Privacy Policy

EmpowerBank Limited is committed to protecting personal information and handling it lawfully, fairly, securely and transparently. This Privacy Policy explains how the Bank collects, uses, shares, stores, protects and retains personal information when individuals use its website, mobile applications, digital platforms, products and services.

This policy is written in plain language so that customers, website users, applicants and other stakeholders can understand how personal information is processed and how privacy rights may be exercised.

1. Who We Are

EmpowerBank Limited is a registered deposit-taking microfinance institution operating in Zimbabwe. The Bank processes personal information in line with the Cyber and Data Protection Act [Chapter 12:07], applicable regulatory requirements and, where relevant, the General Data Protection Regulation.

  • Data Protection Officer: Belinda Kubvoruno.
  • Address: 60 West Road, Avondale, Harare, Zimbabwe.
  • Email: dpo@empowerbank.co.zw or info@empowerbank.co.zw.
  • Telephone: +263 867 700 8035.

2. Scope of This Policy

This policy applies to personal information collected and processed through EmpowerBank websites, online forms, mobile applications, branches, contact channels, products and services. It also applies to processing for customer onboarding, loan applications, account administration, transactions, regulatory reporting, customer support, consent-based marketing, fraud prevention and security monitoring.

3. Personal Information We Collect

Depending on the product, service, interaction or legal requirement, EmpowerBank may collect and process:

  • Identification and verification information, including names, national identification or passport details, date of birth, customer number and Know Your Customer information.
  • Contact and communication information, including telephone numbers, email, residential or postal addresses and communication preferences.
  • Financial, credit, account, loan, affordability, repayment and transaction information.
  • Employment, business and income information where required for account opening, credit assessment, loan processing or regulatory compliance.
  • Online and technical information, including IP address, device and browser details, cookies, usage logs and website activity.
  • Customer service, complaint, consent and data subject rights request records.
  • Special categories of personal information, including biometric or health-related information, only where legally permissible, necessary and protected by appropriate safeguards or explicit consent where required.

4. Data Minimisation and Purpose Limitation

EmpowerBank will collect and process only the minimum personal information that is adequate, relevant and necessary for a specified, explicit and lawful purpose. Personal information will not be further processed in a manner that is incompatible with that purpose unless permitted by law and supported by appropriate safeguards.

5. Why We Collect and Use Personal Information

  • Opening, maintaining and managing accounts and banking relationships.
  • Receiving and processing loan, account and service applications.
  • Verifying identity and conducting Know Your Customer checks.
  • Processing transactions, payments, statements and customer instructions.
  • Assessing creditworthiness, managing credit risk and administering loan facilities.
  • Meeting legal, regulatory, tax, audit, reporting and compliance obligations.
  • Detecting, preventing and investigating fraud, financial crime, cyber incidents and misuse of banking services.
  • Providing customer support, responding to enquiries and resolving complaints.
  • Operating and improving websites, digital channels, products, services, internal controls and customer experience.
  • Sending marketing communications where consent has been given or the law otherwise permits.

6. Lawful Basis for Processing

EmpowerBank processes personal information only where a lawful basis applies. Depending on the circumstances, this may include consent, performance of a contract or pre-contractual steps, compliance with a legal or regulatory obligation, legitimate interests that do not unfairly override individual rights, protection of vital interests, or public interest and official authority where applicable.

7. When We Collect Information

EmpowerBank aims to provide privacy information before or at the time personal information is collected. Notice may be provided through website notices, online form statements, application forms, customer agreements, branch notices, emails or this Privacy Policy. Where information is collected electronically, a link to this policy should be available at the point of collection.

8. Sharing Personal Information and Third-Party Transfers

EmpowerBank may share personal information only where there is a lawful and necessary purpose and appropriate safeguards are in place. Recipient categories may include regulators and public authorities, credit reference bureaus, financial institutions, payment and settlement partners, correspondent institutions, approved technology and hosting providers, cybersecurity and communications providers, auditors, legal advisers, insurers, consultants and other contracted service providers.

