Data Privacy Policy
Website Data Policy

1. Introduction

Mater Dei Hospital ("Mater Dei Hospital", "we", "us" or "our") respects your privacy and is committed to protecting personal information entrusted to us. This Website Privacy Notice explains how Mater Dei Hospital collects, uses, stores, protects and, where appropriate, shares personal information when you visit or interact with our website.

This Notice applies to personal information collected through the Mater Dei Hospital website, including information submitted through the Contact Us facility, online enquiries, community/forum functionality and other website services.

2. Who We Are

Mater Dei Hospital is a private hospital in Bulawayo, Zimbabwe. The Hospital is responsible for processing personal information collected through its website and is committed to complying with the Cyber and Data Protection Act [Chapter 12:07], applicable regulations and POTRAZ requirements.

Data Protection Officer: Tendai Mutema

Email: tendai@materdeihospital.org

Telephone: +263772850478

Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe; P.O. Box 2133, Bulawayo, Zw

3. Information We May Collect

The current website Contact Us form requests Full Name, Email and the department the visitor is contacting. The website also provides a Community Forum and publishes hospital news, newsletters and other content. We may process information submitted through these features and technical information generated by website use, where applicable.

This may include:

Name; Email and contact details; Department selected; Enquiry/message content; Community account/profile information where applicable; IP address, browser/device information and pages visited where collected; Other information voluntarily provided
  • 4. Health and Medical Information
  • Health and medical information is sensitive personal information. Please do not submit detailed medical information through a general Contact Us form or ordinary online communication channel unless Mater Dei Hospital specifically requests it or provides a secure channel. Where health information is lawfully collected through an authorised service, it will be treated as confidential and protected under applicable law, professional obligations and the Hospital's data protection framework.

5. How We Collect Information

We may collect information when you browse the website, submit the Contact Us form, create or use a community/forum account where applicable, submit a message/comment/enquiry, interact with website facilities, or through technical information generated by website infrastructure where applicable.

6. Why We Use Personal Information

We may process personal information to:

Respond to enquiries; Route Contact Us submissions to the relevant department; Administer community/forum functionality; Provide information about Hospital services; Maintain and improve the website; Maintain information security; Prevent misuse or unlawful activity; Comply with legal and regulatory obligations; Respond to lawful authority requests; Protect patients, visitors, staff and the Hospital

7. Lawful Basis

Mater Dei Hospital shall process personal information only where there is a lawful basis under applicable Zimbabwean data protection law. Depending on circumstances, this may include providing a requested service, complying with legal/regulatory obligations, protecting vital interests, pursuing a legitimate lawful operational purpose, or another lawful basis. Where consent is required, it will be obtained appropriately.

8. Sharing of Personal Information

Mater Dei Hospital does not sell personal information. Information may be shared where lawful, necessary and appropriate, including with authorised Hospital departments, healthcare professionals, website/technology service providers, advisers, regulators, government authorities or other competent authorities where legally required or permitted. Appropriate confidentiality, security and data protection obligations should apply to processors acting on the Hospital's behalf.

9. Cross-Border Processing

Where personal information is transferred, stored or accessed outside Zimbabwe, Mater Dei Hospital will assess applicable legal requirements and implement appropriate safeguards and authorisations as required by Zimbabwean data protection law.

10. Data Security

We take reasonable and appropriate technical and organisational measures to protect personal information against unauthorised access, unlawful disclosure, loss, theft, accidental destruction, alteration, misuse and other unauthorised processing. No internet transmission can be guaranteed completely secure, so users should exercise appropriate caution.

11. Retention

Website personal information shall be retained only as long as reasonably necessary for the purpose collected and/or as required by law, regulatory, contractual or legitimate operational requirements. When no longer required and disposal is legally permissible, it shall be securely deleted, destroyed or anonymised.

12. Cookies and Analytics

The website may use cookies or similar technologies for functionality, security, performance and, where applicable, analytics. The exact cookies and analytics services used by the live website must be confirmed by the website administrator before publication. Users may control cookies through browser settings, subject to website functionality.

13. Community Forum and User-Generated Content

The website currently provides a Community Forum with public discussions and a registered user profile facility. Information posted publicly may be visible to other users. Users should not publish patient information, medical records, identification numbers, contact details or other confidential personal information about themselves or another person in public discussions. The Hospital should ensure forum registration, moderation, deletion and retention arrangements are documented.

14. Children's Information

Mater Dei Hospital recognises the importance of protecting children's personal information. Where website services process children's information, appropriate safeguards and applicable requirements concerning parental or legal guardian involvement and consent shall apply.

15. Third-Party Websites and Embedded Content

The website may contain links to or embedded content from third-party services. This Notice does not govern third-party websites. Users should review external privacy notices before submitting information. The Hospital should maintain an inventory of third-party website services and embedded content.

16. Your Data Protection Rights

Subject to applicable law and lawful limitations, you may have rights relating to:

Being informed about processing; Access to your personal information; Correction of your personal information; Objection to certain processing; Deletion where legally applicable; Withdrawal of consent where consent is the lawful basis; Other rights provided by Zimbabwean law

17. How to Exercise Your Rights

Requests should be directed to the Data Protection Officer. You may be required to provide information to verify identity and locate relevant information. Requests will be handled in accordance with applicable legal requirements and the Hospital's Data Subject Request Procedure.

Data Protection Officer: Tendai Mutema

Email: tendai@materdeihospital.org

Telephone: +263772850478

18. Data Breaches

Mater Dei Hospital maintains procedures for identifying, managing, investigating and responding to personal-information breaches. Where notification to POTRAZ, affected data subjects or another competent authority is required by law, the Hospital shall comply with applicable notification requirements.

19. Data Protection by Design

Mater Dei Hospital considers privacy and data protection when introducing or changing website systems, online forms, community/forum functionality, technologies and services involving personal information. Where appropriate, the Hospital will undertake a Data Protection Impact Assessment (DPIA).

20. Changes to This Notice

This Notice may be updated to reflect changes in law, regulatory requirements, website functionality, Hospital services or privacy practices. The latest version will be published on the website, with the Last Updated date revised accordingly.

21. Complaints

If you are concerned about how Mater Dei Hospital has handled your personal information, please contact the DPO first. You may also have the right to lodge a complaint with POTRAZ, as the designated Data Protection Authority, in accordance with applicable law and regulatory procedures.

22. Contact Us

Mater Dei Hospital

Physical Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe

Postal Address: P.O. Box 2133, Bulawayo, Zimbabwe

Telephone: +263 292 240000 / 4

General Email: info@materdeihospital.org

Data Protection Officer: Tendai Mutema

DPO Email: tendai@materdeihospital.org

23. Governing Law

This Privacy Notice shall be interpreted in accordance with the laws of Zimbabwe, including the Cyber and Data Protection Act [Chapter 12:07] and applicable regulations and regulatory requirements.