PAIA Manual

Fusion Technology Group (Pty) Ltd

Manual published in terms of section 51 of the Promotion of Access to Information Act 2 of 2000

Private bodyFusion Technology Group (Pty) Ltd
Registration number2021/318883/07
Head of the private body / Information OfficerWarren Scrimgeour, Director
Date of compilation1 September 2026
Date of last revision1 September 2026
Version1.0
Published athttps://fusiongroup.co.za/paia-manual/

1. Acronyms and abbreviations

TermMeaning
PAIAPromotion of Access to Information Act 2 of 2000
POPIAProtection of Personal Information Act 4 of 2013
CIPCCompanies and Intellectual Property Commission
SARSSouth African Revenue Service
SACAASouth African Civil Aviation Authority
ERPEnterprise resource planning — the business systems clients use to run operations, finance and stock
the RegulatorThe Information Regulator (South Africa)
the RegulationsRegulations Relating to the Promotion of Access to Information, 2021 (GN R.757, Government Gazette 45057, 27 August 2021)
the POPIA RegulationsRegulations Relating to the Protection of Personal Information, 2018 (GN R.1383, Government Gazette 42110, 14 December 2018)
the GuideThe Guide on How to Use PAIA, published by the Regulator under section 10 of PAIA
Responsible partyThe person who determines the purpose of and means for processing personal information (POPIA s1)
OperatorA person who processes personal information for a responsible party, under that party's instruction (POPIA s1)
RequesterA person asking for access to a record, as defined in PAIA s1

2. Purpose of this manual

Section 51(1) of PAIA requires the head of every private body to make a manual available. Since 1 January 2022 there is no exemption for small businesses: the ministerial exemption for private bodies below certain headcount and turnover thresholds lapsed on 31 December 2021 and was not renewed. Fusion Technology Group is a private company with one director and no employees, and the duty applies to it in full.

This manual is written so that a person outside the company can work out three things:

  1. what records Fusion holds, in enough detail to name the record they want;
  2. how to ask for one, what it costs, and what happens next;
  3. how Fusion processes personal information — as a responsible party for its own business records, and as an operator on behalf of other companies whose systems and data it hosts.

The manual covers, in order, each element that section 51(1) requires:

PAIA provisionWhere it is dealt with
s51(1)(a)(i) — contact details of the head of the bodySection 3
s51(1)(a)(ii) — other prescribed informationSection 4
s51(1)(b)(i) — the section 10 Guide and how to get itSection 5
s51(1)(b)(ii) — records available without a formal requestSection 6
s51(1)(b)(iii) — records available under other legislationSection 7
s51(1)(b)(iv) — subjects and categories of records heldSection 8
s51(1)(c)(i) — purpose of processing personal informationSection 9.1
s51(1)(c)(ii) — categories of data subjects and informationSection 9.2
s51(1)(c)(iii) — recipients of personal informationSection 9.3
s51(1)(c)(iv) — planned transborder flowsSection 9.4
s51(1)(c)(v) — information security measuresSection 9.5
s50, s54, s56 and Chapter 4 of Part 3 — request procedure, fees and refusalSections 10, 11 and 13
s77A and s78 — remediesSection 12
s51(3) — availability of this manualSection 14
s51(2) — updating this manualSection 15

Note on section 51(1) itself: POPIA (Schedule, item 12) substituted the whole of section 51(1) with effect from 30 June 2021. The subsection now runs (a), (b)(i)–(iv) and (c)(i)–(v). Manuals still laid out against the old (a)–(f) scheme omit the POPIA block at (c) entirely. This manual follows the current text.

This manual is not the company's privacy policy, and the privacy policy is not this manual. The privacy policy at https://fusiongroup.co.za/privacy/ is a POPIA notice to data subjects. This is a PAIA document with prescribed statutory content. Section 9 below is not discharged by pointing at the policy.

2.1 Records that belong to Fusion's clients, not to Fusion

Two things Fusion runs are named throughout this manual, and both belong to somebody else:

  • Apex Accounting Worx is the product of Apex, a separate registered company. Fusion hosts and operates the platform for Apex under contract. The data on it — including the client data of the accounting firms that use it — belongs to Apex as responsible party. Fusion is Apex's operator. Apex Accounting Worx is not Fusion's own platform and Fusion is not the responsible party for accounting-firm data.
  • AeroDesk is operated for Fusion's aviation client, which is the responsible party for the data on it. Fusion holds that data as operator only.

Fusion also holds copies of client ERP data — extracts, backups, database copies and system logs — on its own infrastructure, for clients whose systems it supports. Those copies are in Fusion's custody but the data belongs to the client, which is the responsible party. Fusion is the operator.

What that means for a request. A request for a record that belongs to Apex, to the aviation client, or to any other client whose data Fusion holds as operator must be directed to that responsible party, which is the body that decides it. Fusion does not decide such requests. If one is sent to Fusion, Fusion will refer it to the responsible party, tell the requester that it has done so, and act only on the responsible party's instruction. Fusion will neither grant nor refuse access to another party's records on its own authority.


