{"id":6094,"date":"2026-04-16T14:51:38","date_gmt":"2026-04-16T14:51:38","guid":{"rendered":"https:\/\/stfcapital.org\/?page_id=6094"},"modified":"2026-04-16T14:51:38","modified_gmt":"2026-04-16T14:51:38","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/stfcapital.org\/index.php\/legal\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<p><!--\n  PRIVACY POLICY \u2014 paste the entire content below into a WordPress\n  \"Custom HTML\" block on a new Page.\n\n  Recommended page settings:\n    Title ..... Privacy Policy\n    Slug ...... privacy-policy\n    Parent .... Legal (if you create a Legal parent page)\n--><\/p>\n<div class=\"stf-legal\">\n<div class=\"stf-hero\">\n    <span class=\"stf-eyebrow\">Document 01 of 04 \u00b7 Privacy Policy<\/span><\/p>\n<h1 class=\"stf-hero-title\">The <em>Privacy Policy<\/em> of the STF Capital mobile application.<\/h1>\n<p class=\"stf-hero-lede\">\n      This document explains, in full, how STF Capital Private Limited (&ldquo;STF<br \/>\n      Capital&rdquo;, &ldquo;we&rdquo;, &ldquo;us&rdquo;) handles the personal data of<br \/>\n      anyone who uses the STF Capital mobile application on Android or iOS. It is the<br \/>\n      controlling record for Google Play Data Safety, our Cyber and Data Protection Act<br \/>\n      disclosures and any contractual warranties we give to clients about their data.\n    <\/p>\n<div class=\"stf-meta\">\n<div><strong>Version<\/strong> 1.0<\/div>\n<div><strong>Effective date<\/strong> 16 April 2026<\/div>\n<div><strong>Last reviewed<\/strong> 16 April 2026<\/div>\n<div><strong>Data controller<\/strong> STF Capital Private Limited<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"stf-toc\">\n<div class=\"stf-toc-title\">On this page<\/div>\n<ol>\n<li><a href=\"#summary\">Summary for Google Play reviewers<\/a><\/li>\n<li><a href=\"#who-we-are\">Who we are and how to reach us<\/a><\/li>\n<li><a href=\"#scope\">Scope of this policy<\/a><\/li>\n<li><a href=\"#legal-basis\">Legal basis for processing<\/a><\/li>\n<li><a href=\"#what-we-collect\">Categories of personal data we collect<\/a><\/li>\n<li><a href=\"#how-we-collect\">How we collect each category<\/a><\/li>\n<li><a href=\"#how-we-use\">Purposes of processing<\/a><\/li>\n<li><a href=\"#processors\">Third-party processors<\/a><\/li>\n<li><a href=\"#sharing\">When we share data and when we do not<\/a><\/li>\n<li><a href=\"#transfers\">International data transfers<\/a><\/li>\n<li><a href=\"#retention\">Retention periods<\/a><\/li>\n<li><a href=\"#security\">Security safeguards<\/a><\/li>\n<li><a href=\"#breach\">Breach notification<\/a><\/li>\n<li><a href=\"#your-rights\">Your rights as a data subject<\/a><\/li>\n<li><a href=\"#how-to-exercise\">How to exercise your rights<\/a><\/li>\n<li><a href=\"#children\">Children and vulnerable persons<\/a><\/li>\n<li><a href=\"#automated\">Automated decisions and profiling<\/a><\/li>\n<li><a href=\"#analytics\">Analytics, cookies and similar tech<\/a><\/li>\n<li><a href=\"#advertising\">Advertising identifiers<\/a><\/li>\n<li><a href=\"#cybdpa\">Zimbabwe CYBDPA compliance<\/a><\/li>\n<li><a href=\"#gdpr\">International alignment<\/a><\/li>\n<li><a href=\"#changes\">Changes to this policy<\/a><\/li>\n<li><a href=\"#contact\">Contact and DPO<\/a><\/li>\n<\/ol><\/div>\n<h2 id=\"summary\">1. Summary for Google Play reviewers<\/h2>\n<p>This section is a faithful, plain-English summary of the full policy below. It is written in the form Google Play reviewers can cross-reference against the Data Safety form submitted in the Play Console. Nothing in this summary overrides the detailed provisions that follow; in the event of any conflict, the substantive text controls.<\/p>\n<ul>\n<li><strong>Who collects the data.