LEGAL
Data processing and the Data Protection Act
This page is for the person in your organisation who has to sign off that using us is defensible: who controls what, what we do as a processor, how a data subject request is handled, how long records are kept, and what we do when something goes wrong.
Draft — not yet reviewed by a legal practitioner
This document sets out how we intend to operate and is published so you can read it before you buy. It has not yet been reviewed by a Zimbabwean legal practitioner. Where it conflicts with the signed agreement between us, the signed agreement applies.
- Drafted
- 4 August 2026
- Last reviewed
- Not yet
- Reviewed by
- To be appointed
- Data controller
- Silverconne Technologies (Pvt) Ltd
- Named officer
- Appointment pending
- Access and deletion
- In the portal, or by email to privacy@silverconne.com
- Retention schedule
- Section 5 of this page
Version of 4 August 2026
1. Compliance statement
Silverconne Technologies (Pvt) Ltd processes personal information in the course of providing business software to organisations in Zimbabwe. We are working to the requirements of the Zimbabwe Data Protection Act (Chapter 11:12), and this page sets out how.
We deliberately do not state a registration or licensing status on this page. Anything we asserted here that we had not verified would undermine the point of the page.
2. Named data controller
- Controller
- Silverconne Technologies (Pvt) Ltd
- Named contact
- Data Protection Officer (appointment pending)
- privacy@silverconne.com
- Address
- Harare, Zimbabwe
The appointment of a named officer is in progress and the name will appear here when it is made. We would rather show you the gap than a name that does not correspond to a real appointment.
3. When we are a controller and when we are a processor
The distinction matters, because it decides who is answerable to the person whose information it is.
| Data | Our role | What that means |
|---|---|---|
| Your own contact details as our client or prospect | Controller | We decide what we hold and why, and we answer to you directly |
| Data your business puts into our software — your customers, pupils, staff | Processor | You decide. We process on your instructions and do nothing else with it |
| Support tickets and the messages in them | Controller for the ticket, processor for anything you attach | We keep the service record; the attachment stays yours |
| Assistant conversations on this site | Controller | We hold the transcript to review answer quality, for 12 months |
| Analytics events on this site | Controller | No name attached, and not linked to a person unless signed in |
Where we are a processor, we do not use your data to train models, we do not sell it, and we do not use it to build a product. If we ever wanted to use anonymised patterns from it, we would ask you first and take no for an answer.
4. Data subject access and deletion
The route depends on whose data it is, and it is worth reading which case applies before you send anything.
- 01You are a Silverconne client or contactRequest an export or a deletion from your account settings in the portal. The request is recorded and tracked, and you can see its status. Without a portal account, email the address above.
- 02You are somebody in our client’s system — a customer, a parent, an employeeYour request goes to the organisation that holds your information, not to us. They are the controller and we cannot lawfully act on their data without their instruction. Tell them, and if they need our help to answer you they know how to reach us.
- 03You are our client and one of your data subjects has asked youTell us and we will help you answer it, including producing an export of that person’s records from your system. There is no charge for that.
| Stage | Timescale |
|---|---|
| Acknowledgement | Within 5 business days |
| Identity confirmed | Before anything is released |
| Export delivered, or deletion completed | Within 30 days |
| Deletion reflected in backups | Within 35 days, as backups roll |
| If we cannot comply in full | We say which record, why, and when the retention period ends |
5. Retention schedule
A documented retention schedule is one of the obligations we take most seriously, because indefinite retention is the default that every system drifts into. This is the schedule, and it is the same one on the privacy policy.
| What | How long we keep it | Why |
|---|---|---|
| Enquiry and lead records | 24 months from the last contact | So we know what was discussed if you come back to us |
| Quotes and orders | 7 years from the date of the document | Accounting and tax record-keeping |
| Invoices, receipts and payment records | 7 years from the date of the document | Accounting and tax record-keeping |
| Client project files and documents | The life of the engagement, then 3 years | Support, warranty and reference |
| Support tickets and their messages | 3 years from closure | Recurring-fault history and service review |
| Assistant conversation transcripts | 12 months | Quality review and abuse investigation |
| Website analytics events | 14 months | Understanding which pages work. No name attached |
| Newsletter subscription | Until you unsubscribe, then 12 months | To honour the unsubscribe if a list is re-imported |
| Job applications | 12 months from the decision, unless you ask us to keep it longer | Future roles and our own hiring record |
| Backups | 35 days rolling | Recovery. A deletion request is applied to live data immediately and works through backups within this window |
Where you are the controller and your own retention rules are shorter than ours, yours apply to your data. Tell us the periods and we will configure them.
6. Sub-processors
We use hosting, email delivery, payment, analytics, error monitoring and AI model providers. Each is bound to process only on our instructions. We will give you the current list by name on request, and we will tell clients before we add one that touches client data.
7. Data leaving Zimbabwe
Some of our infrastructure is hosted outside Zimbabwe, so some processing happens outside the country. We will state the region in writing before you sign, and we will tell you if it changes. If your organisation requires data to remain in Zimbabwe, say so during scoping — it constrains the architecture, and it is far cheaper to constrain it at the start than to migrate later.
8. Security measures
- Encryption in transit and at rest.
- Row-level security on every table holding client data, so isolation is enforced by the database and not only by our application code.
- Documents in a private store, reachable only through short-lived signed links.
- Two-factor authentication on all staff accounts.
- Least-privilege access, reviewed quarterly and revoked on the day someone leaves.
- An audit record of every status change: who, what, when, and the previous value.
- Backups with a restore procedure that we test by actually restoring, not by reading it.
9. If there is a breach
- 01We contain it and record what we knowTimes, systems, and what data was reachable.
- 02We tell affected clients without waiting for a complete pictureWhat happened, what it affects, what we are doing, and what you may need to do. An incomplete notification that arrives quickly is more useful than a polished one that arrives late.
- 03We notify the supervisory authority where we are required toAnd we tell you that we have done so.
- 04We publish what we changedA breach without a change in practice afterwards is a breach that will recur.
10. Getting a signed agreement in place
If your procurement process needs a data processing agreement, a security questionnaire completed, or a named contact for data protection matters, raise it during scoping. We will complete the questionnaire and sign a reasonable agreement. What we will not do is sign something that commits us to a control we do not actually operate.
How we handle personal data day to day is in the privacy policy. This page is the version written for a procurement or compliance review.
Data protection contact
Requests, questions and procurement paperwork all go to the same address, and a person answers them.
- Email privacy@silverconne.com
- Post Harare, Zimbabwe
- Everything else Contact us