Legal centre · PAIA

Access to information,
and how to ask for it.

The manual required of every private body by section 51 of the Promotion of Access to Information Act 2 of 2000, published here because section 51(3)(a) requires it to be on the website. It describes South African procedure specifically: what records this company holds, who to ask, what it costs and how long it takes.

Version 1.0 · Effective 18 August 2026 · Next review 18 February 2027

Why this document is here

The exemption that let most small private bodies skip a PAIA manual ended on 31 December 2021 and was not renewed. Every private body has needed one since 1 January 2022, and it has to be published on the body’s website. This is ours.

Before you file

Four numbers govern a request.

All four come from the statutes, not from our policy. Each is set out in full, with the section it comes from, in the manual below.

R0
request fee for a private body, payable when the request is lodged
No request fee where you are asking for a record containing your own personal information
0 days
to decide the request and notify you in writing, under section 56
Extendable once, by not more than 30 days, under section 57
0 years
retention of due diligence and transaction records, under sections 22 and 23 of the FIC Act
Running from the end of the relationship or the conclusion of the single transaction
0 days
to complain to the Information Regulator about a decision, under section 77A
Unless the Regulator condones a late complaint

Purpose and status of this manual

This is the manual of registered company name — to be confirmed, prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000, referred to throughout as PAIA. It is published on this website because section 51(3)(a) requires a private body to make its manual available on its website where it has one.

Until 31 December 2021, most small private bodies were exempt from the duty to compile a manual under a series of exemption notices issued by the Minister of Justice. That exemption ended on 31 December 2021 and was not renewed. Every private body that meets the definition in PAIA has been required to have a manual since 1 January 2022, regardless of turnover or headcount. This manual exists because of that, and because a desk that asks clients to hand over identity documents and bank statements should be able to explain, in public, what it does with records.

PAIA gives effect to section 32 of the Constitution, which grants everyone the right of access to information held by another person where that information is required for the exercise or protection of any right. Against a private body such as this one, that qualifier matters: a requester must state which right the record is required for, and must explain how the record would assist in exercising or protecting it. This manual explains how to do that.

The manual is written to the structure of the template published by the Information Regulator for private bodies, and follows the order of the matters listed in section 51(1).

One point of scope. Conexus is an over-the-counter desk with clients in more than one country, but the company behind it is a South African private body, so PAIA applies to it and this manual describes South African statutory procedure specifically. If you are reading it from outside the Republic, the rights described here are still available to you: PAIA attaches to the body holding the record, not to the residence of the person asking for it.

Particulars of the private body

Registered nameregistered company name — to be confirmed
Trading nameConexus Crypto
Company registration numberCIPC registration number — to be confirmed
FSCA Financial Services Provider numberFSCA licence number — to be confirmed
Directorsdirectors — to be confirmed
Nature of businessOver-the-counter exchange of crypto assets, principally USDT, against fiat currency
Physical and registered addressTiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925, Western Cape
Second locationJohannesburg, by appointment
Telephone+27 76 560 1228
Email for PAIA requestssupport@conexus-crypto.com
Websiteconexus-crypto.com

Requests must be addressed to the Information Officer at the address above and marked for that person's attention. Where a value appears in braces it has not yet been published on this site; it will be substituted with the verified value and the version number of this manual will change when it is.

The Information Officer and Deputy Information Officers

In a private body, the head of the body is the Information Officer as a matter of law. Section 1 of PAIA defines the head of a private body that is a juristic person as the chief executive officer or equivalent officer, or the person acting as such. The head does not have to be appointed to the role; the role attaches to the office.

Information OfficerInformation Officer — to be confirmed
CapacityHead of the private body as defined in section 1 of PAIA
Deputy Information OfficerInformation Officer — to be confirmed
Postal and physical addressTiny Empire, 37 Buitenkant Street, District Six, Cape Town, 7925
Emailsupport@conexus-crypto.com
Telephone+27 76 560 1228

Deputy Information Officers are designated under section 17 of PAIA, read with section 56 of the Protection of Personal Information Act 4 of 2013, referred to as POPIA, to render the body as accessible as reasonably possible for requesters. A deputy exercises the powers and duties delegated to them by the Information Officer, and a request handled by a deputy is a request handled by the body.

