Legal & compliance

Privacy Policy

This policy describes how Pindah Private Limited collects, uses, stores, and protects personal and operational data across our website, enterprise platforms, and client engagements.

Effective date: May 31, 2026 · Version 2.0

Section 1

Introduction

Pindah Private Limited ("Pindah," "we," "us," or "our") is an enterprise software engineering and technology consulting firm headquartered in Harare, Zimbabwe. We design, deploy, and operate integrated business platforms for organizations across education, healthcare, manufacturing, logistics, insurance, construction, and commercial operations.

We recognize that the data entrusted to us—whether relating to your visit to this website, your correspondence with our team, or the operational records processed within our software platforms—forms part of the critical infrastructure upon which our clients depend. This Privacy Policy explains our practices in clear, substantive terms so that data subjects, client organizations, and authorized representatives can understand how information is handled throughout its lifecycle.

This document applies to personal data processed by Pindah as a data controller (for example, when you contact us or browse our website) and describes our standard commitments when Pindah acts as a data processor on behalf of client organizations using our enterprise modules. Where a separate Data Processing Agreement ("DPA") or client contract governs a specific engagement, that agreement prevails for processor activities to the extent of any inconsistency with this policy.

Section 2

Data Controller Information

Legal entity Pindah Private Limited
Registered jurisdiction Zimbabwe
Principal office Harare, Zimbabwe
General inquiries admin@pindah.org
Telephone +263 714 856 897
Website https://pindah.org
Privacy contact admin@pindah.org (subject line: "Privacy Request")

Where applicable law requires designation of a representative or contact point for cross-border data transfers, we will publish updated contact details on this page or provide them within contractual documentation supplied to enterprise clients.

Section 3

Definitions

For purposes of this policy, the following terms have the meanings set forth below unless context requires otherwise.

Personal data
Any information relating to an identified or identifiable natural person, including identifiers such as name, contact details, online identifiers, location data, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
Operational data
Business records processed within Pindah platforms, which may include personal data embedded in transactions, employee records, patient files, student records, inventory movements, financial entries, or correspondence logs.
Data controller
The entity that determines the purposes and means of processing personal data. For platform-hosted records, the client organization is typically the controller; Pindah acts as processor unless otherwise stated.
Data processor
The entity that processes personal data on behalf of the controller. Pindah processes client operational data under client instruction and applicable contracts.
Data subject
An individual to whom personal data relates, including website visitors, client personnel, students, patients, customers, suppliers, and other end users whose information appears in processed records.
Special category data
Sensitive personal data requiring heightened protection under applicable law, including health information, biometric data where used for identification, and data relating to minors in educational contexts.
Processing
Any operation performed on data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.

Section 4

Scope of Application

This Privacy Policy applies to the following activities and systems, without limitation:

  • The public website located at pindah.org and associated subdomains used for product information, documentation, and inquiry submission;
  • Hosted and deployed instances of Pindah enterprise modules, including but not limited to ERP, CRM, Accounting, Manufacturing, Logistics, Insurance, Construction, HR, Hospital Management, School Management (Frame/SMS), Document Management (DMS), Supply Chain Management (SCM), and related administrative portals;
  • Authentication services, including the Pindah Basa login portal where applicable;
  • Client onboarding, implementation, support communications, and professional services engagements;
  • Educational resource areas of the site, including Zimsec and Cambridge document repositories, where user accounts or upload metadata may be processed;
  • Automated content systems used for publication of general business insights on the News section of this website.

This policy does not apply to third-party websites, applications, or services linked from our platforms unless we explicitly state otherwise. Client organizations may maintain independent privacy policies governing their use of Pindah software to process data relating to their employees, customers, students, or patients.

If you interact with Pindah solely as an employee or authorized user of a client organization, requests regarding operational records stored in a client tenant should generally be directed to that organization in the first instance. We will assist controllers in fulfilling valid requests where contractually required.

