Legal
PAIA manual
Auto Alpha Advisory (Pty) Ltd · Compiled 3 October 2026 · Last updated 3 October 2026
This manual is published under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA). It explains how to ask Auto Alpha Advisory (Pty) Ltd for a record it holds, and how the company processes personal information under the Protection of Personal Information Act 4 of 2013 (POPIA).
Komply and the AIV Index are products of Auto Alpha Advisory (Pty) Ltd, not separate companies. This one manual covers both, and the company's advisory work.
The short version
Asking us for a record
- Fill in Form 2, the Information Regulator's request form, and email it to our Information Officer at hello@autoalphaadvisory.co.za, with proof of your identity.
- Pay the R140.00 request fee when we ask for it. Any fee for copies or search time is stated in our decision.
- We decide within 30 days. We may extend that once, by up to 30 days, and we tell you why.
- If we refuse, or don't decide in time, you can complain to the Information Regulator or apply to court.
1. Contact details PAIA s51(1)(a)
- Private body
- Auto Alpha Advisory (Pty) Ltd, a private company, registration number 2025/213512/07. It trades as Komply.
- Information Officer
- Matthew Owen, Managing Director and head of the company. The head of a private body is its Information Officer (POPIA s1, read with the definition of “head” in PAIA s1).
- Registered with the Information Regulator
- 30 September 2026, registration number 2026-068029
- Deputy Information Officer
- None appointed
- Street address
- 96 New Church Street, Gardens, Cape Town, 8001
- Postal address
- 96 New Church Street, Gardens, Cape Town, 8001
- Phone
- 084 584 1849
- Fax
- None
- hello@autoalphaadvisory.co.za
- Websites
- getkomply.co.za, autoalphaadvisory.co.za and aiv.autoalphaadvisory.co.za
Komply customers can also write to io@getkomply.co.za, which reaches the same person.
2. The Regulator's Guide to PAIA PAIA s51(1)(b)(i)
The Information Regulator publishes a guide on how to use PAIA, compiled under section 10 of the Act. The current version is dated October 2021 and was published by Government Notice 1504 in Government Gazette 45492 on 16 November 2021. It is on the Regulator's PAIA page in English and other official languages, and you can download the English version (PDF) directly.
You may also inspect a copy, in English or Afrikaans, at our street address during normal office hours, or ask us in writing for copies, on the Regulator's Form 1. There is no charge for either (regulation 3 of the PAIA Regulations, 2021).
3. Records available without a request PAIA s51(1)(b)(ii)
Section 52(2) of PAIA once provided for a published notice of the records a person could get without a request. Section 110 of POPIA deleted that subsection, so there is no notice under section 52(2). Everything published on our three websites is available without a request, including this manual and each site's privacy policy and terms.
4. Records available under other laws PAIA s51(1)(b)(iii)
- Companies Act 71 of 2008. Holders of our securities, and in some cases other people, may inspect certain company records under section 26 of that Act.
- Tax Administration Act, 2011. We keep the records tax law requires, and SARS has access to them under that Act.
5. The records we hold PAIA s51(1)(b)(iv)
By subject, these are the categories of records the company holds.
- The company
- Memorandum of Incorporation, registration documents and filings with the Companies and Intellectual Property Commission, the registers of directors and securities, resolutions, contracts, accounting and tax records, and bank records.
- Komply customers
- Workspace and account details, members' email addresses and roles, sign-in and two-factor records, subscription and billing events, and the partner referral code recorded when a workspace is set up.
- Records Komply holds for its customers
- B-BBEE scorecard inputs and results, uploaded B-BBEE certificates and affidavits, SARS return figures and refund and verification tracking, VAT figures added up from a connected Xero organisation, FSCA registers (key individuals and representatives, CPD, complaints, conflicts of interest and cyber incidents) and the documents generated from them, website scan results, and tender-readiness documents. We hold these on our customers' instructions, as their operator under POPIA.
- AIV Index subscribers
- Account details, the brands and competitors a subscriber tracks, the prompts and the answers AI engines give to them, visibility scores, website-readiness audit results, Google Search Console data where the subscriber connects it, billing events, and dashboard chatbot conversations (kept for 30 days).