3. Contact details — section 51(1)(a)(i)

3.1 Head of the private body and Information Officer

For a juristic person, PAIA section 1 defines the "head" as the chief executive officer or equivalent officer, or the person acting as such. As sole director, Warren Scrimgeour is the head of Fusion Technology Group and is therefore its Information Officer by operation of law. No internal appointment or designation is involved.

NameWarren Scrimgeour
CapacityDirector; head of the private body; Information Officer
Street addressEye of Africa, 32 Cayman Road, Eikenhof, Johannesburg, Gauteng
Postal addressEye of Africa, 32 Cayman Road, Eikenhof, Johannesburg, Gauteng — the postal address is the same as the street address
Telephone087 265 0624
FaxNot applicable — the company does not operate a fax line
Emailhello@fusiongroup.co.za
Websitehttps://fusiongroup.co.za
This manualhttps://fusiongroup.co.za/paia-manual/

The company's address and contact details are the same as the head's. Fusion is home-based and has no public premises. See section 14.2 on inspection of this manual at that address.

Registration with the Regulator: the Information Officer was registered with the Information Regulator on 1 September 2026 under registration number 2026-065691. Registration of an information officer is required by POPIA section 55(2), read with Regulation 4 of the POPIA Regulations. That is a POPIA obligation, separate from this manual; it is recorded here for completeness.

3.2 Deputy Information Officers

None have been designated. POPIA section 56 — the provision that governs deputy information officers — permits the designation of "such a number of persons, if any", and PAIA section 17, which it applies, contemplates designating members of staff. Fusion has no employees, so there are no Deputy Information Officers. All requests go to the Information Officer named above.

3.3 Requests and enquiries

All PAIA requests, POPIA data subject requests and related correspondence should be sent to hello@fusiongroup.co.za, marked for the attention of the Information Officer, or posted to the address above.


4. Other prescribed information — section 51(1)(a)(ii)

Section 51(1)(a)(ii) allows the Minister to prescribe further content for manuals by regulation. As at the date of this manual, the Regulations Relating to the Promotion of Access to Information, 2021 prescribe no manual content beyond the statutory list in section 51(1). Nothing further is therefore required under this paragraph. If additional content is prescribed in future, this manual will be updated accordingly.


5. The section 10 Guide and how to obtain it — section 51(1)(b)(i)

The Information Regulator has published a Guide on how to use PAIA, as section 10 requires. The English version is dated 5 September 2021.

The Guide is written for members of the public and contains, among other things:

  • the objects of PAIA;
  • the contact details of the Information Officer of every public body, and of the Regulator;
  • the manner and form of a request for access to a record;
  • the assistance available from an information officer, and from the Regulator, in terms of PAIA;
  • all the remedies in law available to a person in respect of an act or failure to act by a public or private body, and how to exercise them;
  • the schedule of fees payable for access to records;
  • the notices issued in terms of PAIA;
  • the regulations made under PAIA;
  • procedures for lodging an internal appeal (against a public body) or a complaint with the Regulator;
  • a description of the subjects on which public bodies hold records, and the categories of records held on each subject.

How to obtain the Guide:

  • From the Regulator's website: https://inforegulator.org.za/ — the Guide is published there free of charge.
  • From the Regulator directly: The Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001; PO Box 31533, Braamfontein, Johannesburg, 2017; telephone 010 023 5200; email inforeg@inforegulator.org.za. A request for the Guide may be made on Form 1 (Regulation 2).
  • From Fusion: on request to the Information Officer at hello@fusiongroup.co.za, using Form 1 or a plain written request. Fusion will supply a copy or a direct link at no charge.
  • By inspection: at Fusion's registered address by prior arrangement during normal business hours.

The Guide is available in the official languages in which the Regulator has published it. There is no requirement for a private body's own manual to be produced in more than one language; this manual is issued in English, which the Regulator recommends as the minimum for private bodies.


6. Records available without a formal PAIA request — section 51(1)(b)(ii)

Section 51(1)(b)(ii) refers to "the latest notice in terms of section 52(2)". No such notice exists or can exist. POPIA (Schedule, item 13(b)) repealed section 52(2) outright, and amended section 52(1) so that a private body now makes its voluntary-disclosure description available in the prescribed manner rather than submitting it to the Minister for publication in the Gazette. This section is that description.

The following are available to anyone without a PAIA request, without a fee, and without having to show a right:

RecordHow to get it
This PAIA manualPublished at https://fusiongroup.co.za/paia-manual/; emailed on request
Privacy policyhttps://fusiongroup.co.za/privacy/
Published website content — service descriptions, contact details, company informationhttps://fusiongroup.co.za
Company particulars registered with CIPC — registered name, registration number, registered address, director detailsPublicly searchable on the CIPC register; also supplied on request

This list is deliberately short. Once a class of record is described here under section 52(1), Fusion is committed to releasing it automatically, so nothing goes on the list that Fusion is not prepared to hand over to anyone who asks. Commercial documents such as quotations, proposals and scoped service descriptions are not listed and are not automatically available; a request for one is dealt with under PAIA in the ordinary way, and section 68 will often be relevant to it.