Service providers processing personal information on behalf of EmpowerBank must be subject to appropriate written contractual, confidentiality, security and data protection obligations. The Bank will perform proportionate due diligence and oversight based on the nature and risk of the processing.

9. Cookies and Tracking Technologies

The EmpowerBank website may use cookies and similar technologies to operate and secure the site, improve functionality, analyse traffic and performance, remember preferences and support approved communications. Non-essential cookies may be accepted, rejected or managed through available cookie controls or browser settings. Essential cookies required for operation and security may remain active where legally permitted.

Before publication, the Bank will verify and disclose the providers and purposes of any analytics, CAPTCHA, embedded maps or videos, chat widgets, social media plugins, marketing pixels or security monitoring scripts in the cookie notice or this policy, as applicable.

10. Cross-Border Transfers

Where personal information is transferred outside Zimbabwe, EmpowerBank will identify the purpose, recipient, destination, categories of information and applicable safeguards before the transfer. The Bank will assess legal and regulatory requirements, recipient protections, security measures and contractual controls, and will obtain consent or regulatory approval where required.

EmpowerBank uses service arrangements that may involve processing or hosting in the European Union, including the Mambu core banking platform and Microsoft 365 services. These arrangements are subject to appropriate contractual, technical and organisational safeguards, access controls and supplier oversight.

11. Retention and Secure Disposal

EmpowerBank retains personal information only for as long as necessary for the purpose for which it was collected and to meet applicable legal, regulatory, contractual, audit, dispute resolution and operational requirements. Retention periods will be defined and documented in approved records and retention schedules.

When personal information is no longer required and is not subject to a legal hold or approved archive requirement, it will be securely deleted, destroyed, anonymised or otherwise disposed of in accordance with the Retention and Disposal of Records Policy and approved procedures. Destruction must be secure and irreversible, and evidence will be retained where required.

12. Where and How Personal Information Is Stored

Personal information may be stored in secure systems operated by EmpowerBank or approved service providers supporting banking, digital services, records management, hosting, security, communications and operational functions. Access is limited to authorised persons and providers with a legitimate need. Appropriate contractual, technical and organisational safeguards apply to provider-hosted processing and storage.

13. How We Protect Personal Information

EmpowerBank applies proportionate technical, organisational, administrative and physical safeguards against unauthorised access, loss, misuse, alteration, disclosure or destruction. Measures may include encryption or secure handling, HTTPS or other secure transmission, access controls, authentication, privilege management, firewalls, anti-malware, monitoring, backup and recovery, staff confidentiality, awareness, training, secure disposal, incident response and breach management.

14. Privacy Risk Management and Data Protection Impact Assessments

EmpowerBank will identify, assess, record, treat and monitor privacy risks arising from personal information processing. Material risks must have an assigned owner, documented treatment, target dates and proportionate controls, and must be escalated through approved risk and governance processes where necessary.

A Data Protection Impact Assessment must be completed before processing that is likely to create a high risk to the rights and interests of individuals. This includes new or materially changed technologies, extensive profiling or automated decision-making, large-scale or sensitive-data processing, systematic monitoring, significant data matching, or other processing identified as high risk. The assessment must document necessity and proportionality, risks, safeguards, approvals and residual risk before implementation.

15. Your Privacy Rights

Subject to applicable law, individuals may exercise the following rights:

  • The right to be informed about the collection and use of personal information.
  • The right to request access to personal information and receive a copy where legally permitted.
  • The right to request correction of inaccurate or incomplete information.
  • The right to request erasure where legally permitted.
  • The right to request restriction of processing in appropriate circumstances.
  • The right to object to processing in appropriate circumstances.
  • The right to withdraw consent where processing is based on consent.
  • The right to data portability where applicable.
  • Rights relating to automated decision-making and profiling, including requesting human intervention, expressing a point of view and contesting a qualifying decision where permitted by law.
  • The right to lodge a complaint with the relevant data protection authority.