The duties of an Information Officer under section 55 of POPIA include encouraging compliance with the conditions for lawful processing, dealing with requests made to the body, working with the Information Regulator on investigations, and otherwise ensuring compliance with the Act. Regulation 4 of the POPIA Regulations requires an Information Officer to register with the Information Regulator before performing those duties. Our registration position and the practical route for a data-subject request are on the data requests page.

Contact details of the Information Regulator

The Information Regulator is the independent body established under section 39 of POPIA. It regulates both the protection of personal information under POPIA and access to information under PAIA, the latter function having been transferred to it from the South African Human Rights Commission with effect from 30 June 2021. A requester who is unhappy with how this body has dealt with a request may complain to it directly.

BodyInformation Regulator (South Africa)
Physical addressJD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Postal addressP.O. Box 31533, Braamfontein, Johannesburg, 2017
Telephone010 023 5200
General enquiriesenquiries@inforegulator.org.za
PAIA complaintsPAIAComplaints@inforegulator.org.za
POPIA complaintsPOPIAComplaints@inforegulator.org.za
Websiteinforegulator.org.za

The Regulator publishes its own forms, guidance notes and complaint procedures. Where its published contact details differ from those above, the Regulator's own published details are the correct ones, and we would be grateful if you told us so that we can correct this page.

The guide referred to in section 10 of PAIA

Section 10 of PAIA requires the Information Regulator to compile and make available a guide, in each official language, containing the information a person reasonably requires in order to exercise their rights under the Act. The guide explains the objects of PAIA, the particulars of the Information Officer of every public body and the head of every private body, the manner and form of a request, the assistance available from an Information Officer and from the Regulator, the remedies available where a request is refused, the provisions requiring automatic disclosure, and the schedule of prescribed fees.

The guide is available free of charge from the Information Regulator, in print and on its website at inforegulator.org.za, and by enquiry to enquiries@inforegulator.org.za or on 010 023 5200. We will also print a copy of the guide for any person who asks for it at our Cape Town office, at no charge.

If you are not sure whether what you want is a PAIA request at all, ask the Information Officer before you fill in a form. Most of what clients want — a copy of their own trade confirmations, their onboarding file, or the rate applied to a specific settlement — is available from the desk on request in the ordinary course, without any of this machinery.

Categories of records held by the body

Section 51(1)(e) requires a description of the subjects on which the body holds records, and the categories of records held on each subject. The list below is a description of categories. It is not a list of records that will be granted on request, and it is not an undertaking that any particular record exists.

Company and corporate governance records

  • certificate of incorporation, memorandum of incorporation and CIPC filings;
  • share register, register of directors, and records of directors' appointments and resignations;
  • minutes of directors' and shareholders' meetings and resolutions;
  • statutory registers and returns.

Financial records

  • annual financial statements, management accounts, general ledger and supporting journals;
  • banking records, settlement instructions and reconciliations;
  • invoices, receipts and creditor records;
  • tax records, including income tax, VAT where applicable, and PAYE.

Client records

  • onboarding files: identity verification, proof of address, source-of-funds and source-of-wealth documentation, beneficial ownership records and screening results;
  • client agreements, mandates, and the correspondence forming a business relationship;
  • transaction records: quotes issued, quotes accepted, settlement confirmations, wallet addresses and transaction hashes, and bank references;
  • client communications across email, WhatsApp, Telegram, telephone notes and in-person meeting notes;
  • complaints and their handling.

Compliance and regulatory records

  • the Risk Management and Compliance Programme required by section 42 of the Financial Intelligence Centre Act 38 of 2001;
  • customer due diligence and enhanced due diligence records under sections 21 and 21A of that Act;
  • records of reports made to the Financial Intelligence Centre, and related registrations;
  • Travel Rule records generated under Financial Intelligence Centre Directive 9 of 2024;
  • training records, compliance monitoring reports and internal audit records;
  • correspondence with the Financial Sector Conduct Authority, the Financial Intelligence Centre and other regulators.

Employment and human resources records

  • contracts of employment, personnel files and disciplinary records;
  • payroll, leave and benefit records;
  • recruitment records and background checks;
  • occupational health and safety records.

Operational, technology and marketing records

  • supplier and service-provider agreements, including with banks, venues and technology providers;
  • insurance policies;
  • information security policies, access logs and incident records;
  • website content, source code, analytics configuration and consent records;
  • marketing material and the approvals recorded against it.

