Banklink

PAIA Manual

Manual in terms of section 51 of the Promotion of Access to Information Act 2 of 2000

Last updated: September 2026

1. Introduction

1.1

The Promotion of Access to Information Act 2 of 2000 ("PAIA") gives effect to the constitutional right of access to information held by the State and to information held by another person that is required for the exercise or protection of any right.

1.2

This manual is published in terms of section 51 of PAIA. It describes the records held by the company, how to request access to them, and what a requester may do if a request is refused.

1.3

This manual should be read with the Privacy Policy, which explains how personal information is processed under the Protection of Personal Information Act 4 of 2013 ("POPIA").

2. Particulars of the private body

Registered name
K2026171517 (South Africa)
Registration number
K2026171517
Trading as
Banklink
Information Officer
Niel Barnard
Email
privacy@banklink.co.za
Website
https://banklink.co.za

3. The Information Regulator’s guide on how to use PAIA

3.1

The Information Regulator has compiled a guide in terms of section 10 of PAIA, in an easily comprehensible form, containing the information a person needs in order to exercise the rights PAIA confers.

3.2

The guide is available from the Information Regulator at inforegulator.org.za, which also publishes the prescribed forms, the prescribed fees, and contact details for enquiries and complaints.

4. Records available without a request

4.1

No notice has been published in terms of section 52(2) of PAIA specifying categories of records that are automatically available without a request.

4.2

The following are nonetheless published freely at banklink.co.za and require no request: product and feature descriptions, pricing, the Terms of Service, the Privacy Policy, the Refund Policy, API documentation and reference material, and published articles and guides.

5. Records available in terms of other legislation

Certain records are accessible in terms of other legislation rather than PAIA. Depending on the record and the requester, these may include the Companies Act 71 of 2008, POPIA, the Tax Administration Act 28 of 2011, the Income Tax Act 58 of 1962, the Value-Added Tax Act 89 of 1991, the Basic Conditions of Employment Act 75 of 1997, the Labour Relations Act 66 of 1995, and the Electronic Communications and Transactions Act 25 of 2002. Access under those laws follows the procedures they prescribe.

6. Categories of records held

The service is built to pass bank data through rather than accumulate it. What is actually held depends on how the client has configured it, and in the most common configuration no bank credentials and no transaction records are retained at all. Listing a category below does not mean every record in it exists for a given client, nor that it will be released; requests are considered against the grounds for refusal in Chapter 4 of PAIA.

6.1

Held in all cases: corporate records (founding documents, registration details, statutory registers, board and shareholder records, insurance); client account records (organisation and user details, contracts and order forms, roles and permissions, API keys and their scopes, support correspondence, audit logs of user actions); operational records (fetch job and delivery records, usage and billing records, system and security logs, incident records); financial records (invoices, payment and payout records, tax records, and records held by our payment processor as merchant of record); employee and contractor records where applicable; and marketing records (enquiry submissions, mailing preferences, aggregated website analytics).

6.2

Held only where a client links an account for recurring fetches: bank access credentials, held encrypted with a separate key, stored apart from other records, never written to logs and never in plaintext. Where a client instead uses the single-use hosted access flow, credentials are passed directly to the retrieval service to authenticate with the financial institution and are never written to our records at all.

6.3

Held only where a client selects the dashboard destination: retrieved transaction records and bank account metadata. Where a client delivers to a webhook or email address instead, transactions are retrieved, delivered and discarded — they are not written to our records. Our job records retain only the outcome of a fetch, such as the number of records inserted or skipped, and never the retrieved transactions themselves.

6.4

Not held in any configuration: any financial data beyond what the client has expressly configured us to retain. We do not accumulate transaction history, build profiles of end users, or retain retrieved data for our own purposes.

6.5

To be clear about what pass-through means: to retrieve data we must authenticate with the financial institution and handle the retrieved records in order to deliver them. The commitment is that this happens in memory for the purpose the client instructed and is not written to our records, not that the data never passes through our systems.

