← Back to home

Rent 2 — POPIA Information Manual

Required under Section 51 of the Protection of Personal Information Act, 4 of 2013 ("POPIA") Issued by: Smart Station T/A Rent2 ("Rent 2") Effective Date: 15 May 2026 Version: 1.0 Document Status: Draft for Legal Review

This manual is also our PAIA Manual under section 51 of the Promotion of Access to Information Act, 2 of 2000, as supplemented by POPIA section 51.


1. Introduction

This Information Manual describes how Smart Station T/A Rent2, trading as Rent 2, processes personal information and the procedures by which data subjects can exercise their rights under POPIA.

It is published in compliance with:

  • POPIA section 51 (Operator obligations regarding manuals)
  • PAIA section 14 (Information Manual)
  • Promotion of Access to Information Regulations, 2002

2. About Rent 2

Item Detail
Legal name Smart Station T/A Rent2
Trading name Rent 2
Type of entity to be confirmed (e.g. Private Company)
Company registration to be confirmed
VAT registration to be confirmed
Industry Software-as-a-Service (B2B vehicle finance)
Headquarters to be confirmed
Phone (Head Office) to be confirmed
General email info@rent2.co.za
Website https://rent2.co.za
Postal address to be confirmed

3. Information Officer

In terms of POPIA section 56:

Item Detail
Designated Information Officer Angela Grant
Capacity to be confirmed (e.g. Director)
Email privacy@rent2.co.za
Direct phone to be confirmed
Postal address Information Officer, Smart Station T/A Rent2, to be confirmed
Registered with Information Regulator to be confirmed (registration reference: to be confirmed)

3.1 Deputy Information Officer(s)

Name Capacity Email
to be confirmed to be confirmed to be confirmed

4. Information Regulator Contact

For complaints or queries about our compliance:

Information Regulator (South Africa)


5. Records Held by Rent 2

5.1 Categories of Records

Records held about Customers (held as Operator on behalf of Clients)

Record Type Description
Customer profiles Identity, contact, residential, employment, income, banking, NoK details
Applications 6-step wizard data, internal status, reviewer notes, decision
Application documents SA ID, proof of residence, payslips, bank statements, driver's licence, signed consents
Contracts Generated rental agreements, signature audit trails, signed PDFs
Payments Debit order history, manual EFTs, failed transactions, retries
Vehicle telemetry GPS, speed, ignition events (where a tracking device is fitted)
Incidents Accident reports, theft reports, claims
Communications Outbound emails, SMS, WhatsApp messages

Records held about Clients (held as Responsible Party)

Record Type Description
Tenant profiles Company details, owners, directors
Staff users Names, emails, roles, MFA settings, login audit
Subscriptions Tier, history, billing records
Platform invoices Issued, paid, outstanding
Usage metrics Applications, contracts, vehicles, API calls

Records held about marketing-site visitors

Record Type Description
Leads Demo bookings, contact form submissions
Cookie preferences Per-browser consent state
Analytics Anonymised page-view counts (no individual tracking)

Records held about our own staff (Employee records)

Record Type Description
Employee records Personal info, employment history, payroll, leave
Recruitment CVs, interview notes, references

5.2 Records Available Under PAIA

Records published on our website are available without request:

  • This Information Manual
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DPA Template (blank version for prospective Clients)

Records available on written request (see §9):

  • Audited financial statements (last 3 years, redacted)
  • BBBEE certificate (current)
  • Tax clearance certificate (current)
  • Sub-Operator register (current version, where the requestor has a legitimate interest)

5.3 Records Held Under Other Laws

We are required to keep certain records under other South African legislation:

Law Record Retention
Companies Act 71 of 2008 Annual financial statements, minutes, registers 7 years
Tax Administration Act 28 of 2011 Tax records, VAT, PAYE 5 years
National Credit Act 34 of 2005 Credit-related records (for Clients we serve) 5 years (Operator-side)
Basic Conditions of Employment Act 75 of 1997 Employee records 3 years post-termination
POPIA section 14 Records of processing activities 5 years
FICA 38 of 2001 Customer due diligence records (Client-side) 5 years

6. Purposes for Which Personal Information is Processed

We process personal information for the lawful purposes set out in POPIA section 11(1):

Purpose Lawful Basis (POPIA s.11) Notes
Provide the Rent 2 platform to Clients s.11(1)(b) Performance of contract MSA terms
Provide the Customer Portal to Customers post-approval s.11(1)(b) Performance of contract Rent 2 Agreement terms
Bill Clients for the subscription s.11(1)(b) Performance of contract MSA + invoice
Process Customer applications on behalf of Clients s.11(1)(b) (for Client) + Customer's consent Acting as Operator
Authenticate users s.11(1)(b) Required for portal access
Send transactional notifications s.11(1)(b) Account, billing, contract, payment
Send marketing notifications s.11(1)(a) Consent Opt-in only
Detect fraud s.11(1)(f) Legitimate interest Subject to balancing test
Comply with regulators s.11(1)(c) Legal obligation SARS, Information Regulator
Improve the Platform s.11(1)(f) Legitimate interest Only anonymised aggregate data

