and encrypted company devices, and a documented security incident response plan.
9. Availability and updating of this manual
This manual is available on this website and at our offices, and will be updated whenever material changes occur and reviewed at least annually.