Legal
PAIA manual
Last updated
Download this document (.docx)
This is the manual of Splice Computers (Pty) Ltd, trading as Yielde, under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), as amended by the Protection of Personal Information Act 4 of 2013 (POPIA). PAIA gives you the right to ask a private body, such as Yielde, for a record it holds when you need that record to exercise or protect a right. This manual tells you what records we hold, how to ask for them, what it costs and how long it takes. It also explains how we process personal information. If you only want to know what personal information we hold about you, section 7.10 explains the simpler route under POPIA, and section 6 explains what to do if we hold your information for one of our customers.
1. About this manual
1.1 Who we are. Splice Computers (Pty) Ltd is a private company. Yielde is its trading name. Under PAIA we are a private body.
1.2 What we do. We sell two services:
- the Yielde Venue Enquiry Desk (the "Desk"), which answers the enquiries that reach a wedding or function venue's web form or enquiry email; and
- Yielde platform subscriptions (the "platform"), which give a business an AI automation workspace that we run for it.
1.3 Words we use.
- We, us, Yielde: Splice Computers (Pty) Ltd, trading as Yielde.
- Record: any recorded information we hold, in any form, such as a document, an email or a database entry. It does not matter who created it.
- Requester: the person who asks for access to a record.
- Regulator: the Information Regulator of South Africa, which oversees PAIA and POPIA.
- Information Officer: the person who deals with PAIA requests for us (section 2).
- Responsible party and operator: POPIA terms. The responsible party decides why and how personal information is processed. An operator processes it for the responsible party, under a contract.
- Normal business hours: Monday to Friday, 08:00 to 17:00 South African Standard Time, excluding South African public holidays.
2. Our contact details
Send PAIA requests, and questions about this manual, to our Information Officer.
| Item | Detail |
|---|---|
| Full name | Splice Computers (Pty) Ltd |
| Trading name | Yielde |
| Registration number | 2019/272712/07 |
| Director | Maria Cornelia Magrieta Botha |
| Head of the body and Information Officer | By law, the head of Splice Computers (Pty) Ltd is its Information Officer (PAIA section 1; POPIA sections 1 and 55) |
| Email for PAIA requests | support@yielde.dev |
| Phone | 063 611 2952 (from outside South Africa: +27 63 611 2952) |
| Street address | 55 York Street, George, Western Cape, 6529, South Africa |
| Postal address | 55 York Street, George, Western Cape, 6529, South Africa (the same as our street address) |
| Website | https://yielde.dev |
You may email your request, or post or deliver it to 55 York Street, George.
3. The Regulator's guide to PAIA
3.1 What it is. The Information Regulator publishes a guide on how to use PAIA and POPIA to get information (PAIA section 10). It explains your rights, how to make a request, the fees and what you can do if a request is refused.
3.2 Where to get it.
- Online, free. Download it from the Regulator's website in English (PAIA Guide, English) or Afrikaans (PAIA-gids, Afrikaans). The Regulator must make it available in every official language (PAIA Regulations, 2021, regulation 2(1)). Its PAIA page links the versions it publishes.
- From the Regulator. Ask the Regulator for a copy on Form 1 (Form 1, request for a copy of the guide). The Regulator may not charge for it.
- From us. Ask our Information Officer for copies in the official languages you need, on Form 1 (Form 1, request to an information officer). We may not charge for them. To inspect a printed copy of the Guide, in English or Afrikaans, at our registered head office during normal business hours, email support@yielde.dev or call 063 611 2952, and we will arrange a time. (PAIA Regulations, 2021, regulation 3.)
4. Records you can get without a PAIA request
4.1 We have not published a description under section 52 of PAIA. But these records are on our website, free, and you do not need to make a request:
- our company information and legal notices;
- our Terms of Service, Refund Policy, Cancellation Policy, Service Level Agreement, Acceptable Use Policy, Privacy Policy, Cookie Policy, Security page and Sub-processor register;
- our prices, on our pricing page;
- this manual.
