
ConduitID, a product of Conduit Technologies (Private) Limited · Draft — pending legal review
Real compliance item, not just document language: Zimbabwe’s Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 require entities processing personal data to register as a data controller with POTRAZ and appoint a Data Protection Officer. This is a genuine business action item to raise with counsel.
ConduitID is operated by Conduit Technologies (Private) Limited, a company incorporated in Zimbabwe (registration number 122721A0262026), based in Harare. For the purposes of the Cyber and Data Protection Act, Conduit Technologies acts as the data controller for personal information processed through the Platform, except where a veterinary practice acts as controller of its own clinical notes (Section 6). Once our Data Protection Officer appointment is complete, their contact details will be added here.
We’ve broken this down by category rather than lumping everything together as generic "user data," since different categories carry different obligations under Zimbabwean law.
User account data: full name, email, phone number, password (hashed — we cannot see it ourselves, including for support), account role and status, subscription tier, communication preferences, emergency secondary contact details.
Animal identity data: name, species, breed, colour, sex, date of birth, distinguishing features, photographs, the ConduitID digital identifier, microchip number and which external database(s) it’s registered on (where a vet has recorded this), dam/sire linkage, and full ownership history including any transfer’s method, date, and parties.
Health and veterinary data: vaccination records, weight logs, symptom reports, diagnoses, treatment records, veterinarian notes, parasite treatment history, nutrition profile data.
Location data: GPS coordinates from a connected tracking device, geofence boundaries and entry/exit events, historical movement logs.
AI interaction data: the questions and messages you send to a ConduitID AI feature, the AI’s responses including any proposed action and whether you confirmed it, and the underlying animal or account data assembled into context to generate a response.
Technical data: IP address, device and browser information, session and login logs, feature usage logs, error and crash logs.
Payment data: we do not store your full card number or mobile-money PIN — payment processing is handled by our third-party processor (currently Paynow). We retain transaction status, amount, currency, date, and payment method type for accounting and support.
When you use a ConduitID AI feature, the relevant question and supporting context is sent to our third-party AI model provider’s API to generate a response. That provider processes this data as a processor acting on our instructions, not as an independent controller. We select providers who contractually commit not to use API-submitted data to train their general-purpose models — a contractual commitment, not something we can independently verify at a technical level. Where we change providers or materially change what’s sent, we will update this section.
| Category | Purpose | Legal Basis |
|---|---|---|
| User Account Data | Account creation, authentication, communicating with you | Necessary to perform our contract with you |
| Animal Identity Data | Operating the Animal Profile and Digital Identity system, including transfer | Contract necessity; your consent where provided |
| Health and Veterinary Data | Reminders, AI health features, veterinary record-keeping | Your explicit consent, reaffirmed each relevant use |
| Location Data | GPS tracking and geofence alerts you choose to enable | Explicit, opt-in consent — off by default |
| AI Interaction Data | Powering the Care Profile assistant and account-wide adviser | Your consent, by choosing to use these optional features |
| Technical Data | Security, fraud prevention, service improvement | Our legitimate interest in a secure, functioning Platform |
| Payment Data | Processing subscriptions and one-time payments | Contract necessity |
Where we process sensitive personal data — which under the Act includes health data — we rely on your written consent, given through accepting these policies and your affirmative use of features involving health information, except in the narrow situations in Section 8 (Emergency Access) where processing may be necessary to protect vital interests.
This is one of the most important parts of this policy, and we’ve tried to make it as concrete as possible rather than leaving it vague.
Owner: full access to their own Animal Profile(s) — identity, health, location, ownership history. This is the default, foundational access level.
Registered veterinarian on the Platform: access to the specific profile(s) they are treating, granted by the Owner booking an appointment or explicitly sharing access. No blanket access to animals they are not treating. All vet access is logged, including microchip verification specifically.
ZNSPCA and authorised welfare organisations: access limited to what’s necessary to respond to a specific report, or emergency access under Section 8. Not standing, unrestricted access to all profiles.
Other pet owners / the public: no access to another Owner’s profile data, except what an Owner explicitly makes public — a scanned public tag profile intentionally shows limited information, not full health records or precise live location.
