1. Who we are
Wellock Security (Private) Limited (trading as Wellock Security) is responsible for the personal information processed through the website at www.wellocksecurity.co.zw and the applications and services listed in the “Applications covered” section below.
- Legal entity
- Wellock Security (Private) Limited
- Privacy contact
- info@wellocksecurity.co.zw
Telephone: 086-777-197-462
2. Scope of this policy
This policy applies to personal information we process through:
- our website at www.wellocksecurity.co.zw, including its contact, support and privacy-request forms;
- the mobile applications listed under “Applications covered”;
- our client web portal, where it is listed under “Applications covered”;
- our support and privacy-request channels; and
- related digital services we provide to our clients and their authorised staff.
Where you use our services through your employer or a corporate client of ours, that organisation may also have its own responsibilities for your information under its own policies.
3. Applications covered
At the date of this version, this policy describes the processing that takes place through our website and its forms. Each of our applications is added to this section, with a description of the information it processes, once its data profile has been confirmed. Until an application is listed here, please contact us at info@wellocksecurity.co.zw for information about that application.
4. Information we process
We only process the categories of information listed below. Each item is tied to a specific feature and purpose.
| Feature | Information | Source |
|---|---|---|
| Contact / "Initiate Security Protocol" inquiry form | Full name; company name; telephone number; email address; business type; services of interest; free-text message | Directly from the visitor |
| Privacy Choices, Account & Data Deletion and App Support request forms | Full name; email address and/or telephone number; organisation (optional); user ID (optional); application concerned; request type; description you provide | Directly from the requester |
| Web server access and error logs | IP address; browser/device information; pages requested; date and time | Automatically from your browser |
| Form abuse protection (rate limiting) | One-way hash of your IP address (not the address itself), kept for a short period | Automatically from your connection |
| Web fonts and images delivered by third-party content networks | IP address; browser information (sent to the provider when the font/image is fetched) | Automatically from your browser |
| WordPress administrator accounts | Staff name; email; login credentials (hashed); login cookies | From Wellock staff |
5. Sensitive information
Our website does not ask for, and is not designed to process, sensitive personal information such as biometric, genetic, health, religious, political, sexual-life or criminal-history information. Please do not include such information in free-text fields. If any covered application processes a sensitive category, it will be described separately in that application’s entry above.
6. How we collect information
We collect information:
- directly from you, when you complete a form, contact us or use a service;
- from an authorised corporate client or employer that sets up access for you;
- during account setup or an operational transaction, where a covered application provides these;
- automatically from your browser or device (for example, your IP address in our web server logs, or when your browser fetches web fonts and images);
- from customer-support correspondence; and
- from approved third parties where this is described in this policy.
7. Why we use information
We use each item of information only for the purpose it was collected for:
| Feature | Purpose |
|---|---|
| Contact / "Initiate Security Protocol" inquiry form | Respond to your inquiry and design a proposal |
| Privacy Choices, Account & Data Deletion and App Support request forms | Receive, verify and respond to privacy, deletion and support requests |
| Web server access and error logs | Security, abuse prevention and diagnosing technical problems |
| Form abuse protection (rate limiting) | Prevent automated abuse of our forms |
| Web fonts and images delivered by third-party content networks | Display the website correctly |
| WordPress administrator accounts | Administer the website |
We may also use information where necessary to prevent fraud or abuse, to handle disputes and complaints, to keep audit records, and to meet legal and regulatory obligations.
8. Authority and basis for processing
We do not rely on one universal ground for all processing. Our basis for each processing activity is:
| Feature | Basis |
|---|---|
| Contact / "Initiate Security Protocol" inquiry form | Steps taken at your request before entering a contract; your consent given by submitting the form |
| Privacy Choices, Account & Data Deletion and App Support request forms | Legal obligation (data-subject rights); performance of our service to you |
| Web server access and error logs | Our legitimate need to secure and operate the website |
| Form abuse protection (rate limiting) | Our legitimate need to secure the website |
| Web fonts and images delivered by third-party content networks | Our legitimate need to operate the website |
| WordPress administrator accounts | Employment / contractual relationship with staff |
Where we rely on your consent, you may withdraw it as described in the “Consent” section. Where we process information to perform a contract or comply with the law, that processing may continue for as long as those obligations apply.
9. Consent
When you submit a form on our website, you are consenting to us using the information in that form for the purpose stated next to the form. We record your consent as part of the stored form record, together with the date and time of submission.
