LUMA.

PAIA manual

Manual in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, read with section 17 of the Protection of Personal Information Act 4 of 2013. Luma Analytics (Pty) Ltd trading as Luma Automations. Version 1.1, 26 September 2026.

1. Contact details

Private bodyLuma Analytics (Pty) Ltd, registration number 2026/428485/07, trading as Luma Automations
Head of the body and Information OfficerTerence Swart, Director
Postal and physical addressBallito, KwaZulu-Natal, South Africa (online business; contact via email or WhatsApp below)
Telephone083 436 9104
Email[email protected]
Websiteaskluma.co.za

2. The guide from the Information Regulator

The Information Regulator has published a guide, in each official language, on how to use the Act. It is available from the Regulator at inforegulator.org.za, by email at [email protected], or from its offices at JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001.

3. Records available without a request

This manual, and the company's privacy notice at /privacy, are available on this website without a formal request. Company registration details are available from the Companies and Intellectual Property Commission.

4. Records available in terms of other legislation

Records are kept as required by the Companies Act 71 of 2008, the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991 (where applicable), the Basic Conditions of Employment Act 75 of 1997 (where applicable), and the Protection of Personal Information Act 4 of 2013. They are available to the persons those Acts entitle, in the manner those Acts provide.

5. Records held, by subject and category

Company recordsIncorporation documents, registers, resolutions, financial statements, tax returns
Client recordsAgreements, invoices, correspondence, contact details of client staff, access lists for tools the company hosts
Supplier recordsAgreements and data processing terms with service providers, invoices
Operational recordsSource code, deployment records, operational logs (metadata only: time, signed-in user, request size, outcome), the POPIA operating documents described in section 8
Personal informationAs described in section 7

6. How to request access to a record

A request must be made on the prescribed form (Form 2 in the regulations under the Act, available from the Information Regulator), sent to the Information Officer at the address in section 1, and must give enough detail to identify the record and the requester, state which right the requester is exercising or protecting and why the record is needed to do so, and say how the requester would like to receive it. A requester acting for someone else must show authority to do so.

The Information Officer will respond within 30 days of receiving a request. The prescribed request fee and, where applicable, the access fee set in the regulations apply; a personal requester (a person requesting their own personal information) pays no request fee. If a request is refused, the response will say why, and how to appeal or complain to the Information Regulator.

7. Processing of personal information

PurposeTo respond to enquiries; to conclude and perform client agreements; to invoice and keep the records tax law requires; to control access to tools the company hosts for clients; and, as an operator on a client's instruction, to process the client's documents through those tools.
Categories of data subjectProspective and current clients and their staff; suppliers; and, as an operator only, the customers of clients whose documents pass through a tool the company hosts.
Categories of informationNames, business contact details, correspondence, agreements, invoices and payment records. For operator processing: whatever the client's document contains, which the company does not retain.
RecipientsHosted email, calendar and code services used to run the company. For operator processing: the sub-operators named in the client's agreement, currently Cloudflare, Inc. and Anthropic PBC.
Transfers outside the RepublicYes, to service providers chiefly in the United States, each bound by data processing terms that provide substantially similar protection, as section 72 of the Act permits.
Security measuresEncryption in transit throughout; credentials held server-side as secrets; named-user access with single-use codes; no storage or logging of document content; version-controlled deployment; a quarterly control check. Recorded in detail in the operator agreement with each client.

8. Other information

The company keeps a processing register, an Information Officer record, a security compromise response procedure and a data subject request procedure, reviewed annually. The privacy notice at /privacy explains the same processing in plain language.

9. Availability of this manual

This manual is available on this website, and a copy can be requested from the Information Officer. It is available in English.