InfoZambia, operated by Jacana IT Solutions Ltd Last updated: 28 August 2026
1. Purpose and scope
This policy explains the governance standards InfoZambia applies when personal data is handled by staff, contractors, service providers, event partners and sponsors. It supports the Privacy Policy and covers account, listing, contact, community, event, billing, marketing, consent, disclosure, usage and security records.
2. Roles
Jacana IT Solutions Ltd acts as controller for most InfoZambia processing. Service providers that handle data only on documented instructions act as processors and must be bound by appropriate confidentiality, security, deletion, incident and assistance obligations.
A sponsor or partner that decides how to use disclosed information for its own marketing or other purposes is not treated merely as an InfoZambia processor. It acts as an independent controller, or where decisions are genuinely shared, as a joint controller. The applicable arrangement and responsibilities must be recorded before disclosure.
3. Processing principles
Processing must be lawful, fair and transparent; limited to stated purposes; adequate, relevant and not excessive; accurate; retained no longer than necessary; and protected by proportionate technical and organisational measures.
4. Processor and partner governance
Before a material provider or partner receives personal data, InfoZambia must record the service, purpose, data categories, people affected, processing locations, retention, security, sub-processing, incident duties, deletion and rights-assistance arrangements.
Sponsor and event arrangements must additionally record controller roles, approved fields, named purposes, consent wording where used, campaign dates, permitted recipients, suppression handling, onward-sharing restrictions and deletion or return at the end of the engagement.
5. Consent and disclosure records
Where processing relies on consent, InfoZambia records the wording shown, the person’s choice, date, source and any withdrawal. Disclosure records should identify the person or campaign, recipient, fields, purpose, legal basis and date. Suppression records may be kept so that withdrawn or objecting contacts are not contacted again.
6. Security and access
Controls include role-based access, strong authentication, administrative access restriction, secure connections, backups, software maintenance, monitoring and staff confidentiality. Access is limited to what a person needs for their role and is reviewed when roles change.
7. Incidents
Suspected loss, unauthorised access, disclosure or misuse must be escalated promptly. InfoZambia will contain and investigate the incident, document the facts and response, and notify affected people or authorities where required. Processors and partners must cooperate with investigation and remediation.
8. Rights assistance
Processors and partners must assist InfoZambia with access, correction, deletion, restriction, objection and consent-withdrawal requests relevant to the data they hold. Requests are verified and handled within applicable legal timeframes.
9. Retention and deletion
Retention is based on purpose, sensitivity, contractual requirements, legal and accounting duties, security needs and dispute periods. At the end of the approved period or engagement, data is securely deleted, returned, anonymised or restricted unless law requires continued retention.
10. International processing and sub-processors
Material processing locations and transfer safeguards must be reviewed before engagement and when services change. A current list of material processors and locations may be requested from privacy@infozambia.com.
11. Review and accountability
InfoZambia maintains relevant processing, provider, disclosure, incident and retention records. This policy and associated controls are reviewed periodically and after material service or legal changes.
12. Contact
Questions about processing may be sent to privacy@infozambia.com.