- Advisory clients and enquirers
- Enquiries and correspondence, website-audit requests and the reports produced, audit-report purchases, resource downloads, engagement letters, the documents clients give us, and our working papers, reports and invoices.
- Leads and partners
- Waitlist, pilot-seat, contact-form and free-tool sign-ups (email address, the form used, the marketing-consent answer, the referring page and any partner code), and partners' details, referral codes and agreements.
- Operations
- Sign-in and security logs, logs of who viewed a shared link, logs of AI model calls (token counts only, not the text sent), error logs, and aggregate counts of visits to our websites.
6. How to request a record PAIA ss50 to 58
PAIA gives you access to a record of a private body when you need it to exercise or protect a right, you follow the Act's procedure, and no ground for refusal applies (section 50).
Making the request
- Use Form 2, “Request for access to record”, from the Regulator's PAIA page (regulation 7 of the PAIA Regulations, 2021).
- Say which record you want, and which right you need it to exercise or protect. Attach proof of your identity and, if you ask on someone else's behalf, proof that you may (the form asks for both).
- Send it to the Information Officer by email, by post or by hand, using the details in section 1 (section 53(1)).
Fees
We ask for the request fee before we process the request (section 54(1)). Any access fee is stated in the notice of our decision. The amounts are those prescribed for private bodies in Annexure B to the PAIA Regulations, 2021:
- Request fee, payable by every requester
- R140.00
- Photocopy or printed copy of an A4 page
- R2.00 a page
- Copy on a flash drive you provide, or on a compact disc you provide
- R40.00
- Copy on a compact disc we provide
- R60.00
- Transcription of an audio record, per A4 page
- R24.00
- Transcription or copy of visual images
- At the service provider's quoted cost
- Search and preparation, for each hour or part of an hour after the first
- R145.00, to a total of R435.00
- Deposit, if the search will take more than 6 hours
- One third of the fees under items 2 to 8
- Postage, email or other electronic transfer
- The actual cost, if any
Time limits
We decide as soon as reasonably possible, and within 30 days of receiving the request (section 56(1)). We may extend that once, by up to 30 days, for one of the reasons in section 57(1), such as a request for a large number of records; we tell you within the first 30 days, with the reason (section 57). If we don't decide in time, the request is regarded as refused (section 58).
Grounds for refusal
We may refuse access only on the grounds in Chapter 4 of Part 3 of PAIA (sections 62 to 70): for example, to protect another person's privacy (section 63), a third party's commercial information (section 64) or our own (section 68), or a record privileged from production in legal proceedings (section 67).
If you disagree with our decision
Our decision notice tells you that you may complain to the Information Regulator or apply to a court, and how (section 56). A complaint to the Regulator must be made within 180 days of our decision (section 77A(2)). The Regulator's details:
- Address
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- PAIA complaints
- PAIAComplaints@inforegulator.org.za
- Phone
- 010 023 5200
- Website
- inforegulator.org.za
7. How we process personal information PAIA s51(1)(c)
Why we process it s51(1)(c)(i)
- To provide Komply, the AIV Index and our advisory services, and to run the accounts that use them.
- To process our Komply customers' compliance records on their instructions, as their operator.
- To answer enquiries and deliver the website audits, reports and resources people ask for.
- To keep our services secure, prevent abuse and keep audit trails.
- To bill customers and keep the payment records tax law requires.
- To credit partners for the customers they refer.
- To count visits to our websites, in aggregate and without cookies.
Whose information, and what s51(1)(c)(ii)
- Customers' users (Komply and the AIV Index): name, email address, role, sign-in and two-factor records, activity logs and billing details.
- People named in a Komply customer's records: directors and shareholders on B-BBEE certificates; employees, in workforce figures broken down by race and gender; payroll and tax figures; FSCA key individuals, representatives and complainants; and personal information shown on a customer's own website that a scan finds.
- Enquirers and leads: name, email address, company, message, the website they ask us to audit, their marketing-consent answer, IP address and browser details.
- Advisory clients: contact details and the information they give us for an engagement.