Nothing in this section limits a person's right to request any other record under PAIA.


7. Records available in terms of other legislation — section 51(1)(b)(iii)

These are records whose availability is governed by legislation other than PAIA. Listing them here does not mean they are open to the public; it means another statute governs who may see them and on what terms.

LegislationRecords
Companies Act 71 of 2008Memorandum of Incorporation; certificate of incorporation (registration 2021/318883/07); register of directors; register of shareholders; securities register; annual returns filed with CIPC; annual financial statements; directors' resolutions and minutes
Tax Administration Act 28 of 2011, read with the Income Tax Act 58 of 1962 and the Value-Added Tax Act 89 of 1991Income tax returns and assessments; VAT returns; supporting source documents and records required to be retained; correspondence with SARS — retained for the periods those Acts prescribe
PAIA 2 of 2000This manual; records of PAIA requests received and the responses given; records relating to the annual report submitted to the Regulator under sections 32 and 83(4)
POPIA 4 of 2013The Information Officer's registration with the Regulator under section 55(2) read with Regulation 4 of the POPIA Regulations (registration number 2026-065691, registered 1 September 2026); records of data subject requests and responses; records of any notification of a security compromise under section 22; written operator agreements concluded under sections 20 and 21
Electronic Communications and Transactions Act 25 of 2002Data messages generated and received through the website — contact-form submissions and email — and the website's own legal notices. Fusion does not sell, hire or exchange goods or services through its website by electronic transaction, so the supplier-disclosure duties in section 43 do not apply to Fusion's website. Where Fusion has built an e-commerce or auction platform for a client, that platform is operated by the client, and any section 43 duty rests on the client as the supplier

A deliberate exclusion — records that belong to Fusion's clients. Fusion operates AeroDesk for its aviation client and Apex Accounting Worx for Apex, a separate registered company, and it holds copies of client ERP data on its own infrastructure. Where a statute imposes a record-keeping duty on the client — for example the duty on a SACAA Part 145 approved maintenance organisation to keep aircraft maintenance records, or a firm's duty to keep its own accounting records — that duty rests on the client, not on Fusion. Fusion holds the data as an operator. It is not claimed here as a record Fusion holds under that legislation, and a request for it is dealt with as section 2.1 describes.


8. Subjects on which records are held, and categories of records — section 51(1)(b)(iv)

The statutory test is "sufficient detail to facilitate a request". The table below is written so that a requester can identify and name a specific record rather than guess at a broad heading.

Listing a record here does not mean access will be granted. Access is decided against the test in section 50 and the grounds of refusal in Chapter 4 of Part 3 of PAIA — see sections 10 and 11 of this manual. Where a record belongs to a client and Fusion holds it as operator, Fusion does not decide the request at all — see section 2.1.

SubjectCategories of records held
8.1 Company statutory and governanceMemorandum of Incorporation; CIPC registration certificate; annual returns; register of directors; share register; director's resolutions and minutes; company policies
8.2 Client contracting and deliverySigned software development agreements; managed IT support agreements; hosting and operating agreements, including the agreements under which Fusion operates Apex Accounting Worx for Apex and AeroDesk for its aviation client; service level agreements; written operator agreements under POPIA sections 20 and 21; statements of work; quotations and proposals; project plans and delivery schedules; change requests; acceptance and sign-off records; support tickets and incident logs; on-site attendance records for managed IT clients in Gauteng
8.3 Non-disclosure agreements with clientsSigned non-disclosure and confidentiality agreements with clients and prospective clients, whether one-way or mutual, together with the correspondence concluding them and any schedules identifying the confidential material they cover. These are held as a category in their own right because they govern what Fusion may say about a client's business at all, and section 65 will usually be relevant to a request for one
8.4 Intellectual property and technical recordsSource code repositories; system architecture and design documentation; database schemas; API specifications; deployment and infrastructure configuration; build and release artefacts — for the custom business software Fusion builds, including wholesale distribution platforms, manufacturing staff platforms and customer portals, computer vision systems for production lines, and e-commerce and auction platforms. Ownership of any particular item in this category is governed by the client agreement under which it was produced
8.5 Records held while hosting and operating client platforms (held as operator; the client is the responsible party)Apex Accounting Worx, hosted and operated for Apex, a separate registered company: tenant configuration; the practice-management application data of the accounting firms that use the platform and of their own clients; access and audit logs; backups. AeroDesk, hosted and operated for Fusion's aviation client: tenant configuration; aircraft maintenance compliance data; access and audit logs; backups. Fusion did not create this data for its own purposes, does not use it for its own purposes, and does not decide requests for it
8.6 Copies of client ERP data held on Fusion infrastructure (held as operator; the client is the responsible party)Data extracts and exports; scheduled and ad hoc backups; full and partial database copies taken for support, migration, testing or restore purposes; application, transaction and system logs — held on infrastructure Fusion controls, for clients whose ERP and business systems Fusion supports. This is custody, not merely administrative access to a live client system: the copies physically sit on Fusion's infrastructure. Retention of these copies is governed by the agreement with the client concerned rather than by one published period. A request for the underlying data goes to the client as responsible party (section 2.1)
8.7 Supplier and subcontractor recordsSupplier and subcontractor agreements; non-disclosure and confidentiality undertakings given by subcontractors; purchase orders; invoices received; supplier contact and payment records
8.8 Finance and taxInvoices issued; bank statements; general ledger and accounting records; annual financial statements; VAT and income tax returns; SARS correspondence
8.9 Website and marketingContact-form enquiries submitted via fusiongroup.co.za and held in the hello@fusiongroup.co.za mailbox; published website content; web server logs; Cloudflare aggregate analytics reports
8.10 Information governance and complianceThis PAIA manual; the published privacy policy; Information Officer registration records; PAIA request and response records; POPIA data subject request records; security incident records; records of requests referred on to a client responsible party
8.11 General correspondenceEmail and written correspondence with clients, suppliers, subcontractors and professional advisers
8.12 Employee recordsNone. Fusion has no employees and holds no employment contracts, payroll, recruitment, performance, leave, disciplinary or medical-scheme records. This entry is stated expressly so that its absence is not read as an omission

