PAIA manual

# VOVOS PANTRY — PAIA manual

**Private body · Version 1.0 · Prepared 25 September 2026**
Prepared for section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), with related Protection of Personal Information Act 4 of 2013 (POPIA) information.

## 1. Company and scope

VOVOS PANTRY is a South African private company trading as QR YOURS. QR Yours is intended for broad international public use by individuals and businesses, with QR generation, accounts, dynamic links, reporting and hosted PDFs included at launch. New PDF uploads remain unavailable before verified activation. South African incorporation is not a restriction to South African customers. QR Yours is its first and only current business activity. Additional activities are planned for the future; they are not represented as current operations in this manual.

This manual helps people identify company records and request access. Listing a category does not mean every record exists, is publicly available, or must be disclosed without assessing PAIA. Records held by service providers on the company's behalf must also be considered where applicable.

The company currently has one owner/director and no employees. Employee records are therefore not represented as a current record collection. Review this manual when staffing or activities change.

## 2. Contact details

| Item                            | Details                                                                                                       |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------- |
| Registered name                 | VOVOS PANTRY                                                                                                  |
| Company registration number     | 2026/404842/07                                                                                                |
| Head / Information Officer      | Michael Toaney Russell                                                                                        |
| IO registration                 | 2026-067416; registered 22 September 2026; appointed 22 May 2026; certificate designation INFORMATION OFFICER |
| Company position                | Sole director                                                                                                 |
| Deputy Information Officer      | None appointed                                                                                                |
| PAIA and privacy request email  | team@qryours.com                                                                                              |
| Public telephone                | 0714856395 (international: +27 71 485 6395); current until replaced                                           |
| Business / service address      | 71 MELVILE ROAD, ILLOVO, SANDTON, GAUTENG, 2196, South Africa                                                 |
| Correspondence / postal address | Same as business / service address; owner-confirmed correspondence arrangements                               |
| Service website                 | https://qryours.com                                                                                           |
| Published manual                | https://www.qryours.com/paia                                                                                  |

Address requests to the Information Officer. Identity numbers, private credentials and the registration certificate are not reproduced in this public manual.

## 3. PAIA Guide and assistance

The Information Regulator's section 10 Guide explains access rights and procedures, assistance, fees and remedies. The Guide and translations are available through the [Regulator's PAIA page](https://inforegulator.org.za/paia/). A requester may ask the Information Officer for a copy or assistance locating it. The Information Officer maintains access to the current Guide and forms and assists requesters who cannot use the online copies.

Regulator general enquiries: **enquiries@inforegulator.org.za**, **010 023 5200**. Use the current [official website](https://inforegulator.org.za/) for contact changes and the [eServices portal](https://eservices.inforegulator.org.za/) for available complaint services. General enquiries are distinct from a properly lodged complaint.

## 4. Records available without a formal PAIA request

Once published, this manual, public privacy notices, published terms, help pages and openly published product information may be read without Form 2. This does not make account records, private business documents or customer content public. Public availability is limited to pages actually published.

Signed-in QR Yours users have data export and account-deletion functions. These are useful service tools; they do not exhaust statutory access rights or prevent a person without an account from making a request. An export may not contain every record covered by a particular request.

These public materials are offered without relying on a section 52 notice. This manual does not assert that a separate section 52 notice has been issued.

## 5. Records associated with other legislation

The following identifies legislation associated with records where held and applicable. Access under another law follows that law's conditions; a recordkeeping obligation does not automatically make all records public.

| Legislation                                                     | Relevant record subjects, where held/applicable                                                |
| --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| Companies Act 71 of 2008                                        | Incorporation, director/shareholder records, resolutions and accounting records                |
| Income Tax Act 58 of 1962 and Tax Administration Act 28 of 2011 | Tax registrations, returns, supporting financial records and correspondence                    |
| PAIA and POPIA                                                  | Manual, requests, decisions, registration, privacy and security governance                     |
| Electronic Communications and Transactions Act 25 of 2002       | Electronic transactions and service disclosures where applicable                               |
| Consumer Protection Act 68 of 2008                              | Applicable consumer terms, transactions and complaints                                         |
| Value-Added Tax Act 89 of 1991                                  | VAT registration, returns and related records if applicable; no VAT-registration claim is made |

The Information Officer updates this inventory when activities or legal requirements change. Employment-related collections will be added if the company starts employing people.

