> For the complete documentation index, see [llms.txt](https://docs.spendl.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.spendl.money/spendl-compliance-pack/spendl-paia-manual.md).

# Spendl   PAIA Manual

Version 1.2

## 1. Document Control

| **Version**        | 1.2                                                     |
| ------------------ | ------------------------------------------------------- |
| **Effective Date** | 1 July 2026                                             |
| **Approved By**    | Board of Directors                                      |
| **Owner**          | Chief Compliance Officer                                |
| **Next Review**    | July 2027 or sooner on regulatory or operational change |

## 2. Introduction

Light Fusion (Pty) Ltd t/a Spendl Technologies (SPENDL) is committed to transparency, accountability and Treating Customers Fairly (TCF). This Manual enables requesters to exercise the constitutional right of access to information (section 32 of the Constitution), while protecting privacy, confidentiality, and security as required by PAIA, POPIA, FAIS, the FIC Act and related law.

As a Financial Services Provider (FSP 53757) and an Accountable Institution under the FIC Act (Org ID 74993), SPENDL maintains robust recordkeeping, privacy, and complaints frameworks. This Manual integrates PAIA processes with POPIA and FSCA expectations, and is anchored to the Terms and Conditions V1.2.

## 3. Company Information

| **Registered Name**     | Light Fusion (Pty) Ltd t/a Spendl Technologies |
| ----------------------- | ---------------------------------------------- |
| **Registration Number** | 2023/154151/07                                 |
| **FIC Org ID**          | 74993                                          |
| **FSP Number**          | 53757                                          |
| **Physical Address**    | Central Square, Pinelands, Cape Town           |
| **General Email**       | <contact@spendl.money>                         |
| **Website**             | [www.spendl.money](http://www.spendl.money)    |

## 4. Information Officer and Deputy Information Officer(s)

**Information Officer (IO):** Carl Muller

**Deputy Information Officer(s) (DIO):** Greg van der Spuy

**Chief Compliance Officer (CCO):** Carl Muller

**Designated PAIA/POPIA Email:** <compliance@spendl.money>

The IO is registered with the Information Regulator as required by POPIA. Core responsibilities include:

* Promote lawful processing and access in line with PAIA/POPIA.
* Maintain PAIA/POPIA registers (requests, decisions, refusals, breaches).
* Oversee third-party notifications, decisions, and fee administration.
* Liaise with the Information Regulator and FSCA as needed.
* Ensure alignment with the FIC Act and FAIS (complaints/records).

Escalation path: Case Officer to DIO to IO to Chief Compliance Officer to Board (where risk/materiality warrants). Urgent matters (e.g., potential public-interest disclosures, safety risks, legal privilege) escalate immediately to the IO.

## 5. Guide to PAIA and POPIA

A practical Guide is available from the Information Regulator (JD House, 27 Stiemens Street, Braamfontein) and at [www.inforegulator.org.za](http://www.inforegulator.org.za). It explains how to use PAIA/POPIA, fees, and remedies.

## 6. Proactive Disclosure and Records Automatically Available

SPENDL proactively publishes information to reduce formal PAIA requests. Available without a PAIA request (free to view; reproduction fees may apply):

* Public-facing policies: Privacy Policy, Cookie Policy, FAIS Disclosure Notice, Complaints Management Policy, Conflict of Interest Management Policy, TCF Policy (all referenced in the Terms and Conditions and published on the Website).
* Terms and Conditions (including Schedules A to H).
* Fee Schedule (Schedule F of the Terms and Conditions).
* Corporate information available via CIPC; non-confidential notices.
* Press releases, service announcements, and status pages.

If a record is listed here but temporarily unavailable online, you may email <compliance@spendl.money> for a copy.

## 7. Records Available in Terms of Legislation

SPENDL maintains records under (non-exhaustive): PAIA, POPIA, FAIS Act, FIC Act, Companies Act, Income Tax Act, VAT Act, BCEA, LRA, EEA, UIA, COIDA, OHSA, ECTA, CPA, Financial Sector Regulation Act.

