Promotion of Access to Information Act 2 of 2000, read with the Protection of Personal Information Act 4 of 2013. This manual explains what records DoubleDown AI holds, how to ask for access to them, and what happens after you ask.
The head of the private body for PAIA purposes, and the Information Officer for POPIA purposes, is:
No deputy information officers have been designated.
The Information Regulator has compiled a guide, in terms of section 10 of PAIA, on how to use the Act. It is available in each official language from the Regulator:
Some information is published and needs no request at all:
No notice has been published under section 52(2) of PAIA, and no records are automatically available in terms of section 52(1).
Records are grouped by subject. Listing a category here does not mean access will be granted; it means the category exists. Requests are decided one at a time on the grounds in section 9.
| Subject | Categories of records |
|---|---|
| Company | Founding documents, CIPC filings, share register, board and director records, insurance. |
| Finance and tax | Management accounts, invoices issued and received, bank records, SARS returns (VAT, PAYE, income tax), payment gateway settlement records. |
| Customers | Signup records, signed agreements, contact details, subscription and plan history, invoices, support correspondence, and the content each customer creates inside their own dashboard. |
| Product data held on behalf of customers | Leads, bookings, invoices and quotes, email subscribers and campaigns, chatbot conversations, property listings and generated media. We hold these as an operator for the customer, who is the responsible party. |
| Partners | Partner applications, referral attribution, commission calculations and payout records. (Our partner programme applies to the Website Chatbot product only.) |
| Employees and contractors | Contracts, payroll, statutory deductions, leave and performance records. |
| Suppliers and operators | Contracts and correspondence with our hosting, database, payment, email and AI providers. |
| Technical and security | Server, application and access logs, backups, incident records, change history. |
| Marketing | Website content, campaign material, analytics in aggregate form. |
We will respond within 30 days. That period may be extended by up to a further 30 days where the request is for a large number of records or requires a search through records held elsewhere; if we extend it, we will tell you in writing and give reasons.
If you are asking for your own personal information under POPIA rather than under PAIA, you do not need Form 2 and there is no fee to make the request — use Form 2 of the POPIA Regulations, or simply write to the Information Officer. Section 9 of our Privacy Policy sets out those rights, including correction and deletion.
PAIA prescribes two fees for a request to a private body: a request fee, payable before the request is processed, and an access fee for search, preparation and reproduction, payable before the record is handed over. The amounts are those in the PAIA Regulations as amended from time to time, and we charge no more than the prescribed amount.
Current prescribed amounts are published by the Information Regulator; we will confirm the figure that applies to your request in writing when we acknowledge it.
Providing and supporting our products, taking payment, meeting tax and company-law obligations, securing our systems, and — for the Lead Generation product only — collecting business contact details from public sources on a customer's instruction.
Our operators are named individually in section 5 of the Privacy Policy, together with what each one does. We do not sell personal information.
Some operators process data outside South Africa. Those transfers are made under section 72 of POPIA, on the basis of contractual terms binding the recipient to a level of protection substantially similar to POPIA. Section 5A of the Privacy Policy has the detail.
Encryption in transit and at rest, access control and least privilege, per-account authentication with rate limiting and lockout, separation of customer data, logging, and regular backups. The Security & Compliance page describes these in full.
PAIA obliges us to refuse in some cases and permits it in others. The grounds in Chapter 4 of Part 3 include:
Section 70 still requires disclosure where it is in the public interest — where the record would reveal a substantial contravention of the law or an imminent and serious public safety or environmental risk, and the public interest clearly outweighs the harm.
If we refuse, we will say so in writing, give the reasons and the section relied on, and tell you how to take it further.
There is no internal appeal against a decision of a private body. You may:
Contact details for the Regulator are in section 3.
This manual is available free of charge on this page, and on request from the Information Officer by email or in printed form at our address. It is reviewed at least annually and whenever our products or operators change materially.
Version 1.0 · 21 September 2026