1. Introduction
Mater Dei Hospital ("Mater Dei Hospital", "we", "us" or "our") respects your privacy and is committed to protecting personal information entrusted to us. This Website Privacy Notice explains how Mater Dei Hospital collects, uses, stores, protects and, where appropriate, shares personal information when you visit or interact with our website.
This Notice applies to personal information collected through the Mater Dei Hospital website, including information submitted through the Contact Us facility, online enquiries, community/forum functionality and other website services.
2. Who We Are
Mater Dei Hospital is a private hospital in Bulawayo, Zimbabwe. The Hospital is responsible for processing personal information collected through its website and is committed to complying with the Cyber and Data Protection Act [Chapter 12:07], applicable regulations and POTRAZ requirements.
Data Protection Officer: Tendai Mutema
Email: tendai@materdeihospital.org
Telephone: +263772850478
Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe; P.O. Box 2133, Bulawayo, Zw
3. Information We May Collect
The current website Contact Us form requests Full Name, Email and the department the visitor is contacting. The website also provides a Community Forum and publishes hospital news, newsletters and other content. We may process information submitted through these features and technical information generated by website use, where applicable.
This may include:
- 4. Health and Medical Information
- Health and medical information is sensitive personal information. Please do not submit detailed medical information through a general Contact Us form or ordinary online communication channel unless Mater Dei Hospital specifically requests it or provides a secure channel. Where health information is lawfully collected through an authorised service, it will be treated as confidential and protected under applicable law, professional obligations and the Hospital's data protection framework.
5. How We Collect Information
We may collect information when you browse the website, submit the Contact Us form, create or use a community/forum account where applicable, submit a message/comment/enquiry, interact with website facilities, or through technical information generated by website infrastructure where applicable.
6. Why We Use Personal Information
We may process personal information to:
7. Lawful Basis
Mater Dei Hospital shall process personal information only where there is a lawful basis under applicable Zimbabwean data protection law. Depending on circumstances, this may include providing a requested service, complying with legal/regulatory obligations, protecting vital interests, pursuing a legitimate lawful operational purpose, or another lawful basis. Where consent is required, it will be obtained appropriately.
8. Sharing of Personal Information
Mater Dei Hospital does not sell personal information. Information may be shared where lawful, necessary and appropriate, including with authorised Hospital departments, healthcare professionals, website/technology service providers, advisers, regulators, government authorities or other competent authorities where legally required or permitted. Appropriate confidentiality, security and data protection obligations should apply to processors acting on the Hospital's behalf.
9. Cross-Border Processing
Where personal information is transferred, stored or accessed outside Zimbabwe, Mater Dei Hospital will assess applicable legal requirements and implement appropriate safeguards and authorisations as required by Zimbabwean data protection law.
10. Data Security
We take reasonable and appropriate technical and organisational measures to protect personal information against unauthorised access, unlawful disclosure, loss, theft, accidental destruction, alteration, misuse and other unauthorised processing. No internet transmission can be guaranteed completely secure, so users should exercise appropriate caution.
11. Retention
Website personal information shall be retained only as long as reasonably necessary for the purpose collected and/or as required by law, regulatory, contractual or legitimate operational requirements. When no longer required and disposal is legally permissible, it shall be securely deleted, destroyed or anonymised.
12. Cookies and Analytics
The website may use cookies or similar technologies for functionality, security, performance and, where applicable, analytics. The exact cookies and analytics services used by the live website must be confirmed by the website administrator before publication. Users may control cookies through browser settings, subject to website functionality.
13. Community Forum and User-Generated Content
The website currently provides a Community Forum with public discussions and a registered user profile facility. Information posted publicly may be visible to other users. Users should not publish patient information, medical records, identification numbers, contact details or other confidential personal information about themselves or another person in public discussions. The Hospital should ensure forum registration, moderation, deletion and retention arrangements are documented.
14. Children's Information
Mater Dei Hospital recognises the importance of protecting children's personal information. Where website services process children's information, appropriate safeguards and applicable requirements concerning parental or legal guardian involvement and consent shall apply.
15. Third-Party Websites and Embedded Content
The website may contain links to or embedded content from third-party services. This Notice does not govern third-party websites. Users should review external privacy notices before submitting information. The Hospital should maintain an inventory of third-party website services and embedded content.
16. Your Data Protection Rights
Being informed about processing; Access to your personal information; Correction of your personal information; Objection to certain processing; Deletion where legally applicable; Withdrawal of consent where consent is the lawful basis; Other rights provided by Zimbabwean law
17. How to Exercise Your Rights
Requests should be directed to the Data Protection Officer. You may be required to provide information to verify identity and locate relevant information. Requests will be handled in accordance with applicable legal requirements and the Hospital's Data Subject Request Procedure.
Data Protection Officer: Tendai Mutema
Email: tendai@materdeihospital.org
Telephone: +263772850478
18. Data Breaches
Mater Dei Hospital maintains procedures for identifying, managing, investigating and responding to personal-information breaches. Where notification to POTRAZ, affected data subjects or another competent authority is required by law, the Hospital shall comply with applicable notification requirements.
19. Data Protection by Design
Mater Dei Hospital considers privacy and data protection when introducing or changing website systems, online forms, community/forum functionality, technologies and services involving personal information. Where appropriate, the Hospital will undertake a Data Protection Impact Assessment (DPIA).
20. Changes to This Notice
This Notice may be updated to reflect changes in law, regulatory requirements, website functionality, Hospital services or privacy practices. The latest version will be published on the website, with the Last Updated date revised accordingly.
21. Complaints
If you are concerned about how Mater Dei Hospital has handled your personal information, please contact the DPO first. You may also have the right to lodge a complaint with POTRAZ, as the designated Data Protection Authority, in accordance with applicable law and regulatory procedures.
22. Contact Us
Mater Dei Hospital
Physical Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe
Postal Address: P.O. Box 2133, Bulawayo, Zimbabwe
Telephone: +263 292 240000 / 4
General Email: info@materdeihospital.org
Data Protection Officer: Tendai Mutema
DPO Email: tendai@materdeihospital.org
23. Governing Law
This Privacy Notice shall be interpreted in accordance with the laws of Zimbabwe, including the Cyber and Data Protection Act [Chapter 12:07] and applicable regulations and regulatory requirements.