Privacy Policy

Last updated: 28 April 2026 · Effective date: 28 April 2026

1. Identity of Responsible Party

The responsible party (as defined in POPIA Section 1) for the processing of your personal information is:

FieldDetail
Legal name[Imbazo (Pty) Ltd / Trading name — to be registered]
Registration number[To be assigned on incorporation]
Registered address[Physical address — to be confirmed]
Contact emailprivacy@imbazoca.com

2. Information Officer

In terms of POPIA Section 55, our designated Information Officer is:

FieldDetail
Name[Information Officer name — to be appointed]
Emailprivacy@imbazoca.com
Phone[To be confirmed]

For Zimbabwean data subjects, enquiries may also be directed to the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) at www.potraz.gov.zw.

3. Purpose of Collection (POPIA Section 13)

We collect and process personal information for the following specific, explicitly defined purposes:

3.1 Participant Data

Data categoryPurposeLegal basis (POPIA s11)
Name, phone, emailIdentity verification, communicationConsent (s11(1)(a))
Date of birth, genderStudy matching (demographic criteria)Consent (s11(1)(a))
Country, city, provinceGeographic study targetingConsent (s11(1)(a))
Education, employment, incomeSocio-economic study matchingConsent (s11(1)(a))
Languages, ethnicityLinguistic/cultural study matchingConsent (s11(1)(a)); ethnicity is special personal information processed only with explicit consent per s26-s33
Internet access typeStudy feasibility assessmentConsent (s11(1)(a))
Payment detailsDisbursing study participation paymentsContract performance (s11(1)(b))

3.2 Researcher Data

Data categoryPurposeLegal basis
Name, email, institutionAccount creation, communicationContract performance (s11(1)(b))
Payment informationBilling for study servicesContract performance (s11(1)(b))
Study content/criteriaService deliveryContract performance (s11(1)(b))

4. Data Minimisation & Adequacy (POPIA Section 10)

We collect only data that is adequate, relevant, and not excessive for the stated purposes. Participants may decline to provide optional fields (education, income, ethnicity) without affecting core panel membership.

5. Consent (POPIA Section 11)

Participant consent is obtained via our WhatsApp onboarding flow. Consent is:

Consent can be withdrawn at any time by messaging "STOP" to our WhatsApp number or emailing privacy@imbazoca.com.

6. Information Quality (POPIA Section 16)

We take reasonable steps to ensure personal information is complete, accurate, and not misleading. Participants can review and correct their information at any time via WhatsApp or by contacting us.

7. Data Retention (POPIA Section 14)

Data typeRetention periodJustification
Active participant profilesWhile participant is active + 2 years after deactivationService delivery + legal compliance
Completed study data5 years from study completionResearch audit trail, tax records
Consent recordsIndefinite (anonymised after 7 years)Legal compliance proof
Audit logs7 yearsLegal and regulatory compliance
Payment records7 yearsFinancial regulatory requirements
Researcher accountsWhile active + 2 years after last loginService delivery

On deletion request, personal data is erased from active systems within 30 days. Anonymised aggregates may be retained for platform analytics.

8. Cross-Border Transfers (POPIA Section 72)

Sub-processorLocationPurposeSafeguard
Supabase Inc.United StatesDatabase hosting (Postgres)SOC 2 Type II compliant; contractual data processing terms
Meta Platforms Inc.United States / IrelandWhatsApp Business API — participant messagingEU-US Data Privacy Framework; Meta Business DPA
Clerk Inc.United StatesResearcher authenticationSOC 2 compliant; contractual safeguards
Vercel Inc.United States / Global edgeWeb application hostingSOC 2 Type II; DPA with standard contractual clauses
Stripe Inc. (future)United StatesPayment processingPCI DSS Level 1; GDPR-compliant DPA

All sub-processors are bound by data processing agreements that require them to process your data only for specified purposes and to implement appropriate security measures.

9. Security Safeguards (POPIA Section 19)

We implement appropriate technical and organisational measures to protect personal information, including:

10. Your Rights (POPIA Section 23–25)

As a data subject, you have the right to:

To exercise any right, contact us at privacy@imbazoca.com or message "PRIVACY" to our WhatsApp number. We will respond within 30 days.

11. POPIA Section 18 Notification

12. Children's Data

Imbazo does not knowingly collect personal information from persons under the age of 18. Our onboarding flow includes age verification. If we discover we hold data of a minor, it will be deleted immediately.

13. Cookies & Analytics

Our web application uses only essential cookies for session management (authentication). We do not use advertising or tracking cookies. Vercel Analytics may collect anonymised performance metrics (page load times, country-level geographic data).

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email (researchers) or WhatsApp (participants) at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

15. Contact

For any privacy-related enquiries: