TaxComply is operated by Techify Solutions, registered in Zimbabwe under
entity number 84526A0222026, with its registered office at
1604 Vineyard, Mainway Meadows, Waterfalls, Harare ("TaxComply", "we",
"us"). This policy explains what personal information we collect when you use the TaxComply
platform, apps and website (together, the "Service"), why we collect it, who we share it
with, how long we keep it, and the rights you have.
We process personal information in accordance with the Cyber and Data Protection Act
[Chapter 12:07] and its regulations, under the supervision of the Postal and
Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) as the Data Protection
Authority.
1. Who this policy covers
Business customers ("tenants") — the businesses that register for TaxComply and the people who administer their accounts.
Users — owners, administrators, managers, accountants and cashiers a tenant adds to its account.
Tax agents — licensed tax agents a tenant appoints to act on its behalf within TaxComply.
Buyers and suppliers of our tenants — people and businesses whose details appear on fiscal receipts our tenants issue or receive.
Visitors to our website.
2. Our role: controller or processor
For the account and user information you give us, and for the operation and security of the
Service, TaxComply is the data controller.
For the transactional information a tenant processes through the Service — the sales,
receipts, customers, suppliers, stock and purchase records of that tenant's business — the
tenant is the data controller and TaxComply is the
data processor, acting on the tenant's instructions and on the requirements
of Zimbabwean tax law. If you are a customer or supplier of one of our tenants and have
questions about how that business handles your information, please contact that business
first; we will assist them in responding.
3. Information we collect
3.1 Information you give us
Registration and account: name, email address, phone number, business name and trading name, taxpayer identification number (TIN), VAT number, business partner (BP) number, business address and contact details, subscription plan and billing choices.
Users you add: their name, email, phone number, role, and — for cashiers using the till app — a PIN, which we store only as a one-way hash.
Tax agent details: if you are a tax agent, your organisation name, tax agent licence number and expiry, individual licence numbers of your staff, and the clients you are appointed for. We may ask for a copy of your licence to verify it.
Compliance profile: facts about your business you enter so the Service can generate your obligations — for example VAT category, whether you employ staff, whether you are a withholding agent, which levies you are registered for.
Support and correspondence: anything you send us when you contact support.
3.2 Information created when you use the Service
Fiscal receipts, credit notes and debit notes you issue: line items, prices, taxes, payment methods, dates, receipt numbers, cryptographic hashes and signatures, QR verification data, and — where you record them — the buyer's name, TIN, VAT number, address and contact details.
Fiscal device data: the ZIMRA device identifiers, device certificates and, for server-signed devices, the private signing key (stored encrypted; see section 8), fiscal day records and Z-reports.
Point-of-sale data (if you use the till): products, prices, barcodes, stock levels and movements, shifts, cash-ups, which cashier rang each sale, and mobile-money payment requests including the payer's mobile number.
Purchase and supplier data (if you use purchase verification): supplier names, TINs, VAT numbers, supplier invoice details, tax clearance documents you upload, and the results of validating supplier invoices with ZIMRA.
Compliance data: your obligation calendar, compliance state and its history, VAT return drafts, purchase entries, and notes you or your agent add.
Integration data: API keys and webhook endpoints you create, connector credentials for accounting packages you link (stored encrypted), and delivery logs.
Notification data: your notification preferences, language, quiet hours, and a log of messages we sent you (channel, template, time, delivery status).
Audit and security logs: who did what and when in your account, IP address, browser or app version, device identifiers for enrolled tills, login history.
Usage and technical data: pages and features used, error reports, and performance data.
3.3 Information from third parties
ZIMRA: taxpayer name and TIN returned when a device is verified or registered; device configuration including applicable taxes and your branch details; receipt acceptance results and ZIMRA receipt IDs; stock figures held by FDMS for your device; validation results for supplier invoices you ask us to check.
Payment providers (EcoCash, Paynow, and any others you choose): payment status, transaction references, and the mobile number or account used to pay.
Accounting packages you connect (Sage Pastel, Odoo, Zoho Books, QuickBooks, Xero): the sales and purchase records exchanged through the connector.
Tax agents you appoint: actions they take in your account are recorded against their identity.
4. Why we use your information
Purpose
Legal basis
Providing the Service: registering fiscal devices, signing and submitting receipts to ZIMRA, running the till, generating your obligation calendar, compliance state, VAT drafts and reports
Performance of our contract with you; compliance with tax law obligations that apply to your business
Submitting fiscal documents to ZIMRA's Fiscalisation Data Management System and validating supplier invoices on ZIMRA's public portal at your request
Legal obligation (fiscalisation law) and performance of contract
Sending you compliance reminders, alerts and digests by email, SMS, WhatsApp, push or USSD
Performance of contract; your preferences, which you can change at any time
Taking subscription payments and issuing invoices
Performance of contract; legal obligation to keep accounting records
Securing the Service, preventing fraud and misuse, keeping audit trails
Legitimate interests; legal obligation
Support and communication about the Service
Performance of contract; legitimate interests
Improving the Service, including aggregated statistics about how it is used
Legitimate interests
Classification suggestions (suggesting HS codes and tax treatments for products)
Legitimate interests — see section 6 on how this data is anonymised
Complying with law, court orders and requests from ZIMRA or other authorities
Legal obligation
We do not use your information to make automated decisions that have legal effects on you.
Compliance states, obligation dates and VAT drafts are computed from your data and ZIMRA's
published rules to help you and your accountant; they are not tax assessments, and they never
replace your own or your agent's judgement.
