1. Who We Are and What This Notice Covers
CBZ Holdings (“the Group”, “we”, “us” or “our”) is the Data Controller responsible for your personal information. In this Notice, “the Group” means CBZ Holdings and its subsidiaries: CBZ Bank, Red Sphere Finance, Agroyield, CBZ Life, CBZ Insurance, CBZ Risk Advisory, Datvest, CBZ Properties and CBZ Capital. “Branches” and “Business Units” mean our physical branches, agencies and business divisions.
Your privacy is important to us. This Privacy Notice explains what personal information we collect; how and why we collect, use and protect it; who we share it with; how long we retain it; and the rights and choices available to you. It applies whenever you interact with us through our website, mobile app, branches, agents, call centre, ATMs, point-of-sale terminals or any other channel through which we provide products or services.
This Notice is issued in accordance with the Cyber and Data Protection Act [Chapter 12:07], the Banking Act [Chapter 24:20], the Money Laundering and Proceeds of Crime Act [Chapter 9:24], and other applicable legislation. It applies to our customers, prospective customers and other individuals who interact with us, including guarantors, next of kin and beneficiaries.
Our Data Protection Officer can be contacted using the details in Section 13.
2. What Personal Information We Collect
We collect only the personal information we need for the purposes described in this Notice. Not every category below applies to every customer, what we collect depends on the products and channels you use.
| Category | Examples | Why we use it | Lawful basis |
|---|---|---|---|
| Identification & contact information | Full name, national ID/passport number, date of birth, physical and postal address, phone number, email address, specimen signature, tax number (e.g. ZIMRA BP number) | Opening and managing your account; verifying who you are | Contract necessity, legal obligation |
| Financial information | Account and transaction history, balances, income and source of funds, credit history, collateral, card and mobile-wallet numbers | Providing banking, lending, payment and investment services; assessing affordability and risk | Contract necessity, legal obligation |
| Employment & demographic information | Employer, occupation, employment income, marital status, dependants, household income, education | Assessing eligibility for products such as loans and mortgages | Contract necessity, legitimate interest |
| Device & online identifiers | Login credentials, IP address, MAC address, cookie IDs, mobile app identifiers | Operating our website, app and online banking securely | Contract necessity, legitimate interest |
| Behavioural & network activity | Pages visited, app usage, keystroke and interaction patterns used to confirm it is you | Detecting fraud and confirming you (not a bot or a fraudster) are transacting | Legitimate interest (fraud prevention); legal obligation |
| Communications | Content of emails, chat and messages you send us, call recordings, complaint records | Customer service, dispute resolution, staff training, compliance monitoring | Contract; legitimate interest; legal obligation |
| Geolocation | Approximate location from IP address; precise GPS location only with your consent | Branch/ATM locators; fraud detection | Legitimate interest (approximate); consent (precise) |
| Background & screening information | Politically-exposed-person, sanctions and adverse-media screening results; criminal record checks where legally required | Anti-money-laundering, counter-terrorist-financing and sanctions compliance | Legal obligation |
| Inferences & profiling | Credit scores and risk ratings derived from the information above | Assessing creditworthiness and preventing fraud | Legitimate interest; legal obligation |
Identification & contact information
- Examples
- Full name, national ID/passport number, date of birth, physical and postal address, phone number, email address, specimen signature, tax number (e.g. ZIMRA BP number)
- Why we use it
- Opening and managing your account; verifying who you are
- Lawful basis
- Contract necessity, legal obligation
Financial information
- Examples
- Account and transaction history, balances, income and source of funds, credit history, collateral, card and mobile-wallet numbers
- Why we use it
- Providing banking, lending, payment and investment services; assessing affordability and risk
- Lawful basis
- Contract necessity, legal obligation
Employment & demographic information
- Examples
- Employer, occupation, employment income, marital status, dependants, household income, education
- Why we use it
- Assessing eligibility for products such as loans and mortgages
- Lawful basis
- Contract necessity, legitimate interest
Device & online identifiers
- Examples
- Login credentials, IP address, MAC address, cookie IDs, mobile app identifiers
- Why we use it
- Operating our website, app and online banking securely
- Lawful basis
- Contract necessity, legitimate interest
Behavioural & network activity
- Examples
- Pages visited, app usage, keystroke and interaction patterns used to confirm it is you
- Why we use it
- Detecting fraud and confirming you (not a bot or a fraudster) are transacting
- Lawful basis
- Legitimate interest (fraud prevention); legal obligation
Communications
- Examples
- Content of emails, chat and messages you send us, call recordings, complaint records
- Why we use it
- Customer service, dispute resolution, staff training, compliance monitoring
- Lawful basis
- Contract; legitimate interest; legal obligation
Geolocation
- Examples
- Approximate location from IP address; precise GPS location only with your consent
- Why we use it
- Branch/ATM locators; fraud detection
- Lawful basis
- Legitimate interest (approximate); consent (precise)
Background & screening information
- Examples
- Politically-exposed-person, sanctions and adverse-media screening results; criminal record checks where legally required
- Why we use it
- Anti-money-laundering, counter-terrorist-financing and sanctions compliance
- Lawful basis
- Legal obligation
Inferences & profiling
- Examples
- Credit scores and risk ratings derived from the information above
- Why we use it
- Assessing creditworthiness and preventing fraud
- Lawful basis
- Legitimate interest; legal obligation
Depending on the product or channel, we may also collect images and recordings, including CCTV footage, photographs, voice recordings and identity-document images; biometric information used for identity verification or authentication; information about your relationships with other persons or organisations, such as beneficiaries, guarantors, directors, shareholders and authorised signatories; and information about products or services in which you have expressed an interest. Where any of this information is sensitive personal information, Section 3 applies.
