ZRA Gateway — Privacy Policy
1. What we collect
- Account data — your name, email, password (stored hashed) and business details (company name, ZRA TPIN, branch codes, device serials, contact details).
- Fiscal data — the invoices you fiscalise: line items, amounts, taxes, and the signatures/QR data ZRA returns. Customer TPINs appear where you include them on invoices.
- Billing data — your plan, payments and payment references. Card and mobile-money details are processed by DPO Pay and never stored by us.
- Technical data — API request logs (correlation IDs, timestamps, result codes) kept for troubleshooting and security.
2. How we use it
To transmit your invoices to ZRA Smart Invoice, operate your subscription (billing, receipts, renewal and trial notices), secure the platform (rate limiting, audit logs), support you, and meet legal record-keeping duties under Zambian tax law.
3. Sharing
- ZRA — invoice data is transmitted to the Zambia Revenue Authority; that is the Service's purpose.
- DPO Pay — payment processing.
- POS partners — if a software partner provisions or operates your account, they see the data of the merchants they manage.
- We do not sell personal data.
4. Retention
Fiscal records are retained for the period required by Zambian tax law even after account closure. API logs are pruned automatically (currently after 90 days). Other account data is deleted or anonymised on verified request once legal duties allow.
5. Security
Data is encrypted in transit (TLS), API keys are stored hashed, access is role- and tenant-scoped, and payment collection is delegated to DPO Pay. No system is perfectly secure — report suspected issues to the contact below.
6. Your rights
Subject to the Data Protection Act of Zambia, you may request access to, correction of, or deletion of your personal data, and object to processing that is not required for tax-law compliance. Contact us to exercise these rights.
Privacy contact: billing@zragateway.zm · Terms of Service