PAIA & POPIA Compliance Manual
A copy of this manual is available on request from the Information Officer at hello@vaultoftime.com, and for inspection at the registered office during normal business hours.
1. Company Overview & Contact Details
| Company Name | Vault of Time (Pty) Ltd |
| Registration No. | 2025/875420/07 |
| Registered Office | 13 Senator Senekal Street, Viljoenskroon, Free State, South Africa |
| Information Officer | Nthabiseng Patsa |
| Contact Email | hello@vaultoftime.com |
| Website | vaultoftime.com |
Vault of Time is an AI-native product studio. At the date of this version it operates the following products, each with its own data footprint described in this manual: TillTap (a grocery budgeting application, tilltap.co.za); HiyaLater (a small, chronological social network, hiyalater.com); and MilliScoop (a digital generative-art service, milli.vaultoftime.com).
This manual is published on the company’s website and on the website of each product, and is available at the registered office for public inspection during normal business hours. A copy will be provided to any person on request to the Information Officer, and to the Information Regulator on request.
2. The Guide on How to Use PAIA
The Information Regulator has compiled a guide on how to use the Promotion of Access to Information Act, as contemplated in section 10 of the Act. The guide is available from the Information Regulator at www.inforegulator.org.za, and a copy is available for public inspection at the company’s registered office during normal business hours. No fee is charged for inspecting the guide.
3. Records Held in Terms of Other Legislation
Vault of Time maintains records in accordance with the Companies Act 71 of 2008; the Income Tax Act 58 of 1962; the Value Added Tax Act 89 of 1991; the Consumer Protection Act 68 of 2008; the Electronic Communications and Transactions Act 25 of 2002; the Protection of Personal Information Act 4 of 2013; and the Promotion of Access to Information Act 2 of 2000.
4. Schedule of Records Held by the Company
| Record Type | Description |
|---|---|
| TillTap Operational Records | User account identifiers, shopping lists, receipt data submitted by users for parsing, item price history, device push-notification tokens, and aggregated usage analytics. |
| HiyaLater Operational Records | Account identifiers; the sign-in email address; the chosen handle; display name; a self-described place, entered as free text by the user; corner appearance settings; public wall posts; private lists of favourited accounts; commune membership records; posts written inside communes; commune moderation records, including records of removal from a commune; and lifetime counters of communes created. Set out in full at section 5.8. |
| HiyaLater Retained Handles | After an account is deleted, the handle itself is retained together with the date of deletion and, where one was issued, the founder number. The account identifier is removed from this record. See section 5.6 for why this retention is indefinite. |
| MilliScoop Operational Records | Wallet email addresses, payment transaction references, scoop credit balances, redemption records, and artwork identifiers (Milli numbers). |
| Financial Records | Director’s loan ledger, bank statements, tax invoices, payment processor statements, and SARS correspondence. |
| Contractual Records | Terms & Conditions acceptances, purchase records, and licence records. |
5. Processing of Personal Information (POPIA)
5.1 Purpose of Processing
Personal information is collected and processed solely to:
- provide and operate the company’s products — maintaining TillTap accounts and features; operating HiyaLater accounts, walls, communes and their moderation; and honouring MilliScoop scoop credits and artwork records;
- allow people to find and recognise one another on HiyaLater by their chosen handle, and to establish who may enter a commune;
- allow commune moderators to look after the rooms they run, including removing content and removing members;
- process payments and maintain transaction records;
- send transactional communications such as sign-in links and legally required notices;
- secure and improve the services through minimal, aggregated analytics; and
- meet legal obligations, including to the South African Revenue Service and the Information Regulator.
5.2 Categories of Data Subjects
TillTap users; HiyaLater account holders, including those who create or moderate communes; MilliScoop purchasers and free-scoop users; directors of Vault of Time (Pty) Ltd; and service providers.
5.3 Recipients and Operators
Personal information is processed internally and by the following operators under POPIA: Google LLC (Firebase hosting, database, authentication, serverless functions and analytics infrastructure for all products); PayPal (payment processing for MilliScoop; PayPal acts under its own privacy policy in respect of payment credentials, which Vault of Time never receives); and Anthropic PBC (AI processing used by TillTap to parse receipt content submitted by users — no HiyaLater content is sent to any AI service). Information may further be disclosed where legally mandated, specifically to the South African Revenue Service upon lawful request.
