Official Website: www.nashfurnishers.co.zw
1. Welcome & Introduction
At Nash Furnishers (“NASH”, “we”, “us”, or “our”), we respect your privacy and are committed to protecting the personal information you provide to us. Nash Furnishers operates a retail business with physical branches and an online shopping website through which customers can browse products, create or use customer accounts, add products to a Cart or Wishlist, make enquiries, and place orders. We collect and process personal information when you visit our website, register or log in, make enquiries, purchase our products, place an order, arrange delivery or collection, or otherwise interact with us.
This Privacy Notice explains what personal information we collect, why we process it, how we may share it, and the measures we take to protect it. We handle personal information in accordance with Zimbabwe’s Cyber and Data Protection Act [Chapter 12:07] and the Cyber and Data Protection Regulations, 2024 (SI 155), as applicable.
2. Who We Are & How to Reach Us
Nash Furnishers is responsible for the processing of personal information collected through our website, customer interactions, and ordering processes. We have appointed Convex Solution as our Data Protection Officer (DPO) to assist with data protection and privacy matters.
Contact Information
· Physical Address: 41 Kelvin North Road, Graniteside, Harare, Zimbabwe
· Email Address: marketing@nashfurnishers.co.zw
· Phone Number: +263 781201201 | +263 786241709
Data Protection Officer (DPO)
· Name: Luke Fata – Convex Cybersecurity
· Email: dpo@convexcybersecurity.com
· Phone / Mobile: +263 772427273
Regulatory Authority
· Data Protection Authority: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
3. What Personal Information We Collect
The information we collect depends on how you interact with Nash Furnishers. Depending on the service or transaction, this may include:
· Name and surname.
· Phone number and email address.
· Physical address, including delivery or collection details where applicable.
· National identity (ID) number and passport number where required for identity verification or a specific service.
· Gender and, where necessary for a particular service or lawful verification process, other identity details you provide.
· Order and transaction information, including products purchased, order details, delivery or collection details, and relevant payment or refund information.
· Information you provide when you register for an account, create a wishlist, submit an enquiry, or communicate with us.
· Technical and website information, such as IP address, browser/device information, pages visited, cookies, and other information generated through use of our website.
4. How We Collect Your Information
We may collect personal information directly from you when you:
· Place an order or check out on our website.
· Provide information requested during the checkout process.
· Make an enquiry or contact us.
· Register as a customer or otherwise interact with our services.
We may also receive information from service providers or other parties where this is necessary for the operation of our services and permitted by law.
We may also receive relevant information from payment, delivery, technology, or other service providers where this is necessary to provide our services and permitted by law.
5. Why We Process Data
We process your personal information for the following purposes:
· For the sole purposes of registering and managing your order.
· Verifying your identity where necessary.
· Communicating with you about your order, delivery, collection, or customer enquiries.
· Maintaining the security and proper operation of our website, systems, and services.
· Meeting applicable legal and regulatory requirements.
· Communicating important updates, service information, and order-related information.
· Securing and optimising our website, systems, and customer services.
6. Legal Basis for Processing
Where applicable, we rely on the following legal bases for processing personal information:
· Consent: Where you have voluntarily provided consent for a specified processing activity. Where the law permits, you may withdraw consent for processing based on consent.
· Legitimate Interests: Where processing is necessary for legitimate business interests, such as managing orders, maintaining website and systems security, preventing misuse or fraud, and improving our services, provided those interests are not overridden by your rights and interests.
7. Sharing Your Data
We do not sell your personal information. Where necessary and permitted by law, we may share relevant information with trusted parties on a need-to-know basis, including:
· IT and systems service providers that support our website, systems, hosting, security, or related services.
· Regulators and law enforcement authorities where disclosure is required or permitted by law.
· Professional advisers, including external auditors, where reasonably necessary for our business, compliance, or legal obligations.
8. International Data Transfers
If personal information is transferred outside Zimbabwe (for example, through a cloud, hosting, payment, or other technology provider), we will take appropriate steps to ensure that the transfer is handled in accordance with applicable data protection requirements. Where required, appropriate legal safeguards will be put in place, including ensuring equivalent protection or obtaining consent where applicable.
9. Keeping Your Data Safe & Retention
We use reasonable physical, technical, and organisational safeguards to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure.
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to manage orders and customer relationships, to meet legal or regulatory requirements, and to resolve disputes or enforce our rights.
In the event of a personal information security breach, we will take appropriate steps to contain, investigate, and notify the relevant authorities and affected individuals where required by law.
