Privacy Policy

Home – Privacy Policy

Privacy Policy

National Physicians Association of Zimbabwe (NaPAZ) — Effective date: 1 September 2026

1. Introduction

The National Physicians Association of Zimbabwe (“NaPAZ”, “we”, “us”, “our”) is committed to protecting the privacy and personal information of our members, applicants, event participants, website visitors, and other individuals who interact with us. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights available to you under Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07].

This Policy applies to personal information processed through the NaPAZ website (napaz.org.zw), the NaPAZ member portal, our CPD (Continuing Professional Development) programme, subscription and membership management, events, and any other channel through which NaPAZ collects personal information.

2. Who We Are

Data ControllerNational Physicians Association of Zimbabwe (NaPAZ)
Registered / operating address52 Josiah Chinamano Ave, Harare, Zimbabwe
Websitenapaz.org.zw
General enquiriesinfo@napaz.co.zw
Data protection enquiriesinfo@napaz.co.zw

NaPAZ is the data controller responsible for personal information processed for its own membership, CPD, and administrative purposes as described in this Policy. Where NaPAZ engages third-party service providers to process personal information on our behalf, those providers act as data processors under our instruction.

3. Definitions

  • “Personal information” means any information relating to an identified or identifiable natural person.
  • “Processing” means any operation performed on personal information, including collection, storage, use, disclosure, or deletion.
  • “Data subject” means the individual to whom personal information relates.
  • “Data controller” means the entity that determines the purpose and means of processing personal information (NaPAZ, in most cases).
  • “Data processor” means an entity that processes personal information on behalf of a data controller.
  • “The Act” means the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe.

4. Personal Information We Collect

Depending on how you interact with NaPAZ, we may collect the following categories of personal information:

4.1 Membership and identity information

  • Full name, title, date of birth, national ID or passport number
  • Contact details: physical address, email address, phone number
  • Professional registration details (e.g. Medical and Dental Practitioners Council of Zimbabwe registration number), specialty, and qualifications
  • Employer / practice details

4.2 CPD Portal information

  • CPD activity records, points earned, attendance at accredited events, and certificates
  • Uploaded supporting documents (e.g. attendance proof, certificates)

4.3 Subscription and payment information

  • Membership subscription status and history
  • Billing details and limited payment information (full card/bank details are processed directly by our payment gateway, Paynow, and are not stored by NaPAZ — see Section 7)

4.4 Account and technical information

  • Portal login credentials (username and hashed password)
  • IP address, browser type, device information, and website usage data collected via cookies and Google Analytics (see Section 12)

4.5 Communications

  • Correspondence with NaPAZ (email, contact forms, phone calls) and any information you choose to share in that correspondence

We do not intentionally collect special/sensitive categories of personal information (such as health data about you personally, as opposed to your professional practice of medicine) unless you provide it voluntarily, or it is strictly necessary for a specific purpose (for example, in connection with a complaint or an accommodation request), in which case we will seek your explicit consent where required by the Act.

5. How We Collect Information

  • Directly from you, when you register as a member, log in to the member portal, apply for CPD accreditation, register for an event, subscribe, or contact us
  • Automatically, through cookies and Google Analytics when you use our website or portal
  • From third parties, such as the Medical and Dental Practitioners Council of Zimbabwe or event partners, where relevant to verify professional standing or CPD attendance

Under the Act, we process personal information only where we have a valid legal basis, which may include your consent, performance of a contract (e.g. your membership), compliance with a legal obligation, or our legitimate interests (provided these do not override your rights). The table below summarises our main purposes:

PurposeTypical legal basis
Processing membership applications and renewalsPerformance of a contract / consent
Administering the member portal, dashboard, and profilePerformance of a contract
Recording and verifying CPD activity and pointsPerformance of a contract / legitimate interest (professional standards)
Processing subscription payments via PaynowPerformance of a contract
Sending membership, CPD, and event communicationsLegitimate interest / consent (for marketing-type communications)
Understanding website and portal usage via Google AnalyticsLegitimate interest / consent
Complying with regulatory or statutory requirementsLegal obligation

