Privacy Policy
Last updated: December 3, 2025
1. Introduction
Pozi respects your privacy and is committed to safeguarding personal data. This policy explains what information we collect, how we use it, and the choices you have. It applies to information we collect via the Pozi website or mobile app and through related services. Apple's App Review Guidelines require every app to include a privacy policy that identifies what data is collected, how it is collected, all uses of that data, confirms third‑party protections and explains retention and deletion policies (developer.apple.com). Similarly, the Google Play User Data Policy requires developers to be transparent about the access, collection, use, handling and sharing of user data and to limit the use of personal data to disclosed, policy‑compliant purposes (support.google.com). The following sections satisfy those requirements and align with the principles of the Zambian Data Protection Act, which stipulates that personal data must be processed lawfully, collected for explicit purposes, kept accurate and only retained as necessary (securiti.ai).
2. Data We Collect
We collect information that you provide directly, data generated through your use of the Service and information from third parties. This includes:
- Personal Identification Information – such as your name, email address, postal address, phone number, national identity or passport number, student or employee identification and other identifiers you provide when registering or applying for tenancy.
- Account Credentials – login username and hashed password.
- Financial Information – Pozi collects only the bank account number, bank name and branch information you provide so that we can arrange rent and deposit payments via debit order. We do not collect or store electronic card details (credit or debit card numbers, expiry dates or CVV codes), and we do not retain sufficient information to initiate unauthorized withdrawals. Our payment processor uses your account details solely to carry out authorised transactions.
- Property & Lease Information – details about properties you list or rent, lease terms, rental amounts and payment history.
- Usage Data – information about how you interact with our platform, such as device information, log data, IP addresses, operating system, browser type, and pages viewed. We may use cookies and similar technologies to collect this information.
- Third‑Party Data – information from credit bureaus or verification services (with your consent) and data from service providers such as payment processors.
3. How We Collect Data
We collect data:
- When you interact with the platform – e.g., when you create an account, submit a listing, apply for accommodation, make payments or communicate with us.
- Automatically – via cookies and device technologies that log usage information. You can manage cookie preferences in your browser or device settings.
- From third parties – such as identity verification services or payment processors, but only where you have authorised such collection.
4. Legal Basis for Processing and How We Use Data
Our lawful bases include consent, contractual necessity, compliance with legal obligations and legitimate interests, as recognised under the Zambian Data Protection Act (securiti.ai). We use your data to:
- Provide and manage the Service – including connecting tenants and property owners, processing bookings, facilitating payments, managing contracts and enforcing our Terms.
- Verify Identity – to confirm eligibility and prevent fraud. We may use third‑party verification services.
- Communicate with you – regarding your account, lease, updates to our policies, security alerts and marketing communications (with your consent). You may opt out of non‑essential communications.
- Improve our services – by analysing how users interact with the platform and identifying ways to enhance functionality and user experience. Under the Apple Guidelines, apps should request access only to data that is relevant to the core functionality and may not repurpose data without additional consent (developer.apple.com).
- Comply with Legal Obligations – such as anti‑money laundering or tax reporting requirements and obligations to governmental authorities.
We do not sell personal data. The Google Play policy forbids selling personal or sensitive user data and requires that any data transfer to service providers be necessary and accompanied by appropriate safeguards (support.google.com). We will therefore only share your data as described below.
5. Data Sharing and Disclosure
We may share personal data with:
- Property owners and tenants – to the extent necessary to facilitate rental agreements, viewings and communications between parties.
- Service providers – such as hosting providers, analytics companies, payment processors, background‑check services and customer support platforms. We require these partners to protect your data and to use it only for the purpose of providing services to us, offering the same level of protection we provide (developer.apple.com).
- Legal and regulatory authorities – when required to comply with law, to protect the rights of Pozi or others, or to respond to lawful requests. Under the Zambian Data Protection Act, processing may be lawful when necessary for compliance with legal obligations (securiti.ai).
- Corporate transactions – if Pozi is involved in a merger, acquisition or sale, your information may be transferred as part of that transaction, subject to confidentiality obligations.
We do not share data with analytics or advertising partners for the purpose of building profiles or behavioural advertising. Apps may not repurpose personal data without further consent (developer.apple.com).
6. Data Retention
We retain personal data only as long as necessary to fulfil the purposes described here, to comply with legal and regulatory obligations or to resolve disputes. When data is no longer required, we will either delete it or anonymise it. This fulfils the requirement to store data only for the necessary time period (securiti.ai).
7. Security Measures
We implement appropriate technical and organisational measures to secure personal data, including encryption of data in transit, secure servers, role‑based access controls and regular security assessments. We require service providers to use modern cryptography and security practices. Under the Google User Data policy, personal and sensitive user data must be handled securely (support.google.com). Despite these measures, no method of transmission over the Internet is perfectly secure; you acknowledge that we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction and subject to certain exceptions, you may have the right to:
- Access – request a copy of the personal data we hold about you.
- Rectification – update or correct inaccurate data.
- Erasure – request deletion of your personal data where it is no longer needed or where consent has been withdrawn.
- Restriction – ask us to limit how we process your data.
- Objection – object to certain processing, including direct marketing.
- Data portability – obtain a copy of your data in a structured, commonly used, machine‑readable format.
- Withdraw Consent – where processing is based on consent, you may withdraw your consent at any time. Apple guidelines require apps to provide an easily accessible and understandable way to withdraw consent (developer.apple.com).
- Lodge a Complaint – with the relevant data protection authority (e.g., the Data Protection Commission of Zambia) if you believe your rights have been violated.
To exercise these rights, please contact us using the details in the Contact section. We may require you to provide proof of identity.
9. International Transfers
Your data may be transferred to and stored on servers located outside your country. In such cases, we will implement appropriate safeguards—such as standard contractual clauses or other lawful transfer mechanisms—to ensure that your data receives a level of protection equivalent to that required by local law.
10. Cookies and Tracking Technologies
Pozi uses cookies and similar technologies to enable the platform to function and to understand how visitors use our services. We categorise cookies as:
- Essential cookies – necessary for basic site functionality (e.g., account login, session management). You cannot opt out of essential cookies.
- Analytics cookies – help us understand usage patterns and improve the platform. These do not personally identify you and you can disable them through your browser or device settings.
We do not use advertising or marketing cookies to track your behaviour across other sites. Apps on Apple platforms must not track users without obtaining explicit permission (developer.apple.com), and we adhere to that standard.
11. Children's Privacy
Our services are intended for adults and are not directed to persons under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a minor has provided us with personal information, we will delete it.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by posting the new policy on our website or app and by updating the "last updated" date. Continuing to use the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact
For questions or requests regarding this Privacy Policy, please contact:
Email: privacy@pozi.com.na
