Privacy Notice
This Notice explains how Lex Gazette processes personal information relating to registered users, visitors, persons named in Legal Notices, professional contacts and persons who submit a correction, objection, access request or complaint. It is intended to support the openness requirements of the Protection of Personal Information Act 4 of 2013 (POPIA).
1. Responsible party and Information Officer
- Responsible party
- Mmamoage Information Systems (Pty) Ltd
- Registration number
- 2024/312397/07
- Address
- 714 Van Alphen Street, Montana, 0182
- Information Officer
- Katlego Madisha
- Information Officer email
- katlego@lexgazette.co.za
- Privacy requests
- support@lexgazette.co.za
- Corrections
- support@lexgazette.co.za
2. Categories of information
| Category | Examples |
|---|---|
| Account and professional profile | Name, email address, organisation, professional capacity, intended use, role, account status and correspondence. |
| Credentials and recovery | One-way password hash, credential version, email-verification and password-reset token hashes, issue, expiry and use status. |
| Policy acceptance | Terms, Privacy Notice and responsible-use versions, stated purpose, acceptance time, security fingerprint and user agent. |
| Security and access records | Login success and failure, account administration, Gazette access events, session information, a one-way network-address fingerprint, user agent and incident evidence. |
| Gazette-source information | Names, identity or registration numbers, estate references, addresses, case information, professional contacts and other information appearing in publicly issued Legal Notices. |
| Derived authentication information | Normalized fields, source links, verification outcomes, proposed fixes, confidence or review status, and audit information explaining how an outcome was reached. |
| Rights and correction records | Requests, evidence, correspondence, findings, restrictions, annotations, corrections and complaint handling. |
3. Sources of information
Account information is collected from the user. Gazette information is collected from or derived from public Government Gazette records. Authentication may use authoritative or appropriately assessed reference information supplied by public bodies, official registries, professional sources, operators or other responsible parties. The source and provenance of a material field should be retained where practicable.
POPIA permits indirect collection in specified circumstances, including where information is contained in or derived from a public record. Public availability does not remove the remaining duties concerning lawful and reasonable processing, minimality, purpose, quality, openness, security, retention and participation.
4. Purposes
- Register, verify, administer and secure professional accounts.
- Provide authenticated access to source-linked Legal Notices and preserve source fidelity.
- Normalize records, reduce misidentification risk, document authentication outcomes and identify matters requiring review.
- Support lawful legal, fiduciary, insolvency, compliance, due-diligence, risk-management and bona fide research activity.
- Enforce purpose limitation, usage restrictions, rate limits and account controls.
- Respond to access, correction, restriction, objection, complaint and security requests.
- Maintain evidence, audit trails, release integrity, service continuity and legal or regulatory compliance.
- Produce de-identified or aggregate service and cohort statistics for the public landing page.
5. Justification for processing
Depending on the activity, processing may be necessary to perform or prepare an account contract, comply with legal obligations, protect a legitimate interest of a data subject, or pursue the legitimate interests of the responsible party or an authorised professional user, subject to POPIA and a documented balancing assessment. Consent is used only where it is the appropriate justification; acknowledging this Notice is not treated as blanket consent.
For persons named in Gazettes, the service relies on a documented assessment of the public-record source, compatible further processing, information quality, the professional research purpose, the consequences for the person and the safeguards applied. The responsible party must complete and retain any required assessment under POPIA sections 57 and 58 and obtain prior authorisation before affected processing where the statutory conditions concerning unique identifiers and linkage to information processed by other responsible parties are met.
6. Voluntary and mandatory information
Registration is voluntary, but the fields marked required are necessary to create and secure a professional account, communicate account actions, record the stated purpose and evidence policy acceptance. Failure to provide required information means the account cannot be created or activated. Optional organisation information assists professional context and access review.
7. Recipients and operators
Information is made available internally only to authorised personnel who require it for the stated purposes. Necessary information may be processed by contracted hosting, database, backup, email, security, support, professional-advisory and audit providers acting under appropriate authority and safeguards. Information may also be disclosed where required by law, a court, a regulator or a competent authority, or where reasonably necessary to establish, exercise or defend legal rights.
Registered users receive access only under the Terms and responsible-use attestation. Access is not authority to republish or use personal information for an unrelated purpose.
8. Cross-border processing
The production operator must document where hosting, email, backups and support are located. Personal information will not be transferred outside South Africa unless the requirements of POPIA section 72 and any other applicable obligation are satisfied. The configured production Privacy Notice should identify material cross-border arrangements.
9. Security safeguards
Measures include authenticated access, role and status checks, versioned policy gates, one-way adaptive password hashing, single-use expiring action tokens stored only as hashes, session rotation, inactivity timeouts, CSRF protection, security headers, login-rate controls, protected Gazette routes, access logging and database separation. Security is reviewed against reasonably foreseeable internal and external risks. No system can guarantee absolute security.
10. Retention
| Record | Current retention rule |
|---|---|
| Account, role and policy evidence | For the life of the account and the approved post-closure retention period, subject to legal hold and lawful retention review. |
| Security and access events | For the approved security-event retention period, with longer retention where reasonably required for investigation, proof or legal hold. |
| Verification and reset tokens | Until expiry or use, followed by scheduled deletion in accordance with the operational retention process. |
| Gazette, provenance and authentication records | As an enduring source-linked legal research archive, subject to correction, restriction, withdrawal and lawful retention review. |
| Correction, objection and complaint files | For as long as reasonably required to resolve the matter, preserve proof, meet legal obligations and apply the approved retention schedule. |
Records are deleted, destroyed, de-identified or restricted when the responsible party is no longer authorised to retain or use them, subject to legal hold, proof, public-record integrity and lawful archival safeguards.
11. Rights and requests
Subject to POPIA and any applicable limitation, a data subject may ask whether the responsible party holds personal information about them; request access; request correction, deletion or restriction; object on reasonable grounds where the applicable justification permits objection; and lodge a complaint with the Information Regulator. A request may require sufficient information to identify the requester and the relevant record without collecting excessive information.
A correction to Lex Gazette does not amend the official Gazette. Where the official source appears inaccurate, the service may annotate the discrepancy, restrict reliance, record the data subject's position or direct the person to the issuing authority while preserving source fidelity.
Official forms and complaint channels are available from the Information Regulator's POPIA forms page and complaints page.
12. Direct marketing and automated decisions
Lex Gazette account and security messages are service communications, not direct marketing. The current Service does not use Gazette records for unsolicited direct marketing and does not make a decision producing legal or similarly significant effects solely by automated processing. Authentication assists human professional review and may require manual investigation.
13. Cookies and sessions
The Service uses a necessary session cookie to maintain authenticated access and CSRF protection. It is configured as an HTTP-only cookie and is not used for third-party advertising. Production deployment must use HTTPS and the secure-cookie setting.
14. Security compromises
Suspected compromise should be reported promptly through the configured security or privacy channel. The responsible party will investigate, contain, preserve evidence and make notifications required by applicable law.
15. Changes and re-attestation
Material changes are issued as a new version with an effective date and summary. Registered users may be required to review and acknowledge the revised Privacy Notice and accept the associated Terms and responsible-use attestation before protected Gazette material is released. Acceptance history is retained for accountability.