PAIA Section 51 Manual
Last updated: June 23, 2026
Epic Saaz (Pvt) Ltd
PAIA Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended).
Date of compilation: 16 June 2026
Date of last revision: 16 June 2026
1. List of acronyms and abbreviations
“CEO” | Chief Executive Officer |
“CIPC” | Companies and Intellectual Property Commission |
“DIO” | Deputy Information Officer |
“GDPR” | General Data Protection Regulation (EU 2016/679) |
“IO” | Information Officer |
“Minister” | Minister of Justice and Correctional Services |
“OAuth” | Open Authorization (industry-standard authorisation protocol) |
“PAIA” | Promotion of Access to Information Act 2 of 2000 (as amended) |
“POPIA” | Protection of Personal Information Act 4 of 2013 |
“Regulator” | Information Regulator (South Africa) |
“Republic” | Republic of South Africa |
“TLS” | Transport Layer Security (cryptographic protocol) |
2. Purpose of this PAIA manual
This PAIA manual is useful for members of the public to:
check the categories of records held by Epic Saaz (Pvt) Ltd which are available without a formal PAIA request;
understand how to make a request for access to a record of Epic Saaz, by reference to the subjects on which Epic Saaz holds records and the categories of records held on each subject;
know the description of the records of Epic Saaz which are available in accordance with other South African legislation;
access the contact details of the Information Officer who will assist the public with the records they intend to access;
know the description of the Regulator’s guide on how to use PAIA and how to obtain access to it;
know that Epic Saaz processes personal information, the purpose of that processing, and the description of the categories of data subjects and the categories of information relating to them;
know the recipients or categories of recipients to whom personal information may be supplied;
know that Epic Saaz transfers and processes personal information outside the Republic, and the country or recipients to whom that information is supplied; and
know whether Epic Saaz has appropriate security measures to ensure the confidentiality, integrity and availability of personal information that is processed.
3. Key contact details for access to information of Epic Saaz (Pvt) Ltd
3.1 Information Officer (designated under POPIA section 56 read with PAIA section 17)
Name: | George Senzere |
Title: | Founder and Chief Architect |
Tel: | +27 63 592 4758 |
Email: | |
Fax: | Not applicable |
3.2 Deputy Information Officer
No Deputy Information Officer is currently designated. The Information Officer named in 3.1 acts as the single point of contact for all PAIA requests. A Deputy Information Officer will be designated under PAIA section 17(1) and POPIA section 56 once the organisation grows to a size where it is reasonably necessary.
3.3 Access to information general contacts
Email: | privacy@epicsaaz.ai (subject line: “PAIA Request”) |
3.4 Head office
Registered name: | Epic Saaz (Pvt) Ltd |
CIPC reg. no: | K2026251004 |
Postal address: | 24 Kengies Gate, Frederick Road, Broadacre, Fourways, Johannesburg 2191, South Africa |
Physical address: | Same as postal address |
Telephone: | +27 63 592 4758 |
Email: | |
Website: |
4. Guide on how to use PAIA and how to obtain access to the guide
4.1 The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“the Guide”), in an easily comprehensible form, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
4.2 The Guide is available in each of the official languages of the Republic and in braille.
4.3 The Guide contains the description of:
the objects of PAIA and POPIA;
the postal and street address, phone and electronic-mail address of the Information Officer of every public body and every Deputy Information Officer of every public and private body designated under PAIA section 17(1) and POPIA section 56;
the manner and form of a request for access to a record of a public body (section 11) and a private body (section 50);
the assistance available from the Information Officer of a public body in terms of PAIA and POPIA;
the assistance available from the Regulator in terms of PAIA and POPIA;
all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court;
the provisions of PAIA sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;
the provisions of PAIA sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively;
the notices issued in terms of PAIA sections 22 and 54 regarding fees to be paid in relation to requests for access; and
the regulations made in terms of PAIA section 92.
4.4 Members of the public can inspect or make copies of the Guide from the offices of public bodies, private bodies including Epic Saaz (Pvt) Ltd, and the office of the Regulator, during normal working hours.
