Company details
K2026564435 (South Africa) (Pty) Ltd, enterprise number 2026/564435/07, trading as “Relay Audit” (herein “Relay”, “we”, “our” or “us”), is a private company incorporated in accordance with the laws of the Republic of South Africa.
registered address
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
principal place of business
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
Relay’s Information Officer is Neil De Kock.
Information Officer email address
Information Officer telephone number
Relay’s manual prepared under the Promotion of Access to Information Act, 2000 (“PAIA Manual”) is available at www.relayaudit.com/legal/paia-manual.
Definitions
In this Privacy Policy, unless the context indicates otherwise:
“AI Service”
means an approved artificial-intelligence model or provider, accessed through the Aggregator, used to perform a task selected by an auditor or to build or update the Knowledge Graph.
“Aggregator”
means the approved third-party artificial-intelligence model aggregator (gateway) through which Relay accesses AI Services under a single data-processing arrangement, rather than contracting with each AI provider separately.
“Audit Firm”
means an audit firm that uses Relay in connection with an audit engagement.
“Data Subject”
has the meaning assigned to that term in POPIA.
“Knowledge Graph”
means the structured map Relay builds and maintains about the audit information made available to it — including metadata such as file names, sizes and types, content summaries, and the relationships between files — but not the source files themselves.
“Operator”
has the meaning assigned to that term in POPIA.
“Personal Information”
has the meaning assigned to that term in POPIA.
“POPIA”
means the Protection of Personal Information Act, 2013 and its subordinate legislation, as amended from time to time.
“Process”
has the same meaning as “processing” in section 1 of POPIA, and “Processed” and “Processing” shall be interpreted accordingly.
“Responsible Party”
has the meaning assigned to that term in POPIA.
“Special Personal Information”
has the meaning assigned to that term in POPIA.
“Website”
means www.relayaudit.com.
Purpose and scope
This Privacy Policy explains how Relay Processes Personal Information through its business operations, Website and audit-support application and gives effect to the transparency requirements of POPIA.
This Privacy Policy applies to Personal Information relating to:
visitors to the Website and persons who contact Relay or submit enquiries;
representatives and authorised users of Audit Firms;
suppliers, service providers, professional advisers and other business contacts;
job applicants and prospective personnel, where applicable; and
individuals whose Personal Information appears in audit files, source documents or supporting records selected by an authorised auditor for Processing through Relay.
This Privacy Policy must be read with the applicable customer agreement, data processing agreement, engagement-specific notice, consent or authorisation document, terms of use and PAIA Manual.
Relay’s role under POPIA
Relay acts as a Responsible Party where it determines the purpose and means of Processing Personal Information for its own business activities, including Website enquiries, customer administration, user accounts, access management, billing, recruitment, service security, diagnostic records and legal compliance.
For audit engagement information, the Audit Firm generally determines the purpose of the audit and the Processing to be performed. The Audit Firm is therefore generally the Responsible Party and Relay acts as its Operator.
When acting as Operator, Relay Processes Personal Information only with the knowledge and documented authorisation of the Audit Firm, treats it as confidential and does not Process it for an independent purpose.
The Audit Firm remains responsible for ensuring that the audit information is lawfully collected and made available for Processing and for giving any required notices or obtaining any required authorisations or consents.
Personal Information Processed
Depending on the context, Relay may Process the following categories of Personal Information:
names, surnames, identity or passport numbers, signatures, contact details, job titles and roles;
information concerning directors, officers, employees, contractors, customers, suppliers, account holders and other individuals appearing in audit records;
employment information, payroll information, financial and accounting records, bank or payment details, transaction information and other financial information;
trial balances, financial statements, prior-year and current-year workpapers, contracts, leases, invoices, source documents, supporting records, correspondence, audit planning and materiality information;
user-account information, access records, system information, diagnostic information, security-event records and audit logs;
event-level technical and operational records relating to the performance and use of the Relay application (“Service Telemetry”), which exclude the contents of audit files, source documents, prompts, Outputs or workbooks; and, where an Audit Firm enables the relevant functionality, input material and technical metadata relating to an instance in which the application did not perform as expected (a “Diagnostic Sample”);
commercial and administrative information, including contracts, correspondence, invoices, billing records and supplier information;
recruitment information, including CVs, qualifications, employment history and interview information, where applicable; and
Special Personal Information or Personal Information relating to children that is incidentally contained in audit files or supporting records lawfully made available by the Audit Firm.