4.2 Customers can also see some records about their own service without a request. Platform customers can see their account and subscription in their dashboard. Desk venues receive a copy of every reply by default, and every morning's 07:00 email lists the Desk's enquiries and drafts.
5. Records available under other laws
We keep records that other laws require. Some of those laws give certain people their own right to see or copy a record. Where another law gives you access, use that law. This list may not be complete.
| Law | Records |
|---|---|
| Companies Act 71 of 2008 | Company records, such as our memorandum of incorporation, our register of directors and our securities register. Our accounting records and annual financial statements, which we keep for the period section 24 of the Act requires. The Act gives some people a right to inspect or copy some company records. |
| Income Tax Act 58 of 1962 | Tax records |
| Value-Added Tax Act 89 of 1991 | VAT records, including tax invoices and credit notes |
| Tax Administration Act 28 of 2011 | Tax records, which we keep for the period the Act requires. |
| Protection of Personal Information Act 4 of 2013 | Records of the personal information we process. A data subject may ask whether we hold personal information about them and ask for a copy (section 7.10). |
| Electronic Communications and Transactions Act 25 of 2002 | The supplier information we must publish on our website (company information) |
| Consumer Protection Act 68 of 2008 | Written terms of an agreement with a consumer to whom the Act applies. The consumer is entitled to a free copy. |
6. Records we hold
This table lists the subjects on which we hold records, and the categories of records on each. Listing a record here does not mean we will give access to it. PAIA sets out when access may or must be refused (section 7.7).
| Subject | Categories of records |
|---|---|
| Company | Registration documents from the CIPC; our memorandum of incorporation; our register of directors and securities register; other records the Companies Act requires |
| Finance and tax | Tax invoices and credit notes; payment and refund records from Paystack; VAT records; tax returns; accounting records; annual financial statements |
| Platform customers | Accounts and sign-in records; plans, subscriptions and credit balances; orders; signed Data Processing Agreements and their signing records; onboarding material; support requests and correspondence; billing records |
| Desk venues | Signed pilot terms and operator agreements; set-up information (packages, prices, blocked dates, viewing times, languages and contact people); support log; confirmations of viewings (couples recorded by initials only); month-end reports; tax invoices and credit notes; correspondence |
| Information we process for our customers | Platform: our customers' leads', end-users' and callers' information in their workspaces, such as contact details, messages, call audio and transcripts. Desk: the enquiries a venue receives, the replies and drafts, delivery records and an audit log without message text |
| Sales and marketing | Messages sent through our website form and demo requests; for each venue we approach, the published enquiry address, where we found it, the date we wrote and the answer, including a list of venues that said no or asked us to stop; the demos we build for businesses (the business's name and website address, the demo's instructions, its expiry and its reply count) |
| Website and systems | Server logs; error reports; security and audit logs; system settings |
| Suppliers | Contracts and data-processing terms with our service providers; their invoices; correspondence |
| Legal | Our agreements; legal advice and correspondence; records of requests under PAIA and POPIA and our answers |
Records we hold for a customer. When we process personal information for a platform customer or a venue, that customer is the responsible party and we are its operator.
- If you want your own personal information from such a record. The quickest route is to ask that customer, because it is the responsible party (POPIA section 23).
- Platform. Send your request to that customer. Where we hold the data as operator, we will assist the customer to fulfil your access, correction or deletion request across our systems, as the Data Processing Agreement (DPA) requires.
- Desk. Reply to the email you received: it goes to the venue. If your request reaches us instead, we only acknowledge it, and we forward it to the venue within 2 working days.
- If you want to make a PAIA request. You can still make a PAIA request to us for any record we hold, including a record we hold for a customer. Our Information Officer decides it under this manual. Before we decide, we tell the customer, and any other person the record is about, and ask for their views. The time limits in section 7.8 then apply instead of those in section 7.6 (PAIA sections 56(1) and 71 to 73). We must refuse access where disclosure would breach our duty of confidence to the customer (PAIA section 65), or would unreasonably disclose another person's personal information (PAIA section 63). We will not refuse under PAIA section 63 if the person the information is about consents in writing (PAIA sections 63(2)(a) and 72), or if another exception in PAIA section 63(2) applies. We will not refuse under PAIA section 65 if the customer consents in writing to the disclosure (PAIA section 72(1)(b)). PAIA section 70 can require us to disclose a record despite either ground.