3. Health Information and Other Sensitive Information
Some of the information we collect may constitute sensitive personal information under the Cyber and Data Protection Act, including information relating to your health and other categories of sensitive personal information where applicable.
We only collect, use and process sensitive personal information where:
- you have provided your explicit consent
- the collection or processing is required or permitted by law
- the information is necessary for the establishment, exercise or defence of legal claims
- the processing is permitted under applicable data protection laws and regulations.
We implement appropriate technical and organisational measures to protect sensitive personal information against unauthorised access, loss, misuse, disclosure, alteration or destruction. Access to such information is restricted to authorised personnel who require it for legitimate business purposes and is safeguarded through appropriate security controls.
We retain health and other sensitive personal information only for as long as necessary to fulfil the purposes for which it was collected, comply with legal and regulatory obligations, resolve disputes, and enforce our legal rights and agreements. Where processing is based on your consent, you may withdraw that consent at any time by contacting us, subject to any legal, regulatory or contractual requirements that may require us to continue processing certain information.
4. How We Use Your Personal Information
We use your personal information for the following purposes, on the legal grounds described in the table in Section 2 and summarised below:
- Opening, administering and servicing your account and other products (contractual necessity).
- Verifying your identity and carrying out customer due diligence, including for the Financial Intelligence Unit and correspondent banks (legal obligation).
- Processing payments, transfers and other transactions you instruct (contractual necessity).
- Assessing applications for credit, insurance or other products, including credit scoring (legitimate interest / contractual necessity).
- Detecting, investigating and preventing fraud, money laundering, terrorist financing and other financial crime, including sanctions and PEP screening (legal obligation).
- Complying with our reporting obligations to the Reserve Bank of Zimbabwe, POTRAZ, ZIMRA, the Financial Intelligence Unit and NSSA.
- Maintaining the security of our Branches and Head Office, ATMs, systems, staff and customers, including CCTV and call recording (legitimate interest).
- Improving our products, services, systems and digital channels, and fixing errors (legitimate interest).
- Sending you service messages, such as statements, alerts and notices about your account (contract / legal obligation).
- Sending you marketing communications about products and offers, where you have consented (consent).
- Handling queries, complaints and disputes, and defending or pursuing legal claims (legitimate interest / legal obligation)
Automated decision-making and profiling
We may use automated tools and profiling to support fraud detection, transaction monitoring, identity verification, credit assessment and risk management. These tools may analyse information such as your transaction history, account activity, credit information and device or behavioural data. Where a decision is based solely on automated processing and produces legal or similarly significant effects for you, we will inform you where required by law. You may request human intervention, provide additional information, express your point of view and challenge the decision by contacting us using the details in Section 13.
5. How We Collect Your Personal Information
Directly from you
When you apply for a product, transact at a branch or online, contact our call centre or otherwise interact with us, you provide personal information directly. Where a specific feature requires access to your camera, microphone or contacts, such as for document upload, we will first seek your consent, explain why access is required and allow you to withdraw that consent at any time through your device or app settings.
Automatically, through your use of our channels
We collect device and online identifiers and network activity information automatically when you use our website, app or online banking, including through cookies and similar technologies. See our separate Cookie Notice. Depending on your device settings, we may also collect precise location information, which you can control through your device's location-sharing settings.
Through our branches and technology
Our ATMs and point-of-sale terminals process your card and transaction information when you use them. We operate CCTV in and around our branches for the security of customers, staff and property; cameras are indicated by signage, footage is accessed only by authorised personnel and is kept for 90 days unless needed for an investigation, dispute or legal process. Calls to our contact centre may be recorded for training, quality assurance, dispute resolution and compliance purposes; we will tell you this at the start of the call.