Records held on Fusion's behalf by third parties — in Microsoft 365, in Microsoft Azure, or on Fusion's South African web host — remain Fusion's records for PAIA purposes. PAIA's definition of "record" covers information in the possession or under the control of the body, whether or not the body created it. Outsourcing the hosting does not put a record beyond the reach of a request.

The converse is also true, and is the more important point for categories 8.5 and 8.6. Data that physically sits on Fusion's infrastructure but belongs to a client is the client's record. Fusion holds it under the client's instruction, has no authority to release it, and refers any request for it to the client as responsible party.


9. Processing of personal information — section 51(1)(c)

Fusion processes personal information in two distinct capacities, and the answers below differ depending on which applies:

  • As responsible party — for its own business: enquiries, clients, suppliers, finances, compliance. Fusion decides the purpose and the means.
  • As operator — for personal information inside Apex Accounting Worx (belonging to Apex, a separate registered company), inside AeroDesk (belonging to Fusion's aviation client), and inside the copies of client ERP data described at section 8.6. That information belongs to Fusion's clients, who are the responsible parties. Fusion processes it only on their documented instructions under written operator agreements, as POPIA sections 20 and 21 require. Fusion does not decide the purpose or the means, and does not use that information for its own purposes.

Operator-side processing is marked throughout.

9.1 Purpose of the processing — s51(1)(c)(i)

As responsible party:

  • to receive and respond to enquiries submitted through the website contact form;
  • to negotiate, conclude and perform client contracts, non-disclosure agreements and service level agreements;
  • to design, build, deliver, support and maintain custom business software;
  • to provide managed IT support, including on-site attendance at client premises in Gauteng;
  • to procure goods and services from suppliers and subcontractors and to manage those relationships;
  • to invoice, collect payment and maintain accounting records;
  • to comply with obligations under the Companies Act, the Tax Administration Act, PAIA and POPIA.

As operator:

  • to host, operate, support and maintain Apex Accounting Worx on behalf of Apex, and AeroDesk on behalf of Fusion's aviation client, strictly in accordance with their documented instructions under written operator agreements;
  • to hold and process copies of client ERP data — extracts, backups, database copies and logs on Fusion infrastructure — for support, fault diagnosis, migration, testing and restore, strictly in accordance with the instructing client's documented instructions.

Fusion does not use personal information held as operator for any purpose of its own, and does not use it to market to the data subjects.

9.2 Categories of data subjects and of personal information — s51(1)(c)(ii)

Category of data subjectCapacityPersonal information held
Website enquirersResponsible partyName; company name; email address; telephone number; free-text message content; date and time of the enquiry; the visitor's IP address, stored only as a hash and not in the clear
Client contact persons (natural persons at client companies)Responsible partyName; job title; work email address; work telephone number; signatory details; correspondence
Supplier and subcontractor contactsResponsible partyName; company name; email address; telephone number; contract terms; banking details supplied by the supplier for payment
Director (Warren Scrimgeour)Responsible partyIdentity number; contact details; CIPC filing particulars; banking and tax details
Data subjects on Apex Accounting WorxOperator only — responsible party is Apex, a separate registered companyNatural persons who are staff, contacts or clients of the accounting firms using the platform — including names, contact details, and practice-management and financial data, as configured by Apex and its firms
Data subjects on AeroDeskOperator only — responsible party is Fusion's aviation clientAircraft maintenance and certifying personnel — including names, licence and authorisation particulars, and maintenance sign-off records, as configured by the responsible party
Data subjects within copies of client ERP data (section 8.6)Operator only — responsible party is the client whose system the copy was taken fromWhatever personal information the client's own system contains and the extract, backup, database copy or log reproduces — typically employee, customer, supplier and contact records, transaction and order data, and user identifiers and activity in system logs. Fusion does not curate or select this content; it holds a copy of what the client's system holds
EmployeesNone. Fusion has no employees and processes no employee personal information

