Olerin
ServicesAbout
Log inBook a call
Legal

PAIA / POPIA Manual

Beacon Information Security (Pty) Ltd t/a Olerin Cyber · Registration No. 2025/973860/07

Date of compilation: 17 August 2026 · Date of last revision: 17 August 2026

On this page
1. Definitions and Abbreviations2. Purpose of This Manual3. Key Contact Details4. Guide on How to Use PAIA5. Records Available Without a Formal Request6. Records Available Under Other Legislation7. Description of Records Held8. Processing of Personal Information (POPIA)9. Availability of This Manual10. Requests, Forms, and Fees11. Right to Lodge a Complaint

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (“PAIA”), read with the Protection of Personal Information Act 4 of 2013 (“POPIA”).

1. Definitions and Abbreviations

TermMeaning
“the Company” / “Olerin Cyber”Beacon Information Security (Pty) Ltd t/a Olerin Cyber
“PAIA”Promotion of Access to Information Act 2 of 2000, as amended
“POPIA”Protection of Personal Information Act 4 of 2013
“IO”Information Officer
“DIO”Deputy Information Officer
“the Regulator”The Information Regulator (South Africa)
“Republic”Republic of South Africa
“SPI”Special personal information, as defined in section 26 of POPIA

2. Purpose of This Manual

This manual is compiled in terms of section 51 of PAIA to help requesters exercise their constitutional right of access to information held by Olerin Cyber, and in terms of section 51(1)(c) of PAIA (as amended by POPIA) to describe how Olerin Cyber processes personal information as a responsible party.

3. Key Contact Details

Information Officer: Clive Gavin Conlon
Deputy Information Officer: Ross Pollock
Postal/Physical Address: Olive Wood Office Park, 100 Grosvenor St, Witfontein, Kempton Park, 1619
Email: info@olerincyber.com
Telephone: +27 10 882 2170

A Deputy Information Officer has been appointed to assist the Information Officer in the performance of duties under PAIA and POPIA. Olerin Cyber operates on a fully remote basis; the address above is the registered principal place of business for purposes of public inspection of this manual.

4. Guide on How to Use PAIA

The Information Regulator has published a guide, as contemplated in section 10 of PAIA, on how to exercise rights under PAIA and POPIA, available at: https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Guide-English_20210905.pdf

A requester wishing to access a record held by Olerin Cyber must submit a request using the prescribed form (Form 2, as set out in the PAIA Regulations) to the Information Officer at the contact details above. The Information Officer will respond within the timeframes prescribed by PAIA.

5. Records Available Without a Formal Request

Olerin Cyber voluntarily makes the following available without requiring a formal PAIA request:

  • General service and company information published on olerincyber.com
  • Publicly available marketing and blog content

6. Records Available Under Other Legislation

Certain records held by Olerin Cyber may also be accessed via mechanisms provided under other legislation, including but not limited to the Companies Act 71 of 2008, the Tax Administration Act 28 of 2011, and the Basic Conditions of Employment Act 75 of 1997.

7. Description of Records Held

7.1 Client and Engagement Records

  • Client contracts and service level agreements
  • Security assessment and audit reports
  • Incident response reports
  • Forensic investigation artifacts and reports
  • Reported/escalated suspicious emails (e.g. phishing reports submitted by client staff)
  • Security monitoring telemetry and activity logs (e.g. SIEM data, network and endpoint activity)

7.2 Corporate and Financial Records

  • Financial and billing records
  • Vendor and supplier contract details

7.3 Human Resources Records

Olerin Cyber currently operates with three shareholders and no employees. This manual is drafted to also cover employee records for continuity as the Company grows, and includes:

  • Recruitment and onboarding records
  • Payroll and employee contract records

7.4 Marketing, Booking, and Website Records

  • Website enquiry and contact form submissions
  • Appointment booking data (processed via Zapier, populated into Microsoft 365)
  • Bot-verification logs (Cloudflare Turnstile)
  • Security awareness training records (Wizer learning management system)

