Company details and key contacts
K2026564435 (South Africa) (Pty) Ltd, enterprise number 2026/564435/07, trading as “Relay Audit” (herein “Relay”, “we”, “our” or “us”), is a private company incorporated in accordance with the laws of the Republic of South Africa.
registered address
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
principal place of business
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
postal address / mailbox
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
Website
The Information Officer for purposes of PAIA and POPIA is Neil Eduard De Kock.
Information Officer email address
Information Officer telephone number
About Relay and this Manual
Relay provides technology that assists auditors with the preparation of audit workbooks and related audit work. Relay operates on a hybrid basis. It does not retain the source audit files, source documents or generated workbooks, whether on the auditor’s device or centrally. Instead, Relay builds and maintains the Knowledge Graph — the structured metadata, content summaries and relationships it derives about the audit information made available to it — and retains only the Knowledge Graph, together with limited account, configuration, diagnostic, access and security information, stored in Relay’s approved cloud environment, encrypted and access-controlled.
Where an auditor invokes an artificial-intelligence-enabled function, or where building or updating the Knowledge Graph requires it, only the minimum content reasonably required is transmitted, through an approved third-party artificial-intelligence model aggregator (gateway) (the “Aggregator”), to an approved artificial-intelligence provider for live inference (which may take place outside South Africa, including in the European Union, the United States, Asia or Africa). That content is processed on a zero-retention basis and is not stored by the Aggregator or the artificial-intelligence provider after the response is returned, nor used to train, retrain, fine-tune or otherwise improve any artificial-intelligence model.
Relay does not issue or sign audit opinions, reach final audit conclusions, exercise professional judgement or replace the audit firm’s methodology, review procedures or quality-control processes.
This Manual is prepared in accordance with section 51 of PAIA. Its purpose is to describe the Records held by or under the control of Relay, explain how a person may request access to those Records and provide the information required by PAIA and POPIA.
This Manual should be read with Relay’s Privacy Policy, data processing agreements, customer agreements, website terms and other applicable policies or notices.
Relay may amend this Manual from time to time. The current version will be published on the Website and will take effect on the date stated in the updated Manual.
Definitions
In this Manual, unless the context indicates otherwise:
“Aggregator”
means an approved third-party artificial-intelligence model aggregator (gateway) through which Relay accesses artificial-intelligence services, under a single data-processing arrangement, to perform a selected task or to build or update the Knowledge Graph.
“Data Subject”
has the meaning assigned to that term in POPIA.
“Guide”
means the guide on how to use PAIA prepared and updated by the Information Regulator under section 10 of PAIA.
“Head”
means the chief executive officer or equivalent officer of Relay, or a person duly authorised by that officer, as contemplated in PAIA.
“Information Officer”
means Relay’s Information Officer appointed or deemed to be appointed under POPIA and responsible for performing the functions allocated to the Head or Information Officer under PAIA and POPIA.
“Information Regulator” or “Regulator”
means the independent body established under section 39 of POPIA.
“Knowledge Graph”
means the structured metadata, content summaries and relationships that Relay derives and maintains about the audit information made available to it, excluding the source audit files, source documents and generated workbooks themselves.
“Manual”
means this PAIA Manual, as amended from time to time.
“Operator”
has the meaning assigned to that term in POPIA.
“PAIA”
means the Promotion of Access to Information Act 2 of 2000 and its regulations, as amended from time to time.
“Personal Information”
has the meaning assigned to that term in POPIA and includes information relating to an identifiable natural person or, where applicable, an identifiable existing juristic person.
“POPIA”
means the Protection of Personal Information Act 4 of 2013 and its subordinate legislation, as amended from time to time.
“Process”
has the same meaning as “processing” in section 1 of POPIA, and “Processed” and “Processing” shall be interpreted accordingly.
“Record”
means any recorded information in Relay’s possession or under its control, regardless of when it came into existence, who created it or the form or medium in which it is held.
