Skip to content
SilverconneTechnologies

LEGAL

Privacy policy

This policy explains what personal information we collect when you use this site or become a client, what we do with it, how long we keep it, and how you get a copy or have it deleted.

1. Who is responsible for your information

Data controller
Silverconne Technologies (Pvt) Ltd
Contact for privacy matters
Data Protection Officer (appointment pending)
Email
privacy@silverconne.com
Address
Harare, Zimbabwe

The data protection officer named above is an appointment we are in the process of making. Until it is made, privacy requests go to the email address above and are handled by a director.

2. What we collect, and when

Information we hold about you
WhenWhat we collectWhy we need it
You send an enquiry, book a call or configure a websiteName, email address, WhatsApp or phone number, company, and what you wroteTo reply, and to prepare something useful before we speak
You place an orderBilling contact details, company details, tax identifiers where required on an invoiceTo issue a compliant invoice and take payment
You payThe payment reference, method, amount and status. We never see or store your card number or wallet PINTo confirm payment and to reconcile it
You become a clientThe information in your project, including data you upload to the portalTo deliver and support what you bought
You use the assistant on this siteThe conversation, and a session identifierTo answer, and to review answer quality afterwards
You browse the sitePage views and events, with a random identifier stored in your browser. No nameTo see which pages help and which do not
You apply for a roleYour CV and what you sent with itTo assess the application

3. What we use it for

  • Answering you, quoting, and delivering what you bought.
  • Invoicing, taking payment, and keeping the accounting records we are required to keep.
  • Supporting the system you run, including responding to a ticket or a WhatsApp message.
  • Sending you information about your own order, project or booking. These are not marketing and you cannot unsubscribe from them while the engagement is live.
  • Sending you our newsletter, only if you asked for it, with an unsubscribe link in every message.
  • Improving the site and our products, using aggregated analytics rather than individual behaviour.

We do not use your information to make an automated decision that affects you, and we do not profile you for advertising.

4. Who else processes it

We use a small number of service providers to run the business. Each processes information on our instructions and for no other purpose. The categories are:

  • Hosting and database — the infrastructure this site and your portal run on.
  • Email delivery — sending invoices, confirmations and replies.
  • Payment gateway — taking your payment. They hold the payment details; we hold the reference.
  • Analytics — counting page views and conversion events.
  • Error monitoring — recording faults so we can fix them.
  • AI model provider — generating the assistant’s answers from the question and our own published content.

We will name each provider on request. We do not sell your information, and we do not share it with anyone for their own marketing.

5. Where it is stored

Our infrastructure is managed hosting, and some of it sits outside Zimbabwe. We will tell you the exact region in writing before you sign anything, and we will tell you if it changes. If your organisation has a requirement about where its data may be held, raise it during scoping rather than after go-live — it is a solvable constraint if we know about it early.

6. How long we keep it

We keep information for as long as it is needed for the purpose it was collected for, and then for as long as we are required to keep records. In practice:

Retention schedule
WhatHow long we keep itWhy
Enquiry and lead records24 months from the last contactSo we know what was discussed if you come back to us
Quotes and orders7 years from the date of the documentAccounting and tax record-keeping
Invoices, receipts and payment records7 years from the date of the documentAccounting and tax record-keeping
Client project files and documentsThe life of the engagement, then 3 yearsSupport, warranty and reference
Support tickets and their messages3 years from closureRecurring-fault history and service review
Assistant conversation transcripts12 monthsQuality review and abuse investigation
Website analytics events14 monthsUnderstanding which pages work. No name attached
Newsletter subscriptionUntil you unsubscribe, then 12 monthsTo honour the unsubscribe if a list is re-imported
Job applications12 months from the decision, unless you ask us to keep it longerFuture roles and our own hiring record
Backups35 days rollingRecovery. A deletion request is applied to live data immediately and works through backups within this window

Where a retention period is driven by accounting or tax record-keeping, we cannot delete the record on request until that period has run. We will say so, and we will tell you when it expires.

7. Your rights, and how to use them

You can ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it, or object to a particular use of it.

  1. 01If you have a portal accountRequest an export or a deletion from your account settings in the portal. The request is logged and tracked, so you can see its status rather than wondering whether an email arrived.
  2. 02If you do notEmail privacy@silverconne.com and tell us what you want. We may ask you to confirm who you are, because handing your information to somebody else would be the worse failure.
  3. 03What happens thenWe acknowledge within 5 business days and complete the request within 30 days. If we cannot delete something because we are required to keep it, we tell you which record and why.

You can also complain to the supervisory authority responsible for data protection in Zimbabwe. We would rather you came to us first, but you are not required to.

8. How we protect it

  • Encryption in transit, and at rest on our managed infrastructure.
  • Row-level access control in the database, so one client cannot read another client’s records even through a fault in our application.
  • Uploaded documents held in a private store and served only through short-lived signed links.
  • Two-factor authentication required on staff accounts.
  • Access on a need-to-know basis, and removed the day someone leaves.
  • An audit record of who changed what.

No system is beyond compromise. If a breach affects your information we will tell you what happened, what it affects and what we are doing, without waiting until we have a complete picture.

9. Cookies and analytics

This site does not use advertising cookies and does not carry third-party advertising trackers. We store a random identifier in your browser so repeated visits can be counted as one visitor, and we record page views and conversion events against it. It is not linked to your name unless you have signed in.

Blocking it in your browser is fine and nothing on the site depends on it.

10. Children

This site is for businesses and we do not knowingly collect information from children. Our school product holds pupil information, but the school is the controller of it and we process it on the school’s instructions under the agreement we have with them.

11. Changes to this policy

When we change this page we change the dates at the top of it. If a change materially affects what we do with your information, we will tell clients directly rather than relying on you noticing.

Questions about this policy

Ask, and a person will answer. A privacy question is not a support ticket and does not go into a queue.