<\/strong> STF Capital Private Limited, a private company registered in Zimbabwe. The mobile application is published under Google Play application identifier <code>com.stfcapital.app<\/code>.<\/li>\n<li><strong>What personal data the app collects.<\/strong> Name, surname, email address, telephone number, employer and role, username, optional profile photograph, and the documents a client chooses to upload in support of a financial-services application.<\/li>\n<li><strong>What device data the app collects.<\/strong> A Firebase Cloud Messaging device token (to deliver push notifications) and, where a client enables it, a flag indicating that biometric authentication has been set up on the device.<\/li>\n<li><strong>Where the data lives.<\/strong> Our database and file storage are hosted by Supabase (on Amazon Web Services). Push-token routing is performed by Firebase Cloud Messaging. No personal data is sold, shared with advertising networks, or exposed to third-party analytics providers.<\/li>\n<li><strong>How the data is protected.<\/strong> All traffic is TLS 1.3 encrypted in transit. All stored data is encrypted at rest with AES-256. Session tokens and any PIN hash stored on-device are held inside the Android Keystore.<\/li>\n<li><strong>Your rights.<\/strong> You can, at any time, review your profile data, correct it, request a copy, restrict or object to processing, or request deletion of your account.<\/li>\n<\/ul>\n<h2 id=\"who-we-are\">2. Who we are and how to reach us<\/h2>\n<p>The legal entity responsible for the STF Capital mobile application is <strong>STF Capital Private Limited<\/strong>, a private company limited by shares and registered in Zimbabwe. STF Capital is the &ldquo;data controller&rdquo; for the purposes of the Cyber and Data Protection Act (Chapter 12:07), the Constitution of Zimbabwe (2013) section&nbsp;57 (Right to Privacy) and, where applicable, Article&nbsp;4(7) of the EU General Data Protection Regulation.<\/p>\n<div class=\"stf-callout\">\n<div class=\"stf-callout-label\">Registered office<\/div>\n<p>    STF Capital Private Limited<br \/>\n    Unit 9, 75 Roberts Drive, Msasa, Harare, Zimbabwe<br \/>\n    Telephone: +263&nbsp;242&nbsp;485&nbsp;079<br \/>\n    Email: <a href=\"mailto:inquiries@stfcapital.org\">inquiries@stfcapital.org<\/a><br \/>\n    Website: <a href=\"https:\/\/www.stfcapital.org\">www.stfcapital.org<\/a>\n  <\/div>\n<h2 id=\"scope\">3. Scope of this policy<\/h2>\n<p>This policy applies to the STF Capital mobile application when installed on an Android device from the Google Play Store, or on an iOS device from the Apple App Store, and to any server-side services the application communicates with that are owned or controlled by STF Capital.<\/p>\n<p>This policy <strong>does not<\/strong> apply to:<\/p>\n<ul>\n<li>the STF Capital corporate website at <a href=\"https:\/\/www.stfcapital.org\">stfcapital.org<\/a>, which has its own website privacy notice;<\/li>\n<li>correspondence conducted outside the app (email threads or telephone calls);<\/li>\n<li>services offered by third parties you may elect to link to from the app; or<\/li>\n<li>data handled by your device manufacturer, mobile network operator or Google\/Apple in the normal operation of the device platform.<\/li>\n<\/ul>\n<h2 id=\"legal-basis\">4. Legal basis for processing<\/h2>\n<p>Under section 11 of the Cyber and Data Protection Act, personal data must be processed in a &ldquo;lawful, fair and transparent&rdquo; manner. The legal bases we rely on are:<\/p>\n<div class=\"stf-callout\">\n<div class=\"stf-callout-label\">Bases we rely on<\/div>\n<ul>\n<li><strong>Consent<\/strong> &mdash; you affirmatively tick the Privacy Policy and Terms checkbox during registration and may withdraw consent at any time by deleting your account.