Disclosure between users. On HiyaLater, a profile and its wall posts are public and readable by anyone. Posts written inside a commune are readable by the members of that commune and by the people who moderate it. A list of favourited accounts is private to the person who made it, and is never disclosed to the accounts on it. Records of a person’s removal from a commune are visible only to that commune’s moderators.
5.4 Information Security Measures
A general description, as contemplated in section 51(1)(c)(iii) of PAIA, sufficient for a preliminary assessment of suitability and no more specific than is prudent to publish:
- Access to records is enforced at the database layer by declarative security rules evaluated on every read and write, rather than only in application code. Rules deny by default; anything not expressly permitted is refused.
- Operations that require privilege — account deletion, commune creation, joining a commune, and all moderation actions — run as server-side functions rather than in the browser, so the checks cannot be bypassed by a modified client.
- Commune entry phrases are never stored. Each is salted with a value unique to that commune and stored only as a SHA-256 digest, which means a phrase cannot be recovered by the company or by anyone reading the database.
- Records that are private to one person — a favourites list, a commune’s contents, a removal record — are unreadable by other users at the database layer, not merely hidden in the interface.
- Authentication is delegated to Google’s identity infrastructure. Vault of Time does not hold user passwords.
5.5 Cross-Border Data Transfers (Section 72, POPIA)
The company’s products are built on infrastructure operated by Google LLC, and, for MilliScoop and TillTap respectively, by PayPal and Anthropic PBC. Where records are held determines whether a transfer out of the Republic occurs, and this differs by service:
| Service | Records | Location |
|---|---|---|
| Cloud Firestore | HiyaLater profiles, posts, communes and all related records | africa-south1 — Johannesburg, South Africa |
| Cloud Functions | Server-side processing of the above | africa-south1 — Johannesburg, South Africa |
| Firebase Authentication | Sign-in email addresses and account identifiers | United States |
| Cloud Logging | Operational logs, which contain account identifiers | Follows the project’s configured region |
| Firebase Hosting | Static application files; request logs | Distributed globally via content delivery network |
| PayPal | MilliScoop payment processing | Outside South Africa |
| Anthropic PBC | TillTap receipt content submitted for parsing | Outside South Africa |
Accordingly, the substantive content of HiyaLater — what people write, who is in which commune, and everything held about a person other than their sign-in details — is stored in South Africa and is not transferred abroad in the ordinary course. Account sign-in details, some operational logging, and the payment and receipt-parsing processing described above do involve processing outside the Republic.
In compliance with section 72 of POPIA, those transfers rest on: (a) the operators’ data processing terms, which incorporate standard contractual clauses and commitments providing an adequate level of protection substantially similar to the conditions for lawful processing under POPIA; and (b) where applicable, the consent of the data subject, obtained at the point of collection, with cross-border processing disclosed in the applicable privacy policy before submission. The company relies primarily on (a). Consent is secondary, because consent may be withdrawn while a transfer already made cannot be undone.
5.6 Data Retention Schedule
| Category | Retention Period | Trigger for Deletion |
|---|---|---|
| HiyaLater account content — profile, wall posts, commune posts, favourites, memberships, counters | While the account remains active. | Account deletion by the user, or verified deletion request. Removal is immediate and automated, and includes posts written inside communes. |
| HiyaLater retained handles | Indefinite. The handle, the date of deletion and any founder number are kept; the account identifier is removed, so the record cannot be linked back to the person by the company. | Not applicable. Retained so that a handle cannot be reissued to someone else and used to impersonate the person who formerly held it, and so that a founder number is not issued twice. |
| HiyaLater commune removal records | Until lifted by a moderator of that commune, or until the removed person’s account is deleted, whichever is first. | Lifting by a moderator; account deletion. |
| Operational logs containing account identifiers | Per the platform’s configured log retention period. | Automatic expiry. |
| TillTap account data (lists, receipts, preferences) | While the account remains active. | Account deletion by the user or verified deletion request; removal within 30 days, subject to legal holds. |
| MilliScoop wallet email & redemption records | While the wallet holds credits or redeemed Millis. | Wallet deletion request; unredeemed credits refunded before closure. |
| MilliScoop transaction records | 5 years from transaction date (tax and consumer-law obligations). | Expiry of the legal retention period; deletion or anonymisation. |
| MilliScoop unredeemed credits | 3 years from purchase (s63, Consumer Protection Act) or until redeemed. | Redemption, refund, or expiry in accordance with the published Terms. |
| Aggregated analytics | Retained only in aggregated, de-identified form. | Not applicable (not personal information once de-identified). |
| Email correspondence | 3 years from date of correspondence. | Routine deletion cycle. |
5.7 Rights of Data Subjects
Data subjects may, by contacting the Information Officer at hello@vaultoftime.com, exercise the following POPIA rights: the right of access (confirmation of what personal information is held, and a copy of it); the right to correction of inaccurate, incomplete, or outdated information; the right to deletion, subject to the company’s legal retention obligations; the right to object to processing in certain circumstances; and the right to complain to the Information Regulator (www.inforegulator.org.za; JD House, 27 Stiemens Street, Braamfontein, Johannesburg; complaints.IR@justice.gov.za) if they believe their rights have been violated.