Section 5

Categories of Data We Process

The categories of data processed depend on your relationship with Pindah and the services in use. Representative categories include:

Category Examples Typical source
Identity & contact Name, job title, organization, email, telephone, postal address Inquiry forms, contracts, account registration
Account & credentials Username, role assignments, authentication logs, password hashes Identity systems, admin provisioning
Technical & usage IP address, browser type, device identifiers, session timestamps, pages viewed Web servers, application logs, cookies
Financial & commercial Invoicing details, payment references, procurement records, tax identifiers ERP, Accounting, client billing
Workforce Employee IDs, payroll inputs, leave records, performance documentation HR modules under client control
Customer & CRM Lead history, correspondence, sales pipeline, service tickets CRM modules under client control
Education Student identifiers, enrollment, grades, attendance, fee records, guardian contact details SMS / Frame deployments
Healthcare Patient demographics, clinical notes, billing, laboratory results where configured Hospital modules under client control
Documents & files Uploaded PDFs, metadata, version history, workflow approvals, OCR outputs DMS, Zimsec repositories
Communications Support emails, call records, meeting notes, implementation documentation Direct correspondence with Pindah

We do not intentionally collect personal data beyond what is necessary for stated purposes. Clients configure their tenant environments and remain responsible for ensuring that data entered into the platform is collected lawfully and with appropriate notices to data subjects.

Section 6

How We Collect Information

Direct provision

When you email us, request a demonstration, register an account, submit documents, or enter into a commercial agreement, you may provide personal data directly.

Automated technologies

Server logs, session management, security monitoring, and cookies may automatically capture technical information when you access our website or authenticated portals.

Client administration

Authorized administrators at client organizations may create user accounts and upload operational records that contain personal data relating to their personnel or customers.

Integrations

Where clients connect external systems—payment gateways, SMS providers, biometric devices, or legacy databases—data may flow into Pindah platforms through configured interfaces subject to client authorization.

Section 8

Purposes of Processing

We process personal and operational data for the following purposes:

  • Delivering, maintaining, and improving enterprise software modules and hosted environments;
  • Authenticating users and enforcing role-based access controls across multi-tenant and dedicated deployments;
  • Providing implementation, training, technical support, and account management services;
  • Processing inquiries submitted through website contact channels or email;
  • Generating invoices, maintaining commercial records, and fulfilling contractual obligations;
  • Monitoring system performance, diagnosing errors, and conducting capacity planning;
  • Detecting, preventing, and responding to security incidents, fraud, or unauthorized access;
  • Complying with audit, accounting, regulatory, and legal requirements;
  • Publishing anonymized or aggregated analytics that do not identify individuals;
  • Producing general business and technology articles for the public News section using automated generation tools subject to editorial configuration;
  • Exercising or defending legal claims where necessary.

We do not sell personal data. We do not use client tenant operational data for unrelated third-party marketing. Any use of data for product improvement is conducted under contractual terms, with appropriate segregation between client environments.

Section 9

Platform-Specific Processing

The following summaries describe data handling characteristics associated with major Pindah modules. Detailed technical schedules may be appended to client DPAs.

Financial modules process ledger entries, accounts payable and receivable, inventory valuations, multi-currency transactions, tax calculations, and audit trails. Personal data may appear in employee expense claims, customer master records, supplier contacts, and payment metadata. Retention aligns with statutory accounting periods and client-configured archival policies. Access is restricted through segregation of duties and role definitions configured by the client administrator.

CRM modules consolidate interaction history across sales, service, and marketing workflows. Data subjects may include leads, customers, partners, and internal sales personnel. Communication logs, quotation records, and pipeline stages may contain personal identifiers and commercial preferences. Clients determine lawful basis and retention for sales records; Pindah provides export and deletion tooling where configured.

