PRIVACY POLICY
Last updated January 08, 2024
This privacy notice for Smart Zambia Institute (“we,” “us,” or “our”), describes how
and why we might collect, store, use, and/or share (“process”) your information
when you use our services (“Services”), such as when you:
Download and use our mobile application (Boma Iyangana), or any other application
of ours that links to this privacy notice. Reading this privacy notice will help you understand your
privacy rights and choices. If you do not agree with our policies and practices, please
do not use our Services. If you still have any questions or concerns, please contact
us at citizen.support@grz.gov.zm.
Boma Iyangana has been developed to allow any citizen to submit a query or raise a complaint through an online portal to the Government of Zambia. The citizen can also check the status of submitted query or complaint on Boma Iyangana.
The Government of the Republic of Zambia and its employees do not accept liability however arising, including liability for negligence, for any loss resulting from the use of or reliance upon the information and/or reliance on its availability at any time. Boma Iyangana must not be used in case of emergencies. Should an emergency occur, you may wish to contact emergency services accordingly. The user should however appreciate that if the complaint or query is sent after office hours or during weekend, it will only be on the next working day that the matter will be dealt with.
SUMMARY OF KEY POINTS
This summary provides key points from our privacy notice, but you can find
out more details about any of these topics by clicking the link following each
key point or by using our table of contents below to find the section you are
looking for.
What personal information do we process? When you visit, use, or navigate our
Services, we may process personal information depending on how you interact with
us and the Services, the choices you make, and the products and features you use.
Learn more about personal information you disclose to us.
Do we process any sensitive personal information? We do not process sensitive
personal information.
Do we receive any information from third parties? We may receive information
from public databases, marketing partners, social media platforms, and other outside
sources. Learn more about information collected from other sources.
How do we process your information? We process your information to provide,
improve, and administer our Services, communicate with you, for security and fraud
prevention, and to comply with law. We may also process your information for other
purposes with your consent. We process your information only when we have a valid
legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information?
We may share information in specific situations and with specific third parties. Learn
more about when and with whom we share your personal information.
How do we keep your information safe? We have organizational and technical
processes and procedures in place to protect your personal information. However, no
electronic transmission over the internet or information storage technology can be
guaranteed to be 100% secure, so we cannot promise or guarantee that hackers,
cybercriminals, or other unauthorized third parties will not be able to defeat our
security and improperly collect, access, steal, or modify your information. Learn more
about how we keep your information safe.
What are your rights? Depending on where you are located geographically, the
applicable privacy law may mean you have certain rights regarding your personal
information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by
submitting a data subject access request, or by contacting us. We will consider and
act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the
privacy notice in full.
TABLE OF CONTENTS
INFORMATION?
FROM YOU?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register
on the Services, express an interest in obtaining information about us or our products
and Services, when you participate in activities on the Services, or otherwise when
you contact us.
Personal Information Provided by You. The personal information that we collect
depends on the context of your interactions with us and the Services, the choices you
make, and the products and features you use. The personal information we collect
may include the following:
phone numbers
names
email addresses
contact preferences
contact or authentication data
Sensitive Information. We do not process sensitive information.
Social Media Login Data. We may provide you with the option to register with us
using your existing social media account details, like your Facebook, Twitter, or other
Dashboard social media account. If you choose to register in this way, we will collect the information described in the section called “HOW DO WE HANDLE YOUR SOCIAL LOGINS?” below.
Application Data. If you use our application(s), we also may collect the following
information if you choose to provide us with access or permission:
Geolocation Information. We may request access or permission to track
location-based information from your mobile device, either continuously or
while you are using our mobile application(s), to provide certain location-based
services. If you wish to change our access or permissions, you may do so in
your device’s settings.
Mobile Device Access. We may request access or permission to certain
features from your mobile device, including your mobile device’s location, and
other features. If you wish to change our access or permissions, you may do
so in your device’s settings.
This information is primarily needed to maintain the security and operation of our
application(s), for troubleshooting, and for our internal analytics and reporting
purposes.
All personal information that you provide to us must be true, complete, and accurate,
and you must notify us of any changes to such personal information.
Information collected from other sources
In Short: We may collect limited data from public databases, marketing partners,
social media platforms, and other outside sources.
In order to enhance our ability to provide relevant marketing, offers, and services to
you and update our records, we may obtain information about you from other
sources, such as public databases, joint marketing partners, affiliate programs, data
providers, social media platforms, and from other third parties. This information
includes mailing addresses, job titles, email addresses, phone numbers, intent data
(or user behavior data), Internet Protocol (IP) addresses, social media profiles, social
media URLs, and custom profiles, for purposes of targeted advertising and event
promotion. If you interact with us on a social media platform using your social media
account (e.g., Facebook or Twitter), we receive personal information about you such
as your name, email address, and gender. Any personal information that we collect
from your social media account depends on your social media account’s privacy
settings.