From the Group and from other sources
We may obtain your personal information from other companies within the Group (see Section 6) for the purposes described in this Notice, e.g. to maintain a consolidated view of your relationship with us, where we have a lawful basis to do so, including your consent where required by law. We may also obtain information from credit reference bureaus and the credit registry, identity verification and screening services, employers (with your consent, where required), ZIMRA and other public bodies, and fraud-prevention databases, in order to verify your information, assess credit risk, and prevent fraud and financial crime. Where we obtain personal information from another source, we will provide the information required by law unless an applicable exception permits otherwise.
7. How We Protect Your Personal Information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of your information, including encryption of data in transit and at rest, access controls and authentication, network monitoring, secure disposal of records, and regular staff training on data protection.
If a data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Authority (POTRAZ) within 24 hours of becoming aware of the breach and notify affected data subjects as soon as reasonably practicable where required by law. Our notice will describe the nature of the breach, the information affected, the likely consequences, the measures taken or proposed, and the steps you can take to protect yourself. You can help keep your information safe by never sharing your PIN, password or one-time codes with anyone, including our staff, and by reporting suspicious activity to us immediately.
8. How Long We Keep Your Personal Information
We keep personal information only for as long as necessary for the purposes described in this Notice, including to meet our legal and regulatory obligations. As a guide:
- Customer and transaction records: for the duration of our relationship and for at least 10 years after it ends
- CCTV footage: 90 days unless needed for an investigation, dispute or legal proceeding
- Call recordings: 10 years
- Marketing data: until you withdraw consent or object
- Biometric data: only for as long as needed for the purpose it was collected and deleted or irreversibly de-identified thereafter.
After the applicable retention period, we securely delete, anonymise or archive your information in accordance with our internal records-retention policy and procedures. The periods above may be extended where records are required for an investigation, complaint, litigation, legal hold or another legal or regulatory purpose. In determining an appropriate retention period, we consider the purpose of processing, the amount, nature and sensitivity of the information, the risk of harm from unauthorised use or disclosure, and applicable legal requirements.
9. Your Rights and Choices
Subject to the Cyber and Data Protection Act [Chapter 12:07], you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion of your information, where the law allows
- Object to, or request that we restrict, certain processing, such as direct marketing
- Withdraw consent at any time, for any processing that is based on consent (this will not affect processing already carried out, or processing we must continue for legal or contractual reasons, such as KYC and regulatory reporting)
- Request human review of, and express your view on, a purely automated decision that significantly affects you
- Lodge a complaint with the Data Protection Authority (POTRAZ) if you believe we have not handled your information properly.
Some processing is required by law or under our contract with you, including customer due diligence, fraud prevention and statutory reporting, and you cannot opt out of that processing. To exercise any of these rights, contact us using the details in Section 13. We will respond within 30 days, as required by law. We may ask for information needed to verify your identity and authority to make the request. Rights may be limited by applicable law, including where disclosure would adversely affect another person's rights, compromise security or fraud-prevention controls, or conflict with a legal or regulatory obligation. We will explain any lawful refusal or restriction and any available complaint or appeal route.
Marketing and cookies
You can manage marketing communications and cookies at any time:
- Marketing: adjust your preferences in your account settings, or email [email protected]
- Cookies: manage non-essential cookies through the cookie banner on our website, which is set to opt-in by default; see our Cookie Notice for details.
10. Children's and Minors' Information
Some of our products (e.g., minor/junior savings accounts) involve the personal information of children, provided and managed by a parent or legal guardian. We collect and use a minor's personal information only as reasonably necessary to provide the relevant product, with the consent and involvement of a parent or guardian, and apply the same protections described in this Notice. We take reasonable steps to verify the authority of the parent or legal guardian and provide privacy information in a form appropriate to the child's age and understanding where practicable. A parent, legal guardian or other legally authorised representative may exercise the child's data-protection rights by contacting us.
11. Links to Third-Party Services
Our website and app may link to third-party websites, social media platforms, or include third-party features such as plug-ins and widgets. We do not control these third parties and are not responsible for their privacy practices. We encourage you to review their privacy notices before providing them with your information.
12. Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our practices or the law. We will post the updated version on our website and app with a new effective date, and where changes are material, we will notify you through appropriate channels before they take effect.
13. How to Contact Us
- Data Protection Officer
- Matthew Manyati
- [email protected]
- Postal address
- P.O. Box 3313, Harare
- Phone
- +263774132360
Data Protection Authority: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), P.O. Box MP 843, Mount Pleasant, Harare, Zimbabwe / www.potraz.gov.zw, for complaints you believe we have not resolved.