EUNOIA COACHING (PTY) LTD
Registration Number: 2025/218976/07
Prepared in accordance with:
- The Promotion of Access to Information Act, 2 of 2000 (“PAIA”)
- The Protection of Personal Information Act, 4 of 2013 (“POPIA”)
Version 1.0
Effective Date: June 2026
1. INTRODUCTION
Eunoia Coaching (Pty) Ltd (“the Company”) is committed to conducting its business in a manner that respects and protects the constitutional rights of individuals, including the right of access to information and the right to privacy.
This Manual is prepared in accordance with the Promotion of Access to Information Act, 2 of 2000 (“PAIA”), and incorporates the requirements of the Protection of Personal Information Act, 4 of 2013 (“POPIA”).
The purpose of this Manual is to:
- Facilitate requests for access to records held by the Company.
- Provide information regarding the processing of personal information.
- Promote transparency and accountability.
- Inform data subjects of their rights in relation to personal information.
- Describe the measures implemented by the Company to safeguard information entrusted to it.
This Manual applies to all business activities undertaken by Eunoia Coaching (Pty) Ltd including coaching services, leadership development, consulting services, organisational development interventions, assessments, training programmes, workshops, digital products, online services and related business activities.
2. COMPANY PARTICULARS
Registered Name:
Eunoia Coaching (Pty) Ltd
Registration Number:
2025/218976/07
Physical Address:
4 Cockle Close
Richwood
Western Cape
7441
South Africa
Postal Address:
Same as physical address
Website:
www.eunoiacoaching.co.za
General Email:
carol@eunoiacoaching.co.za
Telephone:
062 964 7754
Nature of Business:
Eunoia Coaching (Pty) Ltd provides professional coaching, leadership development, personal growth programmes, organisational development services, human resources consulting, training, facilitation, assessments, digital learning resources and related professional services.
3. INFORMATION OFFICER
Information Officer:
Carol Ann Gerber
Email Address:
carol@eunoiacoaching.co.za
Telephone:
062 964 7754
The Information Officer is responsible for:
- Monitoring compliance with PAIA and POPIA.
- Managing requests for access to information.
- Managing data subject requests.
- Ensuring the lawful processing of personal information.
- Maintaining records of compliance activities.
- Reporting data breaches where required by law.
4. GUIDE TO ACCESSING INFORMATION
The Information Regulator has compiled a guide in terms of Section 10 of PAIA containing information and assistance regarding the exercise of rights under PAIA.
The guide may be obtained from:
The Information Regulator (South Africa)
Website:
www.inforegulator.org.za
Physical Address:
JD House
27 Stiemens Street
Braamfontein
Johannesburg
2001
Email:
PAIACompliance@inforegulator.org.za
Complaints Email:
POPIAComplaints@inforegulator.org.za
5. PURPOSE OF THIS MANUAL
This Manual aims to:
- Promote transparency.
- Facilitate lawful access to information.
- Protect personal information.
- Inform individuals of their rights.
- Explain how information is collected, stored, used, retained and destroyed.
- Provide procedures for requests, complaints and queries.
The Company recognises that personal information is entrusted to it by clients, prospective clients, employees, service providers and business partners and undertakes to process such information responsibly, lawfully and ethically.
6. RECORDS AVAILABLE WITHOUT A FORMAL REQUEST
The following categories of information may be made available without a formal PAIA request, subject to applicable conditions:
- Company profile and service information.
- Marketing materials.
- Public website content.
- Published articles and educational content.
- Publicly available programme information.
- Social media content.
- Contact information made publicly available by the Company.
Availability may be subject to operational requirements and the protection of confidential information.
7. RECORDS HELD BY THE COMPANY
The Company may maintain records including but not limited to:
Corporate Records
- Company registration documents.
- Tax records.
- Accounting records.
- Financial statements.
- Contracts and agreements.
- Insurance records.
- Compliance documentation.
- Policies and procedures.
Client Records
- Client registration forms.
- Service agreements.
- Coaching agreements.
- Consulting agreements.
- Assessment reports.
- Development plans.
- Session records.
- Coaching notes.
- Workshop attendance records.
- Programme participation records.
- Correspondence.
Human Resources Records
Where applicable:
- Employment contracts.
- Payroll records.
- Leave records.
- Performance records.
- Training records.
- Disciplinary records.
Supplier Records
- Service agreements.
- Invoices.
- Payment records.
- Contact information.
Information Technology Records
- Website records.
- System access logs.
- Email records.
- Electronic communications.
- Backup records.
- Security records.
8. PROCESSING OF PERSONAL INFORMATION
The Company processes personal information in accordance with POPIA and only where a lawful basis exists.
Personal information is processed for purposes including:
- Delivering coaching services.
- Delivering consulting services.
- Leadership development programmes.
- Human resources consulting.
- Assessments and profiling tools.
- Communication with clients.
- Contract administration.
- Invoicing and payment processing.
- Marketing communications where consent exists.
- Legal and regulatory compliance.
- Business administration.