## 6. Record subjects and categories

| Subject                               | Categories held or generated in the described operations                                                                  |
| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| Company administration                | Company/director documents, resolutions, regulator correspondence and registration records                                |
| Financial administration              | Accounting and tax records, transaction/subscription references, invoices and payment/refund correspondence, where held   |
| Providers and contracts               | Service arrangements, account administration, procurement and correspondence                                              |
| QR Yours accounts                     | Account identifiers, contact/profile data, authentication references and account lifecycle records                        |
| Dynamic QR service                    | Destinations and change history, QR settings/status, campaigns/placements, domain configuration and relevant diagnostics  |
| Measurement                           | Pseudonymous scan observations, summaries and usage counters; precise fields depend on the implemented analytics version  |
| Safety and operation                  | URL safety results, abuse reports, relevant security/audit events, webhook and cleanup records                            |
| Requests and correspondence           | Access/privacy requests, identity-verification evidence where necessary, decisions, complaints and support correspondence |
| Development and intellectual property | Source/configuration documentation, testing and release records, brand/design material where held                         |
| Other company business                | None currently operated, as confirmed by the owner; review when additional activities begin                               |

Hosted PDF uploads are included in the selected international launch, subject to verified production activation. Bounded harmless-document private-staging tests are recorded in the technical audit; new uploads/replacements and both AWS processing activation gates are currently off. If enabled, records include uploaded bytes and names, object/version identifiers and hashes, quarantine/validation/malware results, access/publication and replacement/deletion status. Existing records remain preserved. No production PDF activation is represented. Periodic destination availability monitoring is deferred; historical records and counters remain, but no launch availability-check service is promised.

## 7. How to request access

Use **Form 2 — Request for Access to Record**, obtainable from the [official PAIA forms page](https://inforegulator.org.za/paia/), and send it to the Information Officer at the approved section 2 address. Describe the record sufficiently to locate it, your contact details and preferred access format. Identify the right you seek to exercise or protect and explain why the requested record is needed for that right. If acting for someone else, supply appropriate proof of authority. Identity checks will be proportionate to the record and risk; do not send identity documents unnecessarily.

A decision is ordinarily due within **30 days** after receipt. PAIA allows a further period of up to **30 days** in specified circumstances; the company must give the required notice and reasons. Silence after the applicable period is treated as refusal. The Information Officer records receipt, applicable deadlines, any extension and the written outcome.

Applicable prescribed fees, exemptions and any permitted deposit must be assessed for the particular request. The Information Officer will communicate fees and the basis for them using the prescribed outcome process; no arbitrary processing charge is imposed. A personal requester is exempt from the PAIA request fee, although applicable access/reproduction charges can differ. POPIA confirmation of whether personal information is held is free. Do not apply a blanket PAIA fee to every privacy enquiry.

Access may be granted, partially granted or refused on a lawful ground. Assess third-party rights, privilege and other applicable protections; consider separating disclosable portions and the statutory public-interest override. If records cannot be found or do not exist, follow PAIA's required notification procedure. A refusal must explain the legal basis and available remedies, without disclosing protected information in the explanation.

There is no compulsory PAIA internal appeal for this private company. You may lodge a complaint with the Information Regulator using **Form 5**, generally within **180 days** of the relevant refusal; nonresponse after the applicable period can also be challenged. Court remedies may be available under PAIA. Consult the Guide/Regulator about the applicable procedure and deadlines; an informal request that the company reconsider must not be assumed to suspend them.

## 8. Personal information processing

### Purposes and people concerned

The described QR Yours processing supports accounts, QR configuration and redirects, scan reporting, service security, payments, requests and operational administration. Corporate processing supports company governance, suppliers and accounting. Grounds must be assessed by purpose; merely publishing this manual does not obtain consent.

| People/entities concerned                    | Information categories                                                                                                                                                                 |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Director/owner and company representatives   | Identity, role, contact and statutory administration information where needed                                                                                                          |
| Account holders and customer representatives | Contact/profile data, identifiers, service settings and subscription references                                                                                                        |
| People opening dynamic links                 | Request/network information processed for delivery/security; scan time, approximate location, broad device information and pseudonymous measurement fields in the newer analytics path |
| People described in customer content         | Information entered into destinations, campaign descriptions or other content                                                                                                          |
| Reporters, requesters and correspondents     | Message content, contact information and necessary verification/case records                                                                                                           |
| Provider contacts                            | Business contact, contractual and payment administration details where held                                                                                                            |
| Other company activities                     | None currently operated; add relevant subjects and information when this changes                                                                                                       |

### Recipients

For the inspected QR Yours implementation: Cloudflare supplies infrastructure; Clerk supplies authentication; Paddle supplies checkout/subscription services; Google Web Risk receives full destination URLs for relevant safety lookups. QR customers receive their own configuration and reporting summaries. Destination services receive navigation requests. Advisers and authorities may receive records where justified. Google Workspace/Gmail handles support and operational email; the configured application no longer uses Resend. Turnstile protects support, abuse and enabled uploads. The selected PDF pipeline uses Cloudflare R2/private validation and AWS S3/GuardDuty; the selected region is us-east-1 (Northern Virginia, USA), with production processing subject to verified activation. Company advisers or financial-service providers receive information only where engaged and needed for the relevant lawful purpose.

