1. RECORDAL AND PURPOSE
1.1. This Manual has been prepared by Astrea Holdings Proprietary Limited in accordance with section 51 of the Promotion of Access to Information Act, 2 of 2000 ("PAIA"), read together with the Protection of Personal Information Act, 4 of 2013 ("POPIA").
1.2. PAIA gives effect to the constitutional right of access to information held by another person where such information is required for the exercise or protection of rights.
1.3. Astrea is a private body as contemplated in PAIA.
1.4. The purpose of this Manual is to identify Astrea, describe categories of records held, explain the access procedure, identify relevant legislation, describe Personal Information Processing and provide a general description of information-security safeguards.
2. INTERPRETATION
2.1. "Astrea" means Astrea Holdings Proprietary Limited.
2.2. "Information Officer" means the person designated as Astrea's Information Officer.
2.3. "PAIA" means the Promotion of Access to Information Act, 2 of 2000, as amended.
2.4. "POPIA" means the Protection of Personal Information Act, 4 of 2013, as amended.
2.5. "Record" bears the meaning contemplated in PAIA.
2.6. "Requester" means a person requesting access to a Record in accordance with PAIA.
3. PARTICULARS OF ASTREA
Registered Name: Astrea Holdings Proprietary Limited
Registration Number: 2026/692250/07
Nature of Business: Online administrative and document-preparation services relating principally to applications contemplated in section 60 of the Mental Health Care Act, 17 of 2002.
Registered Address: 585 Alandale Street, Elarduspark, Pretoria, Gauteng, 0181
Physical Address: 585 Alandale Street, Elarduspark, Pretoria, Gauteng, 0181
Website: https://astreasa.co.za
Email: [email protected]
4. INFORMATION OFFICER
Name: Llanell Londt
Capacity: Information Officer / Head of Private Body
Email: [email protected]
Telephone: 083 926 6631
Physical Address: 585 Alandale Street, Elarduspark, Pretoria, Gauteng, 0181
5. INFORMATION REGULATOR GUIDE
The Information Regulator makes available a Guide intended to assist persons wishing to exercise rights under PAIA. The Guide and prescribed forms may be obtained from the Information Regulator.
6. RIGHT OF ACCESS
6.1. A person does not have an unrestricted right of access to every Record held by Astrea.
6.2. A Requester must satisfy the applicable requirements of PAIA, including demonstrating where required that the Record is required for exercise or protection of a right.
6.3. The mere fact that Astrea possesses a Record does not mean that PAIA requires its disclosure.
7. RECORDS AUTOMATICALLY AVAILABLE
Certain Records may be available without a formal request, including Astrea's Terms and Conditions, Privacy Notice, PAIA Manual, published pricing, general service information, contact information and other material deliberately made public by Astrea.
8. CORPORATE RECORDS
Astrea may hold incorporation documents, memorandum of incorporation, securities records, statutory registers, resolutions, CIPC correspondence, beneficial-ownership records, licences and corporate policies.
9. FINANCIAL AND TAX RECORDS
Records may include accounting information, financial statements, invoices, payment records, proofs of payment, banking records, tax records, budgets and accounting documentation.
10. USER AND APPLICANT RECORDS
Records may include registration information, identity and contact information, login and verification records, Application information, correspondence, support records, declarations, acknowledgements, legal-document acceptance records, payment information and status histories.
11. PATIENT RECORDS
Records may include identity information, medical reports, mental-health information, information concerning capacity, financial and estate information, asset information, pension and investment information, supporting documentation and next-of-kin information.
12. APPLICATION DOCUMENTATION
Records may include prescribed forms, generated application forms, affidavits, next-of-kin documentation, medical reports, identity documents, asset-supporting records, submission memoranda, applicant instructions and generated Application Packs.
13. PROPOSED ADMINISTRATOR RECORDS
Records may include identity, contact, relationship, occupational and address information and information relevant to the proposed appointment.
14. SERVICE-PROVIDER RECORDS
Records may include contracts, confidentiality undertakings, operator agreements, Courier agreements, invoices, contact information, due-diligence records and service-performance documentation.
15. LEGAL AND COMPLIANCE RECORDS
Records may include legal opinions, privileged communications, litigation records, regulatory correspondence, POPIA records, PAIA requests, privacy impact assessments, security incident records, complaints and policies.
16. TECHNOLOGY AND SECURITY RECORDS
Records may include system logs, authentication records, access-control records, audit trails, backup records, incident records, architecture documents, vulnerability information, source code and Intellectual Property records.
Access to security-sensitive information may be refused or restricted where disclosure would compromise information security or another legally protected interest.
17. RECORDS HELD PURSUANT TO LEGISLATION
Astrea may hold records pursuant to legislation including the Companies Act, Consumer Protection Act, Electronic Communications and Transactions Act, Income Tax Act, Tax Administration Act, Value-Added Tax Act where applicable, PAIA, POPIA, Mental Health Care Act and such employment legislation as may become applicable.
18. PROCEDURE FOR REQUESTING ACCESS
18.1. A Requester seeking access to a Record that is not automatically available shall submit the prescribed PAIA request form to Astrea's Information Officer.
18.2. The Requester shall provide sufficient information to identify the Requester, the Record, the form of access required, the right sought to be exercised or protected and why the Record is required.
18.3. Where a request is made on behalf of another person, appropriate proof of authority shall be supplied.
19. FEES
A request may be subject to fees prescribed under PAIA. Astrea shall not impose a fee inconsistent with applicable law.
20. DECISION ON REQUEST
Astrea shall consider a valid request within the periods prescribed by PAIA and shall notify the Requester whether access has been granted, granted in part or refused.
21. GROUNDS FOR REFUSAL
Access may or shall be refused where permitted or required by PAIA, including circumstances involving unreasonable disclosure of third-party Personal Information, confidential commercial information, information supplied in confidence, safety or security, legally privileged records, Astrea's commercial information or records otherwise protected by law.
22. SEVERABILITY
Where only part of a Record is protected from disclosure, Astrea shall consider whether the protected portion can reasonably be severed and access granted to the remainder where required by law.
23. PERSONAL INFORMATION PROCESSING
For purposes of section 51 of PAIA, Astrea may Process Personal Information concerning Users, Applicants, Patients, Proposed Administrators, next of kin, carers, medical practitioners, Couriers, investigators, service providers and other persons relevant to the Services.
24. PURPOSES AND RECIPIENTS
Astrea may Process information for account administration, preparation of section 60 Applications, document generation, payment administration, Courier arrangements, security, compliance and legal rights. Information may lawfully be supplied to the Master, courts, investigators, Couriers, technology providers, professional advisers, regulators and authorised persons.
25. CROSS-BORDER PROCESSING AND SECURITY
Astrea may use cloud or technology providers whose infrastructure is located outside South Africa, subject to applicable cross-border transfer requirements.
Astrea shall implement reasonable technical and organisational safeguards which may include authentication controls, restricted access, password hashing, secure communications, controlled file access, hosting safeguards, logging, backups, vulnerability management, confidentiality measures and incident-response procedures.
26. AVAILABILITY OF THIS MANUAL
This Manual shall be made available through Astrea's Website and by such further means as applicable law requires.
27. UPDATING OF THIS MANUAL
The Information Officer shall review and update this Manual where reasonably necessary to reflect changes to Astrea's business, Records, Processing activities, service providers, technology or legal requirements.
Version: 1.2
Effective date: 24 September 2026