Personal information will not be processed in a manner incompatible with these purposes.
9. CATEGORIES OF PERSONAL INFORMATION PROCESSED
The Company may process personal information including, but not limited to, the following categories:
Personal Details
- Full names
- Identity or passport numbers
- Date of birth
- Gender
- Marital status (where relevant)
- Nationality
Contact Information
- Residential addresses
- Postal addresses
- Email addresses
- Telephone numbers
- Emergency contact details
Financial Information
- Banking details
- Invoicing information
- Payment records
- Tax information where required
Employment and Professional Information
- Curriculum vitae
- Employment history
- Qualifications
- Professional memberships
- Performance information
- Career development information
Coaching and Development Information
- Coaching goals
- Personal development objectives
- Leadership development information
- Reflection exercises
- Coaching session notes
- Development plans
- Progress reports
- Action plans
Assessment Information
The Company may process information obtained through:
- Enneagram assessments
- Leadership assessments
- Personal development assessments
- Workplace behavioural assessments
- Coaching questionnaires
- Self-assessment instruments
- Organisational diagnostic tools
Such information is processed solely for legitimate coaching, consulting, leadership development and organisational development purposes.
10. SPECIAL PERSONAL INFORMATION
In the course of providing coaching and consulting services, the Company may occasionally process special personal information as contemplated in POPIA.
This may include information relating to:
- Religious or philosophical beliefs
- Health or wellness information voluntarily disclosed
- Trade union membership where relevant to consulting assignments
- Employment disputes
- Disciplinary matters
- Grievances
- Workplace conflict
- Diversity and inclusion matters
The Company will only process such information where:
- The data subject has consented;
- Processing is necessary for the provision of services;
- Processing is required by law; or
- Another lawful basis exists in terms of POPIA.
The Company takes particular care to ensure the confidentiality and security of sensitive information.
11. SOURCES OF PERSONAL INFORMATION
Personal information may be collected directly from:
- Clients
- Prospective clients
- Employees
- Contractors
- Service providers
- Business partners
Information may also be obtained through:
- Website enquiries
- Social media interactions
- Coaching sessions
- Training workshops
- Assessments
- Email correspondence
- Virtual meetings
- Referrals
- Publicly available sources
Where personal information is collected indirectly, the Company will process such information in accordance with applicable legislation.
12. RECIPIENTS OF PERSONAL INFORMATION
The Company may share personal information with authorised third parties where necessary for legitimate business purposes.
Recipients may include:
- Professional advisers
- Accountants
- Legal advisers
- Regulatory authorities
- Financial institutions
- Technology service providers
- Cloud storage providers
- Communication platform providers
- Website service providers
Personal information will only be disclosed where a lawful basis exists.
The Company does not sell personal information.
13. THIRD-PARTY OPERATORS
The Company may utilise third-party operators to support business operations.
These may include:
- Microsoft 365
- Zoom
- WhatsApp Business
- Brevo
- Website hosting providers
- Cloud storage providers
- Security and backup providers
The Company takes reasonable steps to ensure that operators implement appropriate security safeguards and process personal information in accordance with applicable legal requirements.
14. CROSS-BORDER TRANSFERS OF PERSONAL INFORMATION
Certain service providers utilised by the Company may store or process information outside the Republic of South Africa.
Where cross-border transfers occur, the Company shall take reasonable steps to ensure that:
- The recipient is subject to adequate data protection laws;
- Appropriate contractual safeguards are in place;
- The transfer is otherwise lawful in terms of POPIA.
15. INFORMATION SECURITY SAFEGUARDS
The Company is committed to securing personal information against loss, misuse, unauthorised access, disclosure, alteration and destruction.
Security measures may include:
- Password protection
- Multi-factor authentication
- Secure cloud storage
- Controlled access to records
- Device security measures
- Data backup procedures
- Anti-malware protection
- Secure document disposal
- Access controls and user permissions
The Company reviews its security measures periodically and updates them as necessary.
16. CONFIDENTIALITY OF COACHING AND CONSULTING INFORMATION
The Company recognises that coaching and consulting engagements frequently involve highly confidential personal and organisational information.
Subject to applicable law:
- Coaching discussions remain confidential.
- Personal development records are treated as confidential.
- Assessment results are protected.
- Coaching notes are restricted to authorised access.
- Information is not disclosed without consent unless required by law.
Where coaching services are sponsored by an employer or organisation, only agreed reporting information will be shared with the sponsoring organisation unless otherwise authorised by the participant or required by law.
This principle forms a fundamental part of the Company’s ethical and professional standards.
17. DATA SUBJECT RIGHTS
Data subjects have the right to:
- Access personal information.
- Request correction of personal information.
- Request deletion of personal information where lawful.
- Object to processing.
- Withdraw consent where applicable.
- Lodge complaints with the Information Regulator.
- Request information regarding the processing of personal information.
Requests may be submitted to the Information Officer.
The Company may require reasonable verification of identity before processing requests.