You may withdraw consent at any time by contacting info@wellocksecurity.co.zw or using Privacy Choices. Withdrawing consent does not affect processing that already took place, and may mean we are unable to respond to your inquiry or request. We never bundle optional marketing consent into acceptance of a service.
11. International and cross-border processing
Some authorised service providers may process information outside Zimbabwe. Where this occurs, we assess and manage the transfer in accordance with applicable Zimbabwean data-protection requirements.
Our current service-provider register indicates that the following categories involve processing outside Zimbabwe: email delivery provider; font and image delivery (content delivery networks).
12. Data security
We protect information using measures that include:
- encrypted HTTPS transport for all connections to our website;
- access controls and role-based permissions for staff who administer the website;
- authentication controls on administrative access;
- protection of our forms against forged and automated submissions;
- storing form submissions in a private area that is not publicly accessible;
- security logging on our web server; and
- an internal incident-response procedure for suspected security breaches.
No method of transmission or storage is completely secure, and we do not claim that our systems are immune from every risk. If we become aware of a security breach affecting your information, we will act in accordance with our incident procedure and our obligations under the Cyber and Data Protection Act.
13. Retention
We retain personal information only for as long as necessary for the purpose for which it was collected and for any additional period required by applicable legal, regulatory, security, audit, fraud-prevention or contractual obligations.
Specific retention periods for each category are set out in our internal retention schedule and are published here once approved. You may ask us about the retention period that applies to your information through Privacy Choices.
Where a legal hold or a legal, regulatory, financial, audit, security or fraud-prevention requirement applies, we may keep specific records for longer, with access restricted to what that requirement justifies.
14. Account deletion
If you hold an account in one of our applications, you may ask us to delete it and the personal information associated with it. To start:
- use the deletion option inside the application, where the application provides one; or
- submit a request through our Account & Data Deletion page, without needing to reinstall the application.
Before deleting anything we verify that the request comes from the account holder or someone authorised to act for them. Once verified, we delete or anonymise the account and its eligible personal data, remove the account from our applicable service providers, revoke active sessions and close the account.
Some records may need to be retained where required for legal, regulatory, financial, audit, security, fraud-prevention or dispute-management purposes. Where retention is required, access will remain restricted and the retained information will not be kept longer than justified by the applicable requirement. We will tell you if any information is retained and why. We will communicate with you using the contact details you provide, and we will confirm completion once the process is finished.
15. Your data-subject rights
Subject to the conditions in the Cyber and Data Protection Act, you have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- object to processing where the Act allows;
- request deletion of information where the Act allows;
- withdraw consent where processing is based on consent; and
- make a privacy enquiry or complaint.
You can exercise any of these through Privacy Choices or by emailing info@wellocksecurity.co.zw. We may need to verify your identity before acting on a request, and we will respond within the time allowed by law.
16. Automated decision-making
Our website does not make any decision about you based solely on automated processing that produces legal or similarly significant effects. If a covered application uses automated decision-making of that kind, its entry in “Applications covered” will explain the purpose, the effect, how you can request human review and how to contact us about it.
17. Children's information
Our services are provided to businesses and their authorised staff and are not directed at children. We do not knowingly collect personal information from children through our website. If you believe a child has provided us with personal information, please contact info@wellocksecurity.co.zw and we will take appropriate steps.
18. Marketing communications
We do not send marketing messages from our website forms. Messages we send in connection with a request or a service you use — such as confirmations, security alerts, one-time codes and operational updates — are service messages, not marketing. If we introduce marketing communications, we will keep them separate from service messages, identify ourselves as the sender, provide an opt-out in every message, record and honour your opt-out, and never treat silence as consent.
19. Changes to this policy
Each version of this policy carries a version number, an effective date and a last-updated date, shown at the top of the page. When we make a material change we publish the new version here and, where appropriate, notify you through the service you use. Earlier versions are kept in our records.
20. Contact
For any question about this policy or your information, contact our privacy team:
Email: info@wellocksecurity.co.zw
Telephone: 086-777-197-462
21. Regulatory contact
The Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) is the Data Protection Authority under the Cyber and Data Protection Act [Chapter 12:07]. If you are not satisfied with how we have handled your information or a request, you may raise the matter with POTRAZ. Any licence, registration or notification status we hold with POTRAZ is stated only in the “Who we are” section; nothing in this policy should be read as a claim that POTRAZ has approved this policy, our website or our applications.