Relay does not intentionally request or specifically collect Special Personal Information or Personal Information relating to children for an audit engagement unless it is necessary for the engagement and separately instructed in writing by the Audit Firm.
How Personal Information is collected
Relay may collect Personal Information:
directly from a person who contacts Relay, submits an enquiry, contracts with Relay, uses an account or applies for a position;
from the Audit Firm that appoints Relay and authorises users to use the application;
from files and folders that an authorised auditor uploads or makes available to Relay, or opens on the auditor’s device, for building or updating the Knowledge Graph or performing a selected task;
automatically from the application or Website in the form of limited account, access, diagnostic and security information;
from suppliers, service providers, professional advisers and business partners; and
from public records or publicly available sources where collection is lawful and relevant.
A person who provides Personal Information about another individual must be authorised to do so and must ensure that any notice required by law has been provided.
Purposes and lawful grounds for Processing
Relay Processes Personal Information only for lawful, specific and reasonable purposes, including to:
respond to enquiries and manage prospective customer relationships;
enter into, perform and administer contracts;
create and administer user accounts and authorised access;
provide, support, secure and maintain the Relay application;
monitor, secure, support, troubleshoot, evaluate and improve the Relay application using Service Telemetry and, where enabled by the Audit Firm, Diagnostic Samples;
receive, read, extract, organise, structure, transmit, transform and analyse audit information selected by the auditor, and build and maintain the Knowledge Graph (metadata, content summaries and relationships) about that information without retaining the source files;
compile draft audit workbooks, link figures to source records and identify exceptions, inconsistencies, missing information and matters requiring auditor review;
assist with sample selection where expressly instructed and in accordance with the Audit Firm’s methodology;
maintain service security, investigate faults, misuse or security Incidents and keep appropriate access and system logs;
administer billing, accounting, tax and business records;
comply with legal, regulatory, professional and contractual obligations;
establish, exercise or defend legal rights and claims;
recruit and evaluate prospective personnel, where applicable; and
send direct marketing where permitted by POPIA and other applicable law.
The applicable lawful ground may include consent, performance of a contract, compliance with a legal obligation, protection of a legitimate interest of the Data Subject or pursuit of Relay’s or a third party’s legitimate interests, subject to POPIA.
Where Personal Information is required to provide a service, administer an account, comply with law or protect service security, failure to provide it may prevent Relay from providing the relevant service or continuing the relationship.
Audit Processing and the Knowledge Graph
Relay operates on a hybrid basis. It does not retain the source audit files, source documents or generated workbooks, whether on the auditor’s device or centrally. Instead, Relay builds and maintains the Knowledge Graph — structured metadata, content summaries and the relationships between the files made available to it. Relay retains only the Knowledge Graph, together with limited account, configuration, diagnostic, access and security information, which are hosted with a reputable cloud provider under appropriate technical and organisational safeguards, encrypted, access-controlled and logically segregated per Audit Firm, and retained and deleted in accordance with the Retention and deletion section below. Where any such information is stored or processed outside South Africa, that transfer will comply with section 72 of POPIA. Relay will give the Audit Firm prior written notice of any material change to the hosting region, and will confirm the current hosting location to the Audit Firm on request.
Relay operates through two processes.