Primarily, your data will be used in the following functions
Further, we process your information to provide, improve, and administer our
Services, communicate with you, for security and fraud prevention, and to comply
with law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on
how you interact with our Services, including:
To facilitate account creation and authentication and otherwise manage
user accounts. We may process your information so you can create and log
in to your account, as well as keep your account in working order.
To respond to user inquiries/offer support to users. We may process your
information to respond to your inquiries and solve any potential issues you
might have with the requested service.
To send administrative information to you. We may process your
information to send you details about our products and services, changes to
our terms and policies, and other similar information.
To save or protect an individual’s vital interest. We may process your
information when necessary to save or protect an individual’s vital interest,
such as to prevent harm.
YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary
and we have a valid legal reason to do so under applicable law, like
with your consent, to comply with laws, to provide you with services to enter into or
fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate
business interests.
The data privacy law relied on by the Division in processing personal data is the Data Protection Act and the Electronic government Act. The division will ensure compliance to these laws at all times. in special circumstances such as when you are located in the EU or UK, note that the above laws still apply.
Legal Obligations.
We may process your information where we believe it is
necessary for compliance with our legal obligations, such as to cooperate with
a law enforcement body or regulatory agency, exercise or defend our legal
rights, or disclose your information as evidence in litigation in which we are
involved.
Vital Interests. We may process your information where we believe it is
necessary to protect your vital interests or the vital interests of a third party,
such as situations involving potential threats to the safety of any person.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (i.e.,
express consent) to use your personal information for a specific purpose, or in
situations where your permission can be inferred (i.e., implied consent). You
can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to
process your information without your consent, including, for example:
If collection is clearly in the interests of an individual and consent cannot be
obtained in a timely way
For investigations and fraud detection and prevention
For business transactions provided certain conditions are met
If it is contained in a witness statement and the collection is necessary to
assess, process, or settle an insurance claim
For identifying injured, ill, or deceased persons and communicating with next
of kin
If we have reasonable grounds to believe an individual has been, is, or may be
victim of financial abuse
If it is reasonable to expect collection and use with consent would compromise
the availability or the accuracy of the information and the collection is
reasonable for purposes related to investigating a breach of an agreement or a
contravention of the laws of Canada or a province
If disclosure is required to comply with a subpoena, warrant, court order, or
rules of the court relating to the production of records
If it was produced by an individual in the course of their employment, business,
or profession and the collection is consistent with the purposes for which the information was produced
If the collection is solely for journalistic, artistic, or literary purposes
If the information is publicly available and is specified by the regulations
PERSONAL INFORMATION?
In Short: We may share information in specific situations described in this section
and/or with government agencies part to the execution of the Boma Iyangana services without your consent.
When we use Google Maps Platform APIs, we may share your information
with certain Google Maps Platform APIs (e.g., Google Maps API, Places API).
We use certain Google Maps Platform APIs to retrieve certain information
when you make location-specific requests.
A full list of what we use information for can be found
in this section and in the previous section titled “HOW DO WE PROCESS
YOUR INFORMATION?” We obtain and store on your device (“cache”) your
location. You may revoke your consent anytime by contacting us at the contact
details provided at the end of this document. The Google Maps Platform APIs
that we use store and access cookies and other information on your devices. If
you are a user currently in the European Economic Area (EU countries,
Iceland, Liechtenstein, and Norway) or the United Kingdom, please take a look
at our Cookie Notice.
Affiliates. We may share your information with our affiliates, in which case we
will require those affiliates to honor this privacy notice. Affiliates include our
parent company and any subsidiaries, joint venture partners, or other
companies that we control or that are under common control with us.
Business Partners. We may share your information with our business
partners to offer you certain products, services, or promotions.
Offer Wall. Our application(s) may display a third-party hosted “offer wall.”
Such an offer wall allows third-party advertisers to offer virtual currency, gifts,
or other items to users in return for the acceptance and completion of an
advertisement offer. Such an offer wall may appear in our application(s) and be
displayed to you based on certain data, such as your geographic area or
demographic information. When you click on an offer wall, you will be brought
to an external website belonging to other persons and will leave our
application(s). A unique identifier, such as your user ID, will be shared with the
offer wall provider in order to prevent fraud and properly credit your account
with the relevant reward.
TECHNOLOGIES?
In Short: We may use cookies and other tracking technologies to collect and store
your information.
We may use cookies and similar tracking technologies (like web beacons and pixels)
to access or store information. Specific information about how we use such
technologies and how you can refuse certain cookies is set out in our Cookie Notice.
In Short: If you choose to register or log in to our Services using a social media
account, we may have access to certain information about you.
We will use the information we receive only for the purposes that are described in this
privacy notice or that are otherwise made clear to you on the relevant Services.
Please note that we do not control, and are not responsible for, other uses of your
personal information by your third-party social media provider. We recommend that
you review their privacy notice to understand how they collect, use, and share your
personal information, and how you can set your privacy preferences on their sites
and apps.