For the three operator rows, a data subject who wants access to, correction of, or deletion of their information must approach the responsible party — Apex, the aviation client, or the client whose ERP system the copy was taken from. Fusion has no authority to decide such a request. It will refer the request to the responsible party, tell the data subject that it has done so, and act only on that party's instruction.

9.3 Recipients or categories of recipients — s51(1)(c)(iii)

RecipientWhat it receives, and why
MicrosoftMicrosoft 365, including Exchange Online, for company email — which carries website contact-form enquiries and general client and supplier correspondence; and Microsoft Azure, which runs the endpoint behind the website contact form. Microsoft acts as an operator to Fusion
CloudflareCookieless web analytics, which produce aggregate traffic statistics with no personal identifiers; and the Cloudflare Turnstile check on the website contact form, which sees the connection details of a visitor submitting the form in order to distinguish a person from an automated submission
The South African hosting provider that operates the server on which fusiongroup.co.za runsHosting of the public website, and the web server logs generated by it
Fusion's accountants and auditorsFinancial and tax records, and the personal information in them, for accounting work, audit and statutory filings
Legal advisorsRecords, and the personal information in them, where legal advice or representation makes disclosure necessary
SARS and CIPCTax and company filings and supporting records, where the law requires them
The Information Regulator, and courts of lawRecords where PAIA, POPIA or an order of court requires disclosure
Client responsible parties (operator side)Personal information Fusion processes as their operator — on Apex Accounting Worx, on AeroDesk, and in copies of client ERP data — disclosed only back to that client or as that client directs in writing

Fusion does not sell personal information, and does not share it for marketing.

9.4 Planned transborder flows of personal information — s51(1)(c)(iv)

Some personal information Fusion holds leaves South Africa. This section says so plainly, because a manual that claimed otherwise would be inaccurate.

ServiceWhere the data sitsEffect
Microsoft 365 / Exchange OnlineCurrently in Microsoft's European datacentres.Mailbox content for this tenant — which includes website contact-form enquiries and general client and supplier correspondence — currently rests in Europe. Microsoft lists South Africa only as a committed geography, and the migration is not yet complete. That is a commitment about future data residency, not a statement that this data is held in South Africa today. When the migration completes, this manual will be updated
Microsoft — support, diagnostics, service routing, spam and malware filteringOther countries, regardless of where the mailbox restsSome Microsoft processing of this data happens outside South Africa in any event, and would continue to do so even after mailbox content moves to South Africa
Microsoft Azure (endpoint behind the website contact form)Microsoft infrastructure; the submission comes to rest in the Microsoft 365 mailboxA contact-form submission is handled by the Azure endpoint and delivered into the mailbox, so it ends up where the mailbox is — currently Europe — and is subject to the same Microsoft processing described in the row above
Cloudflare (web analytics and the Turnstile check on the contact form)Processed across Cloudflare's global network, which operates outside South AfricaAnalytics are cookieless and aggregated, with no personal identifiers. The Turnstile check sees a visitor's connection details at the moment of submission and is processed on that global network
Public website (fusiongroup.co.za)On a server in South AfricaContent served from it, and the web server logs it generates, involve no transborder flow
Apex Accounting Worx and AeroDesk (operator), and copies of client ERP data (operator)On infrastructure Fusion operates under contract with the responsible partyFusion does not transfer this data outside South Africa on its own initiative. Any transborder flow of it would be a matter for the responsible party, which sets the instruction under the operator agreement and which must disclose the position in its own manual and its own section 72 assessment. Fusion will not move this data across a border except on the responsible party's written instruction

Lawful basis for transfer. Fusion relies on POPIA section 72(1)(a): the recipient is subject to a binding agreement that provides a level of protection substantially similar to the conditions for lawful processing under POPIA. In Microsoft's case that agreement is the Microsoft Products and Services Data Protection Addendum, which forms part of Fusion's contract with Microsoft. The same basis is relied on for the other transfers described in this section, through the data-protection terms binding each recipient.

9.5 Information security measures — s51(1)(c)(v)

What follows is a general description, sufficient for a preliminary assessment of suitability. It is deliberately not a full security architecture: publishing one would itself create risk.

