PAIA MANUAL
PREPARED IN ACCORDANCE WITH SECTION 51 OF THE PROMOTION OF ACCESS TO INFORMATION ACT NO. 2 OF 2000 ("PAIA") AS AMENDED BY THE PROTECTION OF PERSONAL INFORMATION ACT NO. 4 OF 2013 ("POPIA")
1. Introduction & Company Overview
GovernX (Pty) Ltd ("GovernX", "the Company", "we", "us") is a private cybersecurity and enterprise data governance company registered under the Companies Act 71 of 2008 of South Africa, headquartered in Cape Town. GovernX designs, develops, and licenses Custos DSPM, an on-premises, air-gapped Data Security Posture Management and AI Governance platform.
This Manual has been compiled in accordance with Section 51 of PAIA to provide details on the records held by GovernX and the procedure to request access to such records.
2. Contact Details & Designated Information Officer
The designated Information Officer of GovernX (Pty) Ltd responsible for handling PAIA requests and POPIA data subject inquiries is:
- Head of Private Body / Information Officer: Managing Director, GovernX (Pty) Ltd
- Registered Office: Cape Town, Western Cape, Republic of South Africa
- Official Statutory Inquiry Channel: GovernX Statutory Inquiries Portal →
- Website: https://governx.co.za
3. The South African Human Rights Commission / Information Regulator Guide
The Information Regulator has, in terms of Section 10 of PAIA, published a Guide on how to use PAIA. Any person wishing to inspect or obtain a copy of this Guide may contact the Information Regulator at:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: [email protected] / [email protected]
Website: https://inforegulator.org.za
4. Records Automatically Available Without Formal PAIA Request (Section 51(1)(c))
The following records are publicly available without submitting a formal PAIA request:
- Public website content and technical documentation published at governx.co.za
- Custos DSPM product overviews, architectural specifications, and partner program guidelines
- This PAIA Manual and the GovernX Privacy Policy
5. Records Held by GovernX (Pty) Ltd (Section 51(1)(e))
GovernX maintains records in the following categories (access subject to lawful grounds for refusal):
- Corporate & Incorporation Records: Memorandum of Incorporation (MOI), share registers, board resolutions, and statutory filings with CIPC.
- Financial & Taxation Records: Annual financial statements, VAT records, tax returns, and auditing workpapers.
- Intellectual Property: Source code repositories, cryptographic licensing keys, architecture specifications, trademarks, and proprietary algorithms regarding Custos DSPM.
- Partner & Commercial Contracts: Master Reseller Agreements, Non-Disclosure Agreements (NDAs), customer enterprise software licenses, and evaluation agreements.
- Human Resources: Employment contracts, payroll records, and internal policies.
6. Procedure for Requesting Access to Records (Section 53)
To request access to records held by GovernX (Pty) Ltd, the requester must:
- Complete the prescribed Form 2 (Request for Access to Record of Private Body) available from the Information Regulator.
- Submit the completed form along with certified proof of identification via the official GovernX Contact & Inquiries Portal or by physical delivery to our Cape Town registered office.
- Provide sufficient detail on the form to enable the Information Officer to identify the record requested and the right being protected or exercised.
- Pay the prescribed non-refundable request fee (if applicable) under PAIA regulations.
7. Processing of Personal Information in Terms of POPIA (Section 51(1)(c)–(e))
- Purpose of Processing: Commercial partner onboarding, technical customer support, enterprise license verification, and statutory compliance.
- Customer Data Independence: Custos DSPM is an in-place, on-premises engine. GovernX does not host, receive, or replicate customer production database records. Customer operational data remains entirely within the customer's sovereign boundary.
- Security Safeguards: Cryptographic Ed25519 digital signatures, AES-256-GCM encryption for stored partner metadata, and strict role-based access control.