<\/li>\n<li><strong>Performance of a contract<\/strong> &mdash; we need your data to assess your application, to underwrite or broker the financial product you request, and to keep you informed about the file.<\/li>\n<li><strong>Legal obligation<\/strong> &mdash; anti-money-laundering, know-your-customer and tax-reporting obligations arising under Zimbabwean statute.<\/li>\n<li><strong>Legitimate interest<\/strong> &mdash; fraud prevention, platform security, customer-support record-keeping and the integrity of our audit logs, which we have balanced against the reasonable expectations of our users.<\/li>\n<\/ul><\/div>\n<h2 id=\"what-we-collect\">5. Categories of personal data we collect<\/h2>\n<p>The STF Capital application collects only the minimum data necessary to deliver the service requested. The following tables enumerate every category of personal data the app is capable of collecting, the specific fields, the on-device path the data flows through, and the authoritative storage location.<\/p>\n<h3>5.1&nbsp;&nbsp;Identity data<\/h3>\n<table class=\"stf-table\">\n<thead>\n<tr>\n<th>Field<\/th>\n<th>Required?<\/th>\n<th>Purpose<\/th>\n<th>Storage<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Given name<\/td>\n<td>Yes<\/td>\n<td>Addressing you correctly in messages and on documents<\/td>\n<td>Supabase <code>public.users<\/code><\/td>\n<\/tr>\n<tr>\n<td>Surname<\/td>\n<td>Yes<\/td>\n<td>Same as above<\/td>\n<td>Supabase <code>public.users<\/code><\/td>\n<\/tr>\n<tr>\n<td>Preferred username<\/td>\n<td>Yes<\/td>\n<td>Display handle in internal communication<\/td>\n<td>Supabase <code>public.users<\/code><\/td>\n<\/tr>\n<tr>\n<td>Role in company<\/td>\n<td>Yes<\/td>\n<td>Routing to the correct advisor; underwriting context<\/td>\n<td>Supabase <code>public.users<\/code><\/td>\n<\/tr>\n<tr>\n<td>Company name<\/td>\n<td>Yes<\/td>\n<td>Underwriting &amp; compliance records<\/td>\n<td>Supabase <code>public.users<\/code>, <code>public.applications<\/code><\/td>\n<\/tr>\n<tr>\n<td>Profile photograph<\/td>\n<td>No (optional)<\/td>\n<td>Personalising the profile screen<\/td>\n<td>Supabase Storage <code>profile-images\/&lt;userId&gt;\/<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>5.2&nbsp;&nbsp;Contact data<\/h3>\n<table class=\"stf-table\">\n<thead>\n<tr>\n<th>Field<\/th>\n<th>Required?<\/th>\n<th>Purpose<\/th>\n<th>Storage<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Email address<\/td>\n<td>Yes<\/td>\n<td>Account identifier, password resets, application-status notifications<\/td>\n<td>Supabase Auth + <code>public.users<\/code><\/td>\n<\/tr>\n<tr>\n<td>Mobile telephone number<\/td>\n<td>Yes<\/td>\n<td>Advisor callbacks, urgent communications<\/td>\n<td>Supabase <code>public.users<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>5.3&nbsp;&nbsp;Application and financial-service data<\/h3>\n<p>Service type, requested products, partner institution, status history, advisor notes, clarification messages, uploaded supporting documents and deal documents produced by STF Capital. Files are validated on-device before upload, limited to 15 MB per file, and accepted types are PDF, PNG, JPG, JPEG, WEBP, DOC, DOCX, XLS, XLSX.<\/p>\n<h3>5.4&nbsp;&nbsp;Account and security data<\/h3>\n<p>Supabase session tokens, optional 6-digit PIN (stored only as a PBKDF2-HMAC-SHA256 hash with a per-install random salt), biometric-enabled flag, failed PIN-attempt counter and last full-login timestamp. All are stored on-device in the Android Keystore and never transmitted.