“Requester”
means a person who makes a request for access to a Record of Relay under PAIA, including a person acting on behalf of another person.
“Responsible Party”
has the meaning assigned to that term in POPIA.
“Website”
means www.relayaudit.com.
Guide on how to use PAIA
The Information Regulator has prepared and made available the Guide in an easily understandable form. The Guide assists a person who wishes to exercise a right under PAIA or obtain access to Personal Information under section 23 of POPIA.
The Guide explains, among other matters:
the objects of PAIA and POPIA;
the contact details of Information Officers and Deputy Information Officers;
how to make a request for access to a Record;
the assistance available from an Information Officer and the Information Regulator;
the remedies available where access is refused or a body fails to respond;
the circumstances in which fees may be payable; and
the provisions concerning PAIA Manuals and Records that are automatically available.
The Guide and PAIA forms are electronically available from the Information Regulator at www.inforegulator.org.za/paia/. A copy may also be requested from Relay’s Information Officer using the details in clause 1.
The guide is also electronically available and can be downloaded from the Information Regulator's website at the following link: https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Guide-English_20210905.pdf
Enquiries concerning the Guide may be directed to the Information Regulator:
Contact item Details Physical address Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 Postal address P.O. Box 31533, Braamfontein, Johannesburg, 2017 Telephone 010 023 5200 Toll-free 0800 017 160 Email enquiries@inforegulator.org.za Website www.inforegulator.org.za
Records available without a formal request
The following categories of Records are generally available without a formal request under PAIA. Availability does not constitute a waiver of any intellectual-property, confidentiality or other rights.
Category Types of Record Website On request Corporate and contact information Public company and contact information published by Relay X X PAIA and privacy information This Manual, Relay’s Privacy Policy and public privacy notices X X Website and product information Public Website content, service descriptions and public-facing product material X X Public communications Public announcements, articles, recruitment notices and other material intentionally made public X X Prescribed forms Links to the Information Regulator’s PAIA forms and guidance X X A Record listed above may be removed, replaced or updated from time to time. A Record not automatically available may be requested using the procedure in clause 9.
Records available under other legislation
Relay may hold Records required under legislation applicable to its business. The inclusion of legislation below does not mean that every Record is available to every person. Access depends on the relevant legislation, PAIA and the circumstances of the request.
Basic Conditions of Employment Act 75 of 1997;
Broad-Based Black Economic Empowerment Act 53 of 2003;
Companies Act 71 of 2008;
Compensation for Occupational Injuries and Diseases Act 130 of 1993;
Consumer Protection Act 68 of 2008, where applicable;
Copyright Act 98 of 1978;
Cybercrimes Act 19 of 2020;
Electronic Communications and Transactions Act 25 of 2002;
Employment Equity Act 55 of 1998;
Income Tax Act 58 of 1962;
Labour Relations Act 66 of 1995;
Occupational Health and Safety Act 85 of 1993;
Promotion of Access to Information Act 2 of 2000;
Protection of Personal Information Act 4 of 2013;
Skills Development Act 97 of 1998 and Skills Development Levies Act 9 of 1999;
Tax Administration Act 28 of 2011;
Trade Marks Act 194 of 1993;
Unemployment Insurance Act 63 of 2001 and Unemployment Insurance Contributions Act 4 of 2002; and
Value-Added Tax Act 89 of 1991.
Other legislation may apply depending on Relay’s activities, workforce, contracts and the nature of a particular Record.
Subjects and categories of Records held by Relay
The following table describes the main subjects and categories of Records that Relay may hold. The fact that a category is listed does not mean that access will necessarily be granted. Each request will be considered under PAIA, including the applicable grounds for refusal.
Subject Categories of Records Corporate and governance Registration and incorporation Records; Memorandum of Incorporation; securities and beneficial-ownership Records; director and shareholder information; resolutions; minutes; governance Records; delegations of authority; statutory submissions and company-secretarial correspondence. Human resources and recruitment Employee, contractor and applicant Records; employment and contractor agreements; identification and contact information; payroll, tax and leave Records; qualifications; performance and disciplinary Records; training; workplace policies; health and safety Records and related correspondence. Financial, tax and accounting Annual financial statements; management accounts; budgets; tax returns; invoices; creditor and debtor Records; banking and payment Records; accounting source documents; auditor correspondence; insurance Records and financial reports. Customers and commercial relationships Customer and prospective-customer contact details; proposals; onboarding Records; mandates; customer agreements; statements of work; data processing agreements; confidentiality agreements; billing and payment Records; support and service correspondence; complaints and relationship-management Records. Relay product and platform operations Product documentation; application and system documentation; software-development and testing Records; architecture and configuration Records; user-account Records; access Records; limited diagnostic and security logs; incident and change-management Records; service-provider and infrastructure Records. Service Telemetry Records; diagnostic sample Records where shared by an audit firm. Audit engagement processing Audit-firm instructions, authorisations and Mandate Records; configuration and task metadata; information required to support the audit firm and evidence that live artificial-intelligence processing was performed under the applicable controls. Relay holds the Knowledge Graph (the structured metadata, content summaries and relationships derived about the audit information) together with limited account, configuration, diagnostic, access and security information. Relay does not retain the source audit files, source documents or generated workbooks, which are therefore not Records held by Relay unless separately placed in Relay’s possession or under its control. Information security, privacy and compliance Privacy and information-security policies; PAIA and POPIA Records; Information Officer Records; data-subject and PAIA request registers; risk assessments; security reviews; incident Records; retention and destruction Records; operator and Sub-Operator agreements; compliance training and audit Records. Intellectual property Trade marks; copyrights; domain-name Records; software and source-code Records; algorithms; technical specifications; designs; know-how; licences; third-party intellectual-property agreements and related correspondence. Website, communications and marketing Website content; enquiries; cohort or pilot applications; public communications; marketing correspondence; customer feedback; limited website hosting, access, error and security logs. Relay’s Website does not currently use cookies. Suppliers, advisers and other business contacts Supplier and service-provider details; contracts; due-diligence Records; banking and tax information; professional-adviser Records; consultant Records; orders; invoices; performance Records and correspondence. Legal, regulatory and insurance Legal opinions and privileged communications; litigation or dispute Records; regulatory correspondence; permits and registrations; claims; insurance policies and related Records.
Processing of Personal Information
Relay Processes Personal Information in accordance with POPIA and its Privacy Policy. Relay may act as a Responsible Party for its own business Processing and as an Operator when it Processes audit engagement information on the documented instructions of an audit firm.
Purposes of Processing
Relay may Process Personal Information to:
respond to enquiries and manage prospective-customer relationships;
enter into, perform and administer contracts;
create, authenticate and administer user accounts and authorised access;
provide, operate, support and secure the Relay application;
monitor, troubleshoot, evaluate and improve the Relay application using event-level technical and operational records (“Service Telemetry”) which exclude the contents of audit files, source documents, prompts, outputs or workbooks and, where an audit firm enables the relevant functionality, input material shared as a diagnostic sample;
receive, read, extract, organise, structure, transform and analyse audit information selected by the auditor, build and maintain the Knowledge Graph, and perform live task-specific Processing, on the documented instructions of an audit firm;
prepare draft audit workbooks, link information to source Records and identify exceptions or matters requiring auditor review;
administer billing, accounting, tax, insurance and business Records;
recruit and manage personnel and contractors;
comply with legal, regulatory and contractual obligations;
investigate security incidents, fraud, misuse and complaints; and
establish, exercise or defend legal rights and claims.
