Manual prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000, including records processed under the Protection of Personal Information Act, 4 of 2013, retention periods and data removal guidelines.
This manual describes Briisk Insur Fintech (Pty) Ltd, the records it holds, how a request for access may be made, and how such a request will be handled.
The Promotion of Access to Information Act, 2 of 2000 (PAIA) gives effect to the constitutional right of access to information held by the State, and to information held by another person that is required for the exercise or protection of any right.
This manual is published in terms of section 51 of PAIA. It describes Briisk Insur Fintech (Pty) Ltd, the records it holds, how a request for access may be made, and how such a request will be handled. It also records the categories of personal information processed, the purposes of processing, and the periods for which records are retained, together with the process by which a person may request deletion of their personal information.
This manual is available on this website and on request from the Information Officer at the address in section 2.
| Name | Briisk Insur Fintech (Pty) Ltd |
| Registration number | 2019/056894/07 |
| Physical address | Black River Park, 2 Fir Street, 1st Floor, Block B, North Park, Observatory, Cape Town, 7925, South Africa |
| Postal address | Black River Park, 2 Fir Street, 1st Floor, Block B, North Park, Observatory, Cape Town, 7925, South Africa |
| Telephone | +27 83 321 9369 |
| Website | www.briisk.io |
| Information Officer | Hanno van Aarde |
| Information Officer email | privacy@briisk.io |
Note on the Information Officer. Under POPIA the Information Officer of a private body is the head of that body — for a company, the chief executive officer or equivalent officer — unless and until deputies are duly designated. The Information Officer must be registered with the Information Regulator.
The Information Regulator has compiled a guide in terms of section 10 of PAIA, containing information reasonably required by a person wishing to exercise a right under the Act. The guide is available from the Information Regulator.
Information Regulator (South Africa)
Briisk has not published a notice under section 52(2) of PAIA.
The following are available on this website or on request, without a formal PAIA request:
The following categories of record are held. Inclusion in this list does not mean that a record will be made available; access is determined against the grounds for refusal in Chapter 4 of Part 3 of PAIA.
| Category | Subject matter | Governing law |
|---|---|---|
| Company records | Memorandum of Incorporation, statutory registers, board and shareholder records, share register | Companies Act 71 of 2008 |
| Financial records | Annual financial statements, accounting records, tax records, banking records | Companies Act; Tax Administration Act; Income Tax Act; Value-Added Tax Act |
| Employee records | Contracts of employment, payroll, leave, disciplinary records, training records, recruitment records | Basic Conditions of Employment Act; Labour Relations Act; Employment Equity Act; Skills Development Act |
| Client and contract records | Client agreements, service level agreements, correspondence, project records | Common law; Companies Act |
| Supplier records | Supplier agreements, due diligence records, invoices, Operator agreements | Companies Act; POPIA |
| Platform and policy records | Policy and quotation data, premium collection records, claims notifications, customer onboarding records held on behalf of clients | FAIS; FICA; insurance legislation; POPIA |
| Identity verification records | KYC and customer due diligence records | FICA |
| Technical records | System logs, audit trails, incident records, security testing reports, architecture documentation | POPIA; ISO/IEC 27001 |
| Compliance records | Information security management system documentation, risk register, compliance reports, regulatory correspondence | POPIA; FAIS |
| Marketing records | Contact lists, consent and opt-out records, campaign records | POPIA; Consumer Protection Act; Electronic Communications and Transactions Act |
Briisk processes personal information in two distinct capacities:
This distinction determines who a data subject must approach to exercise their rights. See section 10.
| Data subject | Categories of information | Capacity |
|---|---|---|
| Policyholders and prospective policyholders | Name, identity number, contact details, banking details, policy and cover details, premium and collection records, claims information, identity verification results | Operator |
| Employees and applicants | Name, identity number, contact details, banking details, qualifications, employment history, remuneration, performance and disciplinary records | Responsible Party |
| Client and supplier contacts | Name, business contact details, role, correspondence | Responsible Party |
| Website and enquiry contacts | Name, contact details, enquiry content, marketing consent and opt-out status | Responsible Party |
| Agents and intermediaries | Name, contact details, accreditation and licence details, sales and commission records |
Briisk maintains a register of suppliers processing personal information, together with the status of the written agreements required under section 21 of POPIA.