7. Categories of Data Subjects and Personal Information

See Privacy Policy section 4 for a comprehensive list. Summary categories:

Category Information Types
Customers (applicants and contract holders) Identity, contact, residential, employment, income, banking, NoK, application/contract data, payments, vehicle telemetry, incidents
Customers' next-of-kin and spouses Limited identity and contact information
Client staff users Name, email, role, login activity
Platform staff Name, email, role, login activity, employment records
Marketing-site visitors Name, company, email, phone (where they submit a form)

8. Recipients of Personal Information

8.1 Internal Recipients

  • The Information Officer and Deputy Information Officer(s)
  • Customer support staff (limited access, audit-logged)
  • Engineering staff (limited access for support / debugging, audit-logged)
  • Senior leadership for executive escalation only

8.2 External Recipients (Sub-Operators)

We use trusted sub-Operators, by function, to deliver the Platform:

  • Cloud database & file storage — South Africa
  • Authentication — EU/USA
  • Transactional email & hosting — South Africa (where available) / global edge
  • SMS messaging — South Africa
  • WhatsApp messaging — USA
  • Electronic signatures — EU
  • Credit-bureau enquiries — South Africa
  • Debit-order collections — South Africa
  • Vehicle telemetry — South Africa
  • Background processing (e.g. document virus-scanning) — EU/USA

Each sub-Operator is bound by a written operator agreement under POPIA section 21. A current register naming the specific sub-Operators is available on request from the Information Officer.

8.3 Cross-Border Transfers

Where personal information leaves South Africa (some operators process data in the EU and/or USA), the recipient is in a jurisdiction with substantially similar data protection laws or is bound by binding corporate rules / a written agreement giving effect to POPIA section 72.


9. Requests for Access to Information (PAIA)

9.1 How to Request

Any person may request access to records using Form 02 of the PAIA Regulations. Submit to:

  • Email: paia@rent2.co.za
  • Postal: Information Officer, Smart Station T/A Rent2, to be confirmed

9.2 Form 02 Requirements

The request must include:

  • Requestor's full name, ID number, address, email, phone
  • Sufficient particulars to identify the record(s) requested
  • The form in which access is preferred (electronic copy, hard copy, inspection)
  • A statement of the right being exercised under the Constitution or other law (if the requestor is asserting one)
  • Where the request is made on behalf of someone else, proof of authority

9.3 Fees

A standard request fee of R 50.00 is payable upfront (PAIA Regulations, refer regulation 7), waived for personal records (records about the requestor).

Access fees are charged at the rates prescribed in the PAIA Regulations:

  • Photocopy: R 1.10 per A4 page
  • Computer-readable form (CD/DVD/USB): R 70.00 per disk
  • Postage at actual cost

9.4 Response Time

  • We acknowledge receipt within 5 working days
  • We decide on the request within 30 days (extendable by 30 days for complex requests, with notice)
  • If granted, we provide access in the form requested where reasonably practicable
  • If refused, we provide reasons in writing and inform the requestor of the right to appeal to the Information Regulator

9.5 Grounds for Refusal

We may refuse access under PAIA Chapter 4 grounds, including:

  • Mandatory protection of personal information of a third party (PAIA s.34)
  • Mandatory protection of commercial information of a third party (PAIA s.36)
  • Protection of confidential information of a third party (PAIA s.37)
  • Defence, security, international relations (PAIA s.41) — unlikely applicable
  • Operations of public bodies (PAIA s.44) — N/A
  • Research information (PAIA s.43) — unlikely
  • Records subject to legal privilege (PAIA s.40)
  • Information that could prejudice commercial activities (PAIA s.36)
  • Information that could endanger life or property (PAIA s.38)

9.6 Appeal

A requestor whose request is refused may:

  • Lodge a complaint with the Information Regulator
  • Apply to the High Court for relief

10. Requests by Data Subjects Under POPIA

A data subject has the rights described in POPIA Chapter 3 Part B:

10.1 Right of Access (s.23)

Submit to privacy@rent2.co.za with proof of identity. We respond within 30 days.

10.2 Right to Correction or Deletion (s.24)

Submit a written request. Where the request is for deletion, we evaluate against retention obligations (NCA, SARS, etc.).

10.3 Right to Object (s.11(3))

Object to direct marketing or to processing based on legitimate interest. We will cease processing immediately for direct marketing, and within reasonable time for other objections (subject to balancing legitimate grounds).

10.4 Right to Withdraw Consent

Where processing is based on consent (e.g., marketing, WhatsApp opt-in), withdraw at any time.