7. How to ask for a record
7.1 Use Form 2. Make your request on Form 2, the Regulator's request for access to a record (Form 2) (PAIA section 53; PAIA Regulations, regulation 7).
7.2 Send it to our Information Officer. Email it to support@yielde.dev, or post or deliver it to 55 York Street, George, Western Cape, 6529. Please mark it "PAIA request".
7.3 What your request must include (PAIA section 53(2)):
- enough detail for us to identify the record or records you want, and to identify you;
- the form of access you want (for example, a copy, or a chance to look at the record);
- a postal address or fax number in South Africa;
- the right you want to exercise or protect, and why you need the record for it (PAIA section 50(1));
- if you want to hear our decision in another way as well as in writing, how and where; and
- if you ask on behalf of someone else, proof of the capacity in which you ask.
7.4 Help with the form. If you cannot read or write, or have a disability, you may make your request orally. Our Information Officer will then fill in Form 2 for you and give you a copy (PAIA Regulations, regulation 7(2)).
7.5 Fees. Section 8 sets out the fees.
- Request fee. Before we process your request, we will ask you to pay the request fee of R140 (PAIA section 54(1)).
- Deposit. If finding and preparing the record will take more than 6 hours, we will ask for a deposit of not more than one third of the access fee (PAIA section 54(2); regulation 8(3)). If we refuse the request, we repay the deposit.
- Access fee. If we grant the request, you pay the access fee for copies, and for search and preparation time beyond the first hour (PAIA section 54(6)). We may hold back the record until you have paid (PAIA section 54(5)).
- We tell you our decision and the fees on Form 3 (PAIA Regulations, regulation 8(1)). You may complain to the Regulator, or apply to court, about a request fee or deposit (PAIA section 54(3)).
7.6 How long it takes.
- We decide as soon as reasonably possible, and within 30 days after we receive your request with the details in section 7.3 (PAIA section 56). If the record concerns someone else, the time limits in section 7.8 apply instead (PAIA section 56(1)).
- We may extend that period once, by up to 30 days, in the cases PAIA allows, for example a request for a large number of records, or if you agree in writing. If we do, we tell you within the first 30 days, with our reasons (PAIA section 57).
- If we do not decide in time, the law treats your request as refused (PAIA section 58).
7.7 When we may refuse. PAIA sets out the grounds on which a private body must or may refuse access (PAIA sections 62 to 70). They include protecting:
- the privacy of another person;
- another business's commercial information, and information given in confidence;
- someone's safety, and property;
- records that are privileged in legal proceedings; and
- our own commercial information, such as trade secrets.
If a record is partly protected, we give you the rest of it (PAIA section 59). If we refuse, we give you our reasons in writing.
7.8 If the record concerns someone else. If the record might hold another person's personal, commercial or confidential information, we must tell that person within 21 days of receiving your request. They have 21 days to object or to consent. We then decide within 30 days after telling them (PAIA sections 71 to 73). If we grant access after telling that person, we give you the record 30 days after we notify them of our decision, unless they complain to the Regulator or apply to court in that time (PAIA section 73(4)). This can add time.
7.9 If you disagree with our decision. You may complain to the Information Regulator within 180 days of our decision, in writing, on Form 5 (Form 5, complaint) (PAIA section 77A). After that complaints procedure, you may apply to court within 180 days (PAIA section 78). The Regulator's contact details are in section 11.
7.10 Asking only for your own personal information. This route is for personal information we hold as a responsible party (section 9). If we hold your information only for a venue or a platform customer, see the note at the end of section 6. You may ask us, free of charge, to confirm whether we hold personal information about you (POPIA section 23(1)(a)). You may ask for a copy or a description of it, including who has had access to it (POPIA section 23(1)(b)). If a fee applies, we give you a written estimate first. You may start with an email to support@yielde.dev. We will tell you if the law needs you to use Form 2 (POPIA section 25 applies PAIA section 53 to access requests). Our Privacy Policy explains this and your other rights.
