Section 1
Introduction
Pindah Private Limited ("Pindah," "we," "us," or "our") is an enterprise software engineering and technology consulting firm headquartered in Harare, Zimbabwe. We design, deploy, and operate integrated business platforms for organizations across education, healthcare, manufacturing, logistics, insurance, construction, and commercial operations.
We recognize that the data entrusted to us—whether relating to your visit to this website, your correspondence with our team, or the operational records processed within our software platforms—forms part of the critical infrastructure upon which our clients depend. This Privacy Policy explains our practices in clear, substantive terms so that data subjects, client organizations, and authorized representatives can understand how information is handled throughout its lifecycle.
This document applies to personal data processed by Pindah as a data controller (for example, when you contact us or browse our website) and describes our standard commitments when Pindah acts as a data processor on behalf of client organizations using our enterprise modules. Where a separate Data Processing Agreement ("DPA") or client contract governs a specific engagement, that agreement prevails for processor activities to the extent of any inconsistency with this policy.
Section 2
Data Controller Information
| Legal entity | Pindah Private Limited |
|---|---|
| Registered jurisdiction | Zimbabwe |
| Principal office | Harare, Zimbabwe |
| General inquiries | admin@pindah.org |
| Telephone | +263 714 856 897 |
| Website | https://pindah.org |
| Privacy contact | admin@pindah.org (subject line: "Privacy Request") |
Where applicable law requires designation of a representative or contact point for cross-border data transfers, we will publish updated contact details on this page or provide them within contractual documentation supplied to enterprise clients.
Section 3
Definitions
For purposes of this policy, the following terms have the meanings set forth below unless context requires otherwise.
- Personal data
- Any information relating to an identified or identifiable natural person, including identifiers such as name, contact details, online identifiers, location data, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
- Operational data
- Business records processed within Pindah platforms, which may include personal data embedded in transactions, employee records, patient files, student records, inventory movements, financial entries, or correspondence logs.
- Data controller
- The entity that determines the purposes and means of processing personal data. For platform-hosted records, the client organization is typically the controller; Pindah acts as processor unless otherwise stated.
- Data processor
- The entity that processes personal data on behalf of the controller. Pindah processes client operational data under client instruction and applicable contracts.
- Data subject
- An individual to whom personal data relates, including website visitors, client personnel, students, patients, customers, suppliers, and other end users whose information appears in processed records.
- Special category data
- Sensitive personal data requiring heightened protection under applicable law, including health information, biometric data where used for identification, and data relating to minors in educational contexts.
- Processing
- Any operation performed on data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
Section 4
Scope of Application
This Privacy Policy applies to the following activities and systems, without limitation:
- The public website located at pindah.org and associated subdomains used for product information, documentation, and inquiry submission;
- Hosted and deployed instances of Pindah enterprise modules, including but not limited to ERP, CRM, Accounting, Manufacturing, Logistics, Insurance, Construction, HR, Hospital Management, School Management (Frame/SMS), Document Management (DMS), Supply Chain Management (SCM), and related administrative portals;
- Authentication services, including the Pindah Basa login portal where applicable;
- Client onboarding, implementation, support communications, and professional services engagements;
- Educational resource areas of the site, including Zimsec and Cambridge document repositories, where user accounts or upload metadata may be processed;
- Automated content systems used for publication of general business insights on the News section of this website.
This policy does not apply to third-party websites, applications, or services linked from our platforms unless we explicitly state otherwise. Client organizations may maintain independent privacy policies governing their use of Pindah software to process data relating to their employees, customers, students, or patients.
If you interact with Pindah solely as an employee or authorized user of a client organization, requests regarding operational records stored in a client tenant should generally be directed to that organization in the first instance. We will assist controllers in fulfilling valid requests where contractually required.