Education platforms manage student enrollment, academic records, attendance, fee billing, parent portals, and staff administration. Data relating to minors receives heightened protection. Schools act as controllers; Pindah processes records under instruction. Features such as SMS notifications to guardians require clients to maintain appropriate consent or legal authority. See Section 17 for additional detail.

Healthcare modules may process patient registration, clinical encounters, laboratory orders, pharmacy dispensing, billing, and medical record attachments. Such data frequently constitutes special category health information. Deployments implement granular clinical roles, session timeouts, and comprehensive audit logging. See Section 18 for additional detail.

Document systems store files, metadata, version histories, workflow states, and search indices. Contributor accounts on educational repositories may log upload activity, file names, and associated user identifiers. OCR and classification features process document contents to enable retrieval. Clients and authorized contributors must not upload unlawful or unnecessary personal data within shared documents.

Operational modules process data relating to production orders, fleet movements, driver assignments, employee lifecycle events, policy administration, claims, site safety records, and subcontractor documentation. Personal data typically appears in workforce, customer, and partner records embedded within operational transactions. Processing supports workflow automation, regulatory reporting, and executive dashboards configured by each client.

Section 10

Cookies, Local Storage & Analytics

Our website and authenticated applications may use cookies and similar technologies for the following purposes:

  • Strictly necessary cookies — Required for authentication, session continuity, load balancing, and security protections. These cannot be disabled without impairing core functionality.
  • Functional cookies — Remember preferences such as language selection or interface configuration where supported.
  • Performance cookies — Collect aggregated information about page load times and navigation patterns to improve reliability.

We minimize use of invasive tracking technologies on the public marketing site. Authenticated enterprise portals may employ additional session mechanisms necessary for secure operation. Browser settings may allow you to refuse cookies; however, certain services may become unavailable if essential cookies are blocked.

Where non-essential cookies requiring consent are introduced in specific jurisdictions, we will present appropriate notice and choice mechanisms consistent with applicable law.

Section 11

Disclosures to Third Parties

We may disclose personal data to the following categories of recipients under contractual and confidentiality obligations:

  • Cloud infrastructure and hosting providers supporting application deployment;
  • Email delivery, SMS gateway, and notification service providers configured by Pindah or the client;
  • Payment processors where commercial transactions are handled electronically;
  • Professional advisers including legal counsel, auditors, and insurers bound by duty of confidentiality;
  • Implementation partners engaged with client authorization for specific projects;
  • Regulatory authorities, courts, or law enforcement when required by valid legal process;
  • Successors in interest in connection with a merger, acquisition, or asset transfer subject to continuity of protection commitments.

Each disclosure is limited to what is reasonably necessary for the stated purpose. Processor relationships are governed by written agreements specifying security requirements, sub-processing restrictions, and breach notification obligations.

Section 12

International Data Transfers

Pindah is based in Zimbabwe and serves clients operating across multiple jurisdictions. Personal data may be stored or processed in Zimbabwe and, where necessary for redundancy, support, or infrastructure efficiency, in other countries where our service providers maintain facilities.

When transferring personal data internationally, we implement appropriate safeguards such as standard contractual clauses, data processing agreements, encryption in transit, and access minimization. Clients requiring data residency within specific geographic boundaries should specify requirements during contracting so that deployment architecture can be aligned accordingly.

Cross-border transfers of special category data, including health or student records, receive additional scrutiny and are configured according to controller instructions and applicable regulatory frameworks.

Section 13

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Retention criteria include:

  • Duration of the contractual relationship and applicable limitation periods for legal claims;
  • Statutory retention requirements for financial, tax, and regulatory records;
  • Client-configured archival and purging policies within tenant environments;
  • Security log retention periods necessary for incident investigation and system integrity;
  • Backup rotation cycles, after which deleted production data becomes inaccessible through normal means.

Upon contract termination, client operational data is handled according to the applicable agreement—typically export followed by secure deletion within an agreed timeframe, unless legal hold requirements apply. A summary retention schedule appears in Appendix A below.

