LEGAL
Privacy policy
How TARISA collects, uses, stores and protects personal information, and your rights over it.
Draft — not yet in force. This policy is being finalised with Zimbabwean legal and data-protection advice before launch. It is published here so you can see the scope we intend to cover. If you have a question about your information now, email hello@tarisa.co.zw and we will answer it directly.
What the final policy will cover
- Who the data controller is, and TARISA’s status under Zimbabwe’s Cyber and Data Protection Act, including our POTRAZ data controller licensing position.
- What we collect. Enquiry information, identity documents supplied for verification, site photographs and their location metadata, provider records, and third-party records obtained during a check.
- The lawful basis for each category, and where we rely on your consent.
- Information about other people. A verification client necessarily supplies information about a third party — a seller, an agent, a contractor. We take this seriously, we will set out how that information is handled, and we will not treat it as if it were the client’s own.
- Retention. How long evidence packs are kept, and why an assurance business needs to keep them longer than a marketing list.
- Cross-border storage and transfer, and any approval that requires.
- Security. Processor contracts, access controls, encryption and breach notification.
- Your rights, how to exercise them, how to complain to us, and how to complain to the regulator.
Last updated 4 August 2026.
