PAIA and POPIA Manual

The manual IRJ Software (Pty) Ltd publishes under section 51 of the Promotion of Access to Information Act.

PAIA and POPIA Manual

Manual prepared under section 51 of the Promotion of Access to Information Act 2 of 2000

IRJ Software (Pty) Ltd, trading as M2North · Date of compilation: 24 September 2026 · Version 2.0

This manual replaces the earlier manual published for IRJ Software cc.

1. Introduction

The Promotion of Access to Information Act 2 of 2000 ("PAIA") gives people the right to request access to records held by private bodies, where the record is needed to exercise or protect a right, subject to the grounds for refusal in the Act. This manual explains:

  • which records IRJ Software (Pty) Ltd ("M2North") holds;
  • how to request access to them;
  • how M2North processes personal information under the Protection of Personal Information Act 4 of 2013 ("POPIA").

This manual covers IRJ Software (Pty) Ltd, the South African company. M2North's United Kingdom company, IRJ.IO LTD, is not a private body under PAIA; how it handles personal information is set out in our Privacy Policy.

2. Contact details (section 51(1)(a))

Name of private bodyIRJ Software (Pty) Ltd, trading as M2North
Registration number2025/303685/07
VAT number4210183820
Head of the private bodyIvan Jenkins, Co-Founder
Information OfficerBrett Misselhorn, General Manager
Emailsupport@m2north.com
Telephone+27 11 856 2000 · 0860 000 626
Physical addressUnit 4, 8 Osborne Lane, Bedfordview Ext 447, 2008
Postal addressPostNet Suite 423, Private Bag X19, Gardenview, 2047
Websitewww.m2north.com

3. The Information Regulator's guide (section 51(1)(b))

The Information Regulator publishes a guide on how to use PAIA and POPIA, in each official language. It is available from the Information Regulator:

  • Website: www.inforegulator.org.za
  • Email: enquiries@inforegulator.org.za
  • Physical address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191

On request, M2North will provide a copy of the guide for inspection at its offices during normal business hours.

4. Records available without a request (section 51(1)(b)(ii) and section 52)

The following are freely available on www.m2north.com:

  • product and service information, pricing, and articles;
  • the Terms of Use, Terms of Payment, Sourcing Terms and Email Disclaimer;
  • the Privacy Policy;
  • this manual;
  • certification information (ISO/IEC 27001:2022, CyberVadis);
  • the public parts of company profiles in the supplier directory.

M2North has not published a notice under section 52(2).

5. Records held under other legislation (section 51(1)(b)(iii))

Where applicable, M2North keeps records in terms of:

  • Companies Act 71 of 2008
  • Income Tax Act 58 of 1962
  • Tax Administration Act 28 of 2011
  • Value-Added Tax Act 89 of 1991
  • Electronic Communications and Transactions Act 25 of 2002
  • Protection of Personal Information Act 4 of 2013
  • National Credit Act 34 of 2005, where credit information is obtained
  • Employment and labour legislation, including:
    • Basic Conditions of Employment Act 75 of 1997
    • Labour Relations Act 66 of 1995
    • Employment Equity Act 55 of 1998
    • Occupational Health and Safety Act 85 of 1993
    • Unemployment Insurance Act 63 of 2001 and Unemployment Insurance Contributions Act 4 of 2002
    • Skills Development Levies Act 9 of 1999
    • Compensation for Occupational Injuries and Diseases Act 130 of 1993
    • National Minimum Wage Act 9 of 2018
  • Broad-Based Black Economic Empowerment Act 53 of 2003
  • Copyright Act 98 of 1978, Trade Marks Act 194 of 1993 and Patents Act 57 of 1978