  • Access control. Multi-factor authentication is enforced on every Microsoft 365 account. The enquiry mailbox at hello@fusiongroup.co.za can be opened by one person only. Access to client systems is on named individual credentials, so that every action is attributable to a person rather than to a shared login.
  • Website transport and browser security. The website is served over HTTPS, with a strict Content-Security-Policy and the related security response headers set on every response.
  • Contact-form protection. The form is protected by Cloudflare Turnstile, an origin allow-list, a honeypot field, submit-timing checks and rate limiting, so that automated and abusive submissions are rejected before they reach the mailbox.
  • Minimisation of visitor data. Visitor IP addresses are hashed rather than stored in the clear.
  • Enforced retention. Website enquiries are deleted 720 days after each message's own date, by an enforced Exchange retention policy rather than by manual housekeeping. Web server logs are kept for 30 days. Business and tax records are kept for the periods the Companies Act and the Tax Administration Act require. Retention of the copies of client ERP data described at section 8.6 is governed by the agreement with the client concerned rather than by one published period.
  • Contractual controls. Written operator agreements with client responsible parties under POPIA section 21; confidentiality undertakings with subcontractors, who are treated as operators under POPIA section 20; non-disclosure agreements with clients (section 8.3).
  • Incident handling. A documented procedure for notifying the Information Regulator and affected data subjects of a security compromise, as POPIA section 22 requires. Where a compromise affects data Fusion holds as an operator — on Apex Accounting Worx, on AeroDesk, or in a copy of client ERP data — Fusion notifies the client responsible party, as section 21(2) requires, and it is that party which carries the section 22 duty.

10. How to request access to a record

10.1 The test a request must meet

Under section 50(1) of PAIA, a requester must be given access to a record of a private body only if:

  1. the record is required for the exercise or protection of any right;
  2. the procedural requirements in PAIA relating to the request have been complied with; and
  3. access is not refused on a ground set out in Chapter 4 of Part 3 of PAIA.

The first of those is the point most requests turn on. A request should state which right is being exercised or protected, and explain why the record is required for that purpose. A general interest in the information is not enough.

Under section 50(2), where a requester is acting in the public interest, the request must be in the public interest as well.

This is stated as the test each request will be assessed against. It is not a standing refusal, and each request is considered on its own facts.

10.2 Requests for records that belong to a client

Before completing a form, please check section 2.1. If the record you want is data on Apex Accounting Worx, data on AeroDesk, or client ERP data of which Fusion holds a copy, the request must go to the responsible party — Apex, the aviation client, or the client whose system the data came from. Fusion cannot decide it. If you send such a request to Fusion, Fusion will refer it to the responsible party and tell you that it has done so, and will act only on that party's instruction.

10.3 The form to use

A request must be made on a form that corresponds substantially with Form 2 of Annexure A to the 2021 Regulations (Regulation 7(1)). Form 2 is headed "Request for Access to Record", is addressed to the Information Officer, and serves both public and private bodies.

Download Form 2: https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-PAIA-Form02-Reg7.pdf

The older Form A (public bodies) and Form C (private bodies) were repealed in 2021, are no longer valid, and are not referred to or annexed in this manual. Because the standard is "corresponds substantially", Fusion will not reject a request purely on the ground of the form used, but requesters are asked to use Form 2.

10.4 What the request must include

  • Sufficient particulars to identify the record and the Information Officer;
  • the form of access required (copy, inspection, or another form under section 29);
  • postal, email or other contact details for the reply, and a statement of whether the requester wishes to be told of the decision in any other manner (with the necessary particulars);
  • the right the requester seeks to exercise or protect, and an explanation of why the record is required for that purpose;
  • proof of identity, as Form 2 requires;
  • where the request is made on behalf of another person, proof of the requester's authority to act;
  • if the requester wishes to be assisted because of a disability, an indication of that fact and of the form of assistance needed.

Send the completed form to hello@fusiongroup.co.za, marked for the attention of the Information Officer, or to the postal address in section 3.

10.5 Requesters who cannot make a request in writing

PAIA section 18(3) obliges the information officer of a public body to accept an oral request from a person who cannot read or write, or who has a disability, and to reduce it to writing. That provision binds public bodies. It does not bind a private body, and Fusion does not claim to be under it.

Fusion nevertheless offers the same accommodation voluntarily. A person who cannot read or write, or who because of a disability cannot complete Form 2, may phone the Information Officer on 087 265 0624. The Information Officer will take the request orally, complete Form 2 from what is said, and send the completed form back to the requester or to a person they nominate, so that the requester can see what has been recorded. The request is then handled exactly as a written request would be.

10.6 What happens next

  1. The clock starts when the request is received. Under section 56(1), the head must decide the request and notify the requester of the decision within 30 days after the request is received. The period may be extended by up to a further 30 days in the circumstances section 57 allows, and the requester will be notified of any extension and the reasons for it.
  2. On receipt, the Information Officer issues a notice under section 54(1) requiring payment of the R140.00 request fee, and the request is not processed further until it is paid. Paying the fee does not restart the 30-day period. That period runs from the date the request was received, whenever the fee happens to be paid.
  3. The decision, the access fee payable, and the form of access are communicated using Form 3 (Regulation 8).
  4. If access is granted, the access fee must be paid before the record is released.
  5. If access is refused, the notice will state adequate reasons, the provision of PAIA relied on, and the remedies available.
  6. Where a request affects a third party, that party is notified and given the opportunity to make representations, as sections 71 to 73 require.
  7. Where the record belongs to a client responsible party, the request is referred on as section 10.2 describes, and the requester is told promptly that it has been referred and to whom.