8. Processing of Personal Information (POPIA)

8.1 Categories of Data Subjects

  • Client organisations’ employees and authorised contacts
  • Olerin Cyber’s own personnel (shareholders, and employees once appointed)
  • Prospective clients and website visitors
  • Job applicants
  • Vendor and supplier contacts
  • Where forensic investigations are conducted under litigation hold, individuals whose personal information incidentally appears within data under investigation

8.2 Categories of Personal Information Processed

  • Standard categories: names, contact details, employment/role details, billing information
  • Technical/security categories: IP addresses, device identifiers, network and endpoint activity logs, email metadata and content relating to reported phishing/suspicious emails
  • Special personal information (section 26 of POPIA): not actively collected. Such information may be incidentally encountered only during forensic investigations conducted under litigation hold, and is retained by Olerin Cyber only where directly relevant to the investigation concerned. It is not otherwise retained.

8.3 Purpose of Processing

  • Delivery of security monitoring, incident response, and forensic investigation services
  • Human resources and payroll administration
  • Marketing, lead management, and appointment scheduling
  • Website functionality and bot/spam protection
  • Security awareness training administration

8.4 Recipients of Personal Information

Personal information may be shared with the following categories of recipients in the course of service delivery: Microsoft (Microsoft 365), Odoo, Zapier, Cloudflare, Wizer, and other subcontractors or professional advisors engaged by Olerin Cyber from time to time.

8.5 Cross-Border Transfers

The majority of personal information processed by Olerin Cyber is hosted within the European Union. Security awareness training records, including learning management system (LMS) data, are hosted in the United States by Wizer. Any transfer of personal information outside the Republic is subject to contractual and technical safeguards consistent with section 72 of POPIA.

8.6 Security Safeguards

Olerin Cyber applies technical and organisational measures appropriate to the nature of the personal information processed, including access controls, monitoring, and encryption where applicable.

9. Availability of This Manual

This manual is available on Olerin Cyber’s website (olerincyber.com) and a copy is available for inspection, free of charge, at the Company’s registered address during normal business hours by prior arrangement, given its fully remote operating model.

10. Requests, Forms, and Fees

Requests for access to records must be submitted using the prescribed PAIA form to the Information Officer. No request fee is currently charged for a standard request. Olerin Cyber reserves the right to charge a reasonable request and/or reproduction fee, calculated in accordance with the fee structure prescribed under PAIA, for requests involving a large volume of records or extensive search and retrieval effort.

11. Right to Lodge a Complaint

There is no internal appeal procedure available against a decision of a private body under PAIA; section 74 (internal appeal) applies only to public bodies. A requester who is refused access to a record, or who believes Olerin Cyber has not complied with PAIA, may lodge a complaint with the Information Regulator in terms of section 77A of PAIA within 180 days of the decision. A requester may only approach a court for relief in terms of section 82 of PAIA after first exhausting this complaints procedure, as required by section 78 of PAIA.

Separately, a data subject who believes their personal information has been processed in a manner inconsistent with POPIA may lodge a complaint with the Information Regulator in terms of section 74 of POPIA.

Contact details for the Information Regulator: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: inforeg@justice.gov.za | POPIAComplaints@inforegulator.org.za

Olerin
Take the free health checkBook a call
Contact
26 7th Ave, Edenvale, Johannesburg, 1609
+27 10 882 2170info@olerincyber.com
Connect
LinkedIn
Facebook
X (Formally Twitter)
Google Business
Instagram
Services
Security Risk AssessmentManaged SecurityAwareness Training
Resources
Free Health CheckFree tools (soon)Insights (soon)
2026 © Beacon Information Security (Pty) Ltd t/a Olerin Cyber. All rights reserved.
Privacy PolicyCookie noticeTerms of UsePAIA Manual