1. Introduction

Steward Bank Limited (“Steward Bank” or “the Bank”) understands the importance of protecting your personal information. This Privacy Statement outlines how we collect, use, and safeguard your data when you share it with the Bank and entrust us with your information. We are committed to maintaining the highest standards of security and privacy for our customers.

This Privacy Statement details how we collect, use, and share your personal information, including the types of data we gather, our methods for doing so, the reasons for sharing it, our security measures, and your choices regarding our use of your data. This notice applies to our websites, mobile applications, and services that display this Privacy Statement.

2. Information we collect

Throughout your relationship with us, and for a period thereafter as required by our data retention policies, we collect and process various categories of personal information. This information is essential for providing our services and meeting our legal and regulatory obligations. The types of information we may collect include:

2.1 Identification and Contact Information: This includes basic details such as your name, address, date of birth, contact details, nationality, government-issued identifiers (e.g., national identification numbers, driver’s license numbers), and signatures.

2.2 Background Information: We may collect background information, including results of background checks and information regarding criminal convictions, where permitted by applicable law.

2.3 Biometric Information: In certain circumstances, we may collect biometric information such as voice prints, iris or retina scans, facial geometry, and palm prints or fingerprints.

2.4 Commercial Information: This includes details related to your interactions with our services, such as purchase and transaction history, product reviews, travel and vacation information, and participation in sweepstakes and contests.

2.5 Communications Data: We may collect information related to your communications with us, including the content of emails, text messages, and other correspondence, as well as call logs and calendar information where Steward Bank is a party to the exchange.

2.6 Demographic Information: We may collect demographic information such as age, gender, citizenship, ethnicity, date of birth, family or marital status, household income, education, professional and employment information, family health information, number of children, vehicle ownership, and information about software or virtual assets owned.

2.7 Device and Online Identifiers: This includes information related to your online activity and devices, such as account login details, Internet Protocol (IP) addresses, smart device information, location coordinates, online and mobile banking security authentication data, mobile phone network information, search history, site visits, and spending patterns.

2.8 Financial Information: We collect financial information such as account and transaction details and history, as well as payment and payee information.

2.9 Financial Circumstances: We may collect information about your financial circumstances, including personal wealth, assets and liabilities, proof of income and expenditure, credit and borrowing history, and financial needs and goals.

2.10 Sensory Information: This may include visual images and personal appearance (e.g., photos, copies of passports, CCTV images), voice recordings, and fingerprints.

2.11 Transaction Information: Our payment services and third-party companies may collect information related to transactions performed by our account holders.

In some limited circumstances, we may process sensitive information to improve our services, comply with legal obligations, or serve the public interest. This may include information about:

2.12 Race or ethnicity: To ensure our services are accessible to all customers.

2.13 Political opinions, religious or philosophical beliefs, or trade union membership: Only when required by law or for legitimate public interest reasons.

We will always handle this information responsibly and in accordance with applicable laws and regulations.

3. Use of your information

We use your personal data to provide our products and services, manage our client relationships, and operate our business effectively. This use is based on several legal grounds, including:

3.1.1 Contractual Necessity: We use your information to fulfil our contractual obligations to you or to take necessary steps before entering into a contract.

3.1.2 Legitimate Interests: We may use your information to pursue our legitimate business interests or those of a third party, provided those interests do not override your rights and freedoms.

3.1.3 Legal Obligations: We use your information to comply with applicable laws and regulations.

3.1.4 Consent: We may use your information for specific purposes, such as sharing it with a third party at your request or for direct marketing communications (by us or specified third parties), when you have given us your explicit consent.

3.2 Any disclosure of your information shall be in accordance with applicable law and regulations. Steward Bank shall assess and review each application for information and may decline to grant such information to the requesting party.

3.3 When sharing your information with recipients in other jurisdictions, we will ensure that they adhere to similar privacy protection requirements as we do – either by law or by legal agreement. We will not sell your information to third parties and will only market to you in line with our legal obligations and your marketing preference, using the communication method you chose.

