Rent 2 — POPIA Information Manual
Required under Section 51 of the Protection of Personal Information Act, 4 of 2013 ("POPIA") Issued by: Smart Station T/A Rent2 ("Rent 2") Effective Date: 15 May 2026 Version: 1.0 Document Status: Draft for Legal Review
This manual is also our PAIA Manual under section 51 of the Promotion of Access to Information Act, 2 of 2000, as supplemented by POPIA section 51.
1. Introduction
This Information Manual describes how Smart Station T/A Rent2, trading as Rent 2, processes personal information and the procedures by which data subjects can exercise their rights under POPIA.
It is published in compliance with:
- POPIA section 51 (Operator obligations regarding manuals)
- PAIA section 14 (Information Manual)
- Promotion of Access to Information Regulations, 2002
2. About Rent 2
| Item | Detail |
|---|---|
| Legal name | Smart Station T/A Rent2 |
| Trading name | Rent 2 |
| Type of entity | to be confirmed (e.g. Private Company) |
| Company registration | to be confirmed |
| VAT registration | to be confirmed |
| Industry | Software-as-a-Service (B2B vehicle finance) |
| Headquarters | to be confirmed |
| Phone (Head Office) | to be confirmed |
| General email | info@rent2.co.za |
| Website | https://rent2.co.za |
| Postal address | to be confirmed |
3. Information Officer
In terms of POPIA section 56:
| Item | Detail |
|---|---|
| Designated Information Officer | Angela Grant |
| Capacity | to be confirmed (e.g. Director) |
| privacy@rent2.co.za | |
| Direct phone | to be confirmed |
| Postal address | Information Officer, Smart Station T/A Rent2, to be confirmed |
| Registered with Information Regulator | to be confirmed (registration reference: to be confirmed) |
3.1 Deputy Information Officer(s)
| Name | Capacity | |
|---|---|---|
| to be confirmed | to be confirmed | to be confirmed |
4. Information Regulator Contact
For complaints or queries about our compliance:
Information Regulator (South Africa)
- Chairperson: Adv Pansy Tlakula
- Postal address: PO Box 31533, Braamfontein, Johannesburg, 2017
- Physical address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg
- General queries: enquiries@inforegulator.org.za
- POPIA complaints: POPIAComplaints@inforegulator.org.za
- PAIA complaints: PAIAComplaints@inforegulator.org.za
- Website: https://inforegulator.org.za
5. Records Held by Rent 2
5.1 Categories of Records
Records held about Customers (held as Operator on behalf of Clients)
| Record Type | Description |
|---|---|
| Customer profiles | Identity, contact, residential, employment, income, banking, NoK details |
| Applications | 6-step wizard data, internal status, reviewer notes, decision |
| Application documents | SA ID, proof of residence, payslips, bank statements, driver's licence, signed consents |
| Contracts | Generated rental agreements, signature audit trails, signed PDFs |
| Payments | Debit order history, manual EFTs, failed transactions, retries |
| Vehicle telemetry | GPS, speed, ignition events (where a tracking device is fitted) |
| Incidents | Accident reports, theft reports, claims |
| Communications | Outbound emails, SMS, WhatsApp messages |
Records held about Clients (held as Responsible Party)
| Record Type | Description |
|---|---|
| Tenant profiles | Company details, owners, directors |
| Staff users | Names, emails, roles, MFA settings, login audit |
| Subscriptions | Tier, history, billing records |
| Platform invoices | Issued, paid, outstanding |
| Usage metrics | Applications, contracts, vehicles, API calls |
Records held about marketing-site visitors
| Record Type | Description |
|---|---|
| Leads | Demo bookings, contact form submissions |
| Cookie preferences | Per-browser consent state |
| Analytics | Anonymised page-view counts (no individual tracking) |
Records held about our own staff (Employee records)
| Record Type | Description |
|---|---|
| Employee records | Personal info, employment history, payroll, leave |
