PAIA Manual
Version: 1.0
Effective date: 18 August 2026
Last reviewed: 18 August 2026
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, as amended (“PAIA”).
1. Introduction and purpose
PAIA gives effect to the constitutional right of access to information held by public and private bodies where that information is required for the exercise or protection of rights. This Manual explains the records held by SMSFlow (Pty) Limited (“SMSFlow”), how to request access, the applicable contacts and forms, and how SMSFlow processes personal information.
This Manual must be read with SMSFlow’s Privacy Notice, Terms of Service, Messaging Acceptable Use Policy and, where applicable, Data Processing Addendum.
2. Particulars of the private body
- Legal name: SMSFlow (Pty) Limited.
- Registration number: 2024/051424/07.
- Status: private company incorporated in the Republic of South Africa.
- Physical, postal and domicilium address: 12 Waterford Office Park, Waterford Drive, Maroeladal, Fourways, 2191, South Africa.
- Telephone: +27 (0) 10 823 5194.
- Website:
https://www.smsflow.co.za. - General enquiries: [email protected].
- Support: [email protected].
- PAIA and privacy enquiries: [email protected].
3. Information Officer
Information Officer: Eugene Smit, CTO, [email protected].
Deputy Information Officer: Lorette du Plooy, Group Head of Legal, [email protected].
PAIA requests must be submitted to the Information Officer using the prescribed procedure and Form 2. SMSFlow may require sufficient proof of identity and, where applicable, proof of authority to act for another person.
4. Information Regulator’s PAIA Guide
The Information Regulator has published a guide explaining how to use PAIA and POPIA. The guide is available in the official languages and can be obtained from the Information Regulator’s PAIA page at https://inforegulator.org.za/paia/ or requested from the Information Officer.
Information Regulator contact details: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; telephone 010 023 5200; and [email protected].
5. Records available without a formal PAIA request
Subject to the relevant website terms and access controls, the following may be available without a formal request:
- public website, product, service and pricing information;
- Terms of Service, Privacy Notice, Messaging Acceptable Use Policy and Data Processing Addendum;
- this PAIA Manual, the subprocessor register and data-deletion instructions;
- public support and developer documentation; and
- other information SMSFlow elects to make publicly available.
Listing a category does not make every record in that category automatically available.
6. Records held by SMSFlow
SMSFlow may hold the following records:
- corporate and governance records, including incorporation, shareholder, director, governance, policy and regulatory records;
- customer and account records, including administrators, users, roles, permissions, authentication, subscriptions, orders, communications, support, complaints and training;
- contractual and commercial records, including agreements, Order Forms, Service Requests, schedules, statements of work, service levels, prices, invoices, payment status, refunds, billing disputes and provider reconciliation;
- financial and tax records, including accounting, purchase orders, tax, payment status, balances and reports;
- employee and recruitment records, subject to employment, privacy and confidentiality restrictions;
- supplier, partner and service-provider records, including contracts, due diligence, payment, assessment, access, correspondence and compliance;
- messaging and communications records, including sender and recipient identifiers, contacts, consent, suppressions, messages, templates, campaigns, schedules, delivery events, replies, conversations, media, automations, assignments and webhooks;
- information-technology and security records, including access controls, API use, audit logs, privileged actions, telemetry, incidents, abuse indicators, diagnostics, backups, disaster recovery, tests and releases;
- legal, compliance and regulatory records, including legal advice, disputes, litigation, audits, investigations, incidents, risk and intellectual property; and
- product, technical and operational records, including specifications, integrations, administration, performance, continuity, releases and development.
Records subject to legal professional privilege or another lawful restriction may be withheld.
7. Records held under other legislation
Where applicable, SMSFlow creates or retains corporate, tax, accounting, employment, health and safety, privacy, access-to-information, consumer, electronic-transaction, telecommunications and financial-control records under legislation including:
- PAIA and the Protection of Personal Information Act 4 of 2013 (“POPIA”);
- the Companies Act 71 of 2008 and Electronic Communications and Transactions Act 25 of 2002;
- the Consumer Protection Act 68 of 2008;
- the Income Tax Act 58 of 1962 and Value-Added Tax Act 89 of 1991;
- the Basic Conditions of Employment Act 75 of 1997, Labour Relations Act 66 of 1995, Employment Equity Act 55 of 1998, and Occupational Health and Safety Act 85 of 1993; and
- other applicable telecommunications, tax, employment, privacy, regulatory and industry legislation.
The inclusion of legislation does not mean every record is automatically available.
8. Processing of personal information
SMSFlow generally acts as responsible party for its website, prospects, accounts, users, contracts, billing, suppliers, authentication, security, audit, support, service quality, product analytics, operations, service announcements and lawful direct marketing.
Where a customer uploads contacts, creates templates or campaigns, sends messages, manages conversations, configures automation or connects external systems, that customer generally determines the purpose and recipients. SMSFlow generally processes that Customer Data as operator on the customer’s documented instructions under the Data Processing Addendum.
9. Data subjects and personal-information categories
Data subjects may include website visitors; prospects; customers; administrators and authorised users; developers; billing and support contacts; message recipients and conversation participants; job applicants and personnel; suppliers and partners; shareholders and directors; professional advisers; and persons involved in security, abuse, complaints, audits or regulatory matters.