10.5 Right to Lodge a Complaint

Direct to the Information Regulator (contact details in §4).


11. Security Measures

We have implemented the security safeguards described in:

  • Privacy Policy section 10
  • DPA section 5.2 and Annexure 4

Highlights:

  • TLS 1.3 transport encryption
  • AES-256 at-rest encryption
  • Row-level security for tenant isolation
  • Mandatory MFA for admin users
  • Annual penetration testing
  • Daily encrypted backups
  • ClamAV virus scanning
  • Immutable audit log

12. Records of Processing Activities (s.14)

We maintain documentation of:

  • Categories of data subjects and personal information
  • Purposes of processing
  • Recipients of personal information
  • Cross-border transfers
  • Time limits for erasure
  • Description of security measures

These records are available to the Information Regulator on request.


13. Approved Codes of Conduct

We are not a member of an industry body with an approved POPIA Code of Conduct. We voluntarily benchmark our practices against:

  • POPIA Code of Conduct for the financial services industry
  • ISO/IEC 27001:2022 (Information Security Management)
  • NIST Cybersecurity Framework

14. Children's Personal Information

We do not knowingly collect personal information of children under 18. Where the Platform's services concern a Customer who is a parent or guardian of a minor (e.g., next-of-kin), we collect only the minor's name and relationship — not their contact or other personal information.

Compliance with POPIA section 34 (Protection of children) is the Client's responsibility as Responsible Party.


15. Special Personal Information

We process the following Special Personal Information (POPIA s.26) only where the Client has a lawful basis under s.27:

  • Ethnic group — collected for BBBEE reporting and statistical purposes only, with the data subject's consent (s.27(1)(a))

We do not process:

  • Religious or philosophical beliefs
  • Political persuasion
  • Health information
  • Sex life information
  • Biometric information (beyond electronic signature)
  • Criminal behaviour

16. Direct Marketing

We send direct marketing communications only with prior opt-in consent as required by POPIA s.69(1)(a). Customers and Clients can opt out at any time via:

  • Email unsubscribe link
  • WhatsApp "STOP" reply
  • SMS "STOP" reply
  • In-app communication preferences

Records of consent and opt-outs are kept for 5 years.


17. Cross-Border Information Transfers (POPIA s.72)

We transfer personal information across borders only where:

  1. The recipient is subject to a law providing an adequate level of protection (e.g., EU GDPR), OR
  2. The recipient is party to a binding corporate rule or agreement requiring POPIA-equivalent protections, OR
  3. The data subject has consented, OR
  4. The transfer is necessary for performance of a contract with the data subject

A list of countries currently receiving transfers:

Country Recipient (by function) Protection Mechanism
USA Authentication, WhatsApp messaging, edge hosting Recipient bound by DPA with POPIA-equivalent terms; certified under EU DPF where applicable
EU E-signature, background processing EU GDPR adequacy + DPA

18. Updates to This Manual

This Manual is reviewed annually and after material changes to:

  • Our business operations
  • POPIA or related legislation
  • Our sub-Operator arrangements
  • Information Regulator guidance

Notifications of material changes are posted on rent2.co.za and emailed to Clients and registered Customers.


19. Useful Forms

The following forms (PAIA Regulations) are available on the Information Regulator's website (https://inforegulator.org.za):

  • Form 02 — Request for Access to Record
  • Form 03 — Outcome of Request and Access Fees
  • Form 04 — Internal Appeal
  • Form 05 — Complaint to Regulator

20. Definitions

Capitalised terms have the meanings given in POPIA and PAIA unless otherwise defined here.


Annexure A — Records Categorisation Schedule

Subject Category Access Retention Storage Location
Customer applications Personal information Client + Customer + IR (with cause) 5y post-decision Cloud storage (South Africa, af-south-1)
Customer contracts Personal information Client + Customer + IR (with cause) 5y post-end Cloud storage (South Africa, af-south-1)
Customer payments Personal information Client + Customer + SARS + IR 5y Cloud storage (South Africa, af-south-1)
Documents (ID, payslips, etc.) Personal information / Special PI Client + Customer + IR (with cause) 5y post-end Cloud storage (South Africa, af-south-1)
Marketing leads Personal information Internal sales + IR (with cause) 24m or until convert Cloud storage (South Africa, af-south-1)
Audit log Operational Internal + IR (with cause) 5y Cloud storage (South Africa, af-south-1)
Employee records Personal information HR + employee + IR 3y post-termination Internal HR system
Subscription invoices Personal information Internal billing + Client + SARS 5y Internal billing system

Revision History

Version Date Author Changes
1.0 2026-05-15 Information Officer Initial publication

This Manual is issued by Smart Station T/A Rent2 pursuant to POPIA section 51 and PAIA section 14. Last reviewed: 15 May 2026. Next scheduled review: 15 May 2027.