| Recruitment | CVs, interview notes, references |
5.2 Records Available Under PAIA
Records published on our website are available without request:
- This Information Manual
- Privacy Policy
- Terms of Service
- Cookie Policy
- DPA Template (blank version for prospective Clients)
Records available on written request (see §9):
- Audited financial statements (last 3 years, redacted)
- BBBEE certificate (current)
- Tax clearance certificate (current)
- Sub-Operator register (current version, where the requestor has a legitimate interest)
5.3 Records Held Under Other Laws
We are required to keep certain records under other South African legislation:
| Law | Record | Retention |
|---|---|---|
| Companies Act 71 of 2008 | Annual financial statements, minutes, registers | 7 years |
| Tax Administration Act 28 of 2011 | Tax records, VAT, PAYE | 5 years |
| National Credit Act 34 of 2005 | Credit-related records (for Clients we serve) | 5 years (Operator-side) |
| Basic Conditions of Employment Act 75 of 1997 | Employee records | 3 years post-termination |
| POPIA section 14 | Records of processing activities | 5 years |
| FICA 38 of 2001 | Customer due diligence records (Client-side) | 5 years |
6. Purposes for Which Personal Information is Processed
We process personal information for the lawful purposes set out in POPIA section 11(1):
| Purpose | Lawful Basis (POPIA s.11) | Notes |
|---|---|---|
| Provide the Rent 2 platform to Clients | s.11(1)(b) Performance of contract | MSA terms |
| Provide the Customer Portal to Customers post-approval | s.11(1)(b) Performance of contract | Rent 2 Agreement terms |
| Bill Clients for the subscription | s.11(1)(b) Performance of contract | MSA + invoice |
| Process Customer applications on behalf of Clients | s.11(1)(b) (for Client) + Customer's consent | Acting as Operator |
| Authenticate users | s.11(1)(b) | Required for portal access |
| Send transactional notifications | s.11(1)(b) | Account, billing, contract, payment |
| Send marketing notifications | s.11(1)(a) Consent | Opt-in only |
| Detect fraud | s.11(1)(f) Legitimate interest | Subject to balancing test |
| Comply with regulators | s.11(1)(c) Legal obligation | SARS, Information Regulator |
| Improve the Platform | s.11(1)(f) Legitimate interest | Only anonymised aggregate data |
7. Categories of Data Subjects and Personal Information
See Privacy Policy section 4 for a comprehensive list. Summary categories:
| Category | Information Types |
|---|---|
| Customers (applicants and contract holders) | Identity, contact, residential, employment, income, banking, NoK, application/contract data, payments, vehicle telemetry, incidents |
| Customers' next-of-kin and spouses | Limited identity and contact information |
| Client staff users | Name, email, role, login activity |
| Platform staff | Name, email, role, login activity, employment records |
| Marketing-site visitors | Name, company, email, phone (where they submit a form) |
8. Recipients of Personal Information
8.1 Internal Recipients
- The Information Officer and Deputy Information Officer(s)
- Customer support staff (limited access, audit-logged)
- Engineering staff (limited access for support / debugging, audit-logged)
- Senior leadership for executive escalation only
8.2 External Recipients (Sub-Operators)
We use trusted sub-Operators, by function, to deliver the Platform:
- Cloud database & file storage — South Africa
- Authentication — EU/USA
- Transactional email & hosting — South Africa (where available) / global edge
- SMS messaging — South Africa
- WhatsApp messaging — USA
- Electronic signatures — EU
- Credit-bureau enquiries — South Africa
- Debit-order collections — South Africa
- Vehicle telemetry — South Africa
- Background processing (e.g. document virus-scanning) — EU/USA
Each sub-Operator is bound by a written operator agreement under POPIA section 21. A current register naming the specific sub-Operators is available on request from the Information Officer.