### International flows

Provider operations can involve countries outside South Africa. Cloudflare edge, support and onward processing are international; Western Europe storage-placement hints are not an EU-only guarantee. Workspace has no selected data-region restriction; no Clerk region restriction is represented. Enabled AWS PDF quarantine and scanning uses Northern Virginia, USA. Provider support and subprocessors can process data in other countries under their applicable agreements. QR Yours must establish the relevant POPIA section 72 safeguard before a restricted transfer, including binding protections and onward-transfer conditions where relying on an agreement. Applicable EU/UK transfer mechanisms must also be completed where required. Request information about relevant providers and safeguards from the Information Officer. Neither accepting this manual nor using the service is blanket consent to transfers.

### Security arrangements

The inspected QR service includes authenticated account access, access restrictions and pseudonymous analytics rather than named scanner profiles. Its newer observation tables do not store full IP addresses or full user-agent strings, although these are processed transiently and provider logs are separate. These measures do not make every record anonymous or establish all company controls.

General arrangements include restricted administrative and account access, ownership checks, verified encrypted transport, private storage, safety validation, incident/request logs and controlled deletion. Hosted documents must pass structural and malware checks before publication. Backups are restricted recovery copies; restored records must be reconciled with completed deletions before use. The operator restricts device access and credential storage and maintains provider agreements and a documented incident procedure. No universal encryption, certification, guaranteed recovery time or detection of every threat is claimed.

### Retention and rights

Retention varies by record and justified purpose. Account deletion has a 14-day recovery period followed by staged cleanup/retries, not instant erasure of all copies. Certain accounting/security records require separate retention. The Privacy Notice and retention schedule describe record-specific periods and manual reviews. The public legal copy is at https://www.qryours.com/privacy. Analytics observations keep pseudonymous daily keys for 30/90 days by plan; daily change is not erasure. General audit/abuse and monthly/lifetime records do not all expire automatically. Cloudflare is the approved main backup provider and ordinary backups have approved 30-day retention. Operational activation, controlled review of existing copies, legal holds and recovery arrangements are separate. This manual does not itself erase records. Reconcile the latest independent deletion ledger before restored data becomes accessible.

People may request access and, where the legal conditions are met, correction, deletion or objection under POPIA. Use the contact above or relevant working account controls. The Information Officer must distinguish these rights from a formal request for other company records under PAIA and apply the correct process. POPIA objections and correction/deletion requests can be supplied in accessible forms substantially equivalent to its Forms 1 and 2, including email; do not confuse those forms with PAIA Form 2. Record telephone correction/deletion requests and provide a free copy/transcript on request. The 2025 amendment requires written notification of action within 30 days of receipt of the outcome; this is not permission to leave a request undecided indefinitely. Deal with it promptly and track both decision and outcome notice. Ordinary account recovery does not extend statutory deadlines.

## 9. Availability and maintenance

This version is made available on publication at https://www.qryours.com/paia, for inspection at the principal place of business by appointment Monday to Friday, 09:00–17:00 South African time, excluding public holidays, and on request. Supply it to the Information Regulator on request. Any charge for a physical copy must follow the prescribed basis; online inspection is free. Contact the Information Officer to arrange inspection or an accessible copy; an appointment is an administrative arrangement, not an additional access fee.

The Information Officer maintains this manual and updates it when contacts, activities, records or processing materially change. Review at least annually as an internal practice. Keep request statistics and check the Regulator's applicable PAIA reporting invitation and filing window; company registration does not itself complete annual reporting.

Responsible for adoption and maintenance: Michael Toaney Russell, sole director and Information Officer. The separate adoption record identifies the effective version and approval date. Next internal review: within 12 months of adoption, or sooner after a material change.

## Drafting sources and limitations

Original company-specific draft structured using the [Information Regulator's private-body manual template](https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Manual-Template-Private-Body.pdf). Procedure references: [official forms and complaint guidance](https://inforegulator.org.za/paia/) and [section 10 Guide](https://inforegulator.org.za/wp-content/uploads/2020/07/PAIA-Guide-English_20210905.pdf). The [Justice-hosted amended PAIA text](https://www.justice.gov.za/legislation/acts/2000-002.pdf) and [2025 POPIA regulation amendments](https://inforegulator.org.za/wp-content/uploads/2025/04/POPIA-2021-Regulations-FINAL-21-Jan-2025.pdf) were checked on 24 September 2026. The amended POPIA regulation 4 no longer repeats the old manual subclause; the PAIA section 51 manual obligation remains.

Prepared from owner statements, the supplied Information Officer certificate, the separately inspected CIPC COR14.3 and engineering records. The certificate records registration 2026-067416; no independent portal-authenticity check is claimed. Registration does not certify this manual or wider compliance. Private identity documents and credentials are not reproduced. Prior drafts and their provenance remain in the internal legal closeout and immutable candidate archive.