POPIA COMPLIANCE
Committed to protecting your privacy.
POPIA Compliance for Grey Swan Designs (Pty) Ltd
Last Updated: 9 October 2026
1. Introduction & Purpose
Grey Swan Designs (Pty) Ltd ("we", "us", or "our") respects your privacy and is committed to protecting the personal information of our clients, website visitors, and business partners. This Privacy Policy details how we collect, process, store, and safeguard your personal information in compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and the Electronic Communications and Transactions Act 25 of 2002 ("ECTA").
By visiting our website (greyswandesigns.co.za), submitting contact forms, requesting quotations, or engaging our digital agency services, you agree to the collection and handling of your data as outlined in this policy.
2. Information Officer Contact Details
In accordance with POPIA, Grey Swan Designs has appointed a designated Information Officer responsible for overseeing privacy inquiries, data subject requests, and regulatory compliance:
Entity Name: Grey Swan Designs (Pty) Ltd
Registration Number: 2019/129658/07
Information Officer: Eric Swanepoel
Email Address: info@greyswandesigns.co.za
Phone Number: +27 78 125 5564
Physical Address: Vredenburg, Western Cape, 7365, South Africa
3. Personal Information We Collect
We collect personal information directly from you when you interact with us or use our services. The types of personal information we process include:
- Identity & Contact Data: Name, surname, business name, company registration details, job title, email address, phone number, and billing/physical address.
- Financial & Billing Information: VAT registration numbers, invoicing history, cleared payment records, and banking details required for accounting.
- Technical & Website Credentials: Administrative access credentials, CMS passwords, FTP logins, domain authorization keys, and server access settings strictly required to deliver website design, hosting, or maintenance services.
- Automated Technical Data: IP address, browser type and version, device identifiers, referral URLs, time zone settings, and website navigation patterns collected via cookies.
- Client Content & Media: Text, images, logos, documents, and media files provided by you to build or maintain your digital assets.
4. Purpose and Legal Basis for Data Processing
We process your personal information strictly for legitimate business purposes under the following POPIA conditions:
- Contract Performance: To fulfill agreements, design and host websites, manage domains, deliver SEO strategies, and provide ongoing technical maintenance.
- Financial Administration: To generate quotations, issue invoices, track account settlements, process payments, and maintain statutory tax records for SARS.
- Communications & Support: To respond to form inquiries, technical support tickets, project revisions, and security alerts.
- Legitimate Interests: To secure our server network, monitor uptime, audit system performance, and prevent fraud or cyber threats.
- Consent: Where you have opted into marketing communications or enabled non-essential website cookies on our consent banner.
5. Cookies and Web Analytics
Our website uses cookies and tracking technologies to optimize navigation and understand site usage.
Cookie Consent Categories:
- Necessary Cookies (Always Active): Essential for site functionality, network security, and storing your consent preferences. They do not retain personally identifiable data.
- Functional Cookies (Optional): Support advanced site features like social media sharing, embedded media, and contact widgets.
- Analytics & Performance Cookies (Optional): Allow us to measure traffic channels, visitor counts, bounce rates, and overall technical responsiveness using Google Analytics.
- Advertisement Cookies (Optional): Used to measure advertising campaign effectiveness and tailor customized content.
You can adjust, enable, or revoke your cookie choices at any time using our website's interactive cookie preferences banner. For details on how Google processes third-party analytics data, review the Google Privacy Policy.
6. Data Disclosure to Third Parties
We do not sell, rent, or trade your personal information. We disclose data strictly to necessary third-party operators bound by confidentiality and security obligations:
- Domain Registries & Hosting Infrastructure: Registry operators (such as ZADNA) and upstream data center hosting providers required to manage your web infrastructure.
- Service Platforms: Cloud storage providers, plugin developers, email software, and web analytics tools used in managing your project.
- Statutory Bodies: Law enforcement, courts, or tax authorities (SARS) when required by South African statutory law.
7. Cross-Border Transfers
Some cloud hosting infrastructure, software integrations, and third-party tools (e.g., Google services, international plugin servers) store or transfer data outside South Africa. Where cross-border processing occurs, we ensure recipient service providers adhere to data protection standards comparable to POPIA Section 72.
8. Security Safeguards
We employ robust technical and organizational security controls to safeguard personal information against accidental loss, unauthorized access, destruction, or disclosure. Safeguards include:
- SSL/TLS web encryption across website assets and forms.
- Encrypted password vaults and restricted role-based administrative access.
- Firewall protection, automated malware scanning, and patched server environments.
- Encrypted off-site backups and strict account termination routines.
9. Data Retention
We retain personal information only for as long as necessary to fulfill the original purposes for which it was collected, or as required by South African legal and accounting statutes (e.g., financial and tax records retained for up to 5 years). Following the expiration of required retention windows, records are securely deleted, destroyed, or de-identified.
10. Your Rights Under POPIA
Subject to applicable statutory requirements, you have the right to:
- Request Access: Ask whether we hold personal information about you and request a copy of those records.
- Request Correction/Deletion: Request that inaccurate, out-of-date, incomplete, or unlawfully obtained personal information be corrected or destroyed.
- Object to Processing: Object to the processing of your personal data on reasonable grounds, or opt out of direct marketing at any time.
- Withdraw Consent: Revoke previously granted consent for non-essential cookies or direct communication.
To exercise any of these rights, email our Information Officer at info@greyswandesigns.co.za with the subject "Privacy Request". Formal requests for internal company records may require following the procedure specified in our PAIA Manual.
11. Complaints
If you are unsatisfied with how we handle your personal data, we encourage you to contact our Information Officer first to resolve the matter. However, you retain the right to submit a formal complaint to the Information Regulator (South Africa):
Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
POPIA Complaints: POPIAComplaints@inforegulator.org.za
PAIA Complaints: PAIAComplaints@inforegulator.org.za
Website: https://inforegulator.org.za/
12. Policy Updates
We review and update this Privacy Policy periodically to reflect legal or operational changes. Updated versions will be published on our website with a revised "Last Updated" date.
Grey Swan Designs (Pty) Ltd
Email: info@greyswandesigns.co.za
Phone: +27 78 125 5564
Address: Vredenburg, Western Cape, South Africa