Retention highlights:

* FIC Act: at least 5 years from termination of relationship or last transaction.
* FAIS/General Code: advice, disclosures and complaints records typically 5 years.
* Tax: generally 5 years from last submission (longer in some cases).

## 8. Categories of Records Held by SPENDL

### 8.1 Company Records

MOI, statutory registers (directors, shareholders), resolutions, audit appointments, board and committee minutes/packs, governance charters.

### 8.2 Financial Records

AFS, management accounts, ledgers, AP/AR, tax filings, payroll, reconciliations, bank statements, audit workpapers.

### 8.3 HR / Personnel

Employment contracts, vetting and onboarding, benefit records, performance and disciplinary, leave and training, health and safety, applications/CVs.

### 8.4 Clients / Customers

Onboarding/KYC (FIC Act), agreements (including Terms and Conditions, Commercial Agreements, MSAs), transaction and Card usage data, complaints files, advice/disclosure records (FAIS), sanctions screening results, communication logs, consent/preferences, blockchain wallet addresses.

### 8.5 Operations and Compliance

Policies/standards, internal audit/compliance reports, COI and gift registers, complaints register, risk assessments, incident and breach logs, ROPA, DPIAs, RMCP documentation.

### 8.6 Technology and Security

Architecture docs, system and vendor inventories, access controls, logs (security/app), DR/BCP plans, vulnerability and penetration testing reports, change records, asset registers and licences, Joint Standards compliance documentation.

### 8.7 Third-Party and Supplier

Contracts (including Programme Partner, liquidity partners, banking partners per the Terms and Conditions), DPAs/operator agreements, due diligence and security questionnaires, SLA reports, audit attestations.

### 8.8 Marketing and Communications

Campaign plans, consents/opt-in logs, analytics (aggregated), website/app telemetry (aggregated), cookie consent logs.

Note: Access may be refused where grounds of refusal apply (Section 11 below).

## 9. Processing of Personal Information (POPIA Alignment)

This section aligns with Part 9 of the Terms and Conditions and the standalone Privacy Policy.

**Data subjects:** B2C Customers, B2B Customers, End Users, prospects, employees, job applicants, suppliers, partners, site/app visitors.

**Categories:** ID and contact data; employment and payroll; financial/banking/transaction data; KYC/AML (including biometric data from liveness verification); blockchain wallet addresses; device/usage/telemetry; recordings; complaints.

**Purposes:** Onboarding and KYC/AML (FIC Act); service delivery (Card, B2B Platform, ITT, Treasury, Off-Ramp); fraud prevention; customer support; regulatory reporting (FSCA/FIC/SARS); HR/payroll; analytics and service improvement; permitted marketing (consent/opt-out per the Terms and Conditions).

**Lawful bases:** Consent (where required); contract; legal obligation (FIC Act/FAIS/tax); legitimate interests (security, fraud, service improvement).

**Recipients:** Programme Partner, banking partners, card scheme, KYC/AML providers, liquidity partners, cloud/IT operators, auditors, regulators (FSCA, FIC, SARS, Information Regulator), law enforcement where lawful.

**Cross-border transfers:** Performed with lawful basis under section 72 of POPIA.

**Safeguards:** Aligned with Joint Standards 1 of 2023 and 2 of 2024.

**Data subject rights:** Access, correction, objection to direct marketing, deletion (where permissible), restriction. Requests via <compliance@spendl.money>.

**Breach notification:** As soon as reasonably possible after confirmation, per POPIA section 22 and Joint Standard 2 of 2024.

## 10. How to Request Access to Records

{% stepper %}
{% step %}

## Before you submit

Check Section 6 (proactive records) and our Website. If still needed, proceed with a PAIA request.
{% endstep %}

{% step %}

## Form and submission

* Use Form 2 (prescribed form under PAIA), available from the Information Regulator’s website: [www.inforegulator.org.za](http://www.inforegulator.org.za).
* Attach proof of identity and, if applicable, authority (mandate/POA).
* Provide sufficient particulars: record description, dates, right to be exercised/protected, preferred form of access, delivery method.
* Send to <compliance@spendl.money> or deliver to Central Square, Pinelands, Cape Town.
  {% endstep %}

{% step %}

## Verification

We verify identity/authority. For Personal Information requests, we may require additional verification to protect data subjects.
{% endstep %}

{% step %}

## Timeframes

* We respond within 30 calendar days.
* Extension (up to 30 more days) if the request is large, complex, or third-party consultations are needed. We will notify you of extensions with reasons.
  {% endstep %}

{% step %}

## Partial access

Where feasible, we grant partial access by redacting exempt portions.
{% endstep %}
{% endstepper %}

## 11. Fees and Deposits

* Request fee (non-personal): R140, payable in advance. Personal information requests are exempt from the request fee.
* Access fees: Depend on format/volume and time spent searching/preparing/redacting, as prescribed under the PAIA Regulations, 2021, published on the Information Regulator’s website: [www.inforegulator.org.za](http://www.inforegulator.org.za).
* Deposits: If search/preparation exceeds 6 hours, we may require a deposit equal to one-third of the estimated access fee.
* Refunds: Deposits refunded where access is refused.

## 12. Grounds for Refusal

We may refuse access where disclosure would:

* Unreasonably disclose Personal Information of a third party (e.g., other Customers' KYC documents).
* Reveal confidential commercial information or trade secrets (e.g., proprietary fraud models, unpublished pricing, vendor security reports).
* Endanger life/safety or prejudice the security of a building/system/network.
* Disclose legally privileged records (e.g., attorney advice on litigation).
* Be frivolous/vexatious or cause an unreasonable diversion of resources.

**Public-interest override:** Even if a refusal ground applies, we must grant access if disclosure would reveal evidence of a substantial contravention of the law or an imminent and serious public safety/environmental risk and the public interest clearly outweighs harm.

## 13. Third-Party Notifications

If a record may affect a third party, we will notify the third party within 21 days, allow 21 days for consent or representations, decide within 30 days, and allow the third party 30 days to object before releasing the record.

## 14. Remedies

* Information Regulator complaint (typically within 180 days of decision).
* High Court application (within 30 days or as otherwise allowed by the court).

## 15. Availability, Languages and Accessible Formats

* Available on SPENDL's Website, for inspection at our offices, and via request.
* Languages: English (primary). Upon reasonable request, we will provide key notices or summaries in another official language.
* Accessible formats: On reasonable request, we provide large print, screen-reader friendly PDFs, or alternative formats.

## 16. Governance

* Board: ultimate accountability for PAIA/POPIA compliance.
* IO: maintain this Manual, registers, and reporting; perform trend analysis on requests and refusals.
* Training: mandatory at onboarding and annually.
* Consequences: non-compliance may lead to disciplinary action; statutory penalties under PAIA/POPIA.

## 17. Review

This Manual is reviewed annually or sooner upon regulatory/operational changes, legal guidance updates, or identified gaps. All updates are Board-approved and version-controlled.

## 18. Contact Details of the Information Regulator

Information Regulator (South Africa)

* JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
* Tel: 010 023 5200
* Email: <PAIAComplaints@inforegulator.org.za> / <POPIAComplaints@inforegulator.org.za>
* Website: [www.inforegulator.org.za](http://www.inforegulator.org.za)

## 19. Version Control

| **Version** | **Effective Date** | **Summary of Changes**                                                                                                            | **Reason for Changes**                                                      | **Approved By**    |
| ----------- | ------------------ | --------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------- | ------------------ |
| 1.1         | 1 September 2025   | Founding version - initial PAIA Manual issued                                                                                     | Initial PAIA/POPIA compliance requirement upon platform launch              | Board of Directors |
| 1.2         | 1 July 2026        | Rewritten with document control, expanded fee and governance sections, named Compliance Officer, and updated Regulator references | Update of information and aligning with the broader compliance pack refresh | Board of Directors |
