PAIA Manual
Promotion of Access to Information Act, 2000 (Act No. 2 of 2000) — Section 51 Manual
Last updated: 24 June 2026
Published in terms of Section 51 of PAIA, as required by South African law.
Summary: This manual tells you what records Dolme SA (Pty) Ltd holds about you through the Chronic Wellness app, and how to access them. For most users, the in-app Settings → Your data → Download my data feature is the fastest route — no formal PAIA request needed. This manual covers the formal process if you need it.
1. Introduction
This manual is published by Dolme SA (Pty) Ltd in terms of Section 51 of the Promotion of Access to Information Act, 2000 (Act No. 2 of 2000) ("PAIA"), as amended by Section 110 of the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) ("POPIA").
Dolme SA (Pty) Ltd is a private body for the purposes of PAIA and the Responsible Party for the purposes of POPIA in respect of personal information processed through the Chronic Wellness application ("the App").
The purpose of this manual is to inform the public about the records held by Dolme SA (Pty) Ltd in relation to the App, and the procedure to follow when requesting access to such records.
2. Contact details of the Information Officer
Organisation: Dolme SA (Pty) Ltd
CIPC registration number: 2017/073721/07
Registered address: 683 Block V, Soshanguve, Pretoria 0152, South Africa
Information Officer: Tebogo Mazibuko
Email: tebogo.rallele@gmail.com
Privacy enquiries: privacy@dolme.co.za
Legal enquiries: legal@dolme.co.za
An Information Officer has been designated as required by Section 55 of POPIA and Section 17 of PAIA.
3. Guide on how to use PAIA
The South African Human Rights Commission (SAHRC) has compiled a guide on how to use PAIA. This guide is available from the SAHRC:
The guide contains information on how to exercise your constitutional right to access information held by public and private bodies.
4. Records held by Dolme SA (Pty) Ltd in relation to Chronic Wellness
In relation to the Chronic Wellness application, Dolme SA (Pty) Ltd holds the following categories of records, which are entered voluntarily by the user:
4.1 User account records
- Email address
- Display name
- Date of birth (optional) and preferred language
- Authentication tokens (encrypted, managed by Supabase Auth)
4.2 Conditions and disorders
- The chronic illness categories selected by the user (e.g. HIV, TB, diabetes, hypertension, asthma)
- The specific disorders, post-surgery recovery items, and mental-health add-ons the user chooses to track
4.3 Symptom logs
- Symptom name, severity, mood, free-text notes, timestamps
- Wellness photos attached to symptom entries (stored in a private Supabase Storage bucket)
4.4 Medication records
- Medication name, dosage, route, frequency, schedule
- Adherence logs (doses taken or skipped) and side-effect / reaction notes entered by the user
4.5 Vital readings
- Blood pressure, glucose, heart rate, temperature, weight, SpO₂, peak flow readings entered by the user
4.6 Daily wellbeing check-ins
- Self-reported mood, sleep, energy, pain, appetite, and concentration entries
4.7 Appointments
- Title, clinician, location, date/time, notes for appointments the user has scheduled
4.8 Medical profile
- Blood type, height, allergies, free-text medical notes
- Medical aid name and number (entered voluntarily)
- Primary care doctor details (entered voluntarily)
- Organ donor status (entered voluntarily)
4.9 Dependent profiles
- Name, date of birth, relationship, and the health-tracking data entered on behalf of minors, elderly family members, or others in the user's care
4.10 Emergency and SOS records
- Emergency contact names and phone numbers
- SOS alert history (timestamp, status)
- GPS coordinates captured at the moment the SOS button is triggered (only at trigger time — never in the background)
- The emergency PIN is stored as a salted hash on the user's device using the platform's secure storage (iOS Keychain / Android Keystore) — it is never transmitted to or held by Dolme
4.11 Caregiver sharing metadata
- Invite codes, the identity of linked caregivers, and the permission categories the user has enabled for each caregiver
4.12 Virtual Clinic + Send-to-Clinic transmission logs
- A record of user-initiated transmissions to a partner clinical workflow system, including the data categories the user confirmed for that transmission. The South African ID number entered to address a transmission is used in transit only and is not retained by the App.
4.13 Technical records
- Anonymised error logs (via the App's error-tracking service — no health content is sent)
- Aggregated, anonymised feature-usage events
All non-device data is stored in Supabase (a hosted PostgreSQL platform with data centres in the EU — eu-central-1, Frankfurt) and protected by Row Level Security policies that ensure users can only access their own data.
5. Records available without a formal request
The following information is freely available without the need to submit a formal PAIA request:
Users can also download all their own personal data at any time via Settings → Your data → Download my data (JSON), without submitting a PAIA request. Users may permanently delete their account and all associated data via Settings → Delete my account.
6. Request procedure
6.1 How to submit a request
A request for access to records held by Dolme SA (Pty) Ltd must be made on the prescribed form (Form 2 — Request for Access to Record of Private Body), available from the SAHRC website or from the Information Officer on request.
The completed form must be submitted to the Information Officer at the contact details in Section 2 above, together with:
- Proof of identity (certified copy of SA ID, passport, or other acceptable identity document)
- The prescribed request fee (if applicable — see 6.2)
6.2 Fees
A request fee and/or access fee may be payable as prescribed by the Minister of Justice and Constitutional Development under PAIA. The Information Officer will notify you of any applicable fees before processing the request. No fee is payable for personal requesters seeking records about themselves.
6.3 Timeframe
The Information Officer will respond to your request within 30 days of receipt. This period may be extended by a further 30 days if the request requires a search through a large number of records, or consultation with a third party.
7. Grounds for refusal
Access to records may be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, including:
- Section 63 — Mandatory protection of privacy of a third party (natural person)
- Section 64 — Mandatory protection of commercial information of a third party
- Section 65 — Mandatory protection of certain confidential information
- Section 66 — Mandatory protection of safety of individuals
- Section 67 — Mandatory protection of records privileged from production in legal proceedings
- Section 68 — Commercial information of the private body
- Section 69 — Research information of a third party or the private body
- Section 70 — Mandatory protection of trade secrets
If a request is refused, the requester may apply to a court of competent jurisdiction for appropriate relief.
8. Remedies available on refusal
If access to a record is refused, the requester may:
- (a) Apply to a court for appropriate relief in terms of Section 78 of PAIA
- (b) Lodge a complaint with the Information Regulator (South Africa):
Information Regulator (South Africa)
Phone: 010 023 5200
PAIA complaints: PAIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za
9. Processing of personal information (POPIA)
In compliance with Section 51(1)(c) of PAIA, as inserted by Section 110 of POPIA, the following information is provided:
9.1 Purpose of processing
Dolme SA (Pty) Ltd processes personal information through the App for the purpose of:
- Providing a personal wellness-tracking service
- Enabling users to log symptoms, medications, vital readings, daily wellbeing check-ins, and appointments
- Generating wellness summaries and PDF reports for the user's own use and to share with their healthcare provider
- Enabling caregiver sharing of categories explicitly authorised by the user
- Managing dependent profiles for minors, elderly family members, or others in the user's care
- Emergency SOS alerts to user-designated contacts, including GPS location at the moment of trigger
- Transmitting user-initiated Virtual Clinic bookings and Send-to-Clinic summaries to a partner clinical workflow system
The App is a wellness-tracking tool. It does not diagnose, treat, prescribe, or provide medical advice, and is not a registered medical device.
9.2 Categories of data subjects
- App users (primary account holders)
- Dependents (minors, elderly family members, or others managed under a primary account)
- Caregivers (linked via invite codes)
- Emergency contacts designated by the user
9.3 Recipients of personal information
- The user themselves (via in-app access, data export, and PDF wellness reports)
- Caregivers (only data categories explicitly shared by the user)
- Supabase (cloud database and storage provider, EU-hosted, under a Data Processing Agreement)
- The App's error-tracking provider (anonymised crash data only — no health content)
- The SMS partner (Clickatell) or the user's device SMS composer, used to send SOS alerts to emergency contacts when the user triggers the emergency button
- The partner clinical workflow system ("Clinical Partner Database"), only for transmissions the user initiates via Virtual Clinic or Send-to-Clinic. Once data lands there, it is governed by that system's own privacy notice and the receiving clinician's professional duties.
9.4 Cross-border transfers
Personal information is stored in Supabase's EU Central (Frankfurt) — eu-central-1 data centres. By using the App, users consent to this cross-border transfer as required by Section 72 of POPIA. Dolme relies on Supabase's contractual safeguards and binding rules on its sub-processors to ensure a standard of protection substantially similar to POPIA.
9.5 Security measures
- All data in transit is encrypted via TLS 1.2+ (TLS 1.3 where supported)
- All data at rest is encrypted by Supabase (AES-256)
- Row Level Security (RLS) ensures each user can access only their own data
- Emergency PINs are stored only as salted hashes on the user's device, never on Dolme's servers
- The Supabase service-role key is never exposed to the client application
9.6 Data subject rights
Users may exercise the following rights under POPIA:
- Right to be informed (this manual and the Privacy Policy)
- Right of access (Section 23) — via in-app Settings → Your data → Download my data
- Right to correction (Section 24) — via in-app profile editing and entry editing
- Right to deletion (Section 24) — via Settings → Delete my account
- Right to object to processing (Section 11(3)) — by contacting the Information Officer
- Right to lodge a complaint with the Information Regulator of South Africa
10. Availability of this manual
This manual is available:
- In the Chronic Wellness app under Settings → PAIA Manual
- On the Dolme website at www.dolme.co.za/chronic-wellness/paia.html
- On request from the Information Officer at the contact details in Section 2
- At the offices of the South African Human Rights Commission
Draft notice: this manual is a draft pending review by a POPIA-qualified South African attorney as part of the Wave 2 legal review. Material changes will be reflected here and in the in-app version (`src/constants/paiaManual.ts`) in lockstep.