Privacy Policy & Data Protection
Effective Date: 1 January 2026 • Last Reviewed: September 2026 • Version 2.4
EPIC Public Accountants, Auditors & Chartered Secretaries is committed to upholding the highest standards of professional secrecy, data integrity, and privacy. All personal and corporate data collected through this portal is processed strictly in accordance with the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe, the Public Accountants and Auditors Act [Chapter 27:12], and international best practice data protection principles.
1. Identification of the Data Controller
The designated Data Controller responsible for the processing of your personal and corporate information is:
EPIC Public Accountants, Auditors & Chartered Secretaries
Suite 508, 5th Floor, CIPF Centre / Bradlow's Building, Cnr Jason Moyo & 9th/10th Avenue, Bulawayo, Zimbabwe
Data Protection Officer (DPO): Compliance & Legal Secretariat
Direct Contact: Landline: 0292262128 | Calls: 0716900138 | Email: admin@epicnetworkgroup.co
2. Categories of Data We Collect
In line with the statutory principle of Data Minimization, we only collect data strictly necessary to deliver professional corporate accounting, audit, tax, and secretarial engagements:
- Identity & Statutory Records: Full legal names, National Identity Card / Passport numbers (required by the Chief Registrar of Companies for CR6 and CR14 director lodgements under COBE [Cap 24:31]), corporate registration numbers, and BP/TIN tax identification numbers.
- Contact Information: Official corporate emails, physical business addresses, designated executive contact numbers, and WhatsApp numbers for critical filing reminders.
- Financial & Fiscal Documentation: Uploaded management accounts, general ledgers, bank statements, asset registers, payroll schedules, and ZIMRA TaRMS tax clearance certificates (ITF 263) supplied for audit verification or tax return preparation.
- Portal Authentication & Audit Logs: Secure password hashes (salted using PBKDF2/SHA-256), session identifiers, transaction references, and timestamped action histories for fraud prevention.
3. Lawful Bases for Processing
We process your personal and commercial data on the following lawful statutory grounds:
- Contractual Necessity: Performing our scope of work (e.g. preparing an external statutory audit, lodging an ITF 12C tax return, reserving a company name, or drafting statutory minutes).
- Statutory Legal Obligations: Fulfilling mandatory reporting obligations under the Income Tax Act [Cap 23:06], the Companies and Other Business Entities Act [Cap 24:31], and the Money Laundering and Proceeds of Crime Act [Cap 9:24].
- Legitimate Professional Interests: Securing the portal against cyber attacks, preventing unauthorized corporate identity theft, and maintaining monotonic financial audit trails.
4. Absolute Confidentiality & Non-Disclosure
We do not sell, rent, commercialize, or trade your personal or corporate data with any third party, broker, or advertising network.
Data is disclosed strictly to authorized statutory agencies only to the extent required to execute your mandate:
- The Zimbabwe Revenue Authority (ZIMRA) for statutory returns, assessments, and tax clearances.
- The Chief Registrar of Companies and Intellectual Property for statutory filings and certifications.
- The National Social Security Authority (NSSA) and PRAZ where statutory registration services are engaged.
5. Storage, Security & Retention
All uploads and database records are held within isolated, encrypted server environments. Strict role-based access control ensures that only authorized chartered partners and audit managers can inspect sensitive client records.
Under Section 37 of the Income Tax Act [Chapter 23:06] and the Companies and Other Business Entities Act, accounting vouchers, audit working papers, and statutory books must be retained for a mandatory minimum period of six (6) years following the financial year-end to which they relate. Records outside statutory retention horizons are purged securely upon request.
6. Your Statutory Rights
Under the Cyber and Data Protection Act [Chapter 12:07], clients and data subjects retain the following rights:
- Right of Access: Request a copy of all personal records and uploaded statutory documents held on your portal profile.
- Right to Rectification: Require the immediate correction of inaccurate director names, registration numbers, or addresses.
- Right to Erasure: Request the deletion of profile accounts, subject to mandatory statutory tax and audit preservation horizons.
- Right to Lodge a Complaint: Right to lodge a formal complaint with the Data Protection Authority under the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
7. Contact the Compliance Office
For data protection inquiries, formal Subject Access Requests (SARs), or data rectification, contact our practice secretariat at:
EPIC Compliance & Data Secretariat
Email: admin@epicnetworkgroup.co
Telephone: Landline: 0292262128 / Direct Calls: 0716900138
Suite 508, 5th Floor, CIPF Centre / Bradlow's Building, Bulawayo, Zimbabwe