Privacy Policy

Last updated: 2026-03-08

1. Who We Are

VitalCheck is operated by Mazano Health (Pvt) Ltd, registered in Zimbabwe. We provide biometric health screening services to employers and insurers for occupational wellness monitoring.

Data Protection Officer: dpo@mazano.co.zw

Supervisory Authority: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)

2. What Data We Collect

We collect the following categories of personal data:

CategoryExamples
IdentityEmployee ID, first name
AuthenticationHashed date of birth (SHA-256 — never stored in plain text)
Health (Special Category)Heart rate, blood pressure, SpO₂, breathing rate, stress level, HRV, wellness score
OccupationalDepartment, shift pattern, site location, job risk category
TechnicalDevice type, scan quality score, timestamps

We do not collect facial images, video recordings, GPS location, or browsing history.

3. How We Use Your Data

  • Perform biometric health screening and generate wellness scores
  • Triage results into risk bands (GREEN / AMBER / RED) for clinical review
  • Detect potential comorbidity patterns for early intervention
  • Generate anonymized, k-aggregated reports for employers and insurers
  • Facilitate clinical follow-up for high-risk findings
  • Comply with legal and regulatory obligations

4. Legal Basis for Processing

  • Explicit consent (GDPR Art.6(1)(a) + Art.9(2)(a); Zim DPA § 30) — for health data processing
  • Contract performance (Art.6(1)(b)) — for employer screening services
  • Vital interests (Art.6(1)(d) + Art.9(2)(c)) — for clinical triage escalation
  • Legitimate interests (Art.6(1)(f)) — for aggregated workforce analytics
  • Legal obligation (Art.6(1)(c)) — for audit trails and regulatory compliance

5. How We Protect Your Data

  • AES-256-GCM encryption for sensitive fields at rest
  • TLS 1.3 encryption for all data in transit
  • JWT session tokens with 1-hour expiry
  • Role-based access control (6 role tiers)
  • k-anonymity enforcement (cohorts below 5 are suppressed)
  • Complete audit trail of all data access
  • DOB hashed client-side (SHA-256) before transmission
  • Patient data isolation by organization

6. Your Rights

Under the Zimbabwe DPA 2021 and GDPR, you have the right to:

RightReferenceHow to Exercise
Access your dataArt.15 / § 14Dashboard → Download My Data
Correct your dataArt.16 / § 15Dashboard → Request Correction
Delete your dataArt.17 / § 17Email dpo@mazano.co.zw
Data portabilityArt.20 / § 16Dashboard → Download My Data (JSON)
Withdraw consentArt.7(3) / § 30Email dpo@mazano.co.zw
Lodge a complaintArt.77 / § 23Contact POTRAZ

7. Data Retention

Data TypeRetention Period
Raw scan dataPer organization policy (default: 2 years)
Anonymized aggregates5 years
Audit logs7 years
Deleted employee records90 days (soft delete), then permanently erased

8. Sub-Processors

ProviderPurposeLocation
Binah.aiVital signs SDK (processing only)Israel / EU
ResendTransactional email deliveryUnited States
Database ProviderData storageSADC region (preferred)
VercelApplication hostingUnited States

All sub-processors are bound by Data Processing Agreements with Standard Contractual Clauses for international transfers.

9. International Transfers

Some of our sub-processors are located outside Zimbabwe and the SADC region. International transfers are protected by EU Standard Contractual Clauses (SCCs) and equivalent safeguards recognized under the Zimbabwe DPA 2021.

We prioritize SADC-region data residency where technically feasible.

10. Children’s Data

VitalCheck is designed for adult employees in workplace settings. We do not knowingly collect data from individuals under 18 years of age.

11. Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify POTRAZ within 72 hours of becoming aware (Zim DPA § 22 / GDPR Art.33)
  • Notify affected individuals without undue delay if the breach is HIGH or CRITICAL severity
  • Document all breaches in our incident register regardless of severity

12. Contact Us

Data Protection Officer

Email: dpo@mazano.co.zw

Mazano Health (Pvt) Ltd

Harare, Zimbabwe

Supervisory Authority

Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)

Block 1, Emerald Park, 30 The Chase (West), Mount Pleasant, Harare

www.potraz.gov.zw