<\/p>\n<h3>5.5&nbsp;&nbsp;Device and technical data<\/h3>\n<p>Firebase Cloud Messaging token, operating system family and version string. We do <strong>not<\/strong> collect IMEI, MAC address, Android ID, SIM card serial, IP geolocation, fine GPS coordinates, SSID of Wi-Fi networks, Bluetooth peripheral lists, installed-app inventory, call history, SMS contents, calendar entries, contact book, microphone audio or keystroke patterns.<\/p>\n<h2 id=\"how-we-collect\">6. How we collect each category<\/h2>\n<ol>\n<li><strong>Directly from you, in the app.<\/strong> During registration, in-app profile edits and application forms, the app asks you to type or upload the fields listed above. You always see the field being collected before you submit it.<\/li>\n<li><strong>Automatically by the platform.<\/strong> The Firebase Cloud Messaging token is generated by Google Play Services on your device and returned to the app through the standard Firebase SDK.<\/li>\n<li><strong>From your action inside STF Capital.<\/strong> When an STF advisor sends you a message or deal document through the internal workflow, that content is written to the application record.<\/li>\n<\/ol>\n<h2 id=\"how-we-use\">7. Purposes of processing<\/h2>\n<ol>\n<li><strong>Service delivery<\/strong> &mdash; creating and operating your STF Capital account, assessing your financial-services application and routing it to the correct internal team.<\/li>\n<li><strong>Communication<\/strong> &mdash; sending you notifications about the status of your application, clarification requests from your advisor and deal documents produced as a result of your application.<\/li>\n<li><strong>Know-Your-Customer and Anti-Money-Laundering<\/strong> &mdash; complying with the Banking Act, the Insurance Act and the Money Laundering and Proceeds of Crime Act of Zimbabwe.<\/li>\n<li><strong>Audit and record-keeping<\/strong> &mdash; creating a contemporaneous, tamper-evident record of who did what and when.<\/li>\n<li><strong>Security<\/strong> &mdash; detecting and preventing unauthorised access, documenting suspicious administrative activity and investigating incidents.<\/li>\n<li><strong>Product improvement<\/strong> &mdash; identifying operational friction, based exclusively on aggregate, de-identified statistics.<\/li>\n<\/ol>\n<p>We do not use personal data for direct marketing or for profiling you for commercial purposes, and we will never sell it.<\/p>\n<h2 id=\"processors\">8. Third-party processors and sub-processors<\/h2>\n<table class=\"stf-table\">\n<thead>\n<tr>\n<th>Processor<\/th>\n<th>Role<\/th>\n<th>Jurisdiction<\/th>\n<th>Data it can see<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Supabase, Inc.<\/td>\n<td>Managed Postgres database, file storage, authentication<\/td>\n<td>United States (on AWS)<\/td>\n<td>All personal data (encrypted at rest)<\/td>\n<\/tr>\n<tr>\n<td>Amazon Web Services, Inc.<\/td>\n<td>Underlying cloud infrastructure<\/td>\n<td>United States \/ Ireland<\/td>\n<td>Encrypted storage volumes only<\/td>\n<\/tr>\n<tr>\n<td>Google LLC &mdash; Firebase Cloud Messaging<\/td>\n<td>Push-notification delivery<\/td>\n<td>Global<\/td>\n<td>FCM token and notification title\/body<\/td>\n<\/tr>\n<tr>\n<td>Google LLC &mdash; Google Play<\/td>\n<td>App distribution and update<\/td>\n<td>Global<\/td>\n<td>Your Google account identifier<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We do not use Firebase Analytics, Firebase Crashlytics, Google Analytics, AdMob or any third-party advertising SDK inside the app.<\/p>\n<h2 id=\"sharing\">9. When we share data and when we do not<\/h2>\n<ul>\n<li><strong>With you.<\/strong> You can always see, export and delete the data in your own account.<\/li>\n<li><strong>With STF Capital staff on a need-to-know basis.<\/strong> Row-Level Security policies in our database enforce this at the query level.