Building and updating the Knowledge Graph: an authorised auditor makes audit files available to Relay, which reads and analyses them — including by transmitting the minimum content reasonably required to an AI Service through the Aggregator — to derive the Knowledge Graph, and does not retain the source files afterwards.
Using the application: an authorised auditor opens an audit file locally and, where an artificial-intelligence function is invoked, Relay consults the Knowledge Graph, compiles only the information needed and transmits the minimum content reasonably required to an AI Service through the Aggregator, returning the output to the user. Any changes to files are processed under 8.2.1 to update the Knowledge Graph.
Relay personnel may access the contents of audit files, source documents, prompts, outputs or workbooks only under role-based, least-privilege and audited access controls, and strictly as necessary to provide, secure or support the service.
Only the minimum content reasonably required to perform the task selected by the auditor, or to build or update the Knowledge Graph, is transmitted to an AI Service through the Aggregator for live Processing, on a zero-retention basis.
The workbooks and other outputs are tools used and reviewed by auditors. Relay does not issue or sign an audit opinion, reach a final audit conclusion, exercise professional judgement or replace the Audit Firm’s methodology, review procedures or quality-control processes.
Artificial-intelligence Processing
Relay reaches AI Services through the Aggregator, which routes each request to an approved AI provider. All prompts, inputs and outputs submitted to an AI Service must be Processed on a zero-retention basis. They may not be stored by the AI Service or the Aggregator after inference and may not be used to train, retrain, fine-tune or otherwise improve an artificial-intelligence model.
Artificial-intelligence inference information is not backed up by Relay or the approved AI Service.
Relay does not use raw or identifiable audit engagement information for marketing, profiling, product development, testing, demonstrations, AI-model training or any other secondary purpose.
Relay may retain and use information for product improvement only where the Audit Firm has given separate, express and prior written consent and the information has first been irreversibly de-identified in accordance with POPIA. Relay will not attempt to re-identify that information. On termination, Relay may irreversibly de-identify information instead of deleting it, in which case that information may be used only in aggregated or statistical form that does not identify the Audit Firm, its client or any Data Subject.
Production Personal Information will not be used in testing, development or demonstration environments unless separately authorised in writing by the Audit Firm and protected by safeguards no less stringent than those applying in production.
Where an Audit Firm enables the relevant functionality, an authorised user may share a Diagnostic Sample with Relay, either for a particular instance or automatically where the Audit Firm activates that setting. Relay uses Diagnostic Samples only to diagnose defects and to test, evaluate, benchmark and improve the application, and never to train, retrain or fine-tune any artificial-intelligence model. Each Diagnostic Sample is deleted within 90 days of receipt, save that Relay may before then convert it into a synthetic analogue containing no Personal Information, which may be retained indefinitely.
Sharing and Sub-Operators
Relay may disclose Personal Information only where reasonably necessary and authorised, including to:
authorised Relay personnel who require access to limited business, account, diagnostic or security information to perform their duties;
the Aggregator and approved AI providers that Process the minimum content transmitted for a selected task or to build or update the Knowledge Graph, and the cloud provider that hosts the Knowledge Graph;
service providers supporting email, accounting, security, communications, hosting and other business functions;
the relevant Audit Firm and its authorised users;
professional advisers, auditors and insurers where reasonably necessary; and
regulators, courts, law-enforcement bodies or other authorities where required or permitted by law.
Approved cloud and AI Sub-Operators currently include:
An approved cloud provider that hosts the Knowledge Graph and limited account, configuration, diagnostic, access and security information;
an approved third-party artificial-intelligence model aggregator (the Aggregator) that routes artificial-intelligence requests to approved AI providers under a single data-processing agreement and remains liable for them; and
the approved AI providers accessed through the Aggregator for live inference, which may take place outside South Africa (including the European Union, the United States, Asia or Africa).
