Zikimall – Zimbabwe's Digital Mall

CBZ Holdings

Privacy Notice

Effective date: 1 October 2026

Contents

1. Who We Are and What This Notice Covers

CBZ Holdings (“the Group”, “we”, “us” or “our”) is the Data Controller responsible for your personal information. In this Notice, “the Group” means CBZ Holdings and its subsidiaries: CBZ Bank, Red Sphere Finance, Agroyield, CBZ Life, CBZ Insurance, CBZ Risk Advisory, Datvest, CBZ Properties and CBZ Capital. “Branches” and “Business Units” mean our physical branches, agencies and business divisions.

Your privacy is important to us. This Privacy Notice explains what personal information we collect; how and why we collect, use and protect it; who we share it with; how long we retain it; and the rights and choices available to you. It applies whenever you interact with us through our website, mobile app, branches, agents, call centre, ATMs, point-of-sale terminals or any other channel through which we provide products or services.

This Notice is issued in accordance with the Cyber and Data Protection Act [Chapter 12:07], the Banking Act [Chapter 24:20], the Money Laundering and Proceeds of Crime Act [Chapter 9:24], and other applicable legislation. It applies to our customers, prospective customers and other individuals who interact with us, including guarantors, next of kin and beneficiaries.

Our Data Protection Officer can be contacted using the details in Section 13.

2. What Personal Information We Collect

We collect only the personal information we need for the purposes described in this Notice. Not every category below applies to every customer, what we collect depends on the products and channels you use.

Identification & contact information

Examples
Full name, national ID/passport number, date of birth, physical and postal address, phone number, email address, specimen signature, tax number (e.g. ZIMRA BP number)
Why we use it
Opening and managing your account; verifying who you are
Lawful basis
Contract necessity, legal obligation

Financial information

Examples
Account and transaction history, balances, income and source of funds, credit history, collateral, card and mobile-wallet numbers
Why we use it
Providing banking, lending, payment and investment services; assessing affordability and risk
Lawful basis
Contract necessity, legal obligation

Employment & demographic information

Examples
Employer, occupation, employment income, marital status, dependants, household income, education
Why we use it
Assessing eligibility for products such as loans and mortgages
Lawful basis
Contract necessity, legitimate interest

Device & online identifiers

Examples
Login credentials, IP address, MAC address, cookie IDs, mobile app identifiers
Why we use it
Operating our website, app and online banking securely
Lawful basis
Contract necessity, legitimate interest

Behavioural & network activity

Examples
Pages visited, app usage, keystroke and interaction patterns used to confirm it is you
Why we use it
Detecting fraud and confirming you (not a bot or a fraudster) are transacting
Lawful basis
Legitimate interest (fraud prevention); legal obligation

Communications

Examples
Content of emails, chat and messages you send us, call recordings, complaint records
Why we use it
Customer service, dispute resolution, staff training, compliance monitoring
Lawful basis
Contract; legitimate interest; legal obligation

Geolocation

Examples
Approximate location from IP address; precise GPS location only with your consent
Why we use it
Branch/ATM locators; fraud detection
Lawful basis
Legitimate interest (approximate); consent (precise)

Background & screening information

Examples
Politically-exposed-person, sanctions and adverse-media screening results; criminal record checks where legally required
Why we use it
Anti-money-laundering, counter-terrorist-financing and sanctions compliance
Lawful basis
Legal obligation

Inferences & profiling

Examples
Credit scores and risk ratings derived from the information above
Why we use it
Assessing creditworthiness and preventing fraud
Lawful basis
Legitimate interest; legal obligation

Depending on the product or channel, we may also collect images and recordings, including CCTV footage, photographs, voice recordings and identity-document images; biometric information used for identity verification or authentication; information about your relationships with other persons or organisations, such as beneficiaries, guarantors, directors, shareholders and authorised signatories; and information about products or services in which you have expressed an interest. Where any of this information is sensitive personal information, Section 3 applies.

3. Health Information and Other Sensitive Information

Some of the information we collect may constitute sensitive personal information under the Cyber and Data Protection Act, including information relating to your health and other categories of sensitive personal information where applicable.

We only collect, use and process sensitive personal information where:

  • you have provided your explicit consent
  • the collection or processing is required or permitted by law
  • the information is necessary for the establishment, exercise or defence of legal claims
  • the processing is permitted under applicable data protection laws and regulations.

We implement appropriate technical and organisational measures to protect sensitive personal information against unauthorised access, loss, misuse, disclosure, alteration or destruction. Access to such information is restricted to authorised personnel who require it for legitimate business purposes and is safeguarded through appropriate security controls.

We retain health and other sensitive personal information only for as long as necessary to fulfil the purposes for which it was collected, comply with legal and regulatory obligations, resolve disputes, and enforce our legal rights and agreements. Where processing is based on your consent, you may withdraw that consent at any time by contacting us, subject to any legal, regulatory or contractual requirements that may require us to continue processing certain information.