In Short: We keep your information for as long as necessary to fulfill the purposes
outlined in this privacy notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the
purposes set out in this privacy notice, unless a longer retention period is required or
permitted by law (such as tax, accounting, or other legal requirements). No purpose
in this notice will require us keeping your personal information for longer than
24 months past the termination of the user’s account.
When we have no ongoing legitimate business need to process your personal
information, we will either delete or anonymize such information, or, if this is not
possible (for example, because your personal information has been stored in backup
archives), then we will securely store your personal information and isolate it from
any further processing until deletion is possible.
In Short: We aim to protect your personal information through a system of
organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational
security measures designed to protect the security of any personal information we
process. However, despite our safeguards and efforts to secure your information, no
electronic transmission over the Internet or information storage technology can be
guaranteed to be 100% secure, so we cannot promise or guarantee that hackers,
cybercriminals, or other unauthorized third parties will not be able to defeat our
security and improperly collect, access, steal, or modify your information. Although
we will do our best to protect your personal information, transmission of personal
information to and from our Services is at your own risk. You should only access the
Services within a secure environment.
In some regions, such as the European Economic Area (EEA), United
Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater
access to and control over your personal information. You may review, change, or
terminate your account at any time.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain
rights under applicable data protection laws. These may include the right (i) to
request access and obtain a copy of your personal information, (ii) to request
rectification or erasure; (iii) to restrict the processing of your personal information; (iv)
if applicable, to data portability; and (v) not to be subject to automated decisionmaking. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting
us by using the contact details provided in the section “HOW CAN YOU CONTACT
US ABOUT THIS NOTICE?” below.
We will consider and act upon any request in accordance with applicable data
protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing
your personal information, you also have the right to complain to your Member State
data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and
Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your
personal information, which may be express and/or implied consent depending on
the applicable law, you have the right to withdraw your consent at any time. You can
withdraw your consent at any time by contacting us by using the contact details
provided in the section “HOW CAN YOU CONTACT US ABOUT THIS NOTICE?”
below or updating your preferences.
However, please note that this will not affect the lawfulness of the processing before
its withdrawal nor, when applicable law allows, will it affect the processing of your
personal information conducted in reliance on lawful processing grounds other than
consent.
Account Information
If you would at any time like to review or change the information in your account or
terminate your account, you can:
Log in to your account settings and update your user account.
Contact us using the contact information provided.
Upon your request to terminate your account, we will deactivate or delete your
account and information from our active databases. However, we may retain some
information in our files to prevent fraud, troubleshoot problems, assist with any
investigations, enforce our legal terms and/or comply with applicable legal
requirements.
If you have questions or comments about your privacy rights, you may email us at
citizen.support@grz.gov.zm.
Most web browsers and some mobile operating systems and mobile applications
include a Do-Not-Track (“DNT”) feature or setting you can activate to signal your
privacy preference not to have data about your online browsing activities monitored
and collected. At this stage no uniform technology standard for recognizing and
implementing DNT signals has been finalized. As such, we do not currently respond
to DNT browser signals or any other mechanism that automatically communicates
your choice not to be tracked online. If a standard for online tracking is adopted that
we must follow in the future, we will inform you about that practice in a revised
version of this privacy notice.
In Short: Yes, we will update this notice as necessary to stay compliant with relevant
laws.
We may update this privacy notice from time to time. The updated version will be
indicated by an updated “Revised” date and the updated version will be effective as
soon as it is accessible. If we make material changes to this privacy notice, we may
notify you either by prominently posting a notice of such changes or by directly
sending you a notification. We encourage you to review this privacy notice frequently
to be informed of how we are protecting your information.
If you have questions or comments about this notice, you may email us at
citizen.support@grz.gov.zm or contact us by post at:
Smart Zambia Institute
Smart Zambia Institute – Electronic Government Division
Government Complex
Lusaka , Lusaka 10101
Zambia
DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country, you may have the right to request
access to the personal information we collect from you, change that information, or
delete it. To request to review, update, or delete your personal information, please fill
out and submit a data subject access request.
We may contact you for feedback to evaluate and/or develop our complaint management system if you agreed to this when you signed up to use Boma Iyangana. If you have changed your mind and would prefer us not to contact you, then you can opt out at any time by sending an e-mail to citizen.support@grz.gov.zm.
Other Issues
Privacy policy pertaining to disclosure of personal data, safeguarding your personal information, information about other individuals and access to personal data are governed by the Data Protection Act of the Republic of Zambia.
The SMART Zambia Institute is a Division under the Office of the President mandated to coordinate and implement electronic government (E-Government) for the citizens, businesses and within government for improved service delivery. The Institute was established through a Government Gazette notice No 836 of 2016.
©2022. SMART Zambia Institute. All Rights Reserved.