PAIA Manual
This manual is for Jude Rosen t/a Kenvero, which makes and runs Citepoint. It describes the records we hold, how to ask for them under the Promotion of Access to Information Act 2 of 2000 (PAIA), and how we process personal information under the Protection of Personal Information Act 4 of 2013 (POPIA). It's prepared in terms of section 51 of PAIA and follows the Information Regulator's template for private bodies.
| Private body | Jude Rosen t/a Kenvero |
|---|---|
| Type | A sole proprietorship in the information and communication sector |
| What it does | Makes and runs Citepoint (citepoint.ai), software that helps businesses get recommended by AI assistants |
| Compiled | 3 October 2026 |
| Last revised | 3 October 2026 |
1. Terms used
- Kenvero, we or us: Jude Rosen t/a Kenvero.
- Information officer: the person who deals with requests under PAIA and POPIA. For a sole proprietor, that's the owner.
- PAIA: the Promotion of Access to Information Act 2 of 2000, as amended.
- POPIA: the Protection of Personal Information Act 4 of 2013.
- Regulator: the Information Regulator (South Africa).
2. What this manual is for
It helps you:
- see which of our records are available without a formal request;
- understand how to request a record, from a description of the subjects we hold records on and the categories of records on each;
- know which records we keep under other laws;
- contact the information officer;
- find the Regulator's guide on how to use PAIA;
- know why we process personal information, whose, who we share it with, whether it leaves South Africa, and how we protect it.
3. Contact details
Information officer
| Name | Jude Rosen, Owner |
|---|---|
| jude@kenvero.com |
Jude Rosen is the head of the private body and its information officer, registered with the Regulator.
Deputy information officer
None is designated. The information officer handles every request.
General contact
| Requests for access to information | jude@kenvero.com |
|---|---|
| Anything about Citepoint | hello@citepoint.ai |
| Websites | kenvero.com and citepoint.ai |
| Postal and street address | Available on request from the information officer |
We deal with requests by email.
4. The Regulator's guide on how to use PAIA
The Regulator has updated and made available a guide on how to use PAIA, as section 10 of PAIA requires, for anyone who wants to exercise a right under PAIA or POPIA. It's available in every official language and in braille. It describes:
- the objects of PAIA and POPIA;
- the contact details of every information officer of a public body and every deputy information officer of a public or private body;
- how to request access to a record of a public body (section 11) and of a private body (section 50);
- the help available from information officers and from the Regulator under PAIA and POPIA;
- every legal remedy for an act or failure to act under PAIA or POPIA, including how to lodge an internal appeal, a complaint to the Regulator, or an application to court;
- the sections that require public and private bodies to publish a manual (sections 14 and 51) and how to get one;
- the voluntary disclosure of categories of records (sections 15 and 52);
- the notices on fees for requests (sections 22 and 54);
- the regulations made under section 92.
You can get the guide:
- from the Regulator's website: in English, and in the other official languages at inforegulator.org.za/paia;
- from us: email the information officer and we'll send it, free, in English or Afrikaans or any other official language the Regulator publishes;
- at the Regulator's office during office hours: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. Email enquiries@inforegulator.org.za, telephone 010 023 5200.
5. Records available without a request
These are on our website, and we'll email a copy to anyone who asks.
| Category | Records | On the website | On request |
|---|---|---|---|
| Legal | Terms of Service, Privacy Policy and this manual | Yes | Yes |
| Product | Pricing, documentation, methodology, changelog and roadmap | Yes | Yes |
| Research and resources | Articles, the AI Recommendation Index and free tools | Yes | Yes |
Customers can also see, export and delete most of their own account data in the Citepoint app.
6. Records kept under other laws
| Category of records | Law |
|---|---|
| Tax returns and assessments, and the invoices, receipts and accounting records behind them | Income Tax Act 58 of 1962; Tax Administration Act 28 of 2011 |
| The business details we publish, and records of online transactions with customers | Electronic Communications and Transactions Act 25 of 2002 |
| Customer agreements, cancellations and refunds | Consumer Protection Act 68 of 2008 |
| Records of how we process personal information, requests from data subjects, and security compromises | Protection of Personal Information Act 4 of 2013 |
| This manual, requests for access and our annual reports to the Regulator | Promotion of Access to Information Act 2 of 2000 |
If another law requires us to keep a record that isn't listed here, we keep it.