4.5 The Guide can also be obtained:
upon request to the Information Officer named in section 3.1 above;
from the Regulator’s website at inforegulator.org.za; and
direct link: https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Guide-English_20210905.pdf.
4.6 A copy of the Guide is available, on request, in English and any other of the official languages of the Republic for which a translation has been published by the Regulator.
5. Categories of records of Epic Saaz (Pvt) Ltd which are available without a person having to request access
The following records are published voluntarily on Epic Saaz’s website and are available without a formal PAIA request:
Category of records | Types of record | On website | On request |
|---|---|---|---|
Corporate | PAIA manual (this document), Privacy Policy, Terms of Service, About page | Yes | Yes |
Product | Marketing pages describing the Epic Saaz platform, Blueprint catalogue, pricing | Yes | Yes |
Editorial | Blog posts, case studies, resources, FAQs | Yes | Yes |
Legal & compliance | OAuth scope disclosures, Limited Use disclosure for Google Workspace APIs, data-deletion procedure | Yes | Yes |
All records above are accessible at https://www.epicsaaz.ai. To request a copy on request, email the Information Officer (section 3.1).
6. Description of the records of Epic Saaz (Pvt) Ltd which are available in accordance with any other legislation
Epic Saaz creates and holds records in accordance with the following South African legislation. These records are subject to the relevant statutory access regime and are released only where required by law or in response to a lawful subpoena, court order, or regulatory request.
Category of records | Applicable legislation |
|---|---|
Memorandum of Incorporation, share register, director/officer records | Companies Act 71 of 2008 |
Annual financial statements, accounting records, tax returns | Companies Act 71 of 2008; Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011 |
VAT records (if registered) | Value-Added Tax Act 89 of 1991 |
Employment contracts, payroll, leave records (if any) | Labour Relations Act 66 of 1995; Basic Conditions of Employment Act 75 of 1997; Employment Equity Act 55 of 1998 |
UIF / SDL / PAYE records (if applicable) | Unemployment Insurance Act 63 of 2001; Skills Development Levies Act 9 of 1999 |
Personal information held in respect of customers, employees, and suppliers | Protection of Personal Information Act 4 of 2013 (POPIA) |
Records of consumer transactions (electronic agreements, terms of service) | Consumer Protection Act 68 of 2008; Electronic Communications and Transactions Act 25 of 2002 |
This PAIA manual and PAIA-request log | Promotion of Access to Information Act 2 of 2000 |
7. Description of the subjects on which Epic Saaz (Pvt) Ltd holds records and categories of records held on each subject
Subject | Categories of records |
|---|---|
Corporate governance | Memorandum of Incorporation; share register; minutes and resolutions; director and officer records. |
Strategic & operational | Business plans; product roadmaps; engineering design documents; incident-response records; vendor and sub-processor agreements. |
Customer / account | User account profiles (email, name, workspace name); tenant configurations; automation workflows authored by customers; usage and execution logs; support correspondence. |
Connected-account credentials | Encrypted OAuth access and refresh tokens for third-party providers (Google, Meta, TikTok, LinkedIn, X, HubSpot, Slack, etc.); credential metadata (account IDs, display names) returned at the OAuth handshake. |
File storage | Per-tenant files uploaded by customers for use in their automations; generated media outputs (where the customer’s workflow produces them). |
Billing & payments | Subscription records; invoice and receipt records (processed via Stripe); payment-method tokens (held by Stripe, not by Epic Saaz); refund records. |
Audit & security | Immutable audit logs of administrative actions; security-incident records; access logs to production systems; backup records. |
Marketing & sales | Newsletter subscribers; lead-magnet downloads; quote requests; sales-call transcripts (with consent); CRM records. |
Human resources | Employment contracts; payroll; leave and performance records (if any). |
Finance & tax | Annual financial statements; ledgers; tax returns; VAT records (where registered); bank statements. |
8. Processing of personal information
8.1 Purpose of processing personal information
Epic Saaz processes personal information for the following purposes:
to provide the Epic Saaz automation platform and the application to subscribed customers;
to authenticate users and manage tenant workspaces;
to send transactional emails (account verification, password reset, billing receipts, approval-flow notifications);
to process subscription payments and reconcile invoices via Stripe;
to enable customer-authorised automations that integrate with third-party platforms (Google Workspace, Meta, TikTok, LinkedIn, etc.) using OAuth tokens the user has explicitly granted;
to provide customer support upon user request;
to comply with statutory record-keeping, tax, and corporate-governance obligations;
to detect, investigate, and prevent fraud, abuse, and security incidents;
(only with the data subject’s express consent) to send marketing communications about Epic Saaz products and services.