8.3 Cross-Border Transfers
Where personal information leaves South Africa (some operators process data in the EU and/or USA), the recipient is in a jurisdiction with substantially similar data protection laws or is bound by binding corporate rules / a written agreement giving effect to POPIA section 72.
9. Requests for Access to Information (PAIA)
9.1 How to Request
Any person may request access to records using Form 02 of the PAIA Regulations. Submit to:
- Email: paia@rent2.co.za
- Postal: Information Officer, Smart Station T/A Rent2, to be confirmed
9.2 Form 02 Requirements
The request must include:
- Requestor's full name, ID number, address, email, phone
- Sufficient particulars to identify the record(s) requested
- The form in which access is preferred (electronic copy, hard copy, inspection)
- A statement of the right being exercised under the Constitution or other law (if the requestor is asserting one)
- Where the request is made on behalf of someone else, proof of authority
9.3 Fees
A standard request fee of R 50.00 is payable upfront (PAIA Regulations, refer regulation 7), waived for personal records (records about the requestor).
Access fees are charged at the rates prescribed in the PAIA Regulations:
- Photocopy: R 1.10 per A4 page
- Computer-readable form (CD/DVD/USB): R 70.00 per disk
- Postage at actual cost
9.4 Response Time
- We acknowledge receipt within 5 working days
- We decide on the request within 30 days (extendable by 30 days for complex requests, with notice)
- If granted, we provide access in the form requested where reasonably practicable
- If refused, we provide reasons in writing and inform the requestor of the right to appeal to the Information Regulator
9.5 Grounds for Refusal
We may refuse access under PAIA Chapter 4 grounds, including:
- Mandatory protection of personal information of a third party (PAIA s.34)
- Mandatory protection of commercial information of a third party (PAIA s.36)
- Protection of confidential information of a third party (PAIA s.37)
- Defence, security, international relations (PAIA s.41) — unlikely applicable
- Operations of public bodies (PAIA s.44) — N/A
- Research information (PAIA s.43) — unlikely
- Records subject to legal privilege (PAIA s.40)
- Information that could prejudice commercial activities (PAIA s.36)
- Information that could endanger life or property (PAIA s.38)
9.6 Appeal
A requestor whose request is refused may:
- Lodge a complaint with the Information Regulator
- Apply to the High Court for relief
10. Requests by Data Subjects Under POPIA
A data subject has the rights described in POPIA Chapter 3 Part B:
10.1 Right of Access (s.23)
Submit to privacy@rent2.co.za with proof of identity. We respond within 30 days.
10.2 Right to Correction or Deletion (s.24)
Submit a written request. Where the request is for deletion, we evaluate against retention obligations (NCA, SARS, etc.).
10.3 Right to Object (s.11(3))
Object to direct marketing or to processing based on legitimate interest. We will cease processing immediately for direct marketing, and within reasonable time for other objections (subject to balancing legitimate grounds).
10.4 Right to Withdraw Consent
Where processing is based on consent (e.g., marketing, WhatsApp opt-in), withdraw at any time.
10.5 Right to Lodge a Complaint
Direct to the Information Regulator (contact details in §4).
11. Security Measures
We have implemented the security safeguards described in:
- Privacy Policy section 10
- DPA section 5.2 and Annexure 4
Highlights:
- TLS 1.3 transport encryption
- AES-256 at-rest encryption
- Row-level security for tenant isolation
- Mandatory MFA for admin users
- Annual penetration testing
- Daily encrypted backups
- ClamAV virus scanning
- Immutable audit log
12. Records of Processing Activities (s.14)
We maintain documentation of:
- Categories of data subjects and personal information
- Purposes of processing
- Recipients of personal information
- Cross-border transfers
- Time limits for erasure
- Description of security measures
These records are available to the Information Regulator on request.
