Legal

Privacy Notice

Zimworx is committed to protecting the privacy and security of your personal information. This notice outlines how we collect, use, process, and protect your data.

Zimbabwe Cyber and Data Protection Act [Chapter 12:07]Costa Rican Law No. 8968Zambian Data Protection Act, No 3 of 2021
1

What Personal Data We Collect

a) Identity and Contact Information

  • Full name
  • Email address, phone number, physical address

b) Application and Employment-Related Information

  • CV/resume details (education, qualifications, skills, work history)
  • Cover letter and application responses
  • Salary expectations
  • References and referee contact details
  • Interview notes, scoring, and assessments
  • Background check results

c) Online and Technical Data

If you apply via our website, we may collect:

  • IP address
  • Device type, browser type
  • Application timestamps

d) Special Category / Sensitive Data (Only Where Necessary)

We may collect sensitive personal information where permitted by law and strictly required, such as:

  • Disability or medical information (for reasonable accommodation purposes)
  • Criminal record information (where legally required for certain roles)

Providing sensitive information is generally optional unless required for a specific role or legal obligation.

2

How We Collect Your Data

We may collect personal information from:

  • You directly (application forms, CV, interviews, emails, calls)
  • Recruitment agencies or headhunters
  • Referees (if you provide their details and consent/contact permission)
  • Public sources such as LinkedIn or professional profiles (where relevant)
  • Pre-employment screening providers (where applicable)
3

Why We Process Your Personal Data

We process candidate information for the following recruitment purposes:

  • To assess your suitability for current job opportunities
  • To manage the recruitment process (shortlisting, interviews, evaluations)
  • To communicate with you regarding your application
  • To verify your qualifications and employment history (where applicable)
  • To perform reference checks (where applicable)
  • To conduct background checks (where legally permitted/required)
  • To issue an offer letter and prepare onboarding documentation
  • To maintain recruitment records and respond to disputes or complaints
  • To meet legal and regulatory obligations (labour, immigration, tax, etc.)
  • To improve our recruitment practices and candidate experience
4

Legal Basis for Processing

We process your personal data under one or more lawful grounds depending on applicable law, including:

  • Consent (where you voluntarily provide information, or where consent is required)
  • Contractual necessity (to take steps prior to entering into an employment contract)
  • Legal obligation (to comply with labour, tax, immigration, and regulatory requirements)
  • Legitimate interests (to recruit suitable candidates, manage recruitment efficiently, and protect the organisation)
  • Vital interests (rare cases, such as emergency contact/medical information)
  • Public interest (where applicable under national law)

Sensitive personal data is only processed where there is a valid lawful basis and additional legal justification.

5

If You Do Not Provide Your Information

Certain personal data is required to assess your application and take steps prior to entering into an employment contract. If you do not provide mandatory information, we may be unable to process your application, assess your suitability, progress your application, or make an offer of employment. Optional information is clearly marked and will not affect your application if not provided.

6

Automated Decision-Making

We do not make hiring decisions solely through automated decision-making. However, we may use recruitment tools that assist with sorting applications (e.g., keyword filtering). Final decisions are made by human reviewers.

7

Who We Share Your Personal Data With

We may share your information on a need-to-know basis with authorised personnel directly involved in the recruitment process.

Internal Parties

  • Recruitment team
  • Human Resources
  • Sales team
  • Hiring managers and interview panels
  • Finance and payroll teams (if you are successful)
  • IT and security teams (where necessary)

External Parties (Third Parties / Processors)

  • Potential Clients
  • Background screening providers
  • Psychometric or assessment providers
  • Medical assessment providers (if required)
  • Legal advisors or regulators where legally required

All third parties are required to protect your information and process it only in accordance with our instructions and applicable law.

8

International Transfers of Personal Data

Where we use service providers or recruitment platforms hosted in another country, your personal data may be transferred internationally. In such cases, we will ensure appropriate safeguards are in place, such as contractual safeguards, approved transfer mechanisms, and adequate security measures.

9

Data Retention

We keep recruitment-related personal data only for as long as necessary. Typical retention periods include:

  • Unsuccessful candidates: up to 12 months after recruitment closure, unless legal requirements require longer retention.
  • Talent pool candidates (with consent): up to 24 months or until you request deletion.
  • Successful candidates: relevant information becomes part of your employee file and is retained in accordance with our HR retention policies.

We may retain certain information longer if required to comply with legal obligations or to resolve disputes.

10

How We Protect Your Information

We implement appropriate technical and organisational security measures, including:

  • Access controls and restricted permissions
  • Secure storage and encrypted systems (where applicable)
  • Secure recruitment platforms
  • Confidentiality obligations for staff
  • Monitoring and audit controls

Despite these safeguards, no system is 100% secure. If a breach occurs, we will respond in accordance with legal requirements.

11

Your Rights as a Data Subject

Depending on applicable law, you may have the right to:

  • Access your personal data
  • Correction of inaccurate or incomplete data
  • Deletion of your data ("right to be forgotten")
  • Object to certain processing activities
  • Restriction of processing
  • Portability (where applicable)
  • Withdraw consent (where processing is based on consent)
  • Lodge a complaint with the relevant regulator

To exercise your rights, contact us using the details in Section 15.

12

Marketing and Unrelated Communications

We will not use your recruitment data to send marketing messages unless you separately opt in.

13

Links to External Websites

Our recruitment website may contain links to third-party websites. We are not responsible for the privacy practices of those third parties. We recommend reviewing their privacy notices.

14

Updates to This Privacy Notice

We may update this Recruitment Privacy Notice from time to time. Any updates will be published on our recruitment website, and the revised version will take effect from the updated date shown at the top.

15. Contact Us

If you have any questions about this notice or how we handle your personal information, please contact our Data Protection Officer:

Melinda Green

Data Protection Officer

[email protected]

© 2026 Zimworx / ZimboJobs. All rights reserved.