7.11 Records for court cases. PAIA does not apply to a record requested for criminal or civil proceedings after those proceedings have started, if another law provides for access to it (PAIA section 7).
8. Fees
These are the fees for private bodies set by the PAIA Regulations, 2021 (Government Notice R. 757, Government Gazette 45057, 27 August 2021, Annexure B).
| Item | What it is for | Fee |
|---|---|---|
| 1 | Request fee, payable by every requester | R140.00 |
| 2 | Photocopy or printed black-and-white copy of an A4 page | R2.00 per page or part of a page |
| 3 | Printed copy of an A4 page | R2.00 per page or part of a page |
| 4 | Copy in a computer-readable form, on a flash drive you provide | R40.00 |
| 4 | Copy in a computer-readable form, on a compact disc you provide | R40.00 |
| 4 | Copy in a computer-readable form, on a compact disc we provide | R60.00 |
| 5 | Transcription of visual images, per A4 page | Outsourced; the fee depends on the service provider's quote |
| 6 | Copy of visual images | Outsourced; the fee depends on the service provider's quote |
| 7 | Transcription of an audio record, per A4 page | R24.00 |
| 8 | Copy of an audio record, on a flash drive you provide | R40.00 |
| 8 | Copy of an audio record, on a compact disc you provide | R40.00 |
| 8 | Copy of an audio record, on a compact disc we provide | R60.00 |
| 9 | Search for and preparation of the record, for each hour or part of an hour after the first hour | R145.00, up to a total of R435.00 |
| 10 | Deposit, if the search takes more than 6 hours | One third of the fee for items 2 to 8 |
| 11 | Postage, email or other electronic transfer | The actual cost, if any |
9. How we process personal information
This section gives the information about our processing that PAIA section 51(1)(c) requires. Our Privacy Policy and Sub-processor register give the full detail. Under POPIA, personal information includes information about an identifiable business, as well as about people.
9.1 Why we process personal information
- To answer enquiries and demo requests, and to arrange and give demos.
- To sort and score the messages sent through our website forms with our own enquiry-sorting automation, which uses an AI model, and to send an automatic acknowledgement.
- To ask a venue once whether it agrees to hear about a demo, and to keep a record of the answer so that we never contact a venue again after it says no or stop.
- To build demo AI assistants for businesses from their public websites, to answer the questions people type into a demo, and to limit how fast one visitor can send them.
- To answer the messages people type into a chat-widget preview of our own demo workspace.
- To provide the platform and the Desk to our customers: accounts, sign-in, set-up, support, reports and, for the Desk, the month-1 guarantee count.
- To process personal information for our customers, on their instructions, as their operator. On the platform, this is the automation, lead qualification, voice and AI Chat work each customer sets up. On the Desk, it is receiving a venue's enquiries, sending one reply to each, sending the venue its daily email and measuring the pilot.
- To take payments, issue tax invoices and credit notes, and keep tax and accounting records.
- To run the company and meet our duties under company law.
- To keep our website and services working and secure.
- To comply with the law, and to protect our legal rights.