4. How We Use Your Personal Information

We use your personal information for the following purposes, on the legal grounds described in the table in Section 2 and summarised below:

  • Opening, administering and servicing your account and other products (contractual necessity).
  • Verifying your identity and carrying out customer due diligence, including for the Financial Intelligence Unit and correspondent banks (legal obligation).
  • Processing payments, transfers and other transactions you instruct (contractual necessity).
  • Assessing applications for credit, insurance or other products, including credit scoring (legitimate interest / contractual necessity).
  • Detecting, investigating and preventing fraud, money laundering, terrorist financing and other financial crime, including sanctions and PEP screening (legal obligation).
  • Complying with our reporting obligations to the Reserve Bank of Zimbabwe, POTRAZ, ZIMRA, the Financial Intelligence Unit and NSSA.
  • Maintaining the security of our Branches and Head Office, ATMs, systems, staff and customers, including CCTV and call recording (legitimate interest).
  • Improving our products, services, systems and digital channels, and fixing errors (legitimate interest).
  • Sending you service messages, such as statements, alerts and notices about your account (contract / legal obligation).
  • Sending you marketing communications about products and offers, where you have consented (consent).
  • Handling queries, complaints and disputes, and defending or pursuing legal claims (legitimate interest / legal obligation)

Automated decision-making and profiling

We may use automated tools and profiling to support fraud detection, transaction monitoring, identity verification, credit assessment and risk management. These tools may analyse information such as your transaction history, account activity, credit information and device or behavioural data. Where a decision is based solely on automated processing and produces legal or similarly significant effects for you, we will inform you where required by law. You may request human intervention, provide additional information, express your point of view and challenge the decision by contacting us using the details in Section 13.

5. How We Collect Your Personal Information

Directly from you

When you apply for a product, transact at a branch or online, contact our call centre or otherwise interact with us, you provide personal information directly. Where a specific feature requires access to your camera, microphone or contacts, such as for document upload, we will first seek your consent, explain why access is required and allow you to withdraw that consent at any time through your device or app settings.

Automatically, through your use of our channels

We collect device and online identifiers and network activity information automatically when you use our website, app or online banking, including through cookies and similar technologies. See our separate Cookie Notice. Depending on your device settings, we may also collect precise location information, which you can control through your device's location-sharing settings.

Through our branches and technology

Our ATMs and point-of-sale terminals process your card and transaction information when you use them. We operate CCTV in and around our branches for the security of customers, staff and property; cameras are indicated by signage, footage is accessed only by authorised personnel and is kept for 90 days unless needed for an investigation, dispute or legal process. Calls to our contact centre may be recorded for training, quality assurance, dispute resolution and compliance purposes; we will tell you this at the start of the call.

From the Group and from other sources

We may obtain your personal information from other companies within the Group (see Section 6) for the purposes described in this Notice, e.g. to maintain a consolidated view of your relationship with us, where we have a lawful basis to do so, including your consent where required by law. We may also obtain information from credit reference bureaus and the credit registry, identity verification and screening services, employers (with your consent, where required), ZIMRA and other public bodies, and fraud-prevention databases, in order to verify your information, assess credit risk, and prevent fraud and financial crime. Where we obtain personal information from another source, we will provide the information required by law unless an applicable exception permits otherwise.

6. Who We Share Your Information With

We disclose personal information only where necessary, and subject to our duty of confidentiality, to:

  • Other companies within the Group, where necessary for the purposes described in this Notice and where we have a lawful basis to do so, including your consent where required by law.
  • Regulators and public authorities, including the Postal and Telecommunications Regulatory Authority in Zimbabwe (POTRAZ), Reserve Bank of Zimbabwe (RBZ), the Financial Intelligence Unit (FIU), Zimbabwe Revenue Authority (ZIMRA), the Deposit Protection Corporation (DPC), National Social Security Authority (NSSA), courts, and law enforcement, where required or permitted by law
  • Other financial institutions and payment infrastructure needed to carry out your instructions, such as correspondent and custodian banks, card schemes, payment switches and SWIFT, credit reference bureaus, and stock exchanges or brokers, where relevant to your product
  • Our service providers and agents, acting only on our instructions under written data-processing agreements, in categories such as IT and cloud hosting, banking operations support, printing and mailing, telecommunications, debt collection, professional advisers, and sales and marketing agencies (with your consent)
  • Any other person or body where you have given your specific consent, or where you have released us from confidentiality.

Recipients are permitted to use personal information only for the purpose for which it was disclosed and must protect it in accordance with applicable law, contractual confidentiality obligations and appropriate security requirements. We do not sell personal information.