7. How We Share Information

We do not sell personal information. We share personal information only with the following categories of recipients:

  • Paynow — our payment gateway, used to process membership subscription and other payments. Paynow processes payment details directly; NaPAZ does not store full card or bank details.
  • Google Analytics — used to understand website and portal usage (see Section 12).
  • Professional and regulatory bodies (e.g. the Medical and Dental Practitioners Council of Zimbabwe), where necessary to verify professional standing or CPD compliance
  • Legal and regulatory authorities, where required by law, court order, or to protect NaPAZ’s legal rights

8. Cross-Border Transfers

Some of the third-party services we use (such as Google Analytics) may store or process personal information outside Zimbabwe. Where personal information is transferred outside Zimbabwe, we take steps intended to ensure that the recipient provides an adequate level of protection consistent with the requirements of the Act.

9. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by law:

CategoryRetention period
Active membership and portal account recordsDeleted upon termination of membership
CPD records and certificates1 year
Subscription/payment recordsAs required by applicable tax and financial record-keeping law
Website/portal technical and log data3 months
General correspondence1 year

At the end of the applicable retention period, personal information is securely deleted or anonymised.

10. Data Security

We implement technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction, appropriate to the nature of the information and the risks involved. These measures may include:

  • Access controls and role-based permissions for the member portal and administrative systems
  • Encryption of data in transit (e.g. HTTPS/TLS) and, where appropriate, at rest
  • Secure password storage (hashed, not stored in plain text)
  • Regular monitoring of hosted systems and services
  • Restricting access to personal information to staff and processors who need it to perform their functions

No system can be guaranteed 100% secure. If you have reason to believe your interaction with NaPAZ is no longer secure, please contact us immediately using the details in Section 17.

11. Your Rights as a Data Subject

Subject to the conditions and exceptions set out in the Act, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete personal information
  • Request deletion of your personal information, where it is no longer necessary for the purposes it was collected, or where you withdraw consent and there is no other legal basis for processing
  • Object to or request restriction of certain processing, including direct marketing
  • Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal
  • Data portability, where technically feasible, to receive certain personal information in a structured, commonly used format
  • Lodge a complaint with the relevant supervisory authority (see Section 16)

To exercise any of these rights, please contact us using the details in Section 17. We will respond within a reasonable timeframe and in accordance with the requirements of the Act. We may need to verify your identity before actioning a request.

12. Cookies and Similar Technologies

Our website and member portal use cookies and similar technologies to operate core functionality (such as keeping you logged in), remember preferences, and understand how the site is used. Specifically:

  • Google Analytics — collects information about how visitors use our website (pages visited, time on site, device and browser information) to help us understand and improve the site.
  • Paynow — used only during checkout/payment to securely process subscription payments.

You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the member portal.

13. Children’s Information

The NaPAZ website and member portal are intended for medical professionals and are not directed at children. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take steps to delete it.

14. Data Breach Notification

In the event of a data breach that is likely to result in a risk to the rights and freedoms of affected individuals, NaPAZ will, in accordance with the Act, notify the relevant supervisory authority and, where required, affected data subjects, without undue delay, together with information about the nature of the breach and the steps being taken to address it.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or legal requirements. The “Effective date” at the top of this Policy indicates when it was last revised. Where changes are material, we will take reasonable steps to notify members (for example, by email or a notice on the member portal).

16. Complaints and Supervisory Authority

If you believe NaPAZ has processed your personal information in a way that does not comply with the Cyber and Data Protection Act [Chapter 12:07], you have the right to lodge a complaint with the relevant data protection supervisory authority in Zimbabwe.

17. Contact Us

If you have any questions about this Privacy Policy, or wish to exercise any of your rights, please contact us:

National Physicians Association of Zimbabwe (NaPAZ)
Address: 52 Josiah Chinamano Ave, Harare, Zimbabwe
Email: info@napaz.co.zw
Website: napaz.org.zw
© 2026 National Physicians Association of Zimbabwe. This document has been drafted with reference to the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe.