Back
Legal

Data Protection Notice

Version 2026-09-06

Draft — pending formal legal review. This notice describes Vimera's current, good-faith data-handling practice under Zimbabwe's Cyber and Data Protection Act [Chapter 12:07]. It has not yet been reviewed and signed off by qualified legal counsel, and POTRAZ registration is in progress rather than complete.

1. Data controller

Vimera acts as the data controller for the personal and business information you provide when creating an account or using the platform.

2. What Vimera collects

  • Account information: name, email, and password (stored hashed, never in plain text).
  • Business information you submit: registration number, ZIMRA TIN, business category, location, and any certificate you upload for verification.
  • Transaction records: wallet ledger entries, invoices, cash-on-delivery orders, and the credit-readiness signals derived from them.
  • Business staff and payroll records a business account chooses to enter: staff names, roles, contract terms, and salary payment history.
  • Business-to-business credit/debt records a business account chooses to enter: counterparty, amount, and repayment history.
  • Evidence files (receipts, payslips, proof-of-payment) a business account attaches to a recorded transaction, stored in a private file store scoped to that business.
  • Personal budgeting data you enter: budget lines, savings goal names, target and saved amounts, and target dates.
  • Loan-introduction requests: the lender you selected, the amount and purpose you entered, and the contact details passed to that lender at your request.
  • Developer submissions to the App Store: developer or company name, contact details, app metadata, screenshots, and the installer or web-app URL you upload.
  • Content reports you submit about forum threads or replies: what you reported, the reason, and any notes, visible to Vimera moderators.
  • Usage data needed to operate the service, including device/browser metadata attached to security events.

3. Why Vimera collects it

To operate your ledger and wallet, calculate fees and tax estimates, run the verification and credit-readiness features you opt into, detect and review fraud signals on wallet activity, and meet Vimera's own accounting and regulatory obligations.

4. Sharing your data

Vimera does not sell personal data. Data is shared only: with payment partners (EcoCash, OneMoney, InnBucks, Paynow) strictly to process a transaction you initiate; with a lender you explicitly choose to share a credit report link with, via a revocable, expiring link; with a partner lender you explicitly ask to be introduced to, limited to the details in that introduction request; or where required by Zimbabwean law or a valid court order. App Store developers receive aggregate install and visit counts for their own listings, not the identity of individual users, unless you contact them directly.

Sly's Advice, Vimera's in-product insights feature, computes its observations entirely within Vimera's own servers from your own already-recorded data — it does not send your data to any third-party AI provider.

If you connect an outside AI assistant or other third-party client to your Vimera account (through Vimera's agent-integration interface), that client signs in as you and can read the business, wallet, inventory and transaction data your account can already see, and can write ledger entries — such as recording a sale or an expense — on your behalf, limited to the tools you have granted it. Vimera does not share data with any such client unless you have connected and approved it, and you can revoke that access at any time; anything the client itself does with the data it reads is governed by that provider's own terms, not Vimera's.

5. Consent-based sharing

Where Vimera's identity layer supports third-party attribute sharing (for example, a lender reading a specific verified attribute), that access is governed by an explicit, scoped, revocable consent grant that you create, not a blanket data release.

6. Your rights

You may request a copy of the personal data Vimera holds about you, request correction of inaccurate data, and request account and data deletion, subject to records Vimera must retain for accounting, tax, or dispute-resolution purposes. Use the data-export option in Settings or contact Vimera through the channel listed on the About page.

7. Retention

Ledger and transaction records are retained for as long as required for accounting, tax, and dispute-resolution purposes, even after an account is closed. Fraud-monitoring flag records are retained for audit purposes.

8. Security

Passwords are never stored in plain text. Wallet transactions are append-only and access is restricted so that only the account owner (and, for shared legs, the counterparty) can read their own ledger. Fraud-monitoring flags and consent-access logs are visible only to authorized verifier/admin roles.

9. Contact

Data protection questions can be sent through the contact channel listed on the Vimera About page.