Briisk hosts its platform on Microsoft Azure. For South African deployments, data storage is configured to remain within South African Azure regions.
The Briisk group includes entities in the United Kingdom and India. Where personal information is accessible from or transferred to those entities, the transfer is subject to section 72 of POPIA.
Personal information is retained only for as long as it is required for the purpose for which it was collected, unless a law requires or permits a longer period, or retention is required for a lawful purpose related to a function or activity.
| Record category | Retention period | Basis |
|---|---|---|
| Company and statutory records | 7 years, and indefinitely for records required for the life of the company | Companies Act 71 of 2008 |
| Accounting and financial records | 7 years from the end of the financial year to which they relate | Companies Act 71 of 2008 |
| Tax records | 5 years from the date of submission of the relevant return | Tax Administration Act 28 of 2011 |
| Employee records | 3 years from the end of employment | Basic Conditions of Employment Act; Employment Equity Act |
| Recruitment records of unsuccessful applicants | Employment Equity Act | |
| Financial services and intermediary records | 5 years from the date the product or service ends | FAIS |
| Customer due diligence and identity verification records | 5 years from the end of the business relationship or the date of the transaction | FICA |
| Policy, premium and claims records | 5 years from the date the policy or claim is finalised, or longer where the insurer requires it | Insurance legislation; client contract |
| Records relating to a complaint or dispute | 5 years from resolution, or longer where legal proceedings are contemplated or under way | Prescription Act; client contract |
| System and security logs | POPIA; ISO/IEC 27001 | |
| Marketing consent and opt-out records | Retained for as long as required to give effect to an opt-out | POPIA |
Where more than one obligation applies to the same record, the longest applicable period governs. Where Briisk holds a record on behalf of a client, the retention period is determined by that client’s instruction and by the law applying to that client, and may exceed the periods above.
On expiry of the retention period, records are deleted or destroyed in a manner that prevents reconstruction.
Briisk applies technical and organisational measures to secure the integrity and confidentiality of personal information in accordance with section 19 of POPIA. These include:
A request for access must be made on the prescribed form and submitted to the Information Officer at the address in section 2.
The request must:
If a requester is unable to make a written request because of illiteracy or disability, the request may be made orally and the Information Officer will reduce it to writing and provide a copy to the requester.
PAIA provides for a request fee and, where access is granted, an access fee calculated in accordance with the regulations.
A personal requester seeking a record containing their own personal information is not required to pay a request fee. Access fees may still apply.
Access may or must be refused on the grounds set out in Chapter 4 of Part 3 of PAIA, including:
Access must be granted, despite any refusal ground other than legal privilege, where disclosure would reveal evidence of a substantial contravention of the law or an imminent and serious public safety or environmental risk, and the public interest in disclosure clearly outweighs the harm.
Separately from the right of access under PAIA, a data subject has rights under POPIA in respect of their personal information.
Where Briisk processes personal information as Operator on behalf of a client, Briisk may not delete that information without the client’s instruction. A data subject in that position should approach the insurer or intermediary with whom they dealt. Where a request is received directly, Briisk will forward it to the responsible client and inform the data subject that it has done so.
Where Briisk is the Responsible Party, a request should be made to the Information Officer at the address in section 2.
Full details of how to make a removal request, including the steps we follow and the periods within which we respond, are set out on our Data Removal Request page.
POPIA does not confer an unconditional right to erasure. Where a law requires Briisk, or the client on whose behalf Briisk acts, to retain a record, that record will be retained notwithstanding a request for its deletion. The retention periods in section 7 apply.
Where information cannot be deleted, Briisk will inform the data subject which information is retained, the reason, and the period of retention. Where the data subject does not wish to be contacted further, their details may be suppressed so that they are not used for marketing or engagement, retaining only the minimum information necessary to give effect to that suppression.
No fee is charged for a correction or deletion request.
A person dissatisfied with the handling of a request should first raise the matter with the Information Officer. A complaint may also be lodged with the Information Regulator using the prescribed form.
A requester may also apply to a court for appropriate relief in accordance with PAIA.
This manual is available:
This manual is reviewed at least annually, and on any material change to the business, the records held, the retention periods or the applicable law.
Approved by the Board of Directors of Briisk Insur Fintech (Pty) Ltd.
Last updated: 01 August 2026