Categories of Data Subjects and Personal Information
Categories of Data Subjects Personal Information that may be Processed Audit firms, authorised users and prospective customers Names, contact details, employer or organisation, professional role, account and authentication Records, contractual and billing information, correspondence, usage, access, diagnostic and security information. Individuals appearing in audit engagement material Names, surnames, identity or passport numbers, signatures, contact details, job titles, employment information, financial and accounting Records, bank or payment details, transactions, contracts, correspondence and other information appearing in audit files selected by the audit firm. This information is processed to perform the selected task and to build and maintain the Knowledge Graph; the source files are not retained by Relay, and content transmitted for live artificial-intelligence inference is processed on a zero-retention basis and is not retained after the response is returned. Employees, contractors and job applicants Identification, contact, employment, payroll, tax, qualification, performance, disciplinary, leave, training, health and safety and recruitment information. Directors, shareholders, investors and advisers Identification and contact information, corporate roles, shareholding or investment information, statutory Records, contracts and correspondence. Suppliers, service providers and other business contacts Names, contact and organisation details, registration and tax information, contracts, banking details, invoices, performance information and correspondence. Website visitors and persons making enquiries Names, email addresses, telephone numbers, organisation and enquiry details voluntarily submitted, together with limited hosting, IP address, request timestamp, access, error and security information. The Website does not currently use cookies. Recipients or categories of recipients
Relay may disclose Personal Information, where lawful and necessary, to:
the relevant audit firm and its authorised users;
an approved cloud provider that hosts the Knowledge Graph and limited account, configuration, diagnostic, access and security information;
the Aggregator and the approved artificial-intelligence providers accessed through it, which Process the minimum content transmitted for a selected task or to build or update the Knowledge Graph, and which may perform inference outside South Africa (including in the European Union, the United States, Asia or Africa);
providers supporting email, accounting, security, communications, hosting, infrastructure and other business functions;
professional advisers, consultants, auditors and insurers;
the South African Revenue Service, the Companies and Intellectual Property Commission, the Information Regulator and other public bodies where required or permitted by law;
courts, law-enforcement bodies and regulators where disclosure is required or permitted by law; and
a lawful successor, investor or purchaser in connection with a corporate transaction, subject to appropriate safeguards.
Cross-border flows of Personal Information
Where an auditor invokes an artificial-intelligence-enabled function, only the minimum information reasonably required to perform the selected task is transmitted, through the Aggregator, to an approved artificial-intelligence provider for live inference. Inference may occur in the European Union, the United States, Asia or Africa. The Knowledge Graph and limited account, configuration, diagnostic, access and security information are hosted with a reputable cloud provider under appropriate technical and organisational safeguards. Where any such information is stored or processed outside South Africa, that transfer will comply with section 72 of POPIA. Relay will give the audit firm prior written notice of any material change to the hosting region, and will confirm the current hosting location to the audit firm on request.
All artificial-intelligence inference must be performed on a zero-retention basis. Prompts, inputs and outputs may not be stored after inference, backed up or used for model training or any secondary purpose.
Relay will transfer Personal Information outside South Africa only where a ground in section 72 of POPIA applies, including where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to POPIA, or where another lawful transfer ground applies.
Information security measures
Relay applies reasonable technical and organisational measures appropriate to the nature and sensitivity of the Personal Information, which may include:
not retaining the source audit files, source documents or generated workbooks, and retaining only the Knowledge Graph and limited account, configuration, diagnostic, access and security information, encrypted and access-controlled;
permitting Relay personnel to access the contents of audit files, source documents, prompts, outputs or workbooks only under role-based, least-privilege and audited access controls and strictly as necessary to provide, secure or support the service;
using secure transport protocols and encryption in transit and, where information is stored by Relay or an approved provider, encryption at rest;
role-based and least-privilege access, unique credentials, strong authentication and multi-factor authentication where supported and appropriate;
zero retention and no backups for artificial-intelligence prompts, inputs and outputs;
limiting audit and diagnostic logs so they do not record source-document contents, prompts or outputs, unless strictly necessary for security and expressly authorised;
confidentiality obligations, appropriate screening and privacy and security training for personnel with authorised access;
security monitoring, incident-response and escalation procedures;
risk assessments, periodic review of safeguards and appropriate service-provider contracts; and
retention and secure-destruction procedures.
