Trust

Data Safety

A transparent summary of the data our services handle, how it is protected, and the choices you have. This page is maintained by WATHACI Corporate Services to answer common security and privacy questions about our advisory work and digital products (POKOTO, Cue Hard-Breaks and WATHACI Connect).

Last updated: 20 July 2026

Data we collect

  • Account information (name, email, phone) when you sign up for a product or engage us as a client.
  • Business information you upload for advisory, compliance or M&E work.
  • Product usage data (transactions in POKOTO, matches in Cue Hard-Breaks, network activity in WATHACI Connect).
  • Technical logs (IP, device, browser) used to secure and improve the services.

Data we do NOT collect

  • We do not sell personal information to third parties.
  • We do not run third-party advertising trackers on our services.
  • We do not collect sensitive categories (health, biometric, political views) unless strictly required for a specific engagement with your explicit consent.

How data is protected

  • Encryption in transit (HTTPS/TLS) across all public services.
  • Encryption at rest for databases and file storage where supported by our providers.
  • Role-based access control and least-privilege principles for staff.
  • Managed cloud infrastructure with regular patching and monitoring.
  • Regular automated backups and tested recovery procedures.
  • Confidentiality obligations for all staff and contractors.

How data is shared

  • With sub-processors (cloud hosting, email delivery, payment processing) under written data processing agreements.
  • With regulators or courts when compelled by Zambian or applicable law.
  • Never with advertisers or data brokers.

Data retention

Client engagement records are typically retained for at least ten (10) years to comply with Zambian corporate, tax and anti-money-laundering law. Product accounts are retained while active and for a reasonable period afterwards for legal and operational reasons. You can request earlier deletion where the law permits.

International storage

Our infrastructure providers may store data outside Zambia. Cross-border transfers rely on lawful mechanisms under the Zambia Data Protection Act No. 3 of 2021 and, where applicable, GDPR safeguards such as Standard Contractual Clauses.

Your choices

  • Access, correct or delete your data by writing to us.
  • Withdraw consent for optional processing (marketing, non-essential cookies).
  • Export your account data from our products on request.
  • Lodge a complaint with the Data Protection Commissioner of Zambia or your local authority.

Incident response

We investigate suspected security incidents promptly. Confirmed personal data breaches that pose a risk to individuals are reported to the Data Protection Commissioner of Zambia within 24 hours (72 hours where GDPR applies) and to affected individuals without undue delay, as required by law.

Report a concern

Please report vulnerabilities or data concerns to support@wathaci.com. We aim to acknowledge every report within two (2) business days.

Shared responsibility

Security is a partnership. WATHACI protects the services we operate; clients and end-users are responsible for securing their accounts, credentials and any devices used to access our products.

Disclaimer

This page is app-owner content maintained by WATHACI. It is not an independent certification. Enabled controls reflect current practice and may evolve as our services grow.