5. Who we share your information with
ZIMRA. We transmit the fiscal documents you create to ZIMRA's FDMS, as fiscalisation law requires, using your registered fiscal device. When you ask us to verify a supplier's invoice, we submit that invoice's identifying details (device ID, date, receipt number, verification code) to ZIMRA's public invoice validation portal. We do not otherwise share your data with ZIMRA, and we have no access to your TaRMS account.
Payment providers you choose to pay with, or that your customers pay you with at the till — only the details needed to process the payment.
Accounting packages and other integrations you connect, and third-party POS or ERP systems you authorise through API keys or webhooks. What is shared is determined by the connector and mappings you configure.
Tax agents you appoint within the Service, for the tax types and period you approve. You can revoke an appointment at any time.
Service providers who help us run the Service under contract and confidentiality obligations: cloud hosting and storage, email, SMS and WhatsApp delivery, USSD aggregation, error monitoring and support tooling. Where a provider processes data outside Zimbabwe, section 9 applies.
Professional advisers, auditors and insurers where necessary.
Authorities, where the law requires it, or to protect the rights, safety or property of TaxComply, our users or others.
A buyer of our business, if TaxComply is sold or merged, subject to this policy.
We do not sell personal information. We do not share your business's
transactional data with other tenants.
6. Anonymised and aggregated data
To suggest HS codes and tax treatments for products, the Service learns from classification
choices made across all tenants. Before any of that data is used for suggestions we remove
the tenant identity, product names, prices and any other identifying detail, and we only use
a pattern once several unrelated tenants have made the same choice. The result cannot be
traced back to you or your products. We may also publish or share aggregated statistics (for
example, the share of sales that are zero-rated in a sector) that do not identify any
business or person.
7. How long we keep information
Fiscal records — receipts, credit and debit notes, fiscal day records, Z-reports, and the supporting audit trail — are kept for at least six years, as required by section 57 of the Value Added Tax Act [Chapter 23:12], section 37B of the Income Tax Act [Chapter 23:06] and section 223 of the Customs and Excise Act [Chapter 23:02]. Older records are moved to secure archive storage but are not deleted within this period, even if you close your account.
Purchase, supplier, compliance and accounting-integration records are kept for the same six-year period, as they support your tax returns.
Account and user information is kept for as long as your account is active and for six years afterwards, so that the fiscal records remain attributable.
Payment records are kept for six years to meet accounting obligations.
Notification logs, delivery logs and technical logs are kept for up to 12 months, unless needed for a security investigation.
Cashier PIN hashes, session tokens and enrolment tokens are deleted when the user or till is removed.
Anonymised classification data (section 6) is not personal information and may be kept indefinitely.
When you close your account we will provide an export of your fiscal records on request,
retain them for the statutory period, and then delete them.
8. How we protect your information
All data is encrypted in transit (TLS) and at rest.
Fiscal device private keys, API secrets, webhook secrets and connector credentials are stored encrypted with keys held separately from the database, and are never shown after creation. For terminal-signed tills, the signing key is generated on the device and never leaves it.
Every fiscal receipt is cryptographically signed and hash-chained, so it cannot be altered after issue without detection.
Access to your account is controlled by roles and permissions you set; every action that changes data is recorded in an audit log you can view.
Our staff can access tenant data only through an audited operator console, for support and fleet monitoring, and never see private keys or secrets.
Backups are encrypted and kept in a separate location; we test restoration regularly.
We follow secure development practices, patch our systems promptly and restrict administrative access.
No system is perfectly secure. If we become aware of a breach affecting your personal
information we will notify you and POTRAZ as the law requires, without undue delay.
9. Where your information is stored
Your data is stored on servers located in Zimbabwe. Some of our service providers (for
example email, SMS and error-monitoring services) may process limited personal information
outside Zimbabwe. Where that happens we ensure the recipient provides an adequate level of
protection, through contractual safeguards that meet the requirements of the Cyber and Data
Protection Act, and we transfer only what the service needs.
10. Your rights
Under the Cyber and Data Protection Act you have the right to:
Access the personal information we hold about you and receive a copy.
Correct information that is inaccurate or incomplete.
Delete your information, subject to the retention periods the law imposes on fiscal and accounting records (section 7).
Object to processing based on our legitimate interests, and to direct marketing.
Restrict processing in certain circumstances.
Withdraw consent where processing is based on consent — for example, notification channels — without affecting processing that took place before.
Lodge a complaint with POTRAZ if you believe we have not handled your information lawfully.
Most account, user and notification information can be viewed and changed directly in the
Service. For anything else, contact our Data Protection Officer (section 14). We will respond
within the period the law allows and will verify your identity before acting on a request.
If you are a customer or supplier of one of our tenants, your rights are exercised against
that business as controller; we will help them respond.
11. Cookies and local storage
Our web application uses strictly necessary cookies and browser storage to keep you signed
in, remember your active fiscal device and preferences, and protect against cross-site
attacks. The till app stores your product catalogue, recent receipts and pending prints on
the device so it can keep working when the connection is poor; it does not store certificates
or secrets. We do not use advertising cookies. If we introduce analytics cookies we will ask
for your consent first.
12. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly
collect personal information from children. If you believe a child has provided us with
information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service or the law changes. We will post the new version
here with a new "last updated" date and, for material changes, notify account owners by email
or in the Service at least 14 days before they take effect.