HiyaLater account holders may delete their own account from within the product at any time, without contacting the Information Officer. Doing so removes their profile, their wall posts, their posts inside communes, their favourites list, their entry in other people’s favourites lists, and their commune memberships. The handle is retained as described in section 5.6.
5.8 HiyaLater — Detail of Personal Information Processed
Provided in the interest of sufficient detail to facilitate a request under section 51(1)(b)(iv) of PAIA.
| Information | Source | Visible to |
|---|---|---|
| Sign-in email address | The person, at sign-up | Nobody but the company and its authentication operator |
| Account identifier | Generated at sign-up | Internal; appears as the author of a post |
| Handle | Chosen by the person; permanent once claimed | Everyone |
| Display name, place, corner appearance settings | Entered by the person; free text | Everyone |
| Founder number, where issued | Assigned by the company to the first 250 accounts | Everyone |
| Wall posts | Written by the person | Everyone |
| Favourites list | Built by the person | The person only. Never disclosed to the person favourited, and never counted or published |
| Commune membership | Created when the person joins a commune | Other members of that commune |
| Commune posts | Written by the person inside a commune | Members and moderators of that commune |
| Commune moderation records | Created by a moderator’s action | Moderators of that commune |
| Lifetime count of communes created | Generated by the company | The person only |
5.9 Data Breach Notification Procedure
In the event of a data breach, the company acts in accordance with section 22 of POPIA: the Information Officer is notified immediately upon discovery; the Information Regulator is notified as soon as reasonably possible; affected data subjects are notified as soon as reasonably possible unless the Regulator directs otherwise; notifications include the nature of the breach, the information involved, and remedial steps taken; and an internal breach log is maintained for all incidents regardless of severity.
6. How to Request Access to a Record
Requests must be made on the prescribed form (Form 2 — Request for Access to Record of Private Body), available from the Information Regulator (www.inforegulator.org.za), and directed to the Information Officer at hello@vaultoftime.com.
A request fee and access fees may be payable as prescribed in terms of section 54 of PAIA. No request fee is payable where the request is for the requester’s own personal information.
The Information Officer will respond within 30 days of receiving the request, which may be extended by a further 30 days in the circumstances set out in section 57 of PAIA. Where access is refused, reasons will be given together with a statement of the requester’s right to apply to court.
7. Grounds for Refusal of Access
Access to records may be refused on the grounds set out in Part 3 of PAIA, including the mandatory protection of third parties’ personal information; commercial information held in confidence; information that could endanger the safety of individuals; information subject to legal privilege; and records required for ongoing legal proceedings.
Requesters should note in particular that the contents of a commune, and the identities of its members, are the personal information of third parties. A request for those records will be refused under section 63 of PAIA unless the third parties concerned consent or another ground in Part 3 permits disclosure.
8. Records Available Without a Request
The company has not, at the date of this version, published a description of categories of records automatically available in terms of section 52(1) of PAIA. Publicly visible product content — HiyaLater profiles, handles and wall posts — is available to anyone without a PAIA request simply by visiting the product.
| Information Officer | Version | Date |
|---|---|---|
| Nthabiseng Patsa | 4.0 | August 2026 |
This manual is reviewed annually or upon any material change to the company’s data processing activities. Version 4.0 supersedes Version 3.0 (July 2026). It records the introduction of HiyaLater; replaces the previous general statement that personal information may be processed outside South Africa with a per-service account of where records are actually held; adds a description of information security measures; declares the indefinite retention of deleted HiyaLater handles and the reason for it; corrects the attribution of the PAIA Guide to the Information Regulator; and removes references to a closed auction platform and to identity documentation that the company did not in fact hold.