7. Processing of personal information

Set out in terms of section 51(1)(e) of PAIA, as amended by POPIA.

7.1

Purpose of the processing: to provide, operate, support and secure the Banklink service; to retrieve and deliver financial account data on client instruction, retaining it only where the client has configured us to; to authenticate users and control access; to bill for usage; to meet legal, tax and regulatory obligations; and to detect, investigate and prevent fraud, abuse and security incidents.

7.2

Categories of data subjects and the information relating to them: clients and their personnel (identity and contact details, authentication identifiers, role and permission records, activity logs); end users whose financial accounts are accessed (bank account metadata, transaction records and access credentials — each retained only where the client has expressly configured retention, and in the default pass-through configuration none of them are); prospective clients (contact details and enquiry content); employees and contractors (employment and remuneration records); and suppliers (contact and payment details).

7.3

Recipients or categories of recipients: our hosting and infrastructure providers; our identity, email delivery and analytics providers; our payment processor acting as merchant of record; the financial institutions from which data is retrieved on instruction; professional advisers including auditors and attorneys; and regulators, law enforcement or courts where disclosure is legally required.

7.4

Planned transborder flows: some service providers process personal information outside the Republic of South Africa. Where personal information is transferred across a border, it is transferred only on a basis permitted by section 72 of POPIA.

7.5

Information security measures: a general description sufficient for a preliminary assessment of suitability — encryption of data in transit and at rest; bank access credentials encrypted with a separate key and stored apart from other records; role-based access control with authentication through a dedicated identity provider; audit logging of user actions; network isolation between service components; secrets held in a dedicated secrets manager rather than in source control; and regular patching and backup of systems. Banklink is operated in line with ISO/IEC 27001:2022 controls; formal certification is in progress.

8. How to request access to a record

8.1

A request must be made on the form prescribed by the PAIA Regulations and sent to the Information Officer at the email address in section 2 above. The company’s postal and street address and telephone number are supplied on request to that address, and a requester who requires them in order to lodge a request should ask.

8.2

The request must provide sufficient particulars to identify the record and the requester, state the form of access required, give an address in the Republic for delivery, and identify the right the requester seeks to exercise or protect together with an explanation of why the record is required for that purpose.

8.3

Where a request is made on behalf of another person, proof of the capacity in which the requester is acting must be attached.

8.4

A request fee and, where access is granted, an access fee are payable at the rates prescribed in the PAIA Regulations. Current amounts are published by the Information Regulator. The Information Officer may require a deposit where preparation is expected to take substantial time, and access may be withheld until the fees are paid.

8.5

The Information Officer will decide on a request within 30 days of receipt and notify the requester of the decision. That period may be extended once by a further 30 days where the request is for a large number of records or requires a search through records held elsewhere, and the requester will be notified of any extension.

9. Grounds on which a request may be refused

Chapter 4 of Part 3 of PAIA sets out the grounds on which access must or may be refused. They include the mandatory protection of the privacy of a third party who is a natural person; the commercial information of the company or a third party, including trade secrets and information whose disclosure would harm commercial or financial interests; information supplied in confidence; records privileged from production in legal proceedings; information whose disclosure would endanger the life or physical safety of an individual or prejudice the security of property or a system; and research information. Where a ground applies to only part of a record, access will be given to the remainder.

10. Remedies available if a request is refused

10.1

PAIA provides no internal appeal against a decision of the head of a private body.

10.2

A requester who is dissatisfied with a decision may lodge a complaint with the Information Regulator, or apply to a court with jurisdiction, within 180 days of the decision.

10.3

Complaints to the Information Regulator are lodged on the forms and at the contact details published at inforegulator.org.za.

11. Availability of this manual

This manual is available on this website, for inspection at the principal place of business during normal business hours, to the Information Regulator on request, and to any person on request against payment of the prescribed fee. It is reviewed and updated as necessary.