Home – Privacy Policy
National Physicians Association of Zimbabwe (NaPAZ) — Effective date: 1 September 2026
The National Physicians Association of Zimbabwe (“NaPAZ”, “we”, “us”, “our”) is committed to protecting the privacy and personal information of our members, applicants, event participants, website visitors, and other individuals who interact with us. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights available to you under Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07].
This Policy applies to personal information processed through the NaPAZ website (napaz.org.zw), the NaPAZ member portal, our CPD (Continuing Professional Development) programme, subscription and membership management, events, and any other channel through which NaPAZ collects personal information.
| Data Controller | National Physicians Association of Zimbabwe (NaPAZ) |
|---|---|
| Registered / operating address | 52 Josiah Chinamano Ave, Harare, Zimbabwe |
| Website | napaz.org.zw |
| General enquiries | info@napaz.co.zw |
| Data protection enquiries | info@napaz.co.zw |
NaPAZ is the data controller responsible for personal information processed for its own membership, CPD, and administrative purposes as described in this Policy. Where NaPAZ engages third-party service providers to process personal information on our behalf, those providers act as data processors under our instruction.
Depending on how you interact with NaPAZ, we may collect the following categories of personal information:
We do not intentionally collect special/sensitive categories of personal information (such as health data about you personally, as opposed to your professional practice of medicine) unless you provide it voluntarily, or it is strictly necessary for a specific purpose (for example, in connection with a complaint or an accommodation request), in which case we will seek your explicit consent where required by the Act.
Under the Act, we process personal information only where we have a valid legal basis, which may include your consent, performance of a contract (e.g. your membership), compliance with a legal obligation, or our legitimate interests (provided these do not override your rights). The table below summarises our main purposes:
| Purpose | Typical legal basis |
|---|---|
| Processing membership applications and renewals | Performance of a contract / consent |
| Administering the member portal, dashboard, and profile | Performance of a contract |
| Recording and verifying CPD activity and points | Performance of a contract / legitimate interest (professional standards) |
| Processing subscription payments via Paynow | Performance of a contract |
| Sending membership, CPD, and event communications | Legitimate interest / consent (for marketing-type communications) |
| Understanding website and portal usage via Google Analytics | Legitimate interest / consent |
| Complying with regulatory or statutory requirements | Legal obligation |
We do not sell personal information. We share personal information only with the following categories of recipients:
Some of the third-party services we use (such as Google Analytics) may store or process personal information outside Zimbabwe. Where personal information is transferred outside Zimbabwe, we take steps intended to ensure that the recipient provides an adequate level of protection consistent with the requirements of the Act.
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by law:
| Category | Retention period |
|---|---|
| Active membership and portal account records | Deleted upon termination of membership |
| CPD records and certificates | 1 year |
| Subscription/payment records | As required by applicable tax and financial record-keeping law |
| Website/portal technical and log data | 3 months |
| General correspondence | 1 year |
At the end of the applicable retention period, personal information is securely deleted or anonymised.
We implement technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction, appropriate to the nature of the information and the risks involved. These measures may include:
No system can be guaranteed 100% secure. If you have reason to believe your interaction with NaPAZ is no longer secure, please contact us immediately using the details in Section 17.
Subject to the conditions and exceptions set out in the Act, you have the right to:
To exercise any of these rights, please contact us using the details in Section 17. We will respond within a reasonable timeframe and in accordance with the requirements of the Act. We may need to verify your identity before actioning a request.
Our website and member portal use cookies and similar technologies to operate core functionality (such as keeping you logged in), remember preferences, and understand how the site is used. Specifically:
You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the member portal.
The NaPAZ website and member portal are intended for medical professionals and are not directed at children. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take steps to delete it.
In the event of a data breach that is likely to result in a risk to the rights and freedoms of affected individuals, NaPAZ will, in accordance with the Act, notify the relevant supervisory authority and, where required, affected data subjects, without undue delay, together with information about the nature of the breach and the steps being taken to address it.
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or legal requirements. The “Effective date” at the top of this Policy indicates when it was last revised. Where changes are material, we will take reasonable steps to notify members (for example, by email or a notice on the member portal).
If you believe NaPAZ has processed your personal information in a way that does not comply with the Cyber and Data Protection Act [Chapter 12:07], you have the right to lodge a complaint with the relevant data protection supervisory authority in Zimbabwe.
If you have any questions about this Privacy Policy, or wish to exercise any of your rights, please contact us: