SahwiGate Privacy Policy
This Privacy Policy explains how SahwiGate ("we", "our", or "us"), in conjunction with the Nyaradzo Group, collects, uses, protects, and discloses your personal data across our event ticketing, funeral transport manifest, and automated chatbot platforms in accordance with the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe.
Zim Cyber Act [Cap 12:07]
Strict adherence to POTRAZ regulatory mandates, consent requirements, and data subject rights.
Zero-Card-Storage Guarantee
Payments handled exclusively via certified gateways (EcoCash, InnBucks, ZimSwitch, Stripe).
Full Data Subject Control
Right to access, rectify, port, or request erasure of your data at any time through our DPO.
Table of Contents
Data Protection Officer
Office of the DPO
For inquiries, data access, or rights requests under Chapter 12:07:
Legal Status, Application & Scope
This Privacy Policy and Data Protection Notice ("Policy") sets out how SahwiGate, operating under and in affiliation with the Nyaradzo Group ("we", "us", "our"), collects, processes, stores, protects, and discloses personal data in connection with:
- The SahwiGate web application (
sahwigate.com) and associated mobile applications. - Digital event ticketing and access control for concerts, sports (including marathons and walkathons), cultural, and corporate functions.
- The Nyaradzo Funeral Transport & Bus Manifest System (including public registration portals, teller portals, and bus boarding manifests).
- Interactive conversational chatbots deployed across Meta WhatsApp Cloud API and related messaging platforms.
This Policy is governed by and construed in strict conformity with the laws of the Republic of Zimbabwe, specifically the Cyber and Data Protection Act [Chapter 12:07] (Act No. 5 of 2021), the Consumer Protection Act [Chapter 14:14], and the National Payment Systems Act [Chapter 24:23].
Key Statutory Definitions
In accordance with Section 3 of the Cyber and Data Protection Act [Chapter 12:07]:
Categories of Personal Data We Collect
We collect only the minimum necessary personal data required to deliver our services:
A. Identity & Contact Information
Full legal name, national identity number (National ID), passport number, gender, date of birth, physical/residential address, mobile telephone number, and email address.
B. Funeral Transport & Bus Manifest Records
Associated funeral service ID, bus vehicle registration number (VRN), allocated seat number, trip type (round-trip or one-way), Next of Kin contact details (name, phone number, physical address), Nyaradzo policyholder verification status, boarding timestamps, and digital ticket UUIDs.
C. Sporting & Event Participation Details
Race distance (e.g. 5km, 10km, 21km, 42km), athletic club affiliation, t-shirt size, bib number, and voluntary emergency medical/safety disclosures.
D. Financial & Transactional Metadata
Payment references, mobile money transaction hashes (EcoCash, InnBucks, OneMoney), ZimSwitch / Paynow gateway tokens, purchase codes, currency (USD, ZWG), and ticket verification logs.
E. Technical, Audit & Chatbot Telemetry
IP address, browser type, device identifiers, session timestamps, multi-factor authentication (MFA) verification logs, immutable database audit trails (audits), and transient WhatsApp conversation state markers.
Lawful Bases for Processing (Section 11)
Under Section 11 of the Cyber and Data Protection Act, we process your data strictly under the following lawful grounds:
1. Performance of a Contract (Section 11(1)(b)): Necessary to generate tickets, allocate funeral bus seats, dispatch digital boarding passes, process admissions, and fulfill ticketing agreements.
2. Explicit and Informed Consent (Section 11(1)(a)): Provided when you opt-in to marketing communications, initiate interactions with our WhatsApp chatbots, or submit voluntary event registration preferences.
3. Compliance with Legal Obligations (Section 11(1)(c)): Fulfilling tax obligations (ZIMRA), anti-money laundering (AML) requirements, public transport passenger manifest safety laws, and statutory regulatory directives.
4. Vital Interests of the Data Subject (Section 11(1)(d)): Processing emergency Next of Kin contacts and medical information in the event of accidents, medical crises, or transit emergencies.
5. Legitimate Business Interests (Section 11(1)(f)): Platform cybersecurity protection, fraud prevention, bot mitigation, and operational auditing.
Funeral Transport & Bus Manifest Processing
When you register for funeral transportation provided by Nyaradzo Group / SahwiGate:
- Policyholder Verification: Your National ID is queried securely against the Nyaradzo / Easipol policyholder database to verify client status and determine policyholder benefits.
- Transport Safety & Manifests: Your name, allocated seat number, trip route, and Next of Kin emergency details are included on the official bus manifest accessible only to authorized dispatchers, bus marshals, and licensed drivers for transit safety.
- No Public Directory: Funeral listings and passenger registrations are private and accessible solely via direct links, unique codes, or authorized teller portals.
WhatsApp Chatbot Conversational Processing
When you interact with the SahwiGate or Nyaradzo Funeral WhatsApp Chatbots via the Meta WhatsApp Cloud API (Graph API v22.0):
- Your mobile phone number and WhatsApp profile name are processed to manage interactive booking sessions.
