1. Security Controls
- HTTPS encryption for all data in transit.
- Encrypted storage for sensitive data at rest.
- Role-based access controls limiting which staff can see what.
- Audit logs for administrative actions.
- Verification controls on identity documents and provider profiles.
- Server-side validation on sensitive operations such as fees and wallet credits.
2. Account Security
You can help keep your account safe by:
- Using a strong, unique password.
- Not sharing your login or one-time codes with anyone.
- Signing out on shared devices.
- Reporting suspicious activity immediately.
3. Breach Notification
In the event of a personal data breach that is likely to affect you, we will notify affected users and the relevant data protection authority as required by Zimbabwean law and any other applicable African data protection frameworks.
4. Responsible Disclosure
If you believe you have found a security vulnerability, please report it confidentially to info@kazi-go.com. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to fix it.
Questions about this policy? Contact us at info@kazi-go.com.