Each Sub-Operator must be bound by written confidentiality, security and data-protection obligations appropriate to the Processing, and Relay remains responsible for managing its Sub-Operators in accordance with POPIA and the applicable agreement. Every AI Sub-Operator and endpoint used must meet two mandatory standards — zero data retention and no use of the data to train, retrain, fine-tune or otherwise improve any artificial-intelligence model — and Relay may add, change or remove Sub-Operators only with the Audit Firm’s prior written consent, provided each continues to meet both standards.
Cross-border Processing
Some artificial-intelligence inference takes place outside South Africa because the AI Services require large-scale computing capacity that is not currently available in South Africa. Relay reaches these AI Services through the Aggregator, on a zero-retention basis.
Only the minimum content reasonably required is transmitted outside South Africa, through the Aggregator to an approved AI provider. The approved destinations are the European Union, the United States, Asia or Africa, as set out in Relay’s Data Retention and Cross-Border Guide.
Each cross-border transfer must comply with section 72 of POPIA. Relay relies on two complementary bases (only one is required):
adequate protection — the Aggregator and each AI provider are bound by data-processing terms providing protection substantially similar to POPIA, with substantially similar onward-transfer restrictions, and the Aggregator remains liable for its sub-processors; and
consent — the Audit Firm obtains the informed consent of its client or the relevant Data Subjects to the cross-border processing described here and in Relay’s Data Retention and Cross-Border Guide.
Where informed consent is relied upon for an audit engagement, the Audit Firm is responsible for obtaining the required consent from its client or relevant Data Subjects before the information is supplied for Processing.
All offshore AI Processing is subject to zero retention. Prompts and outputs may not be stored after inference or used for model training or another secondary purpose.
The Knowledge Graph and limited account, configuration, diagnostic, access and security information are hosted with a reputable cloud provider under appropriate technical and organisational safeguards. Where any such information is stored or processed outside South Africa, that transfer will comply with section 72 of POPIA. Relay will give the audit firm prior written notice of any material change to the hosting region, and will confirm the current hosting location to the audit firm on request.
Retention and deletion
Relay does not retain the source audit files, source documents or generated workbooks. It retains only the Knowledge Graph and limited account, configuration, diagnostic, access and security information.
Relay retains the Knowledge Graph and related information only while the Audit Firm continues to use Relay. Because audit engagements may span several periods, this information is not deleted and re-uploaded each period. It is deleted when the Audit Firm stops using Relay, or earlier on the Audit Firm’s written request, and deletion is confirmed in writing. Relay’s deletion does not affect, and is not a substitute for, the Audit Firm’s own obligation to retain its audit working papers and file under the rules of IRBA and applicable law, which the Audit Firm keeps independently of Relay.
Content transmitted to an AI Service through the Aggregator is not retained after inference and is not included in backups.
Relay retains limited account, access, contractual, billing, diagnostic, security and audit-log information only for the period reasonably required for service operation, security, audit, legal and regulatory purposes.
Audit logs must not record the contents of source documents, AI prompts or AI outputs unless this is strictly necessary for security purposes and expressly authorised by the Audit Firm.
Any platform-level backup containing Personal Information must be encrypted, access-restricted and securely deleted in accordance with Relay’s retention and destruction procedures.
When Personal Information is no longer required or Relay is no longer authorised to retain it, Relay will delete, destroy or de-identify it, subject to any legal retention obligation or requirement to establish, exercise or defend a legal claim.
Security and security Incidents
Relay implements appropriate and reasonable organisational and technical safeguards designed to prevent loss, damage, unauthorised destruction, unlawful access and unlawful Processing of Personal Information.
The safeguards include, where appropriate:
encryption in transit and encryption at rest where Personal Information is stored by Relay or an approved cloud provider;
role-based and least-privilege access, unique credentials, strong authentication and multi-factor authentication where supported and appropriate;
prompt revocation of access when access is no longer required;
confidentiality obligations, background checks and privacy and information-security training for personnel granted access to Personal Information;
logging and monitoring of access and system activity for suspicious or unauthorised activity, with logs protected against unauthorised alteration;
periodic review of the effectiveness of organisational and technical safeguards;
business-continuity, disaster-recovery, remote-working, retention and incident-response procedures; and
appropriate contractual safeguards and security assurance for Sub-Operators.