Section 5
Categories of Data We Process
The categories of data processed depend on your relationship with Pindah and the services in use. Representative categories include:
| Category | Examples | Typical source |
|---|---|---|
| Identity & contact | Name, job title, organization, email, telephone, postal address | Inquiry forms, contracts, account registration |
| Account & credentials | Username, role assignments, authentication logs, password hashes | Identity systems, admin provisioning |
| Technical & usage | IP address, browser type, device identifiers, session timestamps, pages viewed | Web servers, application logs, cookies |
| Financial & commercial | Invoicing details, payment references, procurement records, tax identifiers | ERP, Accounting, client billing |
| Workforce | Employee IDs, payroll inputs, leave records, performance documentation | HR modules under client control |
| Customer & CRM | Lead history, correspondence, sales pipeline, service tickets | CRM modules under client control |
| Education | Student identifiers, enrollment, grades, attendance, fee records, guardian contact details | SMS / Frame deployments |
| Healthcare | Patient demographics, clinical notes, billing, laboratory results where configured | Hospital modules under client control |
| Documents & files | Uploaded PDFs, metadata, version history, workflow approvals, OCR outputs | DMS, Zimsec repositories |
| Communications | Support emails, call records, meeting notes, implementation documentation | Direct correspondence with Pindah |
We do not intentionally collect personal data beyond what is necessary for stated purposes. Clients configure their tenant environments and remain responsible for ensuring that data entered into the platform is collected lawfully and with appropriate notices to data subjects.
Section 6
How We Collect Information
Direct provision
When you email us, request a demonstration, register an account, submit documents, or enter into a commercial agreement, you may provide personal data directly.
Automated technologies
Server logs, session management, security monitoring, and cookies may automatically capture technical information when you access our website or authenticated portals.
Client administration
Authorized administrators at client organizations may create user accounts and upload operational records that contain personal data relating to their personnel or customers.
Integrations
Where clients connect external systems—payment gateways, SMS providers, biometric devices, or legacy databases—data may flow into Pindah platforms through configured interfaces subject to client authorization.
Section 7
Legal Bases for Processing
Where Pindah acts as data controller, we rely on one or more of the following legal bases, as applicable under relevant law:
- Contractual necessity — Processing required to perform a contract with you or your organization, or to take pre-contractual steps at your request (for example, responding to an enterprise inquiry or provisioning a trial environment).
- Legitimate interests — Processing necessary for our legitimate business interests, such as securing our infrastructure, improving platform reliability, publishing general industry insights, or communicating with prospective clients, balanced against data subject rights.
- Legal obligation — Processing required to comply with applicable laws, regulatory requests, tax obligations, or court orders.
- Consent — Where required, we obtain consent for specific activities such as non-essential cookies or optional marketing communications. Consent may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.
- Vital or public interest — In limited circumstances involving healthcare deployments, processing may be necessary to protect vital interests or support delivery of health services under controller direction and applicable regulation.
When acting as processor, Pindah processes personal data solely on documented instructions from the client controller, including with respect to legal bases communicated through the client's own privacy notices to data subjects.
Section 8
Purposes of Processing
We process personal and operational data for the following purposes:
- Delivering, maintaining, and improving enterprise software modules and hosted environments;
- Authenticating users and enforcing role-based access controls across multi-tenant and dedicated deployments;
- Providing implementation, training, technical support, and account management services;
- Processing inquiries submitted through website contact channels or email;
- Generating invoices, maintaining commercial records, and fulfilling contractual obligations;
- Monitoring system performance, diagnosing errors, and conducting capacity planning;
- Detecting, preventing, and responding to security incidents, fraud, or unauthorized access;
- Complying with audit, accounting, regulatory, and legal requirements;
- Publishing anonymized or aggregated analytics that do not identify individuals;
- Producing general business and technology articles for the public News section using automated generation tools subject to editorial configuration;
- Exercising or defending legal claims where necessary.
We do not sell personal data. We do not use client tenant operational data for unrelated third-party marketing. Any use of data for product improvement is conducted under contractual terms, with appropriate segregation between client environments.
Section 9
Platform-Specific Processing
The following summaries describe data handling characteristics associated with major Pindah modules. Detailed technical schedules may be appended to client DPAs.
Section 11
Disclosures to Third Parties
We may disclose personal data to the following categories of recipients under contractual and confidentiality obligations:
- Cloud infrastructure and hosting providers supporting application deployment;
- Email delivery, SMS gateway, and notification service providers configured by Pindah or the client;
- Payment processors where commercial transactions are handled electronically;
- Professional advisers including legal counsel, auditors, and insurers bound by duty of confidentiality;
- Implementation partners engaged with client authorization for specific projects;
- Regulatory authorities, courts, or law enforcement when required by valid legal process;
- Successors in interest in connection with a merger, acquisition, or asset transfer subject to continuity of protection commitments.
Each disclosure is limited to what is reasonably necessary for the stated purpose. Processor relationships are governed by written agreements specifying security requirements, sub-processing restrictions, and breach notification obligations.