Personal information may include identity and business details; contact information; account identifiers; roles, permissions and authentication records; order, subscription, billing, tax, invoice and transaction information; contacts, custom fields, consent and suppression evidence; message, template, campaign, media, conversation, assignment, automation and delivery information; IP address, browser, device, session, cookie, usage, API, webhook, security, audit, error and incident information; and recruitment, supplier and corporate information.
10. Purposes of processing
SMSFlow may process personal information to administer accounts, users, permissions, contracts and subscriptions; provide SMS, WhatsApp and supported messaging functionality; validate, queue, route, send and receive messages; manage campaigns, templates, conversations and automation; record consent and enforce suppressions; authenticate users; secure and audit the Services; prevent fraud and abuse; investigate incidents; provide support; diagnose and improve the Services; administer billing and provider reconciliation; comply with law; establish or defend rights; and administer recruitment, suppliers and SMSFlow’s own lawful marketing.
11. Recipients and cross-border processing
Where necessary and lawful, information may be processed by authorised SMSFlow and Flownamix group personnel; mobile networks and messaging aggregators; Meta and WhatsApp; cloud, storage, identity, security, monitoring, backup, email, support and payment providers; professional advisers, accountants, auditors and insurers; customer-selected applications, integrations and webhook destinations; regulators, courts and law-enforcement authorities; and other parties permitted by law.
Primary SMSFlow platform infrastructure is operated in South Africa where configured. Some account, support, identity, security, payment and WhatsApp information may also be processed in the United States, the European Economic Area, or other countries in which the relevant contracted provider operates. The categories transferred depend on the selected Service and may include account identifiers, contact and messaging information, provider events, support data and security telemetry. SMSFlow applies an appropriate POPIA section 72 transfer condition and maintains further provider information in its subprocessor register.
12. Security measures
SMSFlow implements safeguards appropriate to the nature and risk of processing, which may include tenant isolation; server-side authorisation; least-privilege access; authentication; encryption in transit and at rest where supported; secure credential and secret storage; audit logging; monitoring; backups; incident response; secure development; and technical integrity controls.
SMSFlow is included within the Flownamix group’s ISO/IEC 27001:2022 certification, as stated in the applicable certificate and certified scope. No security measure eliminates all risk.
13. Retention
SMSFlow retains records only as long as reasonably required for their purpose, the contract, law, disputes, security, audit, billing, suppression or reconciliation. The standard schedule is:
- accounting, invoice, purchase-order and tax records: seven years;
- customer account and administrative records: five years after the last purchase, or longer where law requires;
- supplier records: seven years after the relationship ends;
- contracts: agreement term plus the period required for prescription, disputes, legal holds and statutory obligations;
- contacts and prospects: 24 months from the last meaningful interaction or unsuccessful engagement;
- consent and suppression evidence: five years;
- messages, delivery events, conversations and inbox content: 12 months;
- media and message attachments: 90 days;
- templates: life of template plus 24 months;
- provider-operation history: 24 months;
- raw webhooks, failures and dead letters: 90 days;
- normalised events and outbox or inbox records: 12 months;
- standard security telemetry: 12 months;
- security-incident evidence: 24 months after closure;
- audit logs and privileged administrative actions: 24 months;
- backups and disaster-recovery copies: rolling 90 days;
- test and harness evidence: 90 days; and
- test evidence supporting a release, incident or audit finding: 24 months.
SMSFlow is implementing this approved schedule through automated controls and documented operational procedures. Until a relevant automated control is available, the period is applied through an appropriate operational process. A record may be kept longer for law, legal hold, investigation, litigation, statutory recordkeeping, security, audit or suppression. Residual copies may remain in secure backups until expiry or overwrite.
14. Requesting access
A requester must complete prescribed PAIA Form 2, available at https://inforegulator.org.za/paia-forms/, and submit it to [email protected] or the physical address in section 2.
The request must identify the requester and requested record, specify the required form of access and contact details, identify the right to be exercised or protected, and explain why the record is required for that purpose. If acting for another person, the requester must provide proof of authority.
SMSFlow will ordinarily decide a properly submitted request within 30 calendar days, subject to an extension permitted by PAIA. The requester will receive the prescribed outcome and fee notice where applicable.
15. Fees and refusal
Prescribed request, search, preparation, reproduction, copying and delivery fees may apply. SMSFlow may refuse access only where PAIA permits or requires, including to protect third-party personal information, confidential information, trade secrets, commercial information, legal privilege, safety, security, investigations, legal proceedings and other protected interests. Each request is considered on its facts.
16. Complaints and remedies
A requester dissatisfied with a refusal or failure to respond may lodge a complaint with the Information Regulator using PAIA Form 5, available at https://inforegulator.org.za/paia-forms/ or through the Regulator’s eServices portal. A complaint concerning a private body must ordinarily be lodged within 180 days of the refusal, non-response or other decision, subject to PAIA.
PAIA complaints: [email protected]. General enquiries: [email protected]. Telephone: 010 023 5200. Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.
17. Availability, updates and approval
This Manual is available at https://smsflow.co.za/paia/, for inspection at SMSFlow’s principal place of business by reasonable arrangement, on request where required by law, and to the Information Regulator on request.
SMSFlow may update it to reflect changes in law, records, business activities, processing or procedures. The published copy shows the current version and effective date.
This Manual is approved for and on behalf of SMSFlow (Pty) Limited.
