This manual is prepared for Worthic Systems (Pty) Ltd, trading as Worthic, for purposes of the Promotion of Access to Information Act, 2000 ("PAIA") and the Protection of Personal Information Act, 2013 ("POPIA").
1. Company details
Legal name: Worthic Systems (Pty) Ltd
Registration number: 2026 / 436319 / 07
Trading name: Worthic
Registered address: 6 Scantling Road, Knysna, South Africa, 6571
Email: [email protected]
Website: https://worthic.ai
2. Information Officer
Information Officer: Jan Christiaan Oosthuizen
Information Officer appointment date: 2026-06-02
Information Regulator registration number: 2026-024584
Information Regulator registration date: 2026-06-06
Registration certificate issue timestamp: 2026-06-06 14:05:16
Deputy Information Officer: None appointed
Email for PAIA/POPIA requests: [email protected]
The Information Officer registration certificate is retained in Worthic's internal compliance records.
3. Information Regulator contact details
Information Regulator South Africa
Website: https://inforegulator.org.za
Email: [email protected]
Telephone: 010 023 5200
Data subjects may contact the Information Regulator if they believe their rights under POPIA or PAIA have been infringed.
4. Purpose of this manual
This manual explains:
- the categories of records held by Worthic;
- how to request access to records;
- how Worthic processes personal information;
- how data subjects may exercise rights under POPIA;
- the contact point for privacy and access-to-information requests.
5. Description of Worthic's business
Worthic provides a document-first accounting and finance workspace for individuals and businesses. The Service helps users upload, store, organize, extract, review, categorize, report on, and analyze financial and administrative records.
6. Records held by Worthic
Worthic may hold records in the following categories.
6.1 Company records
- incorporation and registration records;
- governance records;
- shareholder, director, and officer records;
- contracts and commercial agreements;
- policies, manuals, procedures, and compliance records;
- intellectual property records;
- tax, accounting, audit, and financial records.
6.2 Customer and user records
- account registration details;
- mobile application access records;
- authentication method, Google OAuth, trusted-device, verification, and step-up approval records;
- workspace membership and roles;
- subscription and billing records;
- billing, subscription, pricing, entitlement, and account-change audit records;
- support communications;
- usage, security, and audit logs;
- data-subject request records.
6.3 Workspace and product records
- customer workspace data;
- uploaded financial and administrative documents;
- extracted and derived document data;
- financial accounts, transactions, reports, categories, budgets, real estate records, investments, and related records;
- AI-assisted outputs, suggestions, review notes, and processing state.
6.4 Employment and contractor records
If applicable, Worthic may hold employment, contractor, payroll, tax, performance, communication, access, and compliance records.
6.5 Supplier and subprocessor records
- supplier contracts;
- service provider due diligence;
- data processing and confidentiality terms;
- invoices, payment records, and support records.
6.6 Security and operational records
- access logs;
- admin access logs;
- billing administration, subscription-change, payment-status, entitlement-change, and pricing-catalog audit records;
- authentication and session records;
- error logs and diagnostics;
- security monitoring records;
- incident records;
- backup and deletion records;
- mobile session, device, token refresh, and logout records;
- Google OAuth sign-in records and provider identifiers and
- two-factor, step-up approval, trusted-device, and sensitive-action verification records.
7. Records automatically available
Publicly available information may include:
- website content;
- published policies;
- public legal notices;
- product information;
- pricing and plan information, where published;
- help or support materials, where published.
8. Requesting access to records under PAIA
Requests for access to records should be sent to [email protected] and marked "PAIA Request".
The request should include:
- the requester's full name and contact details;
- proof of identity and authority, where required;
- a clear description of the records requested;
- the form in which access is requested;
- enough information for Worthic to identify the record;
- whether the request is made on behalf of another person.
Worthic may refuse access where permitted by law, including where disclosure would affect privacy, confidentiality, trade secrets, security, legal privilege, commercial interests, or the rights of another person.
