Privacy Policy
Last updated: 20 May 2026
1. Introduction
Radbit SME Hub ("Radbit," "we," "us," "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at radbitsmehub.co.zw (the "Service").
This policy complies with the Protection of Personal Information Act (POPIA) of South Africa, the Zimbabwe Cyber and Data Protection Act [Chapter 12:07], the General Data Protection Regulation (GDPR) for users in the European Economic Area, and other applicable data protection laws.
2. Information We Collect
2.1 Information You Provide
- Account information: email address, display name, and profile photo
- Business information: business name, industry, business description
- Assessment responses and scores from the Digital Readiness Assessment
- AI-generated content requests and results (business plans, slogans, etc.)
- Community forum posts, replies, and messages
- Payment information (processed by third-party providers — we do not store card details)
2.2 Information Collected Automatically
- Usage data: pages visited, features used, time spent on the Service
- Device information: browser type, operating system, IP address
- Cookies and similar tracking technologies (see Section 5)
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To generate AI-powered business insights and content
- To match you with relevant tenders and business opportunities
- To send notifications about features, tenders, and platform updates
- To process payments and manage your subscription
- To detect and prevent abuse, fraud, or unauthorized access
- To comply with legal obligations
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area, we process your data under the following legal bases:
- Contract performance: to deliver the Service you requested
- Consent: where you have given explicit consent (e.g., marketing)
- Legitimate interests: to improve our Service and ensure security
- Legal obligation: to comply with applicable laws
5. Cookies and Tracking
We use essential cookies for authentication and service operation. We also use analytics cookies to understand how you use our platform.
| Cookie | Purpose | Duration |
|---|---|---|
__session | Authentication session | 1 hour |
cookie_consent | Cookie preference storage | 1 year |
sidebar_state | UI preference (sidebar collapsed state) | 1 year |
You can manage cookie preferences through your browser settings or our cookie consent banner.
6. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service providers: Stripe, PayNow, PayFast, EcoCash (payment processing); Google Cloud (hosting and AI); Sentry (error tracking)
- Legal authorities: where required by law or to protect our rights
- Business transfers: in connection with a merger, acquisition, or sale of assets
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Upon account deletion, we delete or anonymize your data within 30 days, except where retention is required by law (e.g., financial records for 5 years).
8. Your Rights
Under POPIA and GDPR, you have the following rights:
- Right to access: request a copy of your personal data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data ("right to be forgotten")
- Right to restrict processing: limit how we use your data
- Right to data portability: receive your data in a structured format
- Right to object: object to processing based on legitimate interests
- Right to withdraw consent: withdraw consent at any time
To exercise any of these rights, contact us at privacy@radbitsmehub.co.zw or use the Settings → Account & Plan section of the platform.
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including AES-256-GCM encryption for sensitive personal information at rest, TLS 1.3 for data in transit, and regular security audits. However, no method of transmission over the Internet is 100% secure.
10. International Transfers
Your data may be processed on servers located in the United States, South Africa, and the European Union. We ensure appropriate safeguards are in place through standard contractual clauses and adequacy decisions where applicable.
11. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service. Your continued use after changes constitutes acceptance of the updated policy.
13. Contact
For questions, concerns, or data protection requests, contact our Data Protection Officer:
- Email: privacy@radbitsmehub.co.zw
- Data Protection Officer: dpo@radbitsmehub.co.zw
- Zimbabwe: 1st Floor, Union House, 60 Kwame Nkrumah Avenue, Harare
- South Africa: Block B, The Pinnacle, 111 Rivonia Road, Sandton, 2196
For POPIA enquiries, contact the Information Regulator (South Africa): enquiries@inforegulator.org.za. For Zimbabwe Cyber Act enquiries, contact the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ): potraz@potraz.gov.zw.