Back
Legal

Data Protection Notice

Version 2026-07-04

Draft — pending formal legal review. This notice describes Vimera's current, good-faith data-handling practice under Zimbabwe's Cyber and Data Protection Act [Chapter 12:07]. It has not yet been reviewed and signed off by qualified legal counsel, and POTRAZ registration is in progress rather than complete.

1. Data controller

Vimera acts as the data controller for the personal and business information you provide when creating an account or using the platform.

2. What Vimera collects

  • Account information: name, email, and password (stored hashed, never in plain text).
  • Business information you submit: registration number, ZIMRA TIN, business category, location, and any certificate you upload for verification.
  • Transaction records: wallet ledger entries, invoices, cash-on-delivery orders, and the credit-readiness signals derived from them.
  • Usage data needed to operate the service, including device/browser metadata attached to security events.

3. Why Vimera collects it

To operate your ledger and wallet, calculate fees and tax estimates, run the verification and credit-readiness features you opt into, detect and review fraud signals on wallet activity, and meet Vimera's own accounting and regulatory obligations.

4. Sharing your data

Vimera does not sell personal data. Data is shared only: with payment partners (EcoCash, OneMoney, InnBucks, Paynow) strictly to process a transaction you initiate; with a lender you explicitly choose to share a credit report link with, via a revocable, expiring link; or where required by Zimbabwean law or a valid court order.

5. Consent-based sharing

Where Vimera's identity layer supports third-party attribute sharing (for example, a lender reading a specific verified attribute), that access is governed by an explicit, scoped, revocable consent grant that you create, not a blanket data release.

6. Your rights

You may request a copy of the personal data Vimera holds about you, request correction of inaccurate data, and request account and data deletion, subject to records Vimera must retain for accounting, tax, or dispute-resolution purposes. Use the data-export option in Settings or contact Vimera through the channel listed on the About page.

7. Retention

Ledger and transaction records are retained for as long as required for accounting, tax, and dispute-resolution purposes, even after an account is closed. Fraud-monitoring flag records are retained for audit purposes.

8. Security

Passwords are never stored in plain text. Wallet transactions are append-only and access is restricted so that only the account owner (and, for shared legs, the counterparty) can read their own ledger. Fraud-monitoring flags and consent-access logs are visible only to authorized verifier/admin roles.

9. Contact

Data protection questions can be sent through the contact channel listed on the Vimera About page.