- Conversational state data is maintained temporarily in isolated session stores and automatically reset after 24 hours of inactivity.
- Boarding passes and tickets are delivered directly as secure, digitally signed PDF documents.
- Inbound messages are validated using SHA-256 HMAC cryptographic signatures to prevent unauthorized spoofing or tampering.
Payments & Financial Security
SahwiGate complies strictly with the National Payment Systems Act [Chapter 24:23] and PCI-DSS data security standards:
No Storage of Payment Card Details
We do NOT process, store, or transmit complete credit/debit card numbers (PANs) or Card Verification Values (CVVs) on SahwiGate servers. All card transactions are handled directly through certified, encrypted third-party payment gateways (Paynow, Stripe, ZimSwitch).
Mobile money transactions (EcoCash, InnBucks, OneMoney) are authenticated through secure USSD pushes or official API tokens with end-to-end cryptographic verification.
Data Processors & Third-Party Disclosures
We do not sell, rent, or trade your personal data. Disclosures are limited to authorized third parties under strict contractual data processing agreements:
| Third Party Category | Purpose | Safeguards |
|---|---|---|
| Event Organizers & Promoters | Venue admission, attendance lists, and safety compliance | Access limited strictly to ticket validation and check-in statuses |
| Nyaradzo Group / Easipol | Policy verification and funeral transport operations | Encrypted internal API integration with mutual TLS |
| Payment Processors (Paynow, Stripe, EcoCash) | Payment settlement and financial reconciliation | PCI-DSS Level 1 certified gateways and tokenization |
| Cloud Infrastructure (AWS, Backblaze B2) | Secure hosting, encrypted database backups, and PDF storage | AES-256 server-side encryption, ISO 27001 certified data centres |
| Meta Platforms Ireland Ltd | Delivery of automated WhatsApp chatbot messages & tickets | Standard Contractual Clauses & Graph API encryption |
Cross-Border Data Transfers (Section 28)
Where personal data is transferred outside Zimbabwe (e.g. to cloud servers hosted by Amazon Web Services or Meta Platforms API nodes), such transfers comply strictly with Section 28 of the Cyber and Data Protection Act:
- The recipient jurisdiction ensures an adequate level of data protection comparable to Zimbabwean standards.
- Standard Contractual Clauses (SCCs) and binding data processing agreements are in place.
- All data transmitted across borders is protected with industry-standard TLS 1.3 encryption in transit and AES-256 encryption at rest.
Data Retention & Storage Schedule
We retain personal data only for as long as necessary to achieve the specific purposes for which it was collected or to satisfy statutory obligations:
- Financial, Payment & Tax Records: Retained for 7 years in compliance with ZIMRA tax regulations and Reserve Bank of Zimbabwe requirements.
- Funeral Transport Manifests: Retained for 3 years for transport safety verification and regulatory audits.
- Event Ticketing Records: Retained for 2 years post-event to resolve chargebacks, claims, or customer inquiries.
- Transient WhatsApp Chat Sessions: Automatically purged after 24 hours of inactivity.
Information Security Safeguards (Section 24)
In accordance with Section 24 of the Act, we maintain technical, physical, and organizational security measures:
Your Statutory Data Subject Rights (Sections 14–20)
As a data subject under Zimbabwean law, you hold the following non-negotiable statutory rights:
To exercise any of these rights, submit a written request to our Data Protection Officer at dpo@nyaradzo.co.zw. We will respond within thirty (30) days as required by law.
Protection of Minors (Children's Privacy)
SahwiGate does not knowingly register or collect personal information from individuals under the age of eighteen (18) without the explicit verifiable consent of a parent or legal guardian. Where children participate in sporting events (such as fun runs or junior marathons), registration must be completed by an authorized adult.
Data Breach Notification Protocol (Section 25)
In the unlikely event of a security incident resulting in a breach of personal data that presents a risk to the rights and freedoms of data subjects:
- We will notify the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) within seventy-two (72) hours of becoming aware of the breach.
- We will communicate the breach without undue delay to affected data subjects with actionable guidance on mitigating potential adverse effects.
Contact DPO & POTRAZ Regulatory Escalation
If you have questions, concerns, or wish to file a data privacy request, please contact our designated Data Protection Officer:
SahwiGate Data Protection Officer (DPO)
Nyaradzo Group Corporate Head Office, Harare, Zimbabwe
Email: dpo@nyaradzo.co.zw | Telephone: +263 242 796 000
Regulatory Supervisory Authority
If you believe that your data protection rights have been violated and we have failed to resolve your complaint satisfactorily, you have the statutory right under the Cyber and Data Protection Act to lodge a complaint with:
Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
Data Protection Authority (DPA)
Block A, Emerald Park, 30 The Chase, Mt Pleasant, Harare, Zimbabwe
Website: www.potraz.gov.zw | Email: the.regulator@potraz.gov.zw