10. Cookies & Website Analytics
Our website may use cookies and similar technologies to support website functionality, improve the browsing experience, and understand website usage. You may manage cookies through your browser settings, although disabling certain cookies may affect some website functionality.
11. Your Data Protection Rights
Subject to applicable law, you may have the right to:
· Access the personal information we hold about you.
· Request correction of inaccurate or incomplete information.
· Request deletion of personal information where it is no longer required or where applicable by law.
· Object to or request restriction of certain processing activities.
· Withdraw consent where processing is based on consent.
· Raise a privacy complaint with our DPO or the relevant regulator.
To exercise your rights, please contact our Data Protection Officer using the contact details provided above. We may need to verify your identity before responding to a request.
12. Complaints & Dispute Resolution
If you believe your personal information has been handled improperly, please contact our DPO first so that we can investigate and address your concern. Where you remain dissatisfied, you may lodge a complaint with the relevant regulatory authority.
Regulator: Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
Toll-Free Phone: 08004303
Website: www.potraz.gov.zw
13. Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our services, systems, business practices, or applicable legal and regulatory requirements. The latest version will be made available through our website and will show the applicable review date.
Annex A: Legal Compliance Checklist
This Annex provides a compliance mapping between the Nash Furnishers Website & Data Privacy Notice and the applicable requirements of the Cyber and Data Protection Act [Chapter 12:07] (CDPA) and the Cyber and Data Protection Regulations, 2024 (S.I. 155).
The Annex is intended to demonstrate where the principal privacy and data protection requirements are addressed within the Privacy Notice.
|
Requirement |
Statutory Basis (CDPA / S.I. 155) |
Addressed In |
|
Lawfulness, Fairness & Transparency |
CDPA Principles; applicable provisions relating to lawful and transparent processing |
Sections 1, 5, 6 and 11 – Introduction, processing purposes, legal bases and data subject rights |
|
Purpose Limitation |
CDPA Principles; applicable provisions relating to specified and legitimate purposes |
Sections 3, 5 and 6 – Information collected, checkout information and purposes of processing |
|
Data Quality, Accuracy & Retention |
CDPA / S.I. 155 requirements relating to data quality, minimisation and retention |
Sections 3 and 9 – Information collected, data security and retention |
|
Data Controller Registration / Licensing |
S.I. 155 – applicable registration/licensing requirements for data controllers |
Section 2 and supporting compliance records – Identification of Nash Furnishers as the organisation responsible for processing personal information |
|
Appointment of Data Protection Officer (DPO) |
CDPA / S.I. 155 requirements concerning the appointment and functions of a DPO |
Section 2 – Appointment and contact details of the Data Protection Officer |
|
Sensitive / Special Personal Information Safeguards |
CDPA / S.I. 155 requirements concerning sensitive or special categories of personal information |
Sections 3, 6 and 9 – Collection limitations, lawful processing and security safeguards |
|
Children’s Data Safeguards |
CDPA / S.I. 155 requirements concerning processing of children’s personal information |
Sections 3, 6 and 11 – Collection, lawful processing and rights; additional safeguards apply where children’s data is processed |
|
Cross-Border Data Transfer Rules |
CDPA requirements concerning transfers of personal information outside Zimbabwe |
Section 8 – International Data Transfers and appropriate legal safeguards |
|
Data Subject Rights |
CDPA provisions concerning rights of data subjects |
Section 11 – Access, correction, deletion, objection, restriction and withdrawal of consent, subject to applicable law |
|
Breach Notification Protocol |
CDPA / S.I. 155 requirements concerning personal information security breaches |
Section 9 – Breach containment, investigation and notification to relevant authorities and affected individuals where required |
|
Third-Party / Data Processor Controls |
CDPA / S.I. 155 requirements concerning processing by third parties and service providers |
Section 7 – Sharing of information with IT providers, professional advisers, regulators and other authorised parties |
|
Information Security |
CDPA / S.I. 155 requirements relating to appropriate technical and organisational security measures |
Section 9 – Physical, technical and organisational safeguards |
|
Cookies & Website Technologies |
Applicable CDPA transparency, lawful-processing and security principles |
Section 10 – Cookies and website analytics |
|
Complaints and Regulatory Oversight |
CDPA / S.I. 155 provisions relating to complaints and regulatory oversight |
Section 12 – Internal complaint process and escalation to POTRAZ |
|
Privacy Notice Updates |
CDPA transparency and accountability principles |
Section 13 – Changes to the Privacy Notice and publication of the latest review date |