The Aggregator and the approved cloud and AI providers maintain recognised assurance frameworks, including ISO 27001 and SOC 2 Type II where applicable. This does not represent that Relay itself holds those certifications.
No electronic system can be guaranteed to be completely secure. Relay does not warrant that a security Incident can never occur, but will take reasonable measures to prevent, identify, contain, investigate and remediate Incidents.
As soon as reasonably possible after becoming aware of an Incident arising from its Processing, Relay will notify the relevant Audit Firm in writing, provide available details, take reasonable steps to investigate and contain the Incident and cooperate with notifications required under section 22 of POPIA.
Website, cookies and direct marketing
The Website does not currently use cookies.
The Website or its hosting infrastructure may nevertheless generate limited technical and security records, including an IP address, request timestamp and access or error information, where reasonably necessary to deliver, maintain and protect the Website.
If Relay introduces cookies, analytics tools or similar tracking technologies, this Privacy Policy and any required cookie notice or consent mechanism will be updated.
Relay may send information concerning its services, pilots, cohorts, events or related developments where the recipient has consented or where the limited existing-customer exception in POPIA applies.
Electronic direct marketing will include a reasonable method to opt out. An opt-out will not prevent Relay from sending necessary service, contractual, security or administrative communications.
Special Personal Information and children’s information
The Website and Relay’s services are intended for audit firms and business users and are not directed at children.
Special Personal Information or Personal Information relating to children may appear incidentally in audit source documents selected by an Audit Firm.
When acting as Operator, Relay will Process such information only on the Audit Firm’s documented instructions and subject to applicable legal and contractual safeguards.
The Audit Firm must ensure that any required authorisation, consent or other lawful ground exists before such information is selected for Processing through Relay.
Data Subject rights and PAIA
Subject to POPIA and applicable limitations, a Data Subject may:
request confirmation of whether Relay holds Personal Information about them;
request access to Personal Information and information concerning its Processing;
request correction or deletion of inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained Personal Information;
request destruction or deletion of a record that Relay is no longer authorised to retain;
object, in the prescribed manner and on reasonable grounds, to certain Processing;
object at any time to Processing for direct marketing;
withdraw consent where Processing is based on consent, without affecting prior lawful Processing;
submit a complaint to the Information Regulator.
Relay may require sufficient information to verify the identity and authority of a requester before responding.
Data Subject rights are not absolute. Relay may refuse or limit a request where permitted or required by law, including where information must be retained for legal obligations, privileged communications, security or legal claims.
Where Relay acts as Operator, the Audit Firm will ordinarily deal with the Data Subject and the Information Regulator. Relay will promptly inform the Audit Firm of a request, will not respond except on the Audit Firm’s written instruction or as required by law, and will provide reasonable assistance.
Requests for access to records under PAIA must be submitted in accordance with Relay’s PAIA Manual and the prescribed forms.
Complaints and contact details
Questions, requests or complaints concerning this Privacy Policy or Relay’s Processing of Personal Information should first be directed to Relay’s Information Officer:
name
Neil De Kock
email address
telephone number
physical address
24 Albert Road, Tamboerskloof, Cape Town, Western Cape, 8001
A person may also lodge a complaint with the Information Regulator through its eServices portal or the prescribed POPIA complaint process.
The Information Regulator’s current contact details are:
physical address
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191;
telephone number
010 023 5200;
toll-free number
0800 017 160;
general enquiries
POPIA complaints
eServices portal
Changes to this Privacy Policy
Relay may update this Privacy Policy from time to time to reflect changes to its services, technology, legal obligations or Processing activities.
The current version will be published on the Website and will state the date on which it was last updated.