<\/li>\n<li><strong>With the partner institution you nominate<\/strong> (POSB, CBZ, Alliance Insurance, etc.) when you submit an application.<\/li>\n<li><strong>With regulators, auditors and courts<\/strong> where required by law.<\/li>\n<li><strong>In connection with a corporate transaction<\/strong> (merger, acquisition) where the acquirer becomes bound by this policy.<\/li>\n<\/ul>\n<p><strong>We do not sell personal data. Ever.<\/strong> We do not provide it to advertising networks, data brokers, social networks or political organisations.<\/p>\n<h2 id=\"transfers\">10. International data transfers<\/h2>\n<p>Because our managed database and notification infrastructure are operated by Supabase and Google respectively, some of your personal data is transferred outside Zimbabwe. Under section 28 of the Cyber and Data Protection Act, such transfers are permitted provided the receiving jurisdiction offers an adequate level of protection or the controller has implemented appropriate safeguards.<\/p>\n<p>Safeguards we rely on include Supabase&rsquo;s data-processing addendum and Standard Contractual Clauses, Google&rsquo;s data-processing terms, TLS 1.3 encryption in transit and AES-256 at rest, and strict data minimisation.<\/p>\n<h2 id=\"retention\">11. Retention periods<\/h2>\n<table class=\"stf-table\">\n<thead>\n<tr>\n<th>Data category<\/th>\n<th>Retention<\/th>\n<th>Basis<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Active account profile<\/td>\n<td>While active + 12 months after deletion<\/td>\n<td>Contract performance &amp; dispute window<\/td>\n<\/tr>\n<tr>\n<td>Submitted applications<\/td>\n<td>7 years from final status change<\/td>\n<td>Banking and insurance statutory record-keeping<\/td>\n<\/tr>\n<tr>\n<td>Uploaded KYC and supporting documents<\/td>\n<td>7 years from date of upload<\/td>\n<td>Anti-money-laundering obligations<\/td>\n<\/tr>\n<tr>\n<td>Security event log<\/td>\n<td>3 years from event date<\/td>\n<td>Audit and forensic investigation<\/td>\n<\/tr>\n<tr>\n<td>Push-notification token<\/td>\n<td>Until rotated or sign-out<\/td>\n<td>Operational necessity<\/td>\n<\/tr>\n<tr>\n<td>On-device session, PIN hash, biometric flag<\/td>\n<td>Until sign-out or uninstall<\/td>\n<td>Under your exclusive control<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"security\">12. Security safeguards<\/h2>\n<h3>12.1&nbsp;&nbsp;In transit<\/h3>\n<ul>\n<li>TLS 1.3 enforced at the Android Network Security Config layer.<\/li>\n<li>Cleartext HTTP blocked. User-added Certificate Authorities not trusted.<\/li>\n<\/ul>\n<h3>12.2&nbsp;&nbsp;At rest on the server<\/h3>\n<ul>\n<li>Database and file storage encrypted at rest with AES-256 by Supabase \/ AWS.<\/li>\n<li>Every table enforces Row-Level Security policies verified at each query.<\/li>\n<li>Uploaded documents served through one-hour signed URLs only.<\/li>\n<\/ul>\n<h3>12.3&nbsp;&nbsp;At rest on your device<\/h3>\n<ul>\n<li>Session tokens, PIN hash and biometric flag inside Android Keystore.<\/li>\n<li>Android Backup disabled (<code>allowBackup=false<\/code>).<\/li>\n<li>PIN hashed with PBKDF2-HMAC-SHA256, 100,000 iterations, per-install salt.<\/li>\n<li>Exponential lockout after five failed PIN attempts (30s &rarr; 1m &rarr; 5m &rarr; 1h).<\/li>\n<\/ul>\n<h2 id=\"breach\">13. Breach notification<\/h2>\n<p>In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:<\/p>\n<ol>\n<li>notify the Postal and Telecommunications Regulatory Authority of Zimbabwe without undue delay and, where feasible, within <strong>72 hours<\/strong>;<\/li>\n<li>notify affected users directly, by email and by in-app banner;<\/li>\n<li>publish a plain-language post-incident summary on stfcapital.org within 30 days.