Records relating to reports made to the Financial Intelligence Centre are a special case. Section 29 of the FIC Act requires a suspicious or unusual transaction report to be filed, and the Act makes it an offence for a person who knows or suspects that such a report has been made to disclose that fact. We are therefore not able to confirm or deny the existence of any such record, to a client or to anyone else, and a request for one will be refused on that basis.

Records available without a PAIA request

Section 51(1)(c) requires the manual to state whether the body has published a notice under section 52(2) describing categories of records that are automatically available without a request. No such notice has been published by this body.

That said, a substantial amount of information is simply published, and no request of any kind is needed to get it:

Company records that the Companies Act makes available to the public may be obtained directly from the Companies and Intellectual Property Commission, and do not require a request to us.

Records held in terms of other legislation

Section 51(1)(d) requires a description of the records held in terms of other legislation. The list below sets out the principal statutes under which this body creates or retains records. It is not exhaustive, and the fact that a record is held under one of these statutes does not by itself make it accessible under PAIA.

  • Companies Act 71 of 2008 and the Companies Regulations 2011;
  • Financial Intelligence Centre Act 38 of 2001, in particular sections 21, 21A, 22, 23, 28, 29 and 42, and Directive 9 of 2024;
  • Financial Advisory and Intermediary Services Act 37 of 2002, the General Code of Conduct, and the Determination of Fit and Proper Requirements;
  • Financial Sector Regulation Act 9 of 2017;
  • Protection of Personal Information Act 4 of 2013;
  • Promotion of Access to Information Act 2 of 2000;
  • Electronic Communications and Transactions Act 25 of 2002;
  • Tax Administration Act 28 of 2011;
  • Income Tax Act 58 of 1962 and Value-Added Tax Act 89 of 1991;
  • Currency and Exchanges Act 9 of 1933 and the Exchange Control Regulations made under it;
  • Basic Conditions of Employment Act 75 of 1997, Labour Relations Act 66 of 1995, Employment Equity Act 55 of 1998 and Skills Development Act 97 of 1998;
  • Occupational Health and Safety Act 85 of 1993, Compensation for Occupational Injuries and Diseases Act 130 of 1993 and Unemployment Insurance Act 63 of 2001;
  • Consumer Protection Act 68 of 2008, to the extent that it applies;
  • Copyright Act 98 of 1978 and Trade Marks Act 194 of 1993.

Two retention rules are worth naming because they are the ones clients ask about. Sections 22 and 23 of the Financial Intelligence Centre Act require customer due diligence and transaction records to be kept for five years from the date the business relationship ends or the single transaction concludes. The Tax Administration Act imposes its own retention period on the records that support a return. Where those periods conflict with a deletion request, the statutory retention period wins, and we will say so in writing rather than quietly ignoring the request.

How to make a request: the section 53 procedure

A request for access to a record held by this body must be made on the prescribed form. For a private body that is Form 2, the form of request for access to a record of a private body prescribed under section 53(1) of PAIA and set out in the Regulations. Form 2 is available from the Information Regulator's website, and we will email or print a copy for anyone who asks.

A complete request contains:

  • sufficient particulars to enable the Information Officer to identify the record and to identify the requester;
  • the form of access required — inspection, a copy, a transcript, or a copy in an electronic form;
  • a postal address or email address in the Republic;
  • where the requester asks to be informed of the decision in any manner in addition to writing, the manner and the necessary particulars;
  • where the request is made on behalf of another person, proof of the capacity in which the requester is acting, to the satisfaction of the Information Officer;
  • the right the requester seeks to exercise or protect, and an explanation of why the record is required for that purpose. This is a requirement of section 50(1)(a) and it is the requirement that most incomplete requests fail. A private body is not obliged to release a record simply because a person is curious about it.

Send the completed form to the Information Officer at support@conexus-crypto.com, or deliver it to the Cape Town address in this manual. We acknowledge receipt in writing and give the request a reference. If a form is incomplete, we will say what is missing rather than refuse it on a technicality, and we will assist a requester who cannot complete the form because of illiteracy or disability, as section 53 contemplates.

