Privacy and data protection notice
Hospitals.co.zw is designed as a facility directory, not a patient-record system. We do not ask for, collect or sell patient diagnoses, medical histories or clinical records.
Who controls the data
The service is maintained by OnCloud Africa. Privacy, access, correction, objection or deletion requests can be sent to sales@oncloud.africa. Zimbabwe’s Data Protection Authority is POTRAZ.
Information processed
- Facility information: institutional names, addresses, public business telephone numbers, services, map coordinates and source status.
- Usage information: pages, searches, filters, approximate network/device data and outbound clicks processed through Google Analytics, Google AdSense and Cloudflare.
- Location: precise browser location is used only after permission to calculate distance in the browser; it is not intentionally written to our facility database.
- Messages: information voluntarily supplied in correction, claim, advertising or licensing emails.
Purpose and safeguards
We process information to operate and secure the directory, correct listings, measure usefulness, prevent abuse and fund the service through advertising or clearly labelled commercial services. Access to the canonical dataset is restricted; public exports omit email addresses, detailed provenance and other bulk-harvest-enabling fields. HTTPS, least-privilege repository access, validation, backups and correction logs reduce risk.
Advertising, cookies and international providers
Google AdSense and Analytics may use cookies or similar identifiers and may process data outside Zimbabwe. Cloudflare provides hosting, security and delivery. Visitors in the EEA, UK and Switzerland must be shown Google’s certified consent mechanism where required. You can restrict cookies in your browser or use Google’s ad controls.
Zimbabwe law
The Cyber and Data Protection Act [Chapter 12:07] treats information about identifiable people—including health information—as personal or sensitive data. Facility facts are generally institutional data, but personal contact or representative information is handled conservatively. Applicable controller registration, licensing, security, breach-notification and cross-border-transfer duties are reviewed against POTRAZ requirements, including S.I. 155 of 2024. This notice is operational information, not legal advice.
Retention and rights
Correction and commercial correspondence is retained only while needed for the request, records and legal obligations. You may request access, correction or deletion of personal information we control, subject to lawful retention needs. If unresolved, you may contact POTRAZ.