- People who open a shared link: IP address, browser details and the time they viewed it.
- Partners: name, contact details and referral code.
The only special personal information we process is race, in the B-BBEE workforce figures a Komply customer enters. We do not knowingly process children's personal information.
Who may receive it s51(1)(c)(iii)
Supabase
Database, sign-in and file storage for Komply and the AIV Index.
Ireland
Vercel
Hosting for our websites and their server functions.
Germany (Frankfurt); Vercel is a US company
DigitalOcean
Hosting for our website-audit engine, our cookie-free website analytics (Umami) and the AIV Index's answer collection.
The Netherlands (Amsterdam); DigitalOcean is a US company
Resend
Sending Komply's and the AIV Index's email: sign-in links, digests and notices.
United States
Google
Our business email (Google Workspace); for the AIV Index, Gemini answers to tracked prompts and, where a subscriber connects it, Search Console data.
United States
Anthropic
For Komply, two things. It reads uploaded B-BBEE certificates to extract their fields; the certificate is sent as uploaded. It tailors the wording of a conflict-of-interest policy, with key individuals' and representatives' names cut to initials first; the FSP's registered name is sent as it is. For the AIV Index, Claude answers to tracked prompts and the dashboard chatbot.
United States
OpenAI, Perplexity and OpenRouter
For the AIV Index, the tracked prompts, to measure what these AI engines answer. OpenRouter relays prompts to Gemini.
United States
Cloudflare
The anti-spam check on the forms on autoalphaadvisory.co.za.
United States
PayFast
Payments for audit reports and subscriptions. Card details go to PayFast, never to us.
South Africa
CIPC
Komply's company-registry lookup, when a customer uses it.
South Africa
People a customer shares with
A read-only link or PDF that a Komply customer chooses to share.
Wherever they are
Authorities
Information a law requires us to give, such as tax records for SARS.
South Africa
Transfers outside South Africa s51(1)(c)(iv)
Personal information goes to the operators above in the European Union (Ireland, Germany and the Netherlands) and the United States. For each transfer we rely on POPIA s72(1)(a): the recipient is bound by a law (in the EU, the General Data Protection Regulation) or a binding agreement (its data processing terms) that gives the information an adequate level of protection.
How we keep it secure s51(1)(c)(v)
- Each customer's data is kept apart. Komply scopes every database query to the customer's workspace in its code, and queries made with a signed-in user's session are also checked by row-level security in the database.
- Data travels encrypted (TLS) and is encrypted at rest by our hosting providers. Xero tokens are encrypted again, field by field.
- Sign-in is by a single-use email link, with optional two-factor sign-in through an authenticator app.
- Only a workspace's owners and admins can connect integrations and manage its members.
- A value read from an uploaded certificate changes a B-BBEE scorecard only after a person confirms it.
- Key individuals' and representatives' names are cut to initials before policy text is sent to an AI model.
- Card details go to PayFast and never reach us.
- Retention runs on a schedule. Komply deletes sign-up records, logs of who viewed a shared link and logs of AI model calls after 12 months, and a closed workspace's records 12 months after it closes. Payment records are kept for 5 years.
8. Where this manual is available PAIA s51(2) and (3)
This manual is on our website at getkomply.co.za/paia. You may also inspect it at our street address during normal business hours or ask us for a copy, for which we may charge a reasonable amount, and the Information Regulator may ask us for it (section 51(3)). We update it whenever the records we hold or the way we process personal information changes (section 51(2)), and we confirm the Information Officer's details at least once a year (the Regulator's Guidance Note on Information Officers, paragraph 11.1).
9. Sources
Checked against these on 3 October 2026:
- Promotion of Access to Information Act 2 of 2000 (consolidated, as amended by POPIA with effect from 30 June 2021)
- Protection of Personal Information Act 4 of 2013
- Regulations relating to the Promotion of Access to Information, 2021 (GN R.757, Government Gazette 45057, 27 August 2021)
- Information Regulator, Guidance Note on Information Officers and Deputy Information Officers
- Information Regulator, PAIA page (the Guide, Form 2 and the Regulator's contact details)
See also our privacy policy, terms of service and data processing agreement.