Section 14

Security Measures

Security architecture is foundational to Pindah platform design. We implement administrative, technical, and organizational measures aligned with ISO 27001 principles, including:

  • Encryption of data in transit using TLS
  • Encryption at rest where supported by deployment configuration
  • Network segmentation and firewall controls
  • Immutable audit trails for sensitive operations
  • Role-based access control and least-privilege provisioning
  • Secure software development and change management practices
  • Vulnerability monitoring and patch management procedures
  • Personnel confidentiality obligations and security awareness training

No method of transmission or storage is completely secure. While we strive to protect data using commercially reasonable and enterprise-grade controls, we cannot guarantee absolute security. Clients share responsibility for safeguarding credentials, configuring appropriate internal roles, and maintaining endpoint security for devices accessing the platform.

Section 15

Access Controls & Authentication

Access to Pindah systems is granted on a need-to-know basis. Authentication mechanisms may include username and password credentials, multi-factor authentication where enabled, and integration with client identity providers in enterprise deployments.

Administrative privileges are restricted to authorized personnel. Access reviews should be conducted periodically by client administrators to revoke accounts for departed employees or changed roles. Pindah support personnel access client tenant data only when necessary for troubleshooting, under logged and authorized support procedures defined in applicable service agreements.

Repeated failed authentication attempts may trigger account lockout or alerting. Users are responsible for maintaining credential confidentiality and notifying their administrator or Pindah support promptly upon suspected compromise.

Section 16

Your Rights

Depending on applicable law and your relationship with Pindah, you may have the following rights regarding personal data:

  1. Right of access — Obtain confirmation of whether we process your personal data and receive a copy of such data where legally required.
  2. Right to rectification — Request correction of inaccurate or incomplete personal data.
  3. Right to erasure — Request deletion of personal data where no compelling legal basis for continued retention exists.
  4. Right to restriction — Request limitation of processing in defined circumstances.
  5. Right to data portability — Receive personal data you provided in a structured, commonly used format where technically feasible.
  6. Right to object — Object to processing based on legitimate interests or for direct marketing.
  7. Right to withdraw consent — Where processing is consent-based, withdraw consent without affecting prior lawful processing.

To submit a request, contact admin@pindah.org with the subject line "Privacy Request" and sufficient information to verify identity. We respond within timeframes required by applicable law, typically within thirty (30) days unless extension is permitted.

If your data is processed within a client tenant, we may redirect your request to the relevant client organization acting as controller, while providing reasonable assistance to that controller as processor.

Section 17

Education Data

Schools and educational institutions using Frame or SMS modules process substantial information relating to students, many of whom are minors. The institution remains the data controller and is responsible for providing appropriate privacy notices to students, parents, and guardians.

Pindah supports controllers through access controls, audit logging, and configurable retention settings. Features such as grade publication, fee statements, and SMS alerts should be deployed in accordance with institutional policy and applicable education regulations.

We do not knowingly market directly to minors through client tenant data. General website content directed at educational administrators is distinct from student-facing portal functionality governed by each school.

Section 18

Healthcare Data

Hospital and clinic deployments may involve processing of protected health information and other special category data. Healthcare providers configure clinical workflows, consent capture, and departmental access boundaries within the platform.

Pindah implements technical controls appropriate to regulated environments, including authentication requirements, comprehensive audit trails, and segregation between clinical and administrative functions where configured. Business associate or equivalent contractual terms are incorporated into healthcare engagements as required.

Personnel without clinical authorization must not access patient records. Emergency break-glass access, if enabled, is logged and subject to post-event review by the client organization.

Section 19

Automated Processing & Generated Content

Pindah may use automated systems, including large language models accessed through third-party inference providers, to generate general business articles published in the public News section of this website. Such content is intended as informational material for business leaders and is not personalized profiling of individual visitors.