Requests for administrative access logs or security records will be assessed under PAIA/POPIA and may be limited where disclosure would compromise security, confidential investigations, privacy of others, legal obligations, or abuse-prevention controls.
Fees may apply where permitted by PAIA.
9. POPIA personal information processing
Worthic processes personal information as described in its Privacy Policy. Categories may include:
- identity and contact details;
- account and authentication data;
- mobile app access, session, device, and trusted-device records;
- Google OAuth sign-in identifiers and authentication metadata;
- two-factor, step-up approval, and sensitive-action verification records;
- workspace and financial records;
- uploaded financial and administrative documents;
- extracted and derived document data;
- billing and subscription records;
- billing audit records, including subscription changes, payment-status events, entitlement changes, administrative billing actions, related timestamps, actor identifiers, and reason metadata;
- support communications;
- technical, device, usage, security, and audit logs;
- AI workflow inputs, outputs, and corrections.
10. Purposes of processing
Worthic processes personal information to:
- provide, operate, maintain, secure, and improve the Service;
- manage accounts, workspaces, roles, subscriptions, billing, support, mobile access, authentication methods, trusted devices, and step-up security checks;
- record and audit billing, subscription, pricing, payment-status, entitlement, and account administration changes;
- store, extract, organize, review, and analyze documents and records;
- provide AI-assisted workflow assistance;
- communicate with users;
- detect and prevent fraud, misuse, and security incidents;
- verify user identity and authorize sensitive actions through email verification, OAuth, two-factor checks, trusted-device controls, or step-up approvals;
- comply with legal obligations;
- enforce agreements and protect legal rights.
11. Recipients and subprocessors
Worthic may share personal information with authorized workspace users, service providers, subprocessors, payment providers, hosting providers, storage providers, email providers, AI processors, legal advisers, auditors, regulators, courts, and authorities where appropriate.
Where users choose Google sign-in or related OAuth functionality, Worthic may exchange limited authentication information with Google or other configured identity providers for sign-in, account linking, and security purposes. Material service providers are disclosed in Worthic’s Subprocessors page where applicable.
Material subprocessors are listed in Worthic's Subprocessors list.
12. Cross-border transfers
Worthic may process or store personal information outside South Africa where its service providers operate. Worthic uses contractual, organizational, and technical safeguards intended to protect personal information in line with POPIA and other applicable laws.
13. Security safeguards
Worthic uses reasonable technical and organizational safeguards, including access controls, encryption in transit, environment separation, logging, backups, secure hosting and storage, audit controls, and incident response practices.
Worthic limits human access to personal information and customer workspace content to authorized personnel and authorized purposes, such as support, security, reliability, legal compliance, billing/account administration, incident response, or customer-authorized assistance. Worthic does not routinely inspect customer documents as a support practice. Administrative access may be logged and reviewed, and such logs may form part of Worthic’s security and operational records.
Worthic may use mobile session controls, refresh-token controls, trusted-device records, Google OAuth, email verification, two-factor checks, and step-up approvals for sensitive actions. These controls support account security, fraud prevention, access control, and auditability of security-relevant activity.
Worthic maintains audit records for billing, subscription, entitlement, and account administration changes to support accountability, fraud prevention, dispute handling, security review, and compliance.
Security controls are summarized in the Worthic Security Overview.
14. Data-subject rights
Data subjects may request to:
- access personal information;
- correct or update personal information;
- delete personal information where legally available;
- object to processing where legally available;
- withdraw consent where processing is based on consent;
- request restriction of processing where applicable;
- lodge a complaint with Worthic or the Information Regulator.
Requests can be sent to [email protected].
Worthic may need to verify identity and authority before responding.
15. Availability of this manual
This manual is available at www.worthic.ai/legal
16. Updates
Worthic may update this manual from time to time to reflect business, legal, operational, or regulatory changes.