Cross-border transfers

Some of our systems are hosted on cloud infrastructure, and some of our cloud hosting providers, service providers and payment partners (including card schemes and SWIFT) are located outside Zimbabwe, including in South Africa, the USA and Europe. Where we transfer your personal information outside Zimbabwe, we do so only where the law permits, for example because the transfer is necessary to perform a transaction you have requested, because appropriate contractual safeguards are in place, or because you have consented in line with the cross-border transfer requirements of the Cyber and Data Protection Act [Chapter 12:07]. Before making a transfer, we assess whether the recipient and destination provide an adequate level of protection and, where required, implement contractual, technical and organisational safeguards or obtain the necessary authorisation. You may contact our Data Protection Officer for further information about the safeguards that apply to a particular transfer.

7. How We Protect Your Personal Information

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of your information, including encryption of data in transit and at rest, access controls and authentication, network monitoring, secure disposal of records, and regular staff training on data protection.

If a data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Authority (POTRAZ) within 24 hours of becoming aware of the breach and notify affected data subjects as soon as reasonably practicable where required by law. Our notice will describe the nature of the breach, the information affected, the likely consequences, the measures taken or proposed, and the steps you can take to protect yourself. You can help keep your information safe by never sharing your PIN, password or one-time codes with anyone, including our staff, and by reporting suspicious activity to us immediately.

8. How Long We Keep Your Personal Information

We keep personal information only for as long as necessary for the purposes described in this Notice, including to meet our legal and regulatory obligations. As a guide:

  • Customer and transaction records: for the duration of our relationship and for at least 10 years after it ends
  • CCTV footage: 90 days unless needed for an investigation, dispute or legal proceeding
  • Call recordings: 10 years
  • Marketing data: until you withdraw consent or object
  • Biometric data: only for as long as needed for the purpose it was collected and deleted or irreversibly de-identified thereafter.

After the applicable retention period, we securely delete, anonymise or archive your information in accordance with our internal records-retention policy and procedures. The periods above may be extended where records are required for an investigation, complaint, litigation, legal hold or another legal or regulatory purpose. In determining an appropriate retention period, we consider the purpose of processing, the amount, nature and sensitivity of the information, the risk of harm from unauthorised use or disclosure, and applicable legal requirements.

9. Your Rights and Choices

Subject to the Cyber and Data Protection Act [Chapter 12:07], you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of your information, where the law allows
  • Object to, or request that we restrict, certain processing, such as direct marketing
  • Withdraw consent at any time, for any processing that is based on consent (this will not affect processing already carried out, or processing we must continue for legal or contractual reasons, such as KYC and regulatory reporting)
  • Request human review of, and express your view on, a purely automated decision that significantly affects you
  • Lodge a complaint with the Data Protection Authority (POTRAZ) if you believe we have not handled your information properly.

Some processing is required by law or under our contract with you, including customer due diligence, fraud prevention and statutory reporting, and you cannot opt out of that processing. To exercise any of these rights, contact us using the details in Section 13. We will respond within 30 days, as required by law. We may ask for information needed to verify your identity and authority to make the request. Rights may be limited by applicable law, including where disclosure would adversely affect another person's rights, compromise security or fraud-prevention controls, or conflict with a legal or regulatory obligation. We will explain any lawful refusal or restriction and any available complaint or appeal route.

Marketing and cookies

You can manage marketing communications and cookies at any time:

  • Marketing: adjust your preferences in your account settings, or email [email protected]
  • Cookies: manage non-essential cookies through the cookie banner on our website, which is set to opt-in by default; see our Cookie Notice for details.

10. Children's and Minors' Information

Some of our products (e.g., minor/junior savings accounts) involve the personal information of children, provided and managed by a parent or legal guardian. We collect and use a minor's personal information only as reasonably necessary to provide the relevant product, with the consent and involvement of a parent or guardian, and apply the same protections described in this Notice. We take reasonable steps to verify the authority of the parent or legal guardian and provide privacy information in a form appropriate to the child's age and understanding where practicable. A parent, legal guardian or other legally authorised representative may exercise the child's data-protection rights by contacting us.

11. Links to Third-Party Services

Our website and app may link to third-party websites, social media platforms, or include third-party features such as plug-ins and widgets. We do not control these third parties and are not responsible for their privacy practices. We encourage you to review their privacy notices before providing them with your information.

12. Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices or the law. We will post the updated version on our website and app with a new effective date, and where changes are material, we will notify you through appropriate channels before they take effect.

13. How to Contact Us

Data Protection Officer
Matthew Manyati
Email
[email protected]
Postal address
P.O. Box 3313, Harare
Phone
+263774132360

Data Protection Authority: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), P.O. Box MP 843, Mount Pleasant, Harare, Zimbabwe / www.potraz.gov.zw, for complaints you believe we have not resolved.