How to request access to a Record
A private body is required to provide access to a Record only where the Record is required for the exercise or protection of a right, the Requester complies with PAIA’s procedural requirements and access is not refused under a ground permitted or required by PAIA.
A request must be submitted on the prescribed Form 2: Request for Access to Record, available from the Information Regulator at www.inforegulator.org.za/paia-forms/.
The completed Form 2 must be sent to Relay’s Information Officer using the contact details in clauses 1 and 13. The request should provide sufficient information to enable Relay to:
identify the Requester and, where applicable, the person on whose behalf the request is made;
identify the Record requested;
determine the preferred form of access;
identify the right the Requester seeks to exercise or protect;
understand why the requested Record is required for the exercise or protection of that right; and
communicate with the Requester and deliver the decision or Record.
A person acting on behalf of another person must provide satisfactory proof of authority. Relay may request information reasonably required to verify identity, authority or the particulars of the request.
A request must relate to an existing Record. PAIA does not require Relay to answer general questions, create a new Record or provide information that is not recorded and held by or under Relay’s control.
Fees, decisions and grounds for refusal
Relay may require payment of the request fee and any access, search, preparation, reproduction or deposit fees prescribed under PAIA before processing or granting access to a request. The current fee schedule is available from the Information Regulator.
Relay will ordinarily notify the Requester of its decision within 30 days after receiving a valid request. Relay may extend this period once for no more than a further 30 days where PAIA permits an extension, and will notify the Requester of the extension and reasons.
If access is granted, Relay will provide access in the requested form where reasonably possible and may withhold the Record until any prescribed fee is paid.
Access may be refused where PAIA requires or permits refusal, including where disclosure would:
unreasonably disclose Personal Information about a third party;
disclose confidential commercial information or trade secrets of a third party or Relay;
breach a duty of confidence owed to a third party;
endanger the life or physical safety of a person or compromise the security of property or systems;
disclose legally privileged material;
prejudice Relay in commercial competition or reveal research information protected by PAIA; or
otherwise fall within a mandatory or discretionary ground for refusal in PAIA.
Where a Record cannot be found or does not exist, Relay will deal with the request in accordance with PAIA. Where only part of a Record is protected, Relay will consider whether the remaining part can reasonably be severed and disclosed.
If a request is refused, the notice will state adequate reasons for the refusal, identify the applicable provisions of PAIA without revealing protected contents and explain the available complaint or court process.
Complaints and remedies
There is no compulsory internal appeal against a decision of a private body. A Requester or affected third party may, after complying with PAIA’s requirements, lodge a complaint with the Information Regulator or apply to a competent court for appropriate relief.
A complaint to the Information Regulator must be made on the prescribed Form 5 and submitted within the period prescribed by PAIA, generally within 180 days after the relevant decision, failure to respond or other conduct complained of.
PAIA complaints may be submitted through the Information Regulator’s eServices portal or to PAIAComplaints@inforegulator.org.za. A complainant should retain a copy of the Form 2 request, Relay’s response and relevant correspondence.
Availability and updating of this Manual
This Manual is available:
on the Website at www.relayaudit.com/legal/paia-manual;
at Relay’s principal place of business for inspection during normal business hours;
from Relay’s Information Officer upon request, subject to any reasonable prescribed reproduction fee; and
to the Information Regulator upon request.
This Manual is available in English. Relay will make the Guide available at its office in English and the second official language identified in clause 4.5.
Relay will review and update this Manual when reasonably necessary to reflect material changes to its Records, Processing activities, contact information or legal obligations.
Contact details of the Information Officer
| Contact item | Details |
|---|---|
| Name | Neil De Kock |
| Designation | Information Officer |
| Registered address | 24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001 |
| Street address | 24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001 |
| Postal address / mailbox | 24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001 |
| Email address | neil@relayaudit.com |
| Telephone number | +27 71 519 2159 |
| Website | www.relayaudit.com |