Privacy Policy

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your personal information.

Effective Date: 17 January 2026Last Updated: 17 January 2026

Regulatory Compliance Notice

This Privacy Policy is drafted in compliance with the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe, the Statutory Instrument 155 of 2024 (Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations), and the Constitution of Zimbabwe, Article 57 (Right to Privacy). ToraShaout (Pvt) Ltd is registered as a Data Controller with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

1. Introduction and Scope

Welcome to ToraShaout. We are a celebrity video marketplace platform that connects fans with their favourite celebrities through personalised video content. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform, mobile applications, and related services.

ToraShaout (Pvt) Ltd ("ToraShaout", "we", "us", "our"), a subsidiary of StatoTech, is the Data Controller responsible for your personal information. We are committed to protecting your privacy and ensuring that your personal data is processed in accordance with Zimbabwean law and international best practices.

2. Data Controller Information

Data ControllerToraShaout (Pvt) Ltd
Parent CompanyStatoTech
Registered Address7514 Kuwadzana3, Harare, Zimbabwe
Emailinfo@torashout.com
Data Protection OfficerTo Be Appointed
DPO Emaildpo@torashout.com
POTRAZ Registration No.To Be Assigned

3. Key Definitions

As defined under the Cyber and Data Protection Act [Chapter 12:07]:

Personal Information:Information relating to an identifiable person, including names, ID numbers, email addresses, phone numbers, IP addresses, online identifiers, and biometric data.
Data Subject:The natural person to whom personal information relates (you, the user).
Data Controller:The person or entity that determines the purposes and means of processing personal information (ToraShaout).
Processing:Any operation performed on personal information, including collection, storage, use, transfer, or deletion.
Consent:Any freely given, specific, informed, and unambiguous indication of your wishes regarding the processing of your personal information.
Biometric Data:Physiological characteristics including fingerprints, facial recognition features, palm veins, and other unique biological identifiers.

4. Personal Information We Collect

In accordance with the principle of data minimisation, we only collect personal information that is adequate, relevant, and necessary for our stated purposes.

4.1 Information You Provide Directly

  • Account Registration: Full name, email address, phone number, date of birth, username, password (encrypted), profile photograph
  • Identity Verification (for Celebrities): National ID number, passport details, proof of address, bank account or mobile money details for payments
  • Payment Information: Mobile money details (EcoCash, OneMoney), bank account information, transaction history
  • Communications: Messages, video requests, customer support inquiries, feedback
  • Content: Videos uploaded by celebrities, user reviews, comments

4.2 Information Collected Automatically

  • Device Information: IP address, device type, operating system, browser type, unique device identifiers
  • Usage Data: Pages visited, features used, time spent, click patterns, search queries
  • Location Data: General location derived from IP address (we do not collect precise GPS location without explicit consent)
  • Cookies and Similar Technologies: Session cookies, preference cookies, analytics cookies

4.3 Sensitive Personal Information

We may process the following categories of sensitive personal information with your explicit consent:

  • Biometric Data: Facial recognition data for celebrity verification (processed with explicit consent only)
  • Financial Information: Payment details necessary for transactions

5. Legal Basis for Processing

Under the Cyber and Data Protection Act, we process your personal information based on the following lawful grounds:

Legal BasisPurpose Examples
ConsentMarketing communications, non-essential cookies, processing of sensitive data
Contractual NecessityAccount creation, providing our services, processing transactions
Legal ObligationTax records, responding to lawful government requests, fraud prevention
Legitimate InterestsPlatform security, analytics, fraud detection, service improvement

6. Purpose of Processing

In compliance with the principle of purpose limitation, we collect personal information for specific, explicit, and legitimate purposes:

  • To create and manage your account and verify your identity
  • To facilitate transactions between fans and celebrities
  • To process payments and prevent fraud
  • To provide customer support and respond to inquiries
  • To send service-related notifications and updates
  • To improve our platform, develop new features, and conduct analytics
  • To ensure platform security and prevent misuse
  • To comply with legal obligations and respond to lawful requests
  • To enforce our Terms of Service and protect our rights
  • To send marketing communications (only with your explicit consent)

7. Your Rights Under Zimbabwean Law

Under Section 14 of the Cyber and Data Protection Act, you have the following rights regarding your personal information:

Right to be Informed

You have the right to know how your personal information is collected, used, and shared.

Right of Access

You may request a copy of the personal information we hold about you.

Right to Rectification

You may request correction of inaccurate or incomplete personal information.

Right to Erasure

You may request deletion of your personal information in certain circumstances.

Right to Object

You may object to processing of your personal information, including for direct marketing.

Right to Restrict Processing

You may request that we limit how we use your personal information.