9.2 Whose personal information we process, and what it is
| People and businesses | Personal information |
|---|---|
| Visitors to yielde.dev | Server logs (IP address, browser, the page requested and the time). On every page load, a short visit record sent to Sentry (a random visit ID, the time and the browser's identifying string; Sentry also sees the IP address); an error report when a page breaks; and page-load timing for a sample of visits (Sentry, EU region, Germany). The cookies needed to sign in to the dashboard. |
| People who contact us or ask for a demo | Name, email address, phone number, business or venue name, the details and message they send us, and the time and format of any demo. Website-form messages also pass through our own enquiry-sorting automation, which uses an AI model to score them and write short notes on them. Messages typed into a chat-widget preview of our own demo workspace. |
| Venues we approach about the Desk | The venue's name, the enquiry email address or enquiry form it publishes on its website, where we found it (and any words we quoted), the date we wrote and the venue's answer |
| Businesses we build a demo for | The business's name and website address; text from its public website, which can include names and contact details the website publishes, turned into the demo's instructions; a phone number or email address the demo refers people to |
| People who try a demo we built | The questions they type, and their IP address, which our website's server uses to count how many questions each visitor sends in a minute. The count is kept only in that server's working memory. The details in the "Visitors to yielde.dev" row apply too. |
| Platform customers and their staff | Sign-in email address and session records; plan, subscription and credit records; billing details; onboarding material; the signed Data Processing Agreement (signatory's name, email address, signature and signing record); support messages |
| Desk venues and their staff | Names, email addresses and phone numbers; the details the Paystack payment page collects (email address, phone number, the venue's registered name and billing address, and its VAT number if given); tax invoices and credit notes; signed pilot terms and operator agreement; support log; viewing confirmations (couples recorded by initials only); month-end reports |
| People whose information we process for platform customers | Our customers' leads, end-users and callers: contact details, message content, call audio and transcripts, caller identifiers |
| People who send enquiries to a venue that uses the Desk (couples, their families and planners, and function organisers) | Name, email address, phone number if given, event type, event dates, guest count, budget, questions, language and the full message text; the replies and drafts; delivery records. The Desk does not ask for special personal information, such as religion or health, has no field for it, and the AI model is told not to extract it. It can still appear in an enquirer's own words, and the whole message is sent to the AI model. The Desk does not ask for information about children either, but it can appear in a message in the same way. |
| Our director and shareholder, and people who work for us or sign agreements for us | Names and contact details; the details company law requires in our register of directors and securities register (such as full name, identity number, nationality and occupation); signatures on our agreements; records of their access to our systems |
| Our suppliers | Names and business contact details of the people we deal with; contracts; invoices |
| People who report a security weakness | Email address and the report |
Card details are handled by Paystack and are not stored by Yielde.
9.3 Who receives personal information
- Service providers who process it for us:
- hosting, databases and network services: Vercel, Supabase and Cloudflare;
- email: Resend, for the emails our systems send; Google Workspace (Gmail), for our business mailbox (it sends the consent requests we send by email, and holds the answers and our other correspondence); and Google's Gmail, for the inbox where we receive the Desk's alerts;
- payments: Paystack;
- error monitoring: Sentry;
- for our demos, chat-widget previews of our own demo workspace and our enquiry-sorting automation: Amazon Web Services in Cape Town, which runs our self-hosted AI gateway and the automation; OpenRouter, and the AI model provider it passes each call to; and Anthropic and OpenAI, which the gateway calls directly for embeddings, one low-cost model, and when OpenRouter fails;
- electronic signing of the platform Data Processing Agreement: Documenso, self-hosted;
- video calls for demos: Google Meet; and
- WhatsApp, for messages you choose to send us there, and for our messages with venues that use the Desk (for example about support or a viewing).
- Service providers who process our customers' data for us, as sub-processors. On the platform (Table A of our Sub-processor register): Amazon Web Services in Cape Town, Supabase, Vercel, Cloudflare, Resend, Paystack, Documenso (self-hosted), OpenRouter, OpenAI, Anthropic, Retell, Twilio and Sentry. On the Desk (Table B): Cloudflare; OpenRouter; Amazon Web Services (Amazon Bedrock) and, as the fallback, Google Cloud (Vertex AI), which run the Claude model and are reached only through OpenRouter; and Resend. Our Sub-processor register is the authoritative list.
- Our customers. When we act as an operator, the customer we act for receives its own data. For example, a venue receives its enquiries, the Desk's replies and drafts, and its daily email.
- Public authorities, such as the South African Revenue Service or the Information Regulator, when the law requires us to share information.
We do not sell personal information.