If the Information Officer fails to respond within the applicable period, the request is regarded as having been refused (deemed refusal), and the remedies in section 12 apply.


11. Grounds on which access may be refused

Chapter 4 of Part 3 of PAIA sets out when access to a record of a private body must or may be refused. In summary:

SectionGround
s63Unreasonable disclosure of personal information about a third party who is a natural person, including a deceased person
s64Commercial information of a third party — trade secrets; financial, commercial, scientific or technical information the disclosure of which would likely harm the third party's commercial or financial interests; information supplied in confidence whose disclosure would put the third party at a disadvantage in negotiations or commercial competition
s65Information whose disclosure would constitute an actionable breach of a duty of confidence owed to a third party
s66Information whose disclosure could reasonably be expected to endanger the life or physical safety of an individual, or prejudice the security of property or of a means of transport
s67Records privileged from production in legal proceedings
s68Commercial information of Fusion itself — trade secrets; information whose disclosure would likely harm its commercial or financial interests; information whose disclosure would put it at a disadvantage in negotiations or commercial competition; computer programs owned by Fusion and protected by copyright
s69Research information of a third party, or of Fusion, whose disclosure would expose the researcher, the subject matter or the research to serious disadvantage
s70Mandatory disclosure in the public interest — access must be granted despite most of the above grounds where disclosure would reveal a substantial contravention of, or failure to comply with, the law, or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm

Section 68 is likely to be relevant to much of what Fusion holds, given that its records include source code, system designs and client commercial terms. Sections 63, 64 and 65 will frequently be relevant to the client-owned data described at sections 8.5 and 8.6, and to the non-disclosure agreements at section 8.3 — although in the case of client-owned data the prior question is not refusal but referral: the decision belongs to the responsible party, not to Fusion (section 2.1).


12. Remedies — what to do if you are unhappy with a decision

There is no internal appeal against a private body. Internal appeal under PAIA lies only against a decision of the information officer of a public body. Any statement to the contrary in another manual is wrong.

A requester who is dissatisfied with a decision of the head of Fusion Technology Group — including a deemed refusal through non-response — has two remedies:

  1. Complain to the Information Regulator. Use Form 5 (Regulation 10): https://inforegulator.org.za/wp-content/uploads/2020/07/InfoRegSA-PAIA-Form05-Reg10-1.pdf. A complaint must be lodged within 180 days of the decision or of the event complained of. Send it to the Regulator at PO Box 31533, Braamfontein, Johannesburg, 2017, or to the Regulator's contact details in section 5 of this manual, or through the PAIA complaints channel published on the Regulator's website at https://inforegulator.org.za/.
  2. Apply to court under section 78. A requester may apply to a court for appropriate relief in respect of the decision.

Where a request concerned records belonging to a client responsible party and was referred on under section 10.2, the remedies above lie against that responsible party's decision, and are exercised against that body.


13. Fees

The fees below are those prescribed for private bodies in Annexure B to the Regulations Relating to the Promotion of Access to Information, 2021 (GN R.757, Government Gazette 45057, 27 August 2021). They have stood unchanged since 27 August 2021. Public-body fees are different and do not apply here; no public-body fee is quoted anywhere in this manual.

13.1 Request fee

Request fee (section 54(1))R140.00

Payable on receipt of a notice from the Information Officer, before the request is processed further. It is not refundable if access is ultimately refused. As section 10.6 explains, paying it does not restart the 30-day decision period.

Note: this fee is payable by every requester, including a person requesting a record that contains their own personal information. POPIA (Schedule, item 14) deleted the words "other than a personal requester" from section 54(1). Manuals still saying that a personal requester pays no request fee are out of date.

13.2 Access fees

ItemFee
Photocopy or printed copy of an A4 page, or part of a pageR2.00 per page
Copy in computer-readable form — flash drive supplied by the requesterR40.00
Copy in computer-readable form — compact disc supplied by the requesterR40.00
Copy in computer-readable form — compact disc supplied by FusionR60.00
Transcription of an audio record, per A4 pageR24.00
Copy of an audio record — flash drive supplied by the requesterR40.00
Copy of an audio record — compact disc supplied by the requesterR40.00
Copy of an audio record — compact disc supplied by FusionR60.00
Transcription or copy of visual imagesOutsourced; charged at the service provider's quotation
Postage, email or other electronic transferActual expense, if any

13.3 Search and preparation

Search for and preparation of the record for disclosureR145.00 for each hour, or part of an hour, reasonably required
Maximum charged for search and preparationR435.00

Time is charged only for the hours reasonably required, and never more than R435.00 in total.

