STILL ← Back

PAIA Manual

I-nspire Transformations · Section 51 of the Promotion of Access to Information Act, 2000 · Last updated 31 July 2026

This manual explains what records I-nspire Transformations holds and how to request access to them under the Promotion of Access to Information Act, 2000 (PAIA). It also sets out the particulars of our processing of personal information required by section 51(1)(c)(i) of PAIA, read with the Protection of Personal Information Act, 2013 (POPIA).

1. The body

Name: I-nspire Transformations CC
Registration number: 2006/107940/23
Physical and postal address: 274 Delphinus Street, Waterkloof Ridge, Pretoria, Gauteng, 0181, South Africa
Email: jacque@i-nspire.co.za
Website: stillsanctuary.app

Information Officer: Jacqueline Allschwang, I-nspire Transformations CC — jacque@i-nspire.co.za

Requests under PAIA, and requests or complaints under POPIA, should be addressed to the Information Officer at the email address above.

We operate STILL, a guided audio and journalling application, distributed through the Apple App Store and Google Play and available at stillsanctuary.app.

2. The Information Regulator's guide

The Information Regulator has published a guide under section 10 of PAIA, explaining in plain language how to use the Act. It is available free of charge from the Regulator:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
P.O. Box 31533, Braamfontein, Johannesburg, 2017
General enquiries: enquiries@inforegulator.org.za
PAIA complaints: PAIAComplaints@inforegulator.org.za
POPIA complaints: complaints.IR@inforegulator.org.za
inforegulator.org.za

3. Records available without a request

The following are published on stillsanctuary.app and may be accessed freely, without a PAIA request:

4. Categories of records we hold

CategoryIncludes
User recordsEmail addresses of beta testers and account holders, sign-up and last sign-in dates, confirmation status, beta invitation correspondence
Content recordsVault records users have chosen to save online; public reactions and notes posted on shared library pages
Product recordsAudio, music, voice recordings, artwork, written content, source code, designs
Analytics recordsPseudonymous usage events collected with consent — pages viewed, tracks played, session counts
CorrespondenceEmail between us and users, enquirers and service providers
Supplier and contractual recordsAgreements with service providers and contractors, including data processing agreements
Statutory and financial recordsRecords kept under the Companies Act, tax legislation and other applicable law

5. Records held under other legislation

We hold records in terms of, among others, the Companies Act 71 of 2008, the Income Tax Act 58 of 1962, the Value Added Tax Act 89 of 1991, the Tax Administration Act 28 of 2011, the Basic Conditions of Employment Act 75 of 1997 where applicable, the Electronic Communications and Transactions Act 25 of 2002, the Consumer Protection Act 68 of 2008, the Copyright Act 98 of 1978 and POPIA.

6. How to request access

  1. Complete the prescribed Form 2 (Request for Access to Record), available from the Information Regulator's website.
  2. Send it to the Information Officer at jacque@i-nspire.co.za.
  3. Provide enough detail to identify the record and to identify yourself, and state the form of access you would like and how you want to be told the outcome.
  4. If you are asking for a record on behalf of someone else, include proof of your authority.
  5. If you are asking for a record in order to exercise or protect a right, say which right and how the record is needed for it — PAIA requires this of requests to a private body.
  6. Pay the prescribed fees. A request fee may be payable before we process the request, and an access fee may be payable for search, reproduction and delivery. Fees are those prescribed in the PAIA regulations from time to time, and we will tell you the amount before proceeding. There is no request fee for a personal requester asking for their own personal information.
  7. We will decide within 30 days and tell you in writing. That period may be extended in the circumstances PAIA allows, and we will tell you if it is.

7. When access may be refused

PAIA obliges or permits us to refuse a request in certain cases, including where granting it would unreasonably disclose someone else's personal information (section 63), breach a duty of confidence or prejudice commercial information of a third party or of ourselves (sections 64 and 68), endanger a person's life or safety or prejudice property security (section 66), prejudice legal proceedings or disclose privileged information (section 67), disclose our research or a third party's research prematurely (section 69), or where the record cannot be found or does not exist (section 55). Where a ground of refusal applies to only part of a record, we will give access to the rest. If we refuse, we will give reasons and explain your remedies.

8. If you are unhappy with our decision

There is no internal appeal against a decision of a private body. You may lodge a complaint with the Information Regulator using the prescribed form, or apply to a court within 180 days of being told our decision, as section 78 of PAIA provides. The Regulator's contact details are in section 2 above.

9. Processing of personal information

The particulars required by section 51(1)(c)(i) of PAIA are set out below. Our full Privacy Policy describes all of this in more detail.

Purposes of processing

Issuing and managing beta access; authenticating users at sign-in; providing the STILL app and library; storing Vault records where a user has chosen to save them online; displaying reactions and notes that users choose to post publicly; understanding product usage with consent, in order to improve it; responding to correspondence; securing the service and preventing abuse; and meeting our legal obligations.

Categories of data subjects and their information

Data subjectsCategories of personal information
Beta testers and account holdersName where given, email address, sign-in dates, account status, Vault records saved online by choice
Visitors to the websitePseudonymous usage events, approximate location from IP address, device and browser type — collected only with consent
People who post a reaction or noteOptional first name and the text they choose to publish
People who contact usName, email address and the contents of their message
Service providers and contractorsContact details and contractual information

Recipients

Personal information may be shared with our operators and service providers — Supabase for authentication and database services, PostHog for analytics, GitHub for website hosting, Apple and Google for app distribution, and Asan Digital as our development contractor — each under contract and processing only on our instructions. We may also disclose information where the law requires it or to establish or defend a legal claim. We do not sell personal information.

Transborder flows

Personal information is transferred to and stored in the United States, where our authentication, database, analytics and hosting providers operate, and to the European Union in respect of our development contractor and certain app store operations. These transfers are made in accordance with section 72 of POPIA on the basis of written agreements with the recipients, including the European Commission's Standard Contractual Clauses, which bind them to a level of protection substantially similar to POPIA and restrict onward transfer.

Security measures

We limit the personal information we collect. All connections use HTTPS. Authentication is passwordless. Database access is restricted by row-level security so users cannot read one another's records, and administrative access is verified on the server and limited to named individuals. Our providers encrypt data in transit and at rest. We review these measures periodically and when the service changes, as section 19 of POPIA requires.

Requests and complaints under POPIA

Data subjects may request access to, correction of, or deletion of their personal information, and may object to processing, by writing to the Information Officer at jacque@i-nspire.co.za, or by using prescribed Form 2 for access and Form 3 for correction or deletion. Account deletion has a dedicated route at stillsanctuary.app/delete-account.html. Complaints may be made to the Information Regulator at the address in section 2.

10. Availability of this manual

This manual is available free of charge on this page, and on request by email from the Information Officer. It is also available for inspection at our address during ordinary business hours, by prior arrangement.

11. Updates

We review this manual at least annually and update it whenever our records or processing change materially. The date at the top shows the current version.