7. Subjects on which we hold records
| Subject | Categories of records |
|---|---|
| Business administration | Registration with the Regulator, policies, and this manual |
| Finance and tax | Bank statements, supplier invoices and receipts, Lemon Squeezy sales and payout reports, accounting records, tax returns and correspondence with the South African Revenue Service |
| Customers | Accounts and workspaces, plans, subscription and billing status, acceptance of our terms, support requests and other correspondence |
| The Citepoint service | Source code, configuration, databases, service and audit logs, security reviews and incident records |
| Marketing | Free scan results and the email addresses people give to unlock them, unsubscribe records, and daily totals of website and product use |
| Suppliers and operators | Agreements, terms and data processing agreements with the operators in section 10, invoices and correspondence |
| Legal and compliance | Requests under PAIA and POPIA and our responses, records of security compromises, and complaints |
| People who work for us | Kenvero has no employees. If it engages contractors, it keeps their agreements and payment records. |
A record being listed here doesn't mean we'll give access to it: the grounds for refusal in section 8 still apply.
8. How to request access
You have a right of access to a record of a private body if you need it to exercise or protect a right, you follow PAIA's procedure, and no ground for refusal applies (section 50).
- Fill in Form 2, the Regulator's Request for Access to Record (Regulation 7). Describe the record clearly enough for us to find it, say in what form you want access, and say which right you want to exercise or protect and why you need the record for it (section 53). Attach proof of your identity and, if you're asking for someone else, proof that you may act for them.
- Email it to the information officer at jude@kenvero.com. If you'd rather post it or deliver it by hand, ask for the address first.
- Pay the request fee when we ask for it (section 54). You don't pay it if you're asking for records about yourself.
- We decide within 30 days of receiving the request and tell you the outcome (section 56). Where PAIA allows, we may extend that once, by up to 30 days, and we'll tell you why (section 57). If we don't decide in time, the request is treated as refused (section 58).
- If we grant it, we tell you the access fee and how you'll get the record, and give you access once it's paid. If we refuse it, we give our reasons and tell you how to challenge the decision.
Information about other people or businesses. If a record holds a third party's personal, commercial or confidential information, we must tell them about the request and give them 21 days to respond before we decide (section 71).
Grounds for refusal. We may, and sometimes must, refuse access on the grounds in Chapter 4 of Part 3 of PAIA, including to protect:
- the personal information of a third party who is a natural person (section 63);
- a third party's commercial or confidential information (sections 64 and 65);
- the safety of people and property (section 66);
- records privileged from production in legal proceedings (section 67);
- our own commercial information, such as trade secrets, financial, commercial or technical information, and our software (section 68);
- research information (section 69).
We must still give access if the public interest clearly outweighs the harm, under section 70.
Your own personal information. You don't need this process to see the personal information we hold about you. Most of it is in the app, and you can ask us under section 23 of POPIA at hello@citepoint.ai: confirming whether we hold it is free. See the privacy policy.
Remedies. A private body has no internal appeal. If you disagree with a decision, including a refusal, a fee, an extension or the form of access, you may complain to the Regulator within 180 days, using its Form 5 or online, or by email to PAIAComplaints@inforegulator.org.za, or you may apply to a court for relief. The Regulator's guide explains both.
9. Fees
These are the fees for private bodies in Annexure B of the PAIA Regulations, 2021.
| Item | Fee |
|---|---|
| Request fee, not payable when you ask for records about yourself | R140.00 |
| A photocopy or printed black and white copy, per A4 page | R2.00 |
| A copy on a flash drive or CD you provide | R40.00 |
| A copy on a CD we provide | R60.00 |
| A transcription of an audio record, per A4 page | R24.00 |
| A copy of an audio record on a flash drive or CD you provide | R40.00 |
| A copy of an audio record on a CD we provide | R60.00 |
| Searching for and preparing the record, per hour or part of an hour after the first hour | R145.00, at most R435.00 in all |
| Postage | The actual cost |
We send electronic copies by email at no charge. If searching for and preparing the record will take more than six hours, we'll ask for a deposit of a third of the access fee before we start (section 54), and refund it if access is refused. We'll give our bank details with the notice of any fee.
