Manual on the Processing of Personal Information — Ignites Plus (Pty) Ltd · Reg No. 2025/663106/07
This Manual is prepared in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and describes how Ignites Plus (Pty) Ltd, trading as IgnitesPlus ("IgnitesPlus", "we", "us"), a responsible party under POPIA, collects, processes, and protects personal information, and how data subjects may exercise their rights. It is published for transparency and should be read together with our Privacy Policy and Cookie Policy.
This Manual sets out, in one place, the information a data subject reasonably needs to understand how IgnitesPlus processes personal information: who we are, what we collect and why, who we share it with, how long we keep it, how it is protected, and how to exercise your rights or lodge a complaint. Where this Manual and the Privacy Policy differ in emphasis, the Privacy Policy governs day-to-day website use, and this Manual governs as the formal compliance reference.
IgnitesPlus has appointed an Information Officer responsible for ensuring compliance with POPIA, as required by section 55 of the Act. All POPIA-related requests, queries, and complaints should be directed in the first instance to:
The Information Officer is responsible for the encouragement of compliance with the conditions for lawful processing, dealing with requests made under POPIA, working with the Information Regulator on investigations, and otherwise ensuring compliance with POPIA within IgnitesPlus.
IgnitesPlus processes personal information relating to the following categories of data subjects, for the purposes set out below.
Name, contact details, company information, and enquiry details, processed to respond to enquiries, qualify prospects against our Ideal Client Profile, and provide quotations or proposals.
Identity, contact, financial, tax, payroll, and governance information relating to client businesses and their directors, owners, or authorised representatives, processed to deliver Ignite Control, Ignite Studio, and Ignite Diagnostic engagements, including statutory filings made on a client's behalf.
Where payroll falls within an Ignite Control engagement, the names, identity numbers, banking details, and remuneration information of a client's employees, processed solely to deliver the agreed payroll, PAYE, UIF, and SDL compliance scope for that client. IgnitesPlus processes this information as an operator acting on the client's instruction in respect of the client's own employees.
Contact, banking, and engagement information relating to contracted accounting and compliance practitioners, Studio delivery contractors, and other suppliers, processed for engagement, payment, and administrative purposes.
Where IgnitesPlus advertises a role, the CV, contact, and qualification information of applicants, processed solely for recruitment purposes.
Depending on the relationship, this may include: name and contact details; identity numbers and certified ID documentation; proof of residential address; company registration, MOI, director, and beneficial ownership information; bank account and financial transaction records; SARS tax reference numbers and correspondence; VAT, PAYE, UIF, and SDL registration and submission data; payroll and remuneration records; share registers and shareholder information; and website usage and cookie data as described in our Cookie Policy.
IgnitesPlus does not deliberately collect special personal information as defined in section 26 of POPIA (such as race, health, religious or philosophical beliefs, criminal behaviour, trade union membership, or sex life) except where incidentally and unavoidably present in financial or compliance records you provide, and such information is processed only to the extent necessary for the engagement and is not used for any separate purpose.
Personal information may be disclosed, on a need-to-know basis, to:
Where a service provider used by IgnitesPlus stores or processes personal information outside South Africa, we take reasonable steps to ensure an adequate level of protection applies, in line with section 72 of POPIA, before such a transfer occurs.
IgnitesPlus applies reasonable technical and organisational measures appropriate to the sensitivity of the information processed, including role-based access restricting client records to assigned delivery team members; confidentiality undertakings from all staff and retained practitioners; secure document vault submission for sensitive client inputs and access credentials, in place of unsecured email; and use of reputable, security-conscious cloud accounting, payroll, and document platforms.
Subject to the limitations set out in POPIA, a data subject has the right to:
A request to access, correct, or delete personal information, or to object to processing, should be submitted in writing to the Information Officer using the contact details in Section 3, with sufficient detail to identify the requester and the information concerned. IgnitesPlus may request reasonable proof of identity before actioning a request. We will respond within a reasonable period and in accordance with POPIA's timeframes. Certain records, such as statutory tax and compliance filings, cannot be deleted where IgnitesPlus remains under a legal obligation to retain them.
A request for access to a record under the Promotion of Access to Information Act 2 of 2000 ("PAIA") may also be submitted to the Information Officer. IgnitesPlus will process any such request in accordance with PAIA and its own internal access procedures, and may charge the prescribed fees, where applicable.
If you are not satisfied with how IgnitesPlus has handled your request or your personal information, you may lodge a complaint with the Information Regulator of South Africa:
This Manual is reviewed periodically and updated to reflect changes in our processing activities, our service offering, or applicable law. The current version is published at ignitesplus.com and supersedes all prior versions from its Effective Date.
Related Documents