Privacy Policy for Tese Africa
Last Updated: 1/01/26
1. Introduction
Welcome to Tese Africa. Tese Africa ("we," "us," or "our") respects your privacy and is committed to protecting your personal data in accordance with Zimbabwe's Cyber and Data Protection Act [Chapter 12:07] and Statutory Instrument 155 of 2024. This Privacy Policy explains:
- What data we collect.
- How we use, disclose and protect it.
- Your legal rights regarding your data.
By using our services, you consent to this policy. If you disagree, please discontinue use immediately.
2. Information We Collect
We may collect and process the following categories of personal information:
A. Personal Data (Provided by You)
- Identity & Contact Data: Name, email, phone number, physical address, government-issued ID (for verification).
- Financial Data: Payment details Bank Account Details (processed via a secure third-party gateway - Smatpay).
B. Automated Data (Collected via Technology)
- Technical Data: IP address, browser type, device information.
- Usage Data: Pages visited, session duration, clickstream data (via cookies).
C. Third-Party Data
- Social Media/Login Integrations: If you link accounts (e.g., Google, Facebook).
- Publicly Available Data: Property records, business directories (for due diligence).
3. How We Collect Information
- Direct Collection: When you register, fill out forms, or communicate with us.
- Automated Technologies: Through cookies and similar tracking technologies when you use our platform.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: Where you have provided explicit consent (e.g., marketing emails). You may withdraw consent anytime
- Contractual Necessity: Where processing is necessary for the performance of a contract.
- Legal Obligation: Anti-fraud, tax, or to comply with legal and regulatory obligations under Zimbabwean law.
- Legitimate Interests: For purposes such as improving our services and ensuring security.
5. How We Use Your Information
We use your data for:
- Providing and improving our services.
- Processing transactions and verifying identity.
- Communicating updates, offers, and legal notices.
- Complying with legal obligations under Zimbabwean law (e.g., Data Protection Act [Chapter 11:12]).
| Purpose | Legal Basis |
|---|---|
| Provide services (e.g transactions) | Contractual Necessity |
| Verify identity/ownership (KYC compliance) | Legal Obligation |
| Prevent fraud, money laundering | Legitimate Interest |
| Send service updates/promotions (opt-out available) | Consent/Legitimate Interest |
| Analyze website traffic for improvements | Legitimate Interest |
6. Data Sharing & Disclosure
We may share data with:
- Service Providers: Third parties who assist in delivering our services e.g. Payment processors, hosting providers etc.
- Legal Authorities: If required by law (e.g., fraud prevention) or to protect our rights.
- Business Transfers: In case of mergers or acquisitions.
- Business Partners: With your consent, for joint marketing initiatives.
We ensure that all third parties respect the security of your personal data and comply with the Cyber and Data Protection Act
We never sell your data to third-party advertisers.
7. Data Security
We implement:
- Technical Safeguards: SSL/TLS encryption, firewalls, regular penetration testing.
- Administrative Controls: Staff training, strict access permissions (role-based).
- Physical Protections: Secure server locations, restricted facility access.
No system is 100% secure, so we advise users to:
- Use strong passwords.
- Avoid sharing login credentials.
- Monitor accounts for suspicious activity.
8. Your Rights (Under Zimbabwean Law)
You have the right to:
- Access: Request access to your personal data.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data, subject to legal constraints.
- Objection: Object to the processing of your data under certain circumstances.
- Withdrawal: Withdraw consent (where applicable).
- Lodge complaints with the Zimbabwe Data Protection Authority.
To exercise these rights, contact us at info@smatechgroup.com. We respond within 30 days (may extend for complex requests).
9. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy or as required by law:
- Active Users: Until account deletion request.
- Legal Requirements: Tax records (5+ years), transaction history (7+ years).
- Marketing Data: Until consent withdrawal or 2 years of inactivity.
10. Cookies & Tracking Technologies
We use cookies to enhance user experience. You can disable cookies via browser settings. We use:
- Essential Cookies: For site functionality (cannot be disabled).
- Analytics Cookies: Google Analytics (anonymized IPs, opt-out available).
- Marketing Cookies: Only with your consent.
Manage preferences via browser settings or our Cookie Banner.
11. International Data Transfers
If data crosses borders (e.g., cloud servers abroad), we ensure:
- Adequacy Decisions: Recipient countries have comparable data protection laws.
- Safeguards: Standard Contractual Clauses (SCCs) or binding corporate rules.
12. Changes to This Policy
We may update this policy periodically. Updates will be posted here with a new "Last Updated" date. Material changes (e.g., new data uses) may trigger direct notifications. Continued use of our services constitutes acceptance of changes
13. Contact Us
For privacy-related inquiries or your personal data, please contact us at:
Email: legal@smatechgroup.com
Address: 13 Brentwood Avenue, Groombridge, Harare.