Prescribed fees

PAIA prescribes two kinds of fee. A request fee, payable on submission before the request is processed, and an access fee, payable once access has been granted, which covers the cost of searching for, preparing and reproducing the record.

Request fee, private bodyR140.00, payable when the request is lodged
Personal requesterNo request fee is payable by a requester asking for a record containing their own personal information
Access feeCharged at the rates in the prescribed fee schedule for reproduction, and for search and preparation time beyond the free period
DepositWhere search and preparation is likely to exceed six hours, a deposit of not more than one third of the access fee is payable before work begins
Postage and electronic transferActual cost, where a record is posted or transferred at the requester's request

The rates for reproduction and for search and preparation time are those prescribed in the Regulations made under PAIA, as amended from time to time. Rather than reprint figures on a web page that may fall out of date, the Information Officer will send you an itemised calculation in writing, using the current prescribed rates, before any access fee or deposit becomes payable. You may withdraw the request at that point, and if you do, any deposit is refunded.

Where a deposit has been paid and access is subsequently refused, the deposit is refunded. Payment is made by electronic transfer to the account confirmed in writing by the Information Officer; we do not accept cash for this or for anything else.

The decision, the 30-day period and extension

Section 56 of PAIA requires the Information Officer to decide a request and to notify the requester of the decision as soon as reasonably possible, and in any event within 30 days of receipt of the request.

That period may be extended once, for a further period of not more than 30 days, under section 57, where the request is for a large number of records or requires a search through a large number of records and meeting the original period would unreasonably interfere with the activities of the body, or where consultation among divisions of the body or with a third party cannot reasonably be completed in time. Where the period is extended, we must notify you in writing before the original 30 days expires, state the period of the extension, give adequate reasons for it, and tell you that you may lodge a complaint with the Information Regulator or apply to a court against the extension.

Where a record contains information about a third party, sections 71 and 72 require that third party to be given notice and an opportunity to make representations before access is granted, and that consultation runs inside these timelines.

The notice of decision will state whether access is granted, in whole or in part, the access fee payable, the form in which access will be given, and, where access is refused, adequate reasons for the refusal with reference to the specific provision of PAIA relied on, together with the remedies available to you. A failure to respond within the period is deemed to be a refusal under section 58, which triggers the same remedies.

Grounds on which access may be refused

Chapter 4 of Part 3 of PAIA sets out the grounds on which a private body must or may refuse access. The grounds most likely to be relevant to this body are:

  • Section 63 — mandatory protection of the privacy of a third party who is a natural person, where disclosure would involve an unreasonable disclosure of personal information;
  • Section 64 — mandatory protection of the commercial information of a third party, including trade secrets, financial or commercial information whose disclosure would harm that third party's commercial or financial interests, and information supplied in confidence in the course of a tender or negotiation;
  • Section 65 — mandatory protection of information whose disclosure would breach a duty of confidence owed to a third party;
  • Section 66 — protection of the safety of individuals and the protection of property;
  • Section 67 — protection of records privileged from production in legal proceedings;
  • Section 68 — protection of the commercial information of the body itself, including trade secrets and information whose disclosure would put the body at a disadvantage in negotiations or in commercial competition;
  • Section 69 — protection of research information of the body or a third party;
  • Section 70 — the public-interest override, which requires disclosure despite most of the above where the record would reveal a substantial contravention of the law or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm.

In addition, and specific to this desk, records relating to reports made to the Financial Intelligence Centre cannot be disclosed. Section 29 of the FIC Act, read with the tipping-off provisions of that Act, makes disclosure of the fact that a report has been made an offence. A refusal on that basis is not discretionary.

Where only part of a record is protected, section 28 requires severance: we must grant access to the part that can be disclosed and explain what has been withheld and why.

Remedies if a request is refused

Three points are worth being precise about here, because a lot of published manuals are not.

Internal appeal. The internal appeal procedure in section 74 of PAIA applies to decisions of public bodies. There is no statutory internal appeal against a decision of a private body. As a matter of practice, however, this body will reconsider any refusal at the request of the requester: write to the Information Officer within 30 days of the decision, say why you think the refusal is wrong, and a written reconsideration will be issued within 30 days. That is a courtesy we offer, not a statutory step, and it does not stop or extend any statutory time limit.