Right to Data Portability

You may request to receive your personal information in a structured, commonly used format.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact our Data Protection Officer. We will respond to your request within 30 days of receipt. There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.

8. Protection of Children's Data

ToraShaout takes the protection of children's personal information seriously, in compliance with the special provisions for children under the Cyber and Data Protection Act:

  • Our platform is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.
  • Users between 13 and 18 years of age require verifiable parental or guardian consent before creating an account.
  • We conduct regular Data Protection Impact Assessments (DPIAs) for any processing involving children's data, as required by SI 155 of 2024.
  • Parents or guardians may contact us to review, delete, or stop the collection of their child's personal information.
  • If we become aware that we have collected personal information from a child without appropriate consent, we will take immediate steps to delete that information.

9. Disclosure of Personal Information

We may share your personal information with the following categories of recipients:

9.1 Service Providers

Third-party service providers who assist us in operating our platform, including payment processors, cloud hosting providers, analytics services, and customer support tools. All service providers are contractually bound to protect your data and process it only on our instructions.

9.2 Legal Requirements

We may disclose personal information when required by law, court order, or government request, including to POTRAZ and other regulatory authorities.

9.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal information may be transferred. We will notify you of any such change and your choices regarding your information.

9.4 With Your Consent

We may share your information with third parties when you have given explicit consent to do so.

10. Cross-Border Data Transfers

In accordance with Sections 28-29 of the Cyber and Data Protection Act, we ensure adequate protection when transferring personal information outside Zimbabwe:

  • We will notify POTRAZ before any cross-border transfer of personal information.
  • Transfers will only occur to countries or organisations that provide an adequate level of data protection as determined by POTRAZ.
  • Where adequate protection is not assured, we will implement appropriate safeguards such as Standard Contractual Clauses or obtain your explicit consent.
  • Our primary data processing occurs within Zimbabwe. Where international cloud services are used, we ensure contractual protections are in place.

11. Data Security Measures

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, destruction, or alteration:

11.1 Technical Measures

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Secure password hashing using industry-standard algorithms
  • Regular security assessments and penetration testing
  • Firewalls, intrusion detection systems, and access controls
  • Secure development practices and code reviews

11.2 Organisational Measures

  • Staff training on data protection and security
  • Access controls based on the principle of least privilege
  • Regular risk assessments as required by SI 155
  • Documented security policies and procedures
  • Incident response and business continuity plans

12. Data Breach Notification

In the event of a personal data breach, we will comply with the notification requirements under SI 155 of 2024:

NotificationTimeframeDetails
POTRAZWithin 24 hoursWe will report the breach to the Data Protection Authority (POTRAZ) within 24 hours of becoming aware of it.
Affected Data SubjectsWithin 72 hoursIf the breach poses a high risk to your rights and freedoms, we will notify you within 72 hours with details of the breach and steps you can take.

13. Automated Decision-Making

Where we use automated processing to make decisions that significantly affect your rights, we will:

  • Obtain your explicit consent before such processing, as required by the Act.
  • Inform you of the logic involved and the significance of such processing.
  • Provide you with the right to request human intervention and to challenge the decision.
  • Conduct regular reviews of automated systems to ensure fairness and accuracy.

14. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, in accordance with the principle of storage limitation:

Data CategoryRetention Period
Account InformationDuration of account + 2 years after closure
Transaction Records7 years (legal/tax requirements)
Customer Support Communications3 years from resolution
Marketing PreferencesUntil consent withdrawn
Video Content (Celebrities)Duration of agreement + 1 year
Analytics Data2 years (anonymised thereafter)
Security Logs1 year

After the retention period expires, we will securely delete or anonymise your personal information unless retention is required by law.

15. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience. For detailed information, please refer to our separate Cookie Policy. You may manage your cookie preferences through your browser settings or our cookie consent tool.

16. Direct Marketing

We will only send you marketing communications with your explicit opt-in consent. You have the right to object to direct marketing at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your preferences in your account settings
  • Contacting our Data Protection Officer

17. Third-Party Links and Services

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any personal information.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on our platform with a new "Last Updated" date
  • Sending you an email notification if the changes are significant
  • Displaying a prominent notice on our platform

Your continued use of our platform after such changes constitutes acceptance of the updated policy.

19. Complaints and Regulatory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)

Block A, Emerald Business Park

30 The Chase (West), Emerald Hill, Harare

Phone: +263 (4) 333311

Website: www.potraz.gov.zw

We encourage you to contact us first so we can try to resolve your concerns directly.

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

TORASHAOUT

ToraShaout (Pvt) Ltd

7514 Kuwadzana3, Harare, Zimbabwe

Email: info@torashout.com

DPO Email: dpo@torashout.com

By using ToraShaout, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Document Version: 1.0 | Effective: 17 January 2026