Skip to content
Silverconne

LEGAL

Data processing and the Data Protection Act

This page is for the person in your organisation who has to sign off that using us is defensible: who controls what, what we do as a processor, how a data subject request is handled, how long records are kept, and what we do when something goes wrong.

Draft — not yet reviewed by a legal practitioner

This document sets out how we intend to operate and is published so you can read it before you buy. It has not yet been reviewed by a Zimbabwean legal practitioner. Where it conflicts with the signed agreement between us, the signed agreement applies.

Drafted
4 August 2026
Last reviewed
Not yet
Reviewed by
To be appointed

1. Compliance statement

Silverconne Technologies (Pvt) Ltd processes personal information in the course of providing business software to organisations in Zimbabwe. We are working to the requirements of the Zimbabwe Data Protection Act (Chapter 11:12), and this page sets out how.

We deliberately do not state a registration or licensing status on this page. Anything we asserted here that we had not verified would undermine the point of the page.

2. Named data controller

Controller
Silverconne Technologies (Pvt) Ltd
Named contact
Data Protection Officer (appointment pending)
Email
privacy@silverconne.com
Address
Harare, Zimbabwe

The appointment of a named officer is in progress and the name will appear here when it is made. We would rather show you the gap than a name that does not correspond to a real appointment.

3. When we are a controller and when we are a processor

The distinction matters, because it decides who is answerable to the person whose information it is.

Who decides what happens to the data
DataOur roleWhat that means
Your own contact details as our client or prospectControllerWe decide what we hold and why, and we answer to you directly
Data your business puts into our software — your customers, pupils, staffProcessorYou decide. We process on your instructions and do nothing else with it
Support tickets and the messages in themController for the ticket, processor for anything you attachWe keep the service record; the attachment stays yours
Assistant conversations on this siteControllerWe hold the transcript to review answer quality, for 12 months
Analytics events on this siteControllerNo name attached, and not linked to a person unless signed in

Where we are a processor, we do not use your data to train models, we do not sell it, and we do not use it to build a product. If we ever wanted to use anonymised patterns from it, we would ask you first and take no for an answer.

4. Data subject access and deletion

The route depends on whose data it is, and it is worth reading which case applies before you send anything.

  1. 01You are a Silverconne client or contactRequest an export or a deletion from your account settings in the portal. The request is recorded and tracked, and you can see its status. Without a portal account, email the address above.
  2. 02You are somebody in our client’s system — a customer, a parent, an employeeYour request goes to the organisation that holds your information, not to us. They are the controller and we cannot lawfully act on their data without their instruction. Tell them, and if they need our help to answer you they know how to reach us.
  3. 03You are our client and one of your data subjects has asked youTell us and we will help you answer it, including producing an export of that person’s records from your system. There is no charge for that.
What we commit to on a request
StageTimescale
AcknowledgementWithin 5 business days
Identity confirmedBefore anything is released
Export delivered, or deletion completedWithin 30 days
Deletion reflected in backupsWithin 35 days, as backups roll
If we cannot comply in fullWe say which record, why, and when the retention period ends

5. Retention schedule

A documented retention schedule is one of the obligations we take most seriously, because indefinite retention is the default that every system drifts into. This is the schedule, and it is the same one on the privacy policy.

Retention schedule
WhatHow long we keep itWhy
Enquiry and lead records24 months from the last contactSo we know what was discussed if you come back to us
Quotes and orders7 years from the date of the documentAccounting and tax record-keeping
Invoices, receipts and payment records7 years from the date of the documentAccounting and tax record-keeping
Client project files and documentsThe life of the engagement, then 3 yearsSupport, warranty and reference
Support tickets and their messages3 years from closureRecurring-fault history and service review
Assistant conversation transcripts12 monthsQuality review and abuse investigation
Website analytics events14 monthsUnderstanding which pages work. No name attached
Newsletter subscriptionUntil you unsubscribe, then 12 monthsTo honour the unsubscribe if a list is re-imported
Job applications12 months from the decision, unless you ask us to keep it longerFuture roles and our own hiring record
Backups35 days rollingRecovery. A deletion request is applied to live data immediately and works through backups within this window

Where you are the controller and your own retention rules are shorter than ours, yours apply to your data. Tell us the periods and we will configure them.

6. Sub-processors

We use hosting, email delivery, payment, analytics, error monitoring and AI model providers. Each is bound to process only on our instructions. We will give you the current list by name on request, and we will tell clients before we add one that touches client data.

7. Data leaving Zimbabwe

Some of our infrastructure is hosted outside Zimbabwe, so some processing happens outside the country. We will state the region in writing before you sign, and we will tell you if it changes. If your organisation requires data to remain in Zimbabwe, say so during scoping — it constrains the architecture, and it is far cheaper to constrain it at the start than to migrate later.

8. Security measures

  • Encryption in transit and at rest.
  • Row-level security on every table holding client data, so isolation is enforced by the database and not only by our application code.
  • Documents in a private store, reachable only through short-lived signed links.
  • Two-factor authentication on all staff accounts.
  • Least-privilege access, reviewed quarterly and revoked on the day someone leaves.
  • An audit record of every status change: who, what, when, and the previous value.
  • Backups with a restore procedure that we test by actually restoring, not by reading it.

9. If there is a breach

  1. 01We contain it and record what we knowTimes, systems, and what data was reachable.
  2. 02We tell affected clients without waiting for a complete pictureWhat happened, what it affects, what we are doing, and what you may need to do. An incomplete notification that arrives quickly is more useful than a polished one that arrives late.
  3. 03We notify the supervisory authority where we are required toAnd we tell you that we have done so.
  4. 04We publish what we changedA breach without a change in practice afterwards is a breach that will recur.

10. Getting a signed agreement in place

If your procurement process needs a data processing agreement, a security questionnaire completed, or a named contact for data protection matters, raise it during scoping. We will complete the questionnaire and sign a reasonable agreement. What we will not do is sign something that commits us to a control we do not actually operate.

How we handle personal data day to day is in the privacy policy. This page is the version written for a procurement or compliance review.

Data protection contact

Requests, questions and procurement paperwork all go to the same address, and a person answers them.