13.4 Deposit

Where the search and preparation is likely to exceed six hours, a deposit is payable before the request is processed further. The deposit may not exceed one third of the access fee that would be payable if the request were granted.

13.5 Fee for a copy of this manual

This manual is free on the website and free to inspect. If a person asks for a printed copy under section 51(3)(c), the "reasonable amount" charged is the prescribed reproduction rate of R2.00 per A4 page.

13.6 No amount is added to the prescribed fees

The amounts in Annexure B are ceilings that a private body may not exceed. Fusion charges the prescribed amounts and adds nothing to them — no administration charge, no handling charge, and no amount on top of a prescribed figure. The figures in this section are what a requester pays.


14. Availability of this manual — section 51(3)

Section 51(3), as substituted by POPIA, requires this manual to be made available in four ways. All four apply.

14.1 On the website. This manual is published at https://fusiongroup.co.za/paia-manual/ and is free to read and download. Fusion has a website, so publication there is compulsory, not optional.

14.2 At the principal place of business, for public inspection during normal business hours. Fusion's registered address is a private residence and it has no public premises. Inspection at Eye of Africa, 32 Cayman Road, Eikenhof, Johannesburg, Gauteng is available by prior arrangement during normal business hours (08:00 to 17:00, Monday to Friday, excluding public holidays). Arrange an appointment by emailing hello@fusiongroup.co.za or phoning 087 265 0624. Anyone who would rather not travel can obtain the manual free of charge at https://fusiongroup.co.za/paia-manual/ or by email.

14.3 To any person on request. A copy will be emailed free of charge on request. A printed copy is available at R2.00 per A4 page (section 13.5).

14.4 To the Information Regulator on request. This manual will be provided to the Information Regulator whenever the Regulator requests it. PAIA does not require a private body's manual to be filed with the Regulator; the duty in section 51(3)(d) is to make it available on request. Fusion may in addition upload it to the Regulator's voluntary portal at https://eservices.inforegulator.org.za/paiamanuals/default.aspx as evidence of compliance.


15. Updating this manual — section 51(2)

Section 51(2) requires the head of a private body to update the manual on a regular basis. PAIA prescribes no interval. Fusion's practice is:

  • Review at least annually, against the statutory requirements and the Regulator's current guidance.
  • Revise immediately on any of the following: a change of Information Officer; a change of address or contact details; a new platform, product or service line; a new hosting or operating engagement for a client, or the ending of an existing one; the appointment of a new operator or sub-operator; a change in where data is hosted — in particular when Microsoft completes the migration of this tenant's mailbox content from Europe to South Africa; a change in the retention position agreed with a client for copies of that client's ERP data (section 8.6); a change in retention periods generally; a change in the prescribed fees or forms; or the engagement of any employee, which would change sections 3.2, 8.12 and 9.2.

Each revision carries a new date of revision on the cover page, and the superseded version is retained.


16. Annexures

AnnexureDocumentSource
AForm 2 (Regulation 7) — Request for Access to RecordDownload
BPrescribed fees for private bodies (Annexure B to the 2021 Regulations)Reproduced at section 13 above; published at https://inforegulator.org.za/paia-fees-structure-2/
CForm 5 (Regulation 10) — Complaint to the Information RegulatorDownload

For reference, Form 3 (Regulation 8) is the form on which the Information Officer notifies a requester of the outcome of a request and the fees payable: https://inforegulator.org.za/wp-content/uploads/2020/07/Form-3-PAIA.pdf.

Form 4 (Regulation 9), the internal appeal form, is not annexed. Internal appeal does not lie against a private body — see section 12.

The repealed Form A and Form C are not annexed and are not valid.


17. Issued by the head of the private body

This manual is issued in terms of section 51(1) of the Promotion of Access to Information Act 2 of 2000.

NameWarren Scrimgeour
CapacityDirector; head of the private body; Information Officer
ForFusion Technology Group (Pty) Ltd, registration 2021/318883/07
SignedWarren Scrimgeour, in his capacity as head of the private body
Date1 September 2026

A note on this document

This is a statutory document, not marketing material. PAIA section 51 requires Fusion Technology Group to publish it, to keep it accurate, and to update it on a regular basis. It describes what the company actually holds and where that information actually sits — including the fact that mailbox content currently rests in Microsoft's European datacentres rather than in South Africa, and the fact that a good deal of what sits on Fusion's infrastructure belongs to Fusion's clients rather than to Fusion.

One item is marked for confirmation: the retention position agreed with each client for the copies of client ERP data described at section 8.6. That is governed by the individual client agreements rather than by a single published period, and it is recorded as outstanding rather than answered with a figure that would not be true of every client.

Last updated: 1 September 2026. This manual is published at https://fusiongroup.co.za/paia-manual/. If anything here is out of date, or if you think a record has been described too vaguely to make a request, email hello@fusiongroup.co.za and it will be corrected.