18. RETENTION OF RECORDS
The Company retains records only for as long as reasonably necessary to:
- Fulfil contractual obligations;
- Provide services;
- Comply with legal obligations;
- Resolve disputes;
- Protect legitimate business interests.
Retention periods may vary depending on the nature of the information and applicable legal requirements.
A detailed Retention and Destruction Schedule is maintained separately and reviewed periodically.
19. DESTRUCTION OF RECORDS
Where records are no longer required and no legal obligation exists to retain them, records will be securely destroyed.
Methods may include:
- Secure deletion of electronic records;
- Permanent destruction of backup copies where appropriate;
- Shredding of paper records;
- Other secure destruction methods.
The Company takes reasonable steps to prevent unauthorised access during the destruction process.
20. REQUESTS FOR ACCESS TO RECORDS
Requests for access to records held by the Company must be made in accordance with PAIA.
A requester must complete the prescribed request form and submit it to the Information Officer.
Requests must contain sufficient information to:
- Identify the requester;
- Identify the record requested;
- Indicate the form of access required;
- Enable the Company to communicate with the requester.
The Company reserves the right to request proof of identity before processing any request.
21. REQUEST PROCEDURE
The following procedure applies:
Step 1
The requester submits a written request to the Information Officer.
Step 2
The Company acknowledges receipt of the request.
Step 3
The Company evaluates whether:
- The record exists;
- Access may lawfully be granted;
- Any grounds for refusal apply.
Step 4
The requester is informed of:
- Approval of the request;
- Refusal of the request;
- Any fees payable;
- Any extension of time required.
Step 5
Where access is granted, the record will be made available in the agreed format where reasonably possible.
22. TIMEFRAMES
The Company shall respond to requests within the timeframes prescribed by PAIA.
Where necessary, the Company may extend the response period as permitted by law.
The requester will be informed of any extension and the reasons therefore.
23. GROUNDS FOR REFUSAL OF ACCESS
Access to information may be refused where permitted by PAIA, including where disclosure would:
- Infringe the privacy rights of another individual;
- Reveal confidential commercial information;
- Breach contractual confidentiality obligations;
- Compromise legal privilege;
- Endanger the safety of an individual;
- Prejudice commercial interests;
- Interfere with law enforcement activities;
- Reveal proprietary methodologies, intellectual property or trade secrets.
Each request will be considered on its own merits and in accordance with applicable legislation.
24. FEES
Fees may be payable in accordance with the regulations issued under PAIA.
Where applicable, the requester will be informed of:
- Request fees;
- Search and preparation fees;
- Reproduction costs;
- Postage or delivery costs.
The Company reserves the right to require payment of prescribed fees before processing a request.
25. COMPLAINTS AND OBJECTIONS
Any person who believes that:
- Their rights under PAIA have been infringed;
- Their personal information has been processed unlawfully;
- The Company has failed to comply with POPIA;
may lodge a complaint directly with the Information Officer.
Complaints should contain sufficient information to enable proper investigation and resolution.
The Company undertakes to investigate complaints fairly and within a reasonable period.
26. INFORMATION REGULATOR
Should a complainant not be satisfied with the outcome of an internal complaint, they may lodge a complaint with the Information Regulator.
Information Regulator (South Africa)
Physical Address:
JD House
27 Stiemens Street
Braamfontein
Johannesburg
2001
Website:
General Enquiries:
enquiries@inforegulator.org.za
PAIA Enquiries:
PAIACompliance@inforegulator.org.za
POPIA Complaints:
POPIAComplaints@inforegulator.org.za
27. AVAILABILITY OF THIS MANUAL
This Manual shall be made available:
- On request from the Information Officer;
- Through the Company’s website where applicable;
- In any other manner prescribed by law.
The Company reserves the right to update this Manual from time to time in order to reflect legislative, operational or regulatory changes.
28. REVIEW OF THE MANUAL
This Manual shall be reviewed periodically to ensure that it remains:
- Accurate;
- Legally compliant;
- Operationally relevant;
- Aligned with best practice.
The Company may amend the Manual without prior notice where necessary.
The latest version shall supersede all previous versions.
ANNEXURE A
REQUEST FOR ACCESS TO RECORDS FORM
The prescribed PAIA request form published by the Information Regulator shall be utilised for all formal requests for access to records.
The latest version of the prescribed form may be obtained from:
DATA SUBJECT ACCESS REQUEST FORM
Information Required:
- Full Name
- ID Number
- Contact Details
- Description of Personal Information Requested
- Relationship with the Company
- Preferred Method of Communication
- Signature
- Date
REQUEST FOR CORRECTION OR DELETION OF PERSONAL INFORMATION
Information Required:
- Full Name
- ID Number
- Contact Details
- Description of Information Concerned
- Correction Requested
- Reason for Correction or Deletion
- Signature
- Date
OBJECTION TO PROCESSING OF PERSONAL INFORMATION
Information Required:
- Full Name
- ID Number
- Contact Details
- Details of Objection
- Legal Basis for Objection
- Signature
- Date