Section 12
International Data Transfers
Pindah is based in Zimbabwe and serves clients operating across multiple jurisdictions. Personal data may be stored or processed in Zimbabwe and, where necessary for redundancy, support, or infrastructure efficiency, in other countries where our service providers maintain facilities.
When transferring personal data internationally, we implement appropriate safeguards such as standard contractual clauses, data processing agreements, encryption in transit, and access minimization. Clients requiring data residency within specific geographic boundaries should specify requirements during contracting so that deployment architecture can be aligned accordingly.
Cross-border transfers of special category data, including health or student records, receive additional scrutiny and are configured according to controller instructions and applicable regulatory frameworks.
Section 13
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Retention criteria include:
- Duration of the contractual relationship and applicable limitation periods for legal claims;
- Statutory retention requirements for financial, tax, and regulatory records;
- Client-configured archival and purging policies within tenant environments;
- Security log retention periods necessary for incident investigation and system integrity;
- Backup rotation cycles, after which deleted production data becomes inaccessible through normal means.
Upon contract termination, client operational data is handled according to the applicable agreement—typically export followed by secure deletion within an agreed timeframe, unless legal hold requirements apply. A summary retention schedule appears in Appendix A below.
Section 14
Security Measures
Security architecture is foundational to Pindah platform design. We implement administrative, technical, and organizational measures aligned with ISO 27001 principles, including:
- Encryption of data in transit using TLS
- Encryption at rest where supported by deployment configuration
- Network segmentation and firewall controls
- Immutable audit trails for sensitive operations
- Role-based access control and least-privilege provisioning
- Secure software development and change management practices
- Vulnerability monitoring and patch management procedures
- Personnel confidentiality obligations and security awareness training
No method of transmission or storage is completely secure. While we strive to protect data using commercially reasonable and enterprise-grade controls, we cannot guarantee absolute security. Clients share responsibility for safeguarding credentials, configuring appropriate internal roles, and maintaining endpoint security for devices accessing the platform.
Section 15
Access Controls & Authentication
Access to Pindah systems is granted on a need-to-know basis. Authentication mechanisms may include username and password credentials, multi-factor authentication where enabled, and integration with client identity providers in enterprise deployments.
Administrative privileges are restricted to authorized personnel. Access reviews should be conducted periodically by client administrators to revoke accounts for departed employees or changed roles. Pindah support personnel access client tenant data only when necessary for troubleshooting, under logged and authorized support procedures defined in applicable service agreements.
Repeated failed authentication attempts may trigger account lockout or alerting. Users are responsible for maintaining credential confidentiality and notifying their administrator or Pindah support promptly upon suspected compromise.
Section 16
Your Rights
Depending on applicable law and your relationship with Pindah, you may have the following rights regarding personal data:
- Right of access — Obtain confirmation of whether we process your personal data and receive a copy of such data where legally required.
- Right to rectification — Request correction of inaccurate or incomplete personal data.
- Right to erasure — Request deletion of personal data where no compelling legal basis for continued retention exists.
- Right to restriction — Request limitation of processing in defined circumstances.
- Right to data portability — Receive personal data you provided in a structured, commonly used format where technically feasible.
- Right to object — Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent — Where processing is consent-based, withdraw consent without affecting prior lawful processing.
To submit a request, contact admin@pindah.org with the subject line "Privacy Request" and sufficient information to verify identity. We respond within timeframes required by applicable law, typically within thirty (30) days unless extension is permitted.
If your data is processed within a client tenant, we may redirect your request to the relevant client organization acting as controller, while providing reasonable assistance to that controller as processor.
Section 17
Education Data
Schools and educational institutions using Frame or SMS modules process substantial information relating to students, many of whom are minors. The institution remains the data controller and is responsible for providing appropriate privacy notices to students, parents, and guardians.
Pindah supports controllers through access controls, audit logging, and configurable retention settings. Features such as grade publication, fee statements, and SMS alerts should be deployed in accordance with institutional policy and applicable education regulations.
We do not knowingly market directly to minors through client tenant data. General website content directed at educational administrators is distinct from student-facing portal functionality governed by each school.
Section 18
Healthcare Data
Hospital and clinic deployments may involve processing of protected health information and other special category data. Healthcare providers configure clinical workflows, consent capture, and departmental access boundaries within the platform.
Pindah implements technical controls appropriate to regulated environments, including authentication requirements, comprehensive audit trails, and segregation between clinical and administrative functions where configured. Business associate or equivalent contractual terms are incorporated into healthcare engagements as required.