Complaint to the Information Regulator. Since the amendments that took effect on 30 June 2021, a requester may lodge a complaint with the Information Regulator under section 77A of PAIA in respect of a decision of a private body, including a refusal of access, a deemed refusal, a fee that the requester considers excessive, the form of access given, or an extension of the period. The complaint must be in the prescribed form and must be lodged within 180 days of the decision, unless the Regulator condones a late complaint. The Regulator may investigate, attempt to settle the matter, and issue an enforcement notice.

Application to court. A requester may apply to a court under section 78 of PAIA for appropriate relief, either after exhausting the complaint procedure or, in the circumstances allowed by the Act, directly. The application is made to the High Court with jurisdiction, or to a Magistrate's Court designated for that purpose. A court may confirm, amend or set aside the decision and may order access on any conditions it considers appropriate.

Complaints to the Regulator go to PAIAComplaints@inforegulator.org.za. The full contact details are in the section above.

POPIA: processing, objection, correction and deletion

Section 51(1)(f) of PAIA, as amended by POPIA, requires this manual to describe the processing of personal information by the body, including the purpose of processing, the categories of data subjects and of personal information, the recipients to whom it may be supplied, planned transborder flows, and a general description of the security safeguards.

The full account is in the privacy policy, which is the operative document. In summary:

  • Data subjects: clients and prospective clients, their beneficial owners and authorised representatives, employees and job applicants, suppliers and service providers, and visitors to this website.
  • Categories of personal information: identity and contact details, identity and passport numbers, addresses, banking details, wallet addresses, source-of-funds and source-of-wealth information, screening and sanctions results, transaction records, correspondence, and technical data generated by the website.
  • Purposes of processing: establishing and administering a business relationship, executing and settling transactions, complying with the FIC Act, the FAIS Act and tax legislation, managing risk and preventing fraud, keeping records for the periods the law requires, and responding to enquiries.
  • Recipients: banks and payment providers used for settlement, trading venues and liquidity providers, identity verification and sanctions screening providers, auditors, attorneys and other professional advisers, and regulators and law enforcement where the law requires it.
  • Transborder flows: some service providers process information outside South Africa. Section 72 of POPIA permits this only where the recipient is subject to a law, binding corporate rules or an agreement providing an adequate level of protection, or where the data subject consents or the transfer is necessary for the performance of a contract.
  • Security safeguards: access control on a least-privilege basis, encryption of data in transit and of stored client documentation, restricted access to onboarding files, logging of access to client records, staff confidentiality undertakings, and a documented incident response including the notification obligations in section 22 of POPIA.

A data subject may object to processing under section 11(3) of POPIA on Form 1 of the POPIA Regulations, and may request correction or deletion of personal information under section 24(1) on Form 2. Consent for direct marketing by electronic communication under section 69 is obtained on Form 4. The practical procedure for all three, including our undertaking to accept a request in any written form that contains the same information, is set out on the data requests page.

Availability of this manual, and updating

This manual is available:

  • on this website, at this address, free of charge, in a form that can be printed or saved;
  • for inspection at the Cape Town office at Tiny Empire, 37 Buitenkant Street, District Six, during business hours, free of charge, on reasonable notice so that a person is available to hand it to you;
  • by email to any person who requests a copy from the Information Officer;
  • to the Information Regulator, on request.

A printed copy may be requested at the prescribed reproduction fee, and that fee is waived for a copy collected in person at the Cape Town office.

The manual is reviewed at least once a year and whenever the particulars in it change — a change of Information Officer, a change of registered address, a change in the categories of records held, or an amendment to PAIA or its Regulations. The version number and effective date appear at the top of this page. This is version 1.0, effective 18 August 2026, with the next scheduled review by 18 February 2027.

A shortcut most people can use

Before you fill in a form.

Most requests we receive are from clients who want their own records back, and those do not need PAIA at all. Ask your dealer, or use the data requests page. Keep the formal route for the times you actually need it.

Read next

Ask the Information Officer.

Requests, questions about the manual, or a copy of any form mentioned in it. Written requests are acknowledged within two business days with a reference number.

Investing in crypto assets may result in the loss of capital, as the value is variable and can go up as well as down. A crypto asset is not legal tender and is not a regulated deposit. Conexus Crypto provides an exchange service only and does not provide financial, investment, legal or tax advice.
WhatsApp Request a quote