Automated processing within client tenant environments—such as workflow routing in DMS, inventory reorder suggestions, or dashboard aggregations—operates on client-controlled data according to rules configured by authorized administrators. These processes do not produce legal or similarly significant effects on data subjects without human oversight unless explicitly configured and disclosed by the client controller.

We do not use client tenant operational data to train public third-party artificial intelligence models unless explicitly agreed in writing with the client.

Section 20

Incident Response & Breach Notification

Pindah maintains procedures for detecting, investigating, and remediating security incidents. Upon becoming aware of a personal data breach affecting data for which we act as processor, we notify the affected client controller without undue delay and provide information reasonably required to support regulatory notification obligations.

Where Pindah acts as controller, we notify affected individuals and relevant authorities when required by law, describing the nature of the breach, likely consequences, and measures taken to address it.

Clients should report suspected security incidents involving Pindah platforms promptly to admin@pindah.org with the subject line "Security Incident."

Section 21

Sub-Processors

Pindah may engage sub-processors to support infrastructure, communications, or specialized services. Sub-processors are bound by written agreements imposing data protection obligations substantially similar to those imposed on Pindah.

Enterprise clients may request notification of material changes to sub-processor arrangements where provided for in their DPA. Objection mechanisms, if applicable, are defined in contractual documentation rather than this public policy.

A current list of sub-processors material to hosted services may be supplied upon written request by authorized client representatives.

Section 22

Business Transfers

If Pindah undergoes a merger, acquisition, reorganization, or sale of assets, personal data may transfer to the successor entity subject to commitments consistent with this policy. We will provide notice through this website or direct communication to affected clients where practicable before personal data becomes subject to a materially different privacy framework.

Section 23

Regional Provisions

Zimbabwe

As a Zimbabwe-incorporated entity, Pindah processes data in accordance with applicable domestic law and regulatory guidance. Clients and data subjects in Zimbabwe may contact us using the details in Section 25 for inquiries relating to local processing activities.

European Economic Area & United Kingdom

Where GDPR or UK GDPR applies to processing for which Pindah is controller or processor, the legal bases, rights, transfer mechanisms, and breach notification commitments described in this policy are intended to align with those frameworks. Controllers remain responsible for establishing lawful bases for tenant data and providing required notices to data subjects.

Other jurisdictions

Organizations operating in additional regions should raise specific compliance requirements during contracting. Pindah works with clients to accommodate reasonable data residency, access, and documentation needs consistent with enterprise deployment models.

Section 24

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in law, technology, or business practices. Material changes will be indicated by updating the effective date at the top of this page. Continued use of our website or services after publication of changes constitutes acknowledgment of the updated policy where permitted by law.

Enterprise clients under active contracts will receive notification of material processor-related changes through account management channels when required by applicable agreements.

Section 25

Contact

For privacy-related inquiries, requests, or complaints, contact:

Pindah Private Limited
Harare, Zimbabwe
Email: admin@pindah.org
Telephone: +263 714 856 897

We aim to resolve concerns promptly and in good faith. If you believe your rights have not been adequately addressed, you may have the right to lodge a complaint with a supervisory authority in your jurisdiction, in addition to contacting us directly.

Appendix A

Illustrative Retention Schedule

Actual retention may vary by contract, jurisdiction, and client configuration. This schedule is illustrative only.

Record type Typical retention Notes
Website server logs 90–365 days Security and diagnostics
Marketing inquiry records 3 years from last contact Unless longer retention required for active negotiations
Active user account data Duration of account + 30 days Subject to client admin deletion
Financial & tax records (Pindah as controller) Per statutory requirements Often 6–10 years depending on jurisdiction
Client tenant operational data Per contract & client policy Export and deletion upon termination
Backup archives Rotation cycle (e.g. 30–90 days) Deleted data may persist until backup expiry
Support ticket correspondence 2–7 years Depending on support agreement
Automated News article metadata Indefinite while published Public informational content

Document version 2026-05-31 · © 2026 Pindah Private Limited. All rights reserved.