Personnel without clinical authorization must not access patient records. Emergency break-glass access, if enabled, is logged and subject to post-event review by the client organization.
Section 19
Automated Processing & Generated Content
Pindah may use automated systems, including large language models accessed through third-party inference providers, to generate general business articles published in the public News section of this website. Such content is intended as informational material for business leaders and is not personalized profiling of individual visitors.
Automated processing within client tenant environments—such as workflow routing in DMS, inventory reorder suggestions, or dashboard aggregations—operates on client-controlled data according to rules configured by authorized administrators. These processes do not produce legal or similarly significant effects on data subjects without human oversight unless explicitly configured and disclosed by the client controller.
We do not use client tenant operational data to train public third-party artificial intelligence models unless explicitly agreed in writing with the client.
Section 20
Incident Response & Breach Notification
Pindah maintains procedures for detecting, investigating, and remediating security incidents. Upon becoming aware of a personal data breach affecting data for which we act as processor, we notify the affected client controller without undue delay and provide information reasonably required to support regulatory notification obligations.
Where Pindah acts as controller, we notify affected individuals and relevant authorities when required by law, describing the nature of the breach, likely consequences, and measures taken to address it.
Clients should report suspected security incidents involving Pindah platforms promptly to admin@pindah.org with the subject line "Security Incident."
Section 21
Sub-Processors
Pindah may engage sub-processors to support infrastructure, communications, or specialized services. Sub-processors are bound by written agreements imposing data protection obligations substantially similar to those imposed on Pindah.
Enterprise clients may request notification of material changes to sub-processor arrangements where provided for in their DPA. Objection mechanisms, if applicable, are defined in contractual documentation rather than this public policy.
A current list of sub-processors material to hosted services may be supplied upon written request by authorized client representatives.
Section 22
Business Transfers
If Pindah undergoes a merger, acquisition, reorganization, or sale of assets, personal data may transfer to the successor entity subject to commitments consistent with this policy. We will provide notice through this website or direct communication to affected clients where practicable before personal data becomes subject to a materially different privacy framework.
Section 23
Regional Provisions
Zimbabwe
As a Zimbabwe-incorporated entity, Pindah processes data in accordance with applicable domestic law and regulatory guidance. Clients and data subjects in Zimbabwe may contact us using the details in Section 25 for inquiries relating to local processing activities.
European Economic Area & United Kingdom
Where GDPR or UK GDPR applies to processing for which Pindah is controller or processor, the legal bases, rights, transfer mechanisms, and breach notification commitments described in this policy are intended to align with those frameworks. Controllers remain responsible for establishing lawful bases for tenant data and providing required notices to data subjects.
Other jurisdictions
Organizations operating in additional regions should raise specific compliance requirements during contracting. Pindah works with clients to accommodate reasonable data residency, access, and documentation needs consistent with enterprise deployment models.
Section 24
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in law, technology, or business practices. Material changes will be indicated by updating the effective date at the top of this page. Continued use of our website or services after publication of changes constitutes acknowledgment of the updated policy where permitted by law.
Enterprise clients under active contracts will receive notification of material processor-related changes through account management channels when required by applicable agreements.
Section 25
Contact
For privacy-related inquiries, requests, or complaints, contact:
Pindah Private LimitedHarare, Zimbabwe
Email: admin@pindah.org
Telephone: +263 714 856 897
We aim to resolve concerns promptly and in good faith. If you believe your rights have not been adequately addressed, you may have the right to lodge a complaint with a supervisory authority in your jurisdiction, in addition to contacting us directly.
Appendix A
Illustrative Retention Schedule
Actual retention may vary by contract, jurisdiction, and client configuration. This schedule is illustrative only.
| Record type | Typical retention | Notes |
|---|---|---|
| Website server logs | 90–365 days | Security and diagnostics |
| Marketing inquiry records | 3 years from last contact | Unless longer retention required for active negotiations |
| Active user account data | Duration of account + 30 days | Subject to client admin deletion |
| Financial & tax records (Pindah as controller) | Per statutory requirements | Often 6–10 years depending on jurisdiction |
| Client tenant operational data | Per contract & client policy | Export and deletion upon termination |
| Backup archives | Rotation cycle (e.g. 30–90 days) | Deleted data may persist until backup expiry |
| Support ticket correspondence | 2–7 years | Depending on support agreement |
| Automated News article metadata | Indefinite while published | Public informational content |
Document version 2026-05-31 · © 2026 Pindah Private Limited. All rights reserved.