Epic Saaz does not use personal information for advertising, profiling, audience-building, or sale to third parties, and does not train artificial-intelligence or machine-learning models on personal information received through third-party OAuth integrations. For the full Limited Use disclosure for Google Workspace API data, see Privacy Policy section 3.4.
8.2 Description of the categories of data subjects and of the information relating thereto
Category of data subjects | Personal information that may be processed |
|---|---|
Customers (account holders & tenant members) | Email address; display name; profile picture (if supplied); organisation/workspace name; role within the workspace; locale and time-zone; IP address and browser user-agent of authenticated sessions; OAuth tokens and account identifiers for connected third-party platforms (held encrypted at rest); audit records of administrative actions taken in the workspace. |
End users of customer automations | Where a customer’s automation processes data about a third party (for example, contact details a customer’s automation sends a message to), that data is held in transit only and is not used by Epic Saaz beyond the execution of the customer’s configured workflow. |
Marketing-leads / prospects | Email address; first name (if supplied); company (if supplied); marketing-consent preference; UTM parameters of the page that captured the lead. |
Suppliers and sub-processors | Trading name; registration number; VAT number; address; banking details for outbound payments; trade references. |
Employees (if any) | Statutory personnel records: name; ID number; address; banking details for payroll; qualifications; gender; race (for employment-equity reporting); employment contract; performance and leave records. |
8.3 The recipients or categories of recipients to whom the personal information may be supplied
Category of personal information | Recipients or categories of recipients |
|---|---|
User account data + encrypted OAuth tokens | Supabase Inc. (managed Postgres + authentication, sub-processor); AWS (underlying compute and storage, sub-processor). |
Email address + transactional message body | Resend Inc. (transactional email delivery sub-processor). |
Billing email + subscription metadata + payment method details | Stripe Inc. (payment processing sub-processor). |
Prompt / content payloads of AI-generation steps within customer automations | Anthropic; OpenAI; Groq; Fal.ai; Tavily - each as a platform-managed sub-processor governed by the customer’s workflow. Additional providers (Google Gemini, Mistral, Cohere, Perplexity, xAI) available only via Bring Your Own Key (BYOK) with the customer’s own paid-tier contract. |
OAuth tokens for third-party platforms | The connected third-party platform itself (Google, Meta, TikTok, LinkedIn, X, HubSpot, Slack, etc.), only when the customer’s automation needs to call the third-party API. |
SARS-mandated tax records | South African Revenue Service (statutory). |
Employment-equity and statutory employment records | Department of Employment and Labour; Department of Higher Education and Training (statutory). |
Records requested under a lawful court order or regulatory request | The relevant South African court, regulator, or law-enforcement authority. |
All sub-processors are bound by a Data Processing Agreement (DPA) and contractually prohibited from using personal information for any purpose other than to provide the contracted service to Epic Saaz. Sub-processors do not receive third-party OAuth tokens granted by customers (Google Workspace tokens, Meta tokens, etc.) - those tokens are used exclusively by Epic Saaz infrastructure to execute the automations customers configure.