9.4 Transfers outside South Africa
Some personal information is processed outside South Africa. Desk data does not stay in South Africa. On the platform, tenant workspaces run on Amazon Web Services in Cape Town, but other platform services run outside South Africa. Our own systems also use providers in other countries. The table below shows where.
| Information | Where it goes outside South Africa |
|---|---|
| Yielde's own records (website, enquiries, accounts, billing and email) | The United States (Vercel and Resend); the European Union (Supabase in Ireland, and Sentry in Germany); and global networks run by Cloudflare, Google (Meet and Gmail) and WhatsApp. Paystack, which takes our payments, stores data on AWS in Ireland and may transfer data to other Paystack group companies under its binding corporate rules. |
| Our demos (the questions people type into a demo, the demo's instructions built from a business's public website, and visitors' IP addresses), chat-widget previews of our own demo workspace, and website-form messages scored by our enquiry-sorting automation | OpenRouter and the model providers it routes to (the United States and global); the United States (Anthropic and OpenAI, when our gateway calls them directly because OpenRouter failed); Ireland (Supabase, which stores each demo's instructions). Our AI gateway, which passes each call on, runs on Amazon Web Services in Cape Town. Each question and the visitor's IP address first reach our website's server (Vercel, in the United States, with a global edge network). |
| Platform customers' data | Ireland (Supabase); Germany (Sentry); the United States (OpenAI, Anthropic, voice, telephony, email and hosting); OpenRouter and the model providers it routes to (the United States and global); global networks (Cloudflare). Platform tenant workspaces run on Amazon Web Services in Cape Town. |
| Enquiries handled by the Desk | Cloudflare's global network, which receives the venue's forwarded mail and runs the Desk's code; the European Union, where Cloudflare stores the Desk's database; the United States (OpenRouter, and Resend's account data and logs); and, for the Claude model on Amazon Bedrock or Google Vertex AI under zero data retention, outside South Africa: the United States, the European Union or a global cloud region, depending on which zero-data-retention endpoint OpenRouter chooses for the call. Resend sends the Desk's email from Ireland. |
Our Privacy Policy and Sub-processor register set out the legal basis for each transfer under POPIA section 72.
9.5 How we protect personal information
This is a general description. Our Security page gives more detail.
For both services:
- Our website and services use encrypted (HTTPS) connections.
- Secret keys are kept in secrets managers, never in source code.
- Our customers' data is not used to train AI models.
- Anyone can report a security weakness to security@yielde.dev. We acknowledge reports within 24 hours.
- We hold no ISO 27001, SOC 2 or similar certification, and claim none.
Platform:
- Sign-in is by an emailed link, so we store no passwords.
- Admin access to the platform is limited to an explicit email allow-list.
- We do not routinely inspect the content of customers' tenant data. We access it only as the DPA, our Acceptable Use Policy or the law permits.
- Messages from outside systems, such as Paystack, are signature-checked before we act on them.
- Each customer has its own workspace, and database access rules separate one customer's records from another's.
- Our account database is encrypted at rest. Disk-level encryption for platform workspace storage on Amazon Web Services is not switched on yet.
- Our AI gateway logs metadata only (such as the model used and the cost), never the content of prompts or replies.
Desk:
- There are no passwords. Venues use signed links that expire; a link to approve a draft works once.
- Only the one enquiry is sent to the AI model, with zero data retention, and enquirers never receive text written freely by the AI.
- The Desk has no field for special personal information.
- The audit log records events without message text.
- A venue can stop all replies within 60 seconds, and when the Desk is unsure it drafts instead of sending.
- Only one person at Yielde, who runs the Desk, has access to Desk data. Anyone else Yielde later authorises must first sign a written confidentiality undertaking.
10. Where to find this manual
This manual is available:
- on our website, at yielde.dev/paia;
- as a printed copy, for inspection at our principal place of business during normal business hours: email support@yielde.dev or call 063 611 2952, and we will arrange a time;
- to anyone who asks for a copy (email support@yielde.dev); and
- to the Information Regulator, on request.
We update this manual regularly. The date at the top shows the latest version.
11. The Information Regulator
You can contact the Information Regulator about PAIA or POPIA.
| Item | Detail |
|---|---|
| Physical address | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| Phone | 010 023 5200 |
| Toll-free | 0800 017 160 |
| General enquiries | enquiries@inforegulator.org.za |
| PAIA complaints | PAIAComplaints@inforegulator.org.za |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| Website | https://inforegulator.org.za |