16. How to Exercise Privacy Rights

Requests may be submitted to the Data Protection Officer through the contact details in section 1. EmpowerBank may verify identity and request reasonable clarification before processing a request. Requests will be handled in a concise, transparent, intelligible and accessible manner, normally free of charge unless the law permits otherwise.

EmpowerBank aims to provide the requested information within 14 calendar days where the request is valid, verified and straightforward. The maximum internal completion period is 30 calendar days from receipt of a valid and verified request. Where completion within 14 days is not possible, the requester will be updated, the reason will be documented and the due date will be monitored through the Data Subject Access Request Register.

The detailed steps, responsibilities, verification controls, exemptions, redactions, response methods and recordkeeping requirements are contained in the approved Data Subject Access Request Procedure, request form and register.

17. Withdrawal of Consent

Where processing is based on consent, consent may be withdrawn at any time by contacting the Data Protection Officer, emailing dpo@empowerbank.co.zw or info@empowerbank.co.zw, or using an available unsubscribe or preference-management option. Withdrawal does not affect processing lawfully carried out before the request.

18. Marketing and Communications

EmpowerBank may send promotional messages, product information or offers where consent has been given or the law otherwise permits. Individuals may opt out at any time through an unsubscribe option, by updating communication preferences, or by contacting the Data Protection Officer. Service and regulatory communications may still be sent where necessary.

19. Automated Decision-Making and Profiling

EmpowerBank may use automated systems for credit scoring, fraud prevention, service personalisation, risk assessment or security monitoring. Where an automated decision produces a significant effect, EmpowerBank will provide meaningful information about the relevant processing where required and will support available rights to human intervention, expression of a point of view and contesting the decision.

20. Reporting Privacy Concerns, Complaints and Data Breaches

A person who believes personal information has been misused, accessed without authorisation, improperly disclosed, lost, altered or processed unlawfully may report the matter to the Data Protection Officer using the contact details in section 1. EmpowerBank will record, assess, investigate and resolve the matter under approved incident response, complaint-handling and breach notification procedures.

Where a personal data breach is confirmed, EmpowerBank will contain and investigate the breach, assess its nature and likely impact, preserve evidence, implement corrective action, maintain an incident record and make notifications required by law or applicable regulatory directives. POTRAZ will be notified within 24 hours, RBZ within 3 hours, and affected data subjects within 72 hours where the incident has a high impact, subject to the applicable legal and regulatory notification requirements.

The policy establishes the notification obligation. Detailed roles, escalation paths, report content, communications, evidence handling and closure requirements are contained in the Incident Response Procedure and Data Breach Notification Procedure.

21. Transparency and Accountability

EmpowerBank may publish or provide appropriately aggregated transparency information about processing practices, regulatory requests, third-party sharing, cross-border transfers, data subject requests, privacy incidents, training, audits and control improvements. Public reporting will not disclose personal, confidential or security-sensitive information.

22. Governance, Training and Compliance

The Data Protection Officer oversees implementation of this policy, supports compliance monitoring and advises on privacy risks and impact assessments. Heads of Department and information owners are responsible for lawful processing, data minimisation, access control, retention, incident reporting and implementation of corrective actions within their areas. All employees and relevant contractors must complete required data protection awareness and comply with the policy and supporting procedures.

23. Changes to This Privacy Policy

This Privacy Policy may be updated to reflect changes in law, regulation, technology, website functionality, products, services or business practices. The current version will be published on the EmpowerBank website and will state its effective date.

24. Contact Us

Questions, requests, complaints or concerns about this Privacy Policy or EmpowerBank processing of personal information may be directed to:

  • Data Protection Officer, EmpowerBank Limited.
  • 60 West Road, Avondale, Harare, Zimbabwe.
  • Email: dpo@empowerbank.co.zw or info@empowerbank.co.zw.
  • Telephone: +263 867 700 8035.

25. Related Documents

  • Data Subject Access Request Procedure, Request Form and Register.
  • Incident Response Procedure.
  • Data Breach Notification Procedure.
  • Retention and Disposal of Records Policy.
  • Data Protection Impact Assessment methodology or template.
  • Information Security and relevant access control policies.