<\/li>\n<\/ol>\n<h2 id=\"your-rights\">14. Your rights as a data subject<\/h2>\n<ul>\n<li><strong>Right of access<\/strong> &mdash; copy of the personal data we hold about you.<\/li>\n<li><strong>Right to rectification<\/strong> &mdash; correct inaccurate data.<\/li>\n<li><strong>Right to erasure<\/strong> &mdash; delete the data we hold about you.<\/li>\n<li><strong>Right to restrict processing<\/strong> &mdash; pause processing during a dispute.<\/li>\n<li><strong>Right to data portability<\/strong> &mdash; structured, machine-readable copy.<\/li>\n<li><strong>Right to object<\/strong> &mdash; to processing based on legitimate interests.<\/li>\n<li><strong>Right not to be subject to solely automated decisions.<\/strong><\/li>\n<li><strong>Right to withdraw consent<\/strong> &mdash; at any time.<\/li>\n<li><strong>Right to lodge a complaint<\/strong> &mdash; with the Data Protection Authority.<\/li>\n<\/ul>\n<h2 id=\"how-to-exercise\">15. How to exercise your rights<\/h2>\n<p>Three equally valid channels, no fee, English \/ Shona \/ Ndebele accepted:<\/p>\n<ol>\n<li><strong>In the app.<\/strong> Open your Profile screen to update details, trigger a password reset, or request account deletion.<\/li>\n<li><strong>By email.<\/strong> <a href=\"mailto:inquiries@stfcapital.org\">inquiries@stfcapital.org<\/a> with subject &ldquo;Data Subject Request&rdquo;.<\/li>\n<li><strong>By post.<\/strong> STF Capital Private Limited, Attn: DPO, Unit 9, 75 Roberts Drive, Msasa, Harare, Zimbabwe.<\/li>\n<\/ol>\n<p>Substantive requests are answered within <strong>30 days<\/strong>, extendable to 60 for complex cases with written notice.<\/p>\n<h2 id=\"children\">16. Children and vulnerable persons<\/h2>\n<p>The app is intended for adults only. You must be at least 18 to register. We do not knowingly collect data from children; if discovered, it is deleted promptly.<\/p>\n<h2 id=\"automated\">17. Automated decisions and profiling<\/h2>\n<p>Underwriting and advisory decisions are always taken by a natural person. No outcome that materially affects you is produced solely by an automated system. You have the right to obtain human intervention, express your point of view and contest any decision.<\/p>\n<h2 id=\"analytics\">18. Analytics, cookies and similar technologies<\/h2>\n<p>The mobile app sets no cookies. No Google Analytics, Firebase Analytics, Crashlytics, Mixpanel, Amplitude, Segment, Hotjar, Fullstory, Sentry, Bugsnag or comparable telemetry. No advertising identifiers, no Facebook Pixel, no TikTok Pixel, no third-party behavioural SDK.<\/p>\n<h2 id=\"advertising\">19. Advertising identifiers and third-party SDKs<\/h2>\n<p>We do not access the Google Advertising ID (AAID) or the iOS IDFA. The only third-party SDKs embedded in the app are listed in our <a href=\"\/open-source\/\">Open Source Attributions<\/a> page.<\/p>\n<h2 id=\"cybdpa\">20. Zimbabwe Cyber and Data Protection Act compliance<\/h2>\n<p>The Cyber and Data Protection Act [Chapter&nbsp;12:07] of 2022 is the controlling data-protection statute in Zimbabwe. Our practices map to its operative provisions:<\/p>\n<table class=\"stf-table\">\n<thead>\n<tr>\n<th>CYBDPA provision<\/th>\n<th>Our practice<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Section 11 &mdash; lawfulness, fairness and transparency<\/td>\n<td>Purposes and bases in \u00a74, \u00a77; fields disclosed in \u00a75 before collection.<\/td>\n<\/tr>\n<tr>\n<td>Section 12 &mdash; purpose limitation<\/td>\n<td>Each field has a single declared purpose; not repurposed for marketing, profiling or sale.<\/td>\n<\/tr>\n<tr>\n<td>Section 13 &mdash; data minimisation<\/td>\n<td>Minimum data needed, set out in \u00a75.<\/td>\n<\/tr>\n<tr>\n<td>Section 14 &mdash; accuracy<\/td>\n<td>Users correct their own data in-app; rectification in \u00a715.