Kustomcode Logo
Statutory Compliance Manual

POPIA & PAIA Section 51 Manual

Prepared in accordance with Section 51 of the Promotion of Access to Information Act (PAIA Act 2 of 2000) and giving effect to the Protection of Personal Information Act (POPIA Act 4 of 2013).

Responsible Entity: Zash Holdings Pty Ltd t/a KustomcodeReg: FPB8/2026/435135Effective Date: 1 January 2026

1. Organization & Information Officer Details

Pursuant to Section 51(1)(a) of PAIA and Section 17 of POPIA, the designated Information Officer coordinates all statutory access requests and data subject rights communications:

Registered Legal Entity: Zash Holdings Pty Ltd trading as Kustomcode
Company Registration: FPB8/2026/435135
Designated Information Officer: Data Protection Officer / Head of Legal Engineering
Physical Address: Polokwane, Limpopo / Sandton, Gauteng, Republic of South Africa
Official Email: contact@kustomcode.xyz / legal@kustomcode.xyz
Website: https://kustomcode.xyz

2. Guide on How to Use PAIA (Section 51(1)(b))

The Information Regulator of South Africa has compiled a comprehensive guide containing information on how to exercise any right contemplated in PAIA and POPIA.

The Guide is available in all official languages on the Information Regulator website (https://inforegulator.org.za) or can be inspected at the offices of the Information Regulator during standard business hours.

3. Schedule of Records Held by Kustomcode

We maintain records across the following operational domains:

Statutory & Governance Records
  • Memorandum of Incorporation (MOI)
  • Director minutes and CIPC filings
  • Tax returns and VAT records (SARS compliance)
Customer & Telematics Data
  • Developer API token allocations & quota logs
  • KustomFleet dispatch and ePOD records
  • PayFast & payment confirmation tokens

4. POPIA Processing Notice & Safeguards

Under POPIA Section 17, Kustomcode processes personal information only where statutory justification exists (consent, contractual necessity, or legitimate operational interest):

Technical & Organizational Security Safeguards
  • End-to-end TLS 1.3 encryption and AES-256 field-level database encryption.
  • Zero-Knowledge biometric handling (immediate in-memory burn).
  • Strict multi-tenant schema partitioning and automated quarterly security audits.
  • Continuous intrusion detection and rate-limiting at edge gateways.

5. Data Subject Access Request (DSAR) Procedure

To request access to, objection of (POPIA Form 1), or correction/deletion of (POPIA Form 2) personal records:

  1. Submit a written request to contact@kustomcode.xyz specifying the nature of the records sought.
  2. Provide proof of identity (valid South African Smart ID or International Passport).
  3. The Information Officer will evaluate the request and respond within thirty (30) calendar days as prescribed by PAIA Section 56.

6. Information Regulator Contact Details

If a data subject is not satisfied with our response or handling of personal information, complaints may be lodged directly with the South African Information Regulator:

Entity: The Information Regulator (South Africa)
General Inquiries: enquiries@inforegulator.org.za
POPIA Complaints: POPIAComplaints@inforegulator.org.za
PAIA Complaints: PAIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za