A new owner during an ownership transfer: zero access while a transfer is pending — the intended new owner receives only a notification. Access only transfers at the moment they explicitly accept. If declined, or the request expires after seven days, no data beyond their own name and email (referenced in the notification) has been shared.
An administrator: can access data as necessary for support, security, fraud remediation, and — in narrow, logged circumstances — to directly reassign ownership where normal owner-consent cannot resolve a genuine dispute or data error. Every such action requires a stated reason and is permanently logged.
Conduit Technologies staff generally: access limited to what’s necessary for support, security, fraud investigation, or platform operation, on a need-to-know basis. We do not sell, and do not otherwise provide, your data to third parties for their own marketing purposes.
What requires your consent: enabling GPS tracking and sharing location beyond the Owner (opt-in, off by default); sharing a profile with a vet outside the normal booking flow; using any AI feature (implicit in choosing to use it); any use of your data beyond operating the Platform, such as anonymised research use, which we will seek explicit consent for and update this policy before doing.
What must remain confidential: your account password, which we cannot read; your payment credentials, held by our processor and not by us; and any profile data you have not chosen to share.
ConduitID does not sell your personal data, or your animal’s data, to third parties. Where we share data with vets, shelters, ZNSPCA, or service providers who help us operate the Platform — our hosting provider, email and SMS providers, our payment processor, our AI model provider — this is done to provide the service you’ve asked for, or to operate the Platform itself, under contractual terms limiting that provider’s use of the data. It is never a commercial data sale.
We are treating this area with particular care, and this section will likely be refined further once we have specific legal counsel input on the classification of animal-specific health data, as distinct from the personal data of the human owner, under Zimbabwean law.
Self-reported entries (an owner logging a symptom, a home treatment, a weight measurement) are the Owner’s own responsibility for accuracy. Clinical entries made by a verified veterinarian are that veterinarian’s professional responsibility, exactly as their own practice records would be. AI-generated health summaries are neither owner-authored nor vet-authored, clearly distinguishable in the interface, and never treated as a clinical record in their own right.
Where a human is identifiable in connection with health data — an owner’s name attached to a treatment record, a household member mentioned in a vet’s note — that identifiable information is treated as personal data under the Act, and where it reveals or relates to health context, we treat it with the elevated protection sensitive data requires.
An honest, open question we are not pretending to have resolved: the Act’s core protections are built around the personal data of natural persons. An animal’s own health record does not obviously fall within that framework except insofar as it’s linked to an identifiable human owner. We are treating ConduitID’s animal health records with genuinely careful, consent-based handling regardless of how this technical classification is ultimately resolved by counsel.
GPS tracking is off by default, and only active if you connect a compatible device and explicitly enable it for that animal. You can disable tracking and delete historical location data at any time through account settings. We do not share precise location data publicly under any circumstance — a public lost-animal listing may show a general area if you choose, never live coordinates. Geofence entry/exit events are logged for as long as that geofence remains active.
ConduitID includes a real, working ownership transfer feature, and because it moves an animal’s entire record — identity, health history, and ownership history — from one person’s account to another, it deserves explicit treatment here.
When a current Owner initiates a transfer, the record is temporarily locked against further edits, but no data is yet shared with the intended new owner — they receive only a notification. Only upon explicit acceptance does the new owner gain access to the full record; if declined or expired after seven days, no ongoing access has been granted. Upon a completed transfer, any access the previous owner had granted to others is automatically revoked — the new owner starts from a clean slate and must re-grant any access they wish to extend.
In narrow circumstances — a genuine dispute, a data-entry correction, or fraud remediation — an administrator may directly reassign ownership without the two-step consent process. This always requires a stated, logged reason, and the animal’s ownership-history record reflects it the same way a normal transfer would.