<\/td>\n<\/tr>\n<tr>\n<td>Section 15 &mdash; storage limitation<\/td>\n<td>Retention in \u00a711, enforced by automated lifecycle jobs.<\/td>\n<\/tr>\n<tr>\n<td>Section 16 &mdash; integrity and confidentiality<\/td>\n<td>Safeguards in \u00a712.<\/td>\n<\/tr>\n<tr>\n<td>Section 17 &mdash; accountability<\/td>\n<td>This policy, DPIAs and RoPAs available on regulator request.<\/td>\n<\/tr>\n<tr>\n<td>Sections 18&ndash;22 &mdash; data subject rights<\/td>\n<td>\u00a714, \u00a715.<\/td>\n<\/tr>\n<tr>\n<td>Section 23 &mdash; breach notification<\/td>\n<td>72-hour to Authority; direct to users. \u00a713.<\/td>\n<\/tr>\n<tr>\n<td>Section 28 &mdash; international transfers<\/td>\n<td>\u00a710.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"gdpr\">21. International alignment (GDPR \/ OECD)<\/h2>\n<p>For users in the EEA or UK, this policy is read alongside the EU GDPR (Reg. 2016\/679) and retained UK GDPR. We designate our Zimbabwean office as the central contact for Data Subject Access Requests in those territories and answer on the GDPR timetable (one calendar month).<\/p>\n<h2 id=\"changes\">22. Changes to this policy<\/h2>\n<p>We update this policy whenever practices change materially. When we do: the Version\/Effective date fields at the top change, an in-app banner notifies active users, and a plain-language changelog is appended at the bottom of this page.<\/p>\n<h2 id=\"contact\">23. Contact and data protection officer<\/h2>\n<div class=\"stf-callout\">\n<div class=\"stf-callout-label\">Data Protection Officer &mdash; STF Capital<\/div>\n<p>    Attn: The Data Protection Officer<br \/>\n    STF Capital Private Limited<br \/>\n    Unit 9, 75 Roberts Drive, Msasa, Harare, Zimbabwe<br \/>\n    Telephone: +263&nbsp;242&nbsp;485&nbsp;079<br \/>\n    Email: <a href=\"mailto:inquiries@stfcapital.org\">inquiries@stfcapital.org<\/a> (subject: &ldquo;Data Protection&rdquo;)\n  <\/div>\n<p>You may also lodge a complaint with the Data Protection Authority of Zimbabwe, administered under POTRAZ at <a href=\"http:\/\/www.potraz.gov.zw\/\">www.potraz.gov.zw<\/a>.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Document 01 of 04 \u00b7 Privacy Policy The Privacy Policy of the STF Capital mobile application. This document explains, in full, how STF Capital Private Limited (&ldquo;STF Capital&rdquo;, &ldquo;we&rdquo;, &ldquo;us&rdquo;) handles the personal data of anyone who uses the STF Capital mobile application on Android or iOS. It is the controlling record for Google Play &hellip; <\/p>\n<p class=\"more-link-wrap\"><a href=\"https:\/\/stfcapital.org\/index.php\/legal\/privacy-policy\/\" class=\"more-link\"><span>Read More<span class=\"screen-reader-text\"> &#8220;Privacy Policy&#8221;<\/span><\/span><i class=\"opal-icon-arrow-right\" aria-hidden=\"true\"><\/i><\/a><\/p>\n","protected":false},"author":6309,"featured_media":0,"parent":6092,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-6094","page","type-page","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/pages\/6094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/users\/6309"}],"replies":[{"embeddable":true,"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/comments?post=6094"}],"version-history":[{"count":1,"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/pages\/6094\/revisions"}],"predecessor-version":[{"id":6095,"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/pages\/6094\/revisions\/6095"}],"up":[{"embeddable":true,"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/pages\/6092"}],"wp:attachment":[{"href":"https:\/\/stfcapital.org\/index.php\/wp-json\/wp\/v2\/media?parent=6094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}