6. Subjects and categories of records held (section 51(1)(b)(iv))

SubjectCategories of records
CompanyRegistration documents, share register, minutes and resolutions, statutory returns
Finance and taxFinancial statements, accounting records, invoices, banking records, tax and VAT returns
Human resourcesEmployment contracts, personnel files, payroll, leave, training, disciplinary records
Customers and network membersContracts, account records, correspondence, billing records
PlatformCompany profiles, verification and screening results, compliance documents, trade documents exchanged on the platform, user accounts and activity logs
Sales and marketingEnquiries, business analysis submissions and non-disclosure agreements, newsletter subscriptions, marketing material
Suppliers and operatorsContracts, operator agreements, correspondence
Information technology and securityPolicies, ISO/IEC 27001 records, risk assessments, incident records, system and security logs
LegalAgreements, litigation records, intellectual property records

Listing a category does not mean that access to a record in it will be granted. Every request is assessed against the grounds for refusal in Chapter 4 of Part 3 of PAIA.

7. Processing of personal information (section 51(1)(c), POPIA)

7.1 Purposes

  • Providing the M2North platform and website services.
  • Verifying companies, directors and bank accounts, and screening for sanctions, fraud and trading risk.
  • Processing trade documents between buyers and suppliers.
  • Responding to enquiries and preparing business analyses.
  • Marketing to people who have opted in, and to existing customers.
  • Employment and supplier administration.
  • Meeting legal, tax, audit and security obligations.

7.2 Categories of data subjects and their personal information

Data subjectPersonal information
Contact people and users at customers, suppliers and network membersName, contact details, job title, login and activity records
Directors and signatories of companies on the networkName, identity details used for verification, such as identity numbers, and screening results
Website visitors and enquirersContact details, enquiry content, business analysis answers, NDA acceptance records, device and usage information
Newsletter subscribersName, email address, subscription preferences
Employees and job applicantsIdentity and contact details, qualifications, employment and payroll records, banking and tax details
Suppliers and operators of M2NorthContact people, contractual and banking details

7.3 Recipients

Personal information may be shared with:

  • IRJ.IO LTD, M2North's United Kingdom company;
  • other network members, as needed to provide the platform;
  • operators that process information on M2North's behalf, namely:
    • cloud hosting providers;
    • email and messaging providers;
    • analytics providers;
    • verification, screening and credit data providers;
    • professional advisers and auditors;
  • regulators, courts and law enforcement, where the law requires it.

7.4 Planned transborder flows

Personal information passes between South Africa and the United Kingdom, where M2North also operates. Some operators store or process personal information in other countries, including the European Union and the United States. These transfers are made in line with section 72 of POPIA.

7.5 Security measures

M2North's information security management system is certified to ISO/IEC 27001:2022 (certificate ZA10649E). Its controls include:

  • encryption of information in transit and at rest;
  • role-based access control;
  • logging and monitoring;
  • backups;
  • incident response;
  • staff confidentiality obligations;
  • operator agreements.

M2North achieved a CyberVadis Silver rating in 2026.

8. How to request access (section 51(1)(e))

  1. Use the prescribed form. Requests must be made on Form 2 of the PAIA Regulations, 2021, which is available from the Information Regulator's website. Send it to the Information Officer using the contact details in section 2.
  2. Give enough detail. Include enough detail to identify the record and yourself, the form of access you want, and the right you are seeking to exercise or protect.
  3. Fees. A requester (other than a personal requester asking for their own personal information) must pay the prescribed request fee before the request is processed. An access fee may also be payable. Fees are those prescribed in the PAIA Regulations, 2021, as amended from time to time.
  4. Timeframes. M2North will decide on the request within 30 days. That period may be extended once by up to 30 days, as PAIA allows, with notice.
  5. Refusal. Access may be refused on the grounds in PAIA, for example to protect the privacy of third parties, commercial information of third parties, confidential information, or safety and security.
  6. Remedies. A requester who is dissatisfied with a decision may lodge a complaint with the Information Regulator, or apply to a court, within the periods PAIA prescribes.

Requests by a data subject for their own personal information, or to correct or delete it, can also be made under POPIA by emailing the Information Officer. See the Privacy Policy.

9. Availability of this manual (section 51(3))

This manual is available:

  • on www.m2north.com;
  • for inspection at M2North's offices during business hours, free of charge;
  • on request from the Information Regulator.