Lemon Designs Compliance

PAIA Manual

A section 51 PAIA manual describing records, access procedures and POPIA-related information for the private body.

Effective: 6 September 2026

Lemon Designs, also known as Lemon Web Designs is the business and service provider referred to as “Lemon Designs”, “we”, “us” or “our” in this policy.

Section 51 PAIA manual: This page is intended to function as the electronic manual for the private body. The responsible person should verify the legal identity, Information Officer, physical address and language availability before relying on it as the final manual.

1Purpose of This Manual

This manual is prepared with reference to section 51 of the Promotion of Access to Information Act 2 of 2000 (“PAIA”). It explains what records may be held by the private body, how access may be requested, and information relevant to the processing of personal information under POPIA.

2Private Body Details

Trading nameLemon Designs, also known as Lemon Web Designs
Websitehttps://lemondesigns.co.za/
Emailinfo@lemondesigns.co.za
Telephone+27 79 442 8855
Business locationBellville, Cape Town, Western Cape, South Africa

3Information Officer

Name: To be completed in the plugin settings
Email: info@lemondesigns.co.za

An Information Officer must be registered with the Information Regulator before assuming the statutory duties attached to that role.

4Information Regulator PAIA Guide

The Information Regulator publishes a guide explaining how PAIA works and how to exercise access rights. Current guidance, forms and eServices are available from the Information Regulator.

5Records Available Without a Formal PAIA Request

  • Public pages and information published on the Lemon Designs website.
  • Public service descriptions, portfolio material and public contact information.
  • Published legal, privacy, cookie and compliance policies.
  • Other records that the business has intentionally made public.

6Categories of Records That May Be Held

  • Corporate and statutory: business records, registrations, policies and compliance records where applicable.
  • Client and project: enquiries, quotations, agreements, specifications, correspondence, approvals, deliverables and support records.
  • Finance: invoices, statements, payment records, accounting and tax records.
  • Supplier and operator: hosting, domain, software, contractor, platform and service-provider records.
  • Human resources: employee or contractor records where applicable.
  • Marketing and communications: campaigns, mailing records, website content, social media and portfolio information.
  • IT and security: system information, logs, backup records, access records and security documentation where applicable.
  • POPIA: privacy requests, consents, objections, processing records, operator arrangements and security-incident records where applicable.

7How to Request Access

A person seeking access to a record must use the prescribed PAIA process and provide enough detail to identify the requester, the requested record, the preferred form of access and the right that the record is required to exercise or protect. Requests should be directed to the Information Officer using the details above.

Identity or authority may need to be verified. PAIA permits prescribed request and access fees in applicable circumstances. Access may be refused where a lawful ground of refusal applies.

8POPIA Categories of Data Subjects

  • Prospective and existing clients and their representatives.
  • Website visitors and people who submit enquiries.
  • Suppliers, contractors and service-provider representatives.
  • Employees or applicants where applicable.
  • Business contacts and other persons who communicate with Lemon Designs, also known as Lemon Web Designs.

9Purposes & Categories of Personal Information

Personal information may include identity and contact information, business details, billing information, project content, correspondence, technical information and website/security data. It is processed for enquiries, contracts, service delivery, support, billing, record keeping, security, legal compliance and legitimate business administration as more fully described in the Privacy Policy.

10Recipients & Operators

Where necessary, personal information may be shared with or processed by hosting providers, cloud platforms, email providers, accounting services, payment providers, software vendors, security providers, contractors and other operators or recipients involved in service delivery, legal compliance or business administration.

11Cross-Border Flows

Cloud and software providers may process information outside South Africa. Cross-border transfers are handled in accordance with POPIA where applicable.

12Security Measures

Reasonable technical and organisational measures are used to protect personal information. Depending on the system, these may include access controls, secure credentials, updates, backups, hosting security, restricted privileges, encryption where appropriate, monitoring and incident response procedures.

13Availability of This Manual

This manual is available electronically on the website. A copy may also be requested from the Information Officer. Additional official-language availability should be confirmed with the Information Officer and configured in this compliance manager.

14Updates

This manual may be updated when records, processes, contact details or legal requirements change.

Proud South African Web Design Companies member