PAIA manual
Manual in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, read with section 17 of the Protection of Personal Information Act 4 of 2013. Luma Analytics (Pty) Ltd trading as Luma Automations. Version 1.1, 26 September 2026.
1. Contact details
| Private body | Luma Analytics (Pty) Ltd, registration number 2026/428485/07, trading as Luma Automations |
|---|---|
| Head of the body and Information Officer | Terence Swart, Director |
| Postal and physical address | Ballito, KwaZulu-Natal, South Africa (online business; contact via email or WhatsApp below) |
| Telephone | 083 436 9104 |
| [email protected] | |
| Website | askluma.co.za |
2. The guide from the Information Regulator
The Information Regulator has published a guide, in each official language, on how to use the Act. It is available from the Regulator at inforegulator.org.za, by email at [email protected], or from its offices at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.
3. Records available without a request
This manual, and the company's privacy notice at /privacy, are available on this website without a formal request. Company registration details are available from the Companies and Intellectual Property Commission.
4. Records available in terms of other legislation
Records are kept as required by the Companies Act 71 of 2008, the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991 (where applicable), the Basic Conditions of Employment Act 75 of 1997 (where applicable), and the Protection of Personal Information Act 4 of 2013. They are available to the persons those Acts entitle, in the manner those Acts provide.
5. Records held, by subject and category
| Company records | Incorporation documents, registers, resolutions, financial statements, tax returns |
|---|---|
| Client records | Agreements, invoices, correspondence, contact details of client staff, access lists for tools the company hosts |
| Supplier records | Agreements and data processing terms with service providers, invoices |
| Operational records | Source code, deployment records, operational logs (metadata only: time, signed-in user, request size, outcome), the POPIA operating documents described in section 8 |
| Personal information | As described in section 7 |
6. How to request access to a record
A request must be made on the prescribed form (Form 2 in the regulations under the Act, available from the Information Regulator), sent to the Information Officer at the address in section 1, and must give enough detail to identify the record and the requester, state which right the requester is exercising or protecting and why the record is needed to do so, and say how the requester would like to receive it. A requester acting for someone else must show authority to do so.
The Information Officer will respond within 30 days of receiving a request. The prescribed request fee and, where applicable, the access fee set in the regulations apply; a personal requester (a person requesting their own personal information) pays no request fee. If a request is refused, the response will say why, and how to appeal or complain to the Information Regulator.
7. Processing of personal information
| Purpose | To respond to enquiries; to conclude and perform client agreements; to invoice and keep the records tax law requires; to control access to tools the company hosts for clients; and, as an operator on a client's instruction, to process the client's documents through those tools. |
|---|---|
| Categories of data subject | Prospective and current clients and their staff; suppliers; and, as an operator only, the customers of clients whose documents pass through a tool the company hosts. |
| Categories of information | Names, business contact details, correspondence, agreements, invoices and payment records. For operator processing: whatever the client's document contains, which the company does not retain. |
| Recipients | Hosted email, calendar and code services used to run the company. For operator processing: the sub-operators named in the client's agreement, currently Cloudflare, Inc. and Anthropic PBC. |
| Transfers outside the Republic | Yes, to service providers chiefly in the United States, each bound by data processing terms that provide substantially similar protection, as section 72 of the Act permits. |
| Security measures | Encryption in transit throughout; credentials held server-side as secrets; named-user access with single-use codes; no storage or logging of document content; version-controlled deployment; a quarterly control check. Recorded in detail in the operator agreement with each client. |
8. Other information
The company keeps a processing register, an Information Officer record, a security compromise response procedure and a data subject request procedure, reviewed annually. The privacy notice at /privacy explains the same processing in plain language.
9. Availability of this manual
This manual is available on this website, and a copy can be requested from the Information Officer. It is available in English.