8.4 Planned trans-border flows of personal information
Epic Saaz transfers and processes personal information outside the Republic of South Africa as follows:
Destination | Purpose | Lawful basis under POPIA s.72 |
|---|---|---|
AWS eu-central-1, Frankfurt, Germany (European Union) | Primary hosting of the platform database, encrypted OAuth-token vault, file storage, and application servers. | s.72(1)(a) - Germany is an EU Member State subject to the General Data Protection Regulation, providing adequate protection substantially similar to POPIA; AWS Europe executes EU Standard Contractual Clauses with Epic Saaz. |
Stripe (United States; EU sub-processor where available) | Payment processing. | s.72(1)(c) - necessary for the performance of the service contract with the data subject. |
Resend (United States) | Transactional email delivery. | s.72(1)(c) - necessary for the performance of the service contract with the data subject. |
Third-party LLM providers (United States; United Kingdom; Canada) | AI text/image generation as triggered by the customer’s automation. | s.72(1)(b) - the data subject (customer) consents to the transfer when activating an automation that includes an AI generation step. |
Connected third-party API endpoints (various jurisdictions) | Calling the third-party API on the customer’s behalf with the OAuth token the customer granted. | s.72(1)(b) - the data subject consents by connecting the credential. |
For more detail see Privacy Policy section 10.
8.5 General description of information security measures
Epic Saaz implements the following technical and organisational security measures to ensure the confidentiality, integrity and availability of personal information under its care:
Encryption at rest - OAuth access and refresh tokens, user API keys, and other sensitive secrets are encrypted at rest using AES-256-GCM with a per-value 12-byte initialisation vector generated via cryptographically secure randomness. The encryption key is held in environment configuration with strict file-system access controls and is never written to the database.
Encryption in transit - TLS 1.2 or higher on all production endpoints; HSTS (HTTP Strict Transport Security) is enforced; unencrypted HTTP connections are refused.
Tenant isolation - database-level Row-Level Security (RLS) policies enforce that data belonging to one customer tenant is never accessible to another tenant, even at the row level via direct SQL queries.
Access control - access to production systems is restricted to a small named group of engineering and operational personnel; least-privilege principles apply; multi-factor authentication is required; an immutable audit trail logs every access.
Credential lifecycle - OAuth tokens are refreshed only while an automation that uses them is active. On disconnect or account deletion, encrypted tokens are irreversibly destroyed within minutes and cannot be recovered.
Backup and recovery - encrypted off-site backups are taken on a documented schedule and are tested for recoverability.
Vulnerability management - dependency vulnerability scanning runs on each build; security advisories from upstream maintainers are monitored.
Incident response — security incidents are investigated within 24 hours of detection; affected data subjects and the Regulator are notified in accordance with POPIA section 22 (see Privacy Policy section 6.5).
Anti-virus / anti-malware - endpoint protection and content scanning on uploaded files.
Sub-processor due diligence - all sub-processors are bound by a Data Processing Agreement requiring equivalent security commitments.
9. Availability of this manual
A copy of this PAIA manual is available:
on Epic Saaz’s website at https://www.epicsaaz.ai/legal/paia-manual;
at the head office of Epic Saaz (Pvt) Ltd at the address listed in section 3.4 above, for public inspection during normal business hours;
to any person upon request to the Information Officer (section 3.1), subject to payment of a reasonable prescribed fee per A4-size photocopy as contemplated in annexure B of the PAIA Regulations; and
to the Information Regulator upon request.
How to request access to a record: a request for access to a record of Epic Saaz must be made on Form C (Form 2 of the PAIA Regulations), addressed to the Information Officer named in section 3.1 above, by email to privacy@epicsaaz.ai with the subject line “PAIA Request”. The Information Officer will respond within 30 calendar days of receipt as required by PAIA section 56. The prescribed request fee and access fee (if any) apply per annexure B of the PAIA Regulations.
Remedies: a requester who is dissatisfied with a decision of the Information Officer may lodge a complaint with the Information Regulator at inforegulator.org.za or apply to the appropriate court for relief.
10. Updating of this manual
The Information Officer of Epic Saaz (Pvt) Ltd will update this manual on a regular basis to reflect changes in the categories of records held by Epic Saaz, changes in legislation, and any change in the Information Officer or registered address. The date of the most recent revision appears at the top of this manual.
Issued by
George Senzere
Founder and Chief Architect, Epic Saaz (Pvt) Ltd
Information Officer (POPIA s.55)
This manual was last updated on the date shown at the top. Material changes will be communicated via the “Date of last revision” field above and (for material changes) via email to active account contacts.