Tymbr

PAIA and POPIA manual

Manual of Gareth Saul trading as 20 East, a private body, prepared under section 51 of the Promotion of Access to Information Act 2 of 2000 (PAIA), as amended by the Protection of Personal Information Act 4 of 2013 (POPIA). Last updated 19 September 2026.

1. Purpose of this manual

PAIA gives people the right to access records held by private bodies when they need them to exercise or protect a right. POPIA regulates how personal information is processed. Section 51 of PAIA requires every private body to publish a manual explaining what records it holds and how to request them. The exemption that once applied to small private bodies ended on 31 December 2021, so this manual applies to 20 East regardless of its size.

20 East is the trading name of Gareth Saul, a sole proprietor who operates Tymbr, a transcription service at tymbr.dev.

2. Head of the private body and Information Officer

As a sole proprietor, Gareth Saul is both the head of the private body and its Information Officer. No deputy has been appointed.

NameGareth Saul
Trading as20 East
Physical address18 Lyndhurst Road, Kenilworth, Cape Town, 7708
Postal address18 Lyndhurst Road, Kenilworth, Cape Town, 7708
Telephoneno telephone line; email hello@tymbr.dev for questions and complaints
Emailhello@tymbr.dev
Websitehttps://tymbr.dev

3. The Information Regulator's guide

The Information Regulator has published a guide under section 10 of PAIA that explains, in every official language, how to use the Act. The guide is available from the Regulator:

The Information Regulator (South Africa)
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Email: enquiries@inforegulator.org.za
Website: https://inforegulator.org.za

4. Records we hold

20 East holds the following categories of record. Access to a record is not automatic; it depends on the requester's right of access under PAIA and the grounds for refusal in Part 3 of the Act.

CategoryExamples
Business and statutory recordsTax registrations and returns, bank records, accounting records, insurance, domain and trademark records
Customer account recordsAccount email addresses, sign-in identities, device credentials, purchase and credit usage records, support correspondence
Customer contentAudio recordings, transcripts, speaker rosters and voiceprints stored by customers in their own Tymbr accounts. These are held by 20 East as an operator on the customer's behalf.
Supplier and operator recordsAgreements and correspondence with Cloudflare, Mistral, Google Cloud and the payment processor
Technical recordsSource code, system configuration, security and access logs, incident records
Personnel recordsNone. 20 East has no employees.

5. Records available without a request

These records are published and may be read without a PAIA request:

In addition, a Tymbr account holder can view, download and delete their own recordings, transcripts, rosters, voiceprints, device credentials and purchase history directly in the web app at app.tymbr.dev, without making a formal request.

6. Records available under other legislation

Certain records may be available under other laws, independent of PAIA, including:

7. How to request a record

A request for access to a record must be made on Form 2, prescribed in the PAIA Regulations of 2021. The form is available from the Information Regulator's website or from us on request. Send the completed form to the Information Officer at hello@tymbr.dev or 18 Lyndhurst Road, Kenilworth, Cape Town, 7708.

The request must:

We will respond within 30 days of receiving the request and any fee that is payable. We may extend this once by up to 30 days where the Act allows, and we will tell you if we do. If you are a data subject asking for your own personal information, we will deal with it under POPIA and will not charge the PAIA request fee.

8. Fees

PAIA allows a private body to charge a request fee and an access fee, at the amounts set in Annexure B of the PAIA Regulations of 2021 as amended from time to time. We do not set our own amounts and will quote the current prescribed amounts when we receive a request.

FeeWhen it applies
Request feePayable when the request is made, except by a data subject requesting their own personal information
Access feeCovers search, preparation and reproduction time and materials, at the prescribed rates
DepositMay be requested where search and preparation will take more than six hours, up to one third of the estimated access fee

If a request is refused, no access fee is charged and any deposit is refunded.

9. Grounds for refusal and remedies

We may refuse access on the grounds set out in Chapter 4 of Part 3 of PAIA, including where a record would unreasonably disclose another person's personal information, would reveal commercial or confidential information of a third party, or is privileged. Where customer content is concerned, the customer is the responsible party for other people's information in their recordings, and we will refer the request to them unless the law requires us to act.

If we refuse, we will give written reasons. You may then apply to a court, or lodge a complaint with the Information Regulator at PAIAComplaints@inforegulator.org.za.

10. Processing of personal information

This section gives the information required by section 51(1)(c) to (f) of PAIA, as inserted by POPIA.

Purpose of processing

20 East processes personal information to open and secure Tymbr accounts, to transcribe and store recordings on customers' instructions, to recognise speakers where a customer has enrolled voiceprints with consent, to sell and account for prepaid credit, and to keep the service secure and lawful.

Categories of data subjects and information

Data subjectsPersonal information
Customers (account holders)Name and email address, sign-in identity, device credentials, purchase and usage records, support correspondence, IP addresses in logs
People who appear in customers' recordingsVoice, words spoken, names assigned in speaker rosters, and, where the customer has obtained consent, voiceprints (biometric information, which is special personal information)
Suppliers and contactsBusiness contact details and correspondence

Recipients

Personal information is shared only with operators that provide our infrastructure under written processing terms: Cloudflare (hosting, storage, database, queues and sign-in), Mistral (transcription and diarisation), Google Cloud (voiceprint inference and later sign-in) and Yoco (Yoco Technologies (Pty) Ltd, South Africa) (payments). We disclose information to authorities only where the law requires.

Planned transborder flows

Audio is transcribed in the European Union by Mistral. Cloudflare and Google Cloud may process information in regions outside South Africa under contractual terms that meet section 72 of POPIA. No other cross-border flows are planned.

General security measures

All data is scoped to one account and every access is checked against it. Data is encrypted in transit and at rest, and voiceprints are separately encrypted. Production access is restricted to the Information Officer with multi-factor authentication. Customers can delete their own content at any time, and deleted content is purged from backups within 30 days. Security incidents are logged and, where personal information is affected, reported to the Information Regulator and the affected data subjects under section 22 of POPIA.

11. Where to find this manual

This manual is published at https://tymbr.dev/paia.html. A copy is available free of charge by emailing hello@tymbr.dev, for inspection at our place of business during business hours, and to the Information Regulator on request, as the PAIA Regulations require. It is available in English. It will be updated whenever the information in it changes, and at least once a year.