13. Approved Codes of Conduct
We are not a member of an industry body with an approved POPIA Code of Conduct. We voluntarily benchmark our practices against:
- POPIA Code of Conduct for the financial services industry
- ISO/IEC 27001:2022 (Information Security Management)
- NIST Cybersecurity Framework
14. Children's Personal Information
We do not knowingly collect personal information of children under 18. Where the Platform's services concern a Customer who is a parent or guardian of a minor (e.g., next-of-kin), we collect only the minor's name and relationship — not their contact or other personal information.
Compliance with POPIA section 34 (Protection of children) is the Client's responsibility as Responsible Party.
15. Special Personal Information
We process the following Special Personal Information (POPIA s.26) only where the Client has a lawful basis under s.27:
- Ethnic group — collected for BBBEE reporting and statistical purposes only, with the data subject's consent (s.27(1)(a))
We do not process:
- Religious or philosophical beliefs
- Political persuasion
- Health information
- Sex life information
- Biometric information (beyond electronic signature)
- Criminal behaviour
16. Direct Marketing
We send direct marketing communications only with prior opt-in consent as required by POPIA s.69(1)(a). Customers and Clients can opt out at any time via:
- Email unsubscribe link
- WhatsApp "STOP" reply
- SMS "STOP" reply
- In-app communication preferences
Records of consent and opt-outs are kept for 5 years.
17. Cross-Border Information Transfers (POPIA s.72)
We transfer personal information across borders only where:
- The recipient is subject to a law providing an adequate level of protection (e.g., EU GDPR), OR
- The recipient is party to a binding corporate rule or agreement requiring POPIA-equivalent protections, OR
- The data subject has consented, OR
- The transfer is necessary for performance of a contract with the data subject
A list of countries currently receiving transfers:
| Country | Recipient (by function) | Protection Mechanism |
|---|---|---|
| USA | Authentication, WhatsApp messaging, edge hosting | Recipient bound by DPA with POPIA-equivalent terms; certified under EU DPF where applicable |
| EU | E-signature, background processing | EU GDPR adequacy + DPA |
18. Updates to This Manual
This Manual is reviewed annually and after material changes to:
- Our business operations
- POPIA or related legislation
- Our sub-Operator arrangements
- Information Regulator guidance
Notifications of material changes are posted on rent2.co.za and emailed to Clients and registered Customers.
19. Useful Forms
The following forms (PAIA Regulations) are available on the Information Regulator's website (https://inforegulator.org.za):
- Form 02 — Request for Access to Record
- Form 03 — Outcome of Request and Access Fees
- Form 04 — Internal Appeal
- Form 05 — Complaint to Regulator
20. Definitions
Capitalised terms have the meanings given in POPIA and PAIA unless otherwise defined here.
Annexure A — Records Categorisation Schedule
| Subject | Category | Access | Retention | Storage Location |
|---|---|---|---|---|
| Customer applications | Personal information | Client + Customer + IR (with cause) | 5y post-decision | Cloud storage (South Africa, af-south-1) |
| Customer contracts | Personal information | Client + Customer + IR (with cause) | 5y post-end | Cloud storage (South Africa, af-south-1) |
| Customer payments | Personal information | Client + Customer + SARS + IR | 5y | Cloud storage (South Africa, af-south-1) |
| Documents (ID, payslips, etc.) | Personal information / Special PI | Client + Customer + IR (with cause) | 5y post-end | Cloud storage (South Africa, af-south-1) |
| Marketing leads | Personal information | Internal sales + IR (with cause) | 24m or until convert | Cloud storage (South Africa, af-south-1) |
| Audit log | Operational | Internal + IR (with cause) | 5y | Cloud storage (South Africa, af-south-1) |
| Employee records | Personal information | HR + employee + IR | 3y post-termination | Internal HR system |
| Subscription invoices | Personal information | Internal billing + Client + SARS | 5y | Internal billing system |
Revision History
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 2026-05-15 | Information Officer | Initial publication |
This Manual is issued by Smart Station T/A Rent2 pursuant to POPIA section 51 and PAIA section 14. Last reviewed: 15 May 2026. Next scheduled review: 15 May 2027.