Where a genuine emergency exists — a lost, injured, or endangered animal, or a credible welfare concern — a limited cascade applies: Owner → Owner’s designated secondary contact (if set) → treating veterinarian → nearest ZNSPCA branch or equivalent welfare body. Only the minimum information necessary is disclosed. Access must be activated by a party with a legitimate basis, and every activation is logged with who accessed what, when, and why. Access is time-limited to the emergency itself.
| Data Category | Retention Approach |
|---|---|
| Account login credentials, contact details | Deleted or anonymised within a reasonable period of account deletion |
| Animal identity core record | May persist beyond account deletion given ConduitID’s purpose as a persistent identity system, unless deletion of that profile is specifically requested |
| Health and veterinary history | Retained as part of the animal’s ongoing record for future caregivers, unless full deletion is requested |
| Ownership and transfer history | Retained as part of the animal’s identity record — often the relevant evidence in a future dispute |
| GPS and location history | Retained only while tracking remains enabled, or until deleted directly |
| AI conversation history | Retained to support ongoing conversational context; deletable on request |
| Technical and error logs | Retained only as long as necessary for security monitoring and diagnosis, then purged on a rolling basis |
Where Zimbabwean law or a legitimate business purpose, such as defending against a legal claim, requires longer retention, we will do so, limited to what’s genuinely necessary for that purpose.
Under the Cyber and Data Protection Act, you have rights including: the right to be informed when your data is collected; the right to access the personal data we hold about you; the right to correction of inaccurate data; the right to object to certain processing; and the right to request deletion in certain circumstances, subject to Section 11. To exercise these rights, contact us through Section 16. We will respond within a reasonable time and may need to verify your identity for a request involving sensitive data. If you believe we have not handled your data appropriately, you have the right to lodge a complaint with POTRAZ, Zimbabwe’s data protection authority.
ConduitID is designed for use by adults. Pets are, however, often a family matter, and a minor may be photographed in content an adult submits, or mentioned incidentally. We do not knowingly collect account information directly from a minor, and accounts are intended to be created and controlled by an adult. Content incidentally including a minor is treated with the same access controls as any other content — not given special public visibility — and we do not use any incidental data about a minor for marketing or profiling. If you believe we hold information about a minor that shouldn’t be there, contact us and we will investigate and remove it. As ConduitID’s registration is adult-only by design, we do not currently directly process children’s personal data as a core function of the Platform, but will continue to review this as features develop.
Real, specific controls, not just a general assurance: encrypted storage and authenticated access controls; duplicate-microchip detection at registration, with any attempt logged (including IP and device information) and flagged for admin review; full audit logging of sensitive actions including microchip verification, ownership transfer, and emergency access, each logged with who, when, and why; role-based access restrictions.
An honest limitation, not papered over: our strongest identity-fraud protections are anchored to the microchip number, where one exists. For an animal without a chip — the majority on the Platform today — registration relies on an owner’s attestation rather than independent verification. We consider this a known limitation we intend to continue improving, not a solved problem.
In the event of a breach posing a real risk to your rights or freedoms, we will investigate and contain it as quickly as reasonably possible, notify POTRAZ as required, and notify affected users directly where the breach poses a meaningful risk, describing what happened and what we’re doing. Account compromise from your own failure to safeguard your password is not treated as a ConduitID breach, though we’ll still help you secure your account.
No AI feature on ConduitID writes a change to your animal’s record without your explicit confirmation — a proposed action is exactly that, proposed, until you approve it. No decision that meaningfully affects your legal rights, such as an account suspension or an administrator-initiated ownership transfer, is made by an automated system alone; these are taken by a human administrator. You may ask at any time whether specific content was AI-generated — this is generally already indicated in the interface.
Some of ConduitID’s technical infrastructure — cloud hosting, and certain third-party providers including our AI model provider — may be located outside Zimbabwe. Where data is transferred to a country that does not assure an adequate level of protection, we rely on one or more legal bases recognised under Section 29 of the Cyber and Data Protection Act, which may include your consent or necessity for performing our contract with you. We are reviewing our specific infrastructure providers against this requirement as part of ongoing legal compliance work, and this section will be updated with more specific detail once that review, and related counsel input, is complete.
Questions about this Privacy Policy, or requests to exercise your data rights, can be directed to Conduit Technologies (Private) Limited through the contact details provided on the Platform.
We may update this Privacy Policy from time to time, particularly as we complete formal legal review and as the Platform’s features develop. Material changes will be communicated with reasonable advance notice, and the date at the top of this document will always reflect the most recent substantive revision.
Questions? support@conduitid.net