10. How we process personal information
Why we process it
To run Kenvero and Citepoint: to create and manage accounts; to do the work customers ask for, such as research, writing, publishing and tracking; to take payment through our reseller; to send service email and support customers; to run free scans and send the reports people ask for; to find contact addresses that sites publish themselves, for pitches our customers send; to keep the service secure and prevent abuse; to meet our legal, tax and accounting obligations; to answer requests under PAIA and POPIA; and to improve the product from daily totals.
Whose information, and what
| Data subjects | Personal information we may process |
|---|---|
| Customers and their team members | Email address; name and profile picture if they sign in with Google; a one-way hash of the IP address an account was created from; their workspace content; encrypted integration credentials; hashed sessions and API keys; Search Console and Google Analytics totals if they connect them; Lemon Squeezy customer and subscription identifiers, plan and status; correspondence |
| People who run a free scan | The domain scanned, the results, a one-way hash of their IP address, and their email address if they give it |
| Visitors to citepoint.ai and to pages we host | IP address and browser user agent in service logs kept briefly. Visit counts are stored with nothing that identifies a visitor |
| Contacts found for pitches | A contact address that a site publishes itself, with the site's name |
| People who contact us or make requests | Name, email address and correspondence, and for a PAIA request, proof of identity and authority |
| Suppliers and operators | Names and contact details of their staff, account and billing details, invoices |
| Contractors, if any | Name, contact details, agreement and payment details |
Who we may share it with
These operators process personal information for us:
| Operator | What it handles |
|---|---|
| Cloudflare | Hosting, database, queues, page delivery, and sign-in links, invites and notifications |
| Anthropic | Site analysis, writing pages and tools, asking your tracked questions on Claude |
| OpenAI | Researching and drafting pages, reading AI answers, and asking questions on ChatGPT when the app can't be read |
| DataForSEO | Answers from ChatGPT, Gemini, Perplexity, Google AI Overviews and AI Mode, and search volume |
| Sign-in, Search Console and Google Analytics data if you connect them, and asking questions on Gemini when the app can't be read | |
| GitHub | Opening pull requests in the repositories you choose |
| Lemon Squeezy | Payments, subscriptions, sales tax and invoices, as our reseller |
| Zoho | Our business email, including messages sent to hello@citepoint.ai |
We also share personal information where the law requires it, for example with the South African Revenue Service, the Regulator or a court, and with professional advisers such as an accountant or attorney, who are bound to keep it confidential.
Sending it outside South Africa
Yes, we do. Our database and the pages we host are stored by Cloudflare, with the database in London, United Kingdom, and pages served from Cloudflare's global network. The other operators above also process information outside South Africa, mostly in the United States. Any category of personal information in this section may be transferred, as far as each operator's role needs it. As section 72 of POPIA requires, each operator is bound by a written agreement that holds it to protection comparable to POPIA, and the transfers are necessary to perform our contracts with customers.
How we protect it
- All traffic is encrypted in transit over HTTPS, with HSTS.
- Integration credentials and tokens are encrypted at rest with AES-GCM.
- Sessions, sign-in links and API keys are stored only as hashes, and IP addresses kept to limit abuse are one-way hashes.
- Every request is checked against the person's workspace and role. Admin access is restricted, checked on every action and written to an audit log.
- Rate limits and spending limits guard against abuse.
- Secrets live in Cloudflare's encrypted secret store, never in code, and code is scanned for secrets before every change goes live.
- We review the service's security regularly. If a security compromise affects personal information, we notify the Regulator and the people affected, as section 22 of POPIA requires.
11. Getting a copy of this manual
- On our website, at citepoint.ai/paia.
- By email from the information officer, free.
- In print, on request: R2.00 per A4 page, plus postage. We have no public office, so to inspect a printed copy in person, arrange it with the information officer.
- The Regulator may ask for a copy at any time.
12. Updates
We review this manual at least once a year and whenever our records or how we process personal information change, and update the date at the top.
Issued by Jude Rosen, Owner and information officer, Jude Rosen t/a Kenvero.
See also the terms of service and the privacy policy.