4. How we obtain your information

We collect personal data directly from a variety of sources, including:

4.1 Directly from you: When you interact with us by phone, in branch, or through our online channels (website, mobile apps, online banking, or electronic messaging).

4.2 From third parties: This may include service providers, credit reference and fraud prevention agencies, law enforcement and government bodies, industry and trade associations, and other banks (where legally permitted).

4.3 Through your account activity: Information generated by your use of our services, such as payment transactions and payee details.

4.4 From your device and technology: Data from the devices you use to access our services (e.g., device data, location, IP address, or phone number) and information about how you use those services.

4.5 From publicly available sources: Such as press reports, company registers, and online search engines.

4.6 From public social media: Information you have chosen to share publicly on platforms like Facebook and Twitter.

5. Sharing your information

To effectively provide our services and meet legal obligations, we may share your personal data with certain internal and external parties, including:

5.1 Steward Bank Subsidiaries: Information may be shared within our corporate group to improve operational efficiency and provide integrated services.

5.2 Service Providers: We engage trusted third-party service providers who assist us in delivering our products and services. These providers are contractually obligated to protect your information.

5.3 Regulatory Bodies: We may disclose information to regulatory bodies or when legally required to comply with applicable laws and regulations or in the public interest.

5.4 Banking and Financial services: In certain circumstances, we may share information with other financial institutions, such as correspondent banks, remittance partners, stock exchanges, and credit rating agencies, to facilitate transactions and provide specific financial services, as outlined in relevant agreements.

5.5 Account and Service Management: We may share information with service providers and agents who assist us in managing your accounts and providing related services.

We ensure that any sharing of your information is conducted securely and in accordance with applicable data protection laws.

6. Your rights

You have certain rights regarding the personal information we hold about you. The table below outlines these rights and explains when they apply.

Rights

Description

6.1     Access – You have a right to get access to the personal information we hold about you.

If you would like a copy of the personal information we hold about you, or for more information on how to get access to your information and the documents we need you to submit, please visit our nearest branch or please contact us at  Steward Bank on +2638677020267

6.2    Rectification – You have the right to correct any inaccuracies in your personal information and to complete any information that is missing.

If you believe that any of the information that we hold about you is inaccurate, you have a right to request that we restrict the processing of that information and to rectify the inaccurate personal information.

6.3    Right to be informed-You have a right to know what specific types of personal data is being collected, why it is being collected, how the data will be used and how it will stored.

This information is provided in this statement.

6.4    Right to give and withdraw your consent.

You have a right to object to us processing your personal information. Please note that if you object to us processing your information, we may have to suspend the operation of your account and/or the products and services we provide to you.

6.5    Right to Deletion- You have a right to request that we delete false or misleading information you feel we hold about you

Please note that if you request that we delete your information, we may have to suspend the operation of your account and/or the products and services we provide to you.

6.6    Right to Complaint- You have the right to lodge a complaint with the Data Protection Authority if you believe your rights have been infringed.

You can send your complaints to the

Data Protection Officer.

Steward Bank

79 Livingstone Ave,

Harare

Contact number: + 2638677020267 or send an email to dataprotection@stewardbank.co.zw

6.7    You have a right to object to automated decision-making or profiling.

Under certain circumstances, the Bank adopts automated processing which may be required to offer you services. Please note that if you request that we no longer use automated processing on your personal information, we may fail to provide you with the services you may have requested and may have to suspend the operation of your account and/or the products and services we provide to you.

6.8    Marketing – You have a right to object to direct marketing.

You have a right to object at any time to processing of your personal information for direct marketing purposes, including profiling you for the purposes of direct marketing.

7. How do we secure your information?

We are committed to protecting the security of your information. To prevent unauthorized access or disclosure, we have implemented appropriate physical, electronic, and managerial safeguards. These include encryption for all online transactions and adherence to internationally recognized banking security practices for storing personal information.

8. How long do we retain your personal information?

We retain your personal information only for as long as necessary to fulfil the purposes described in this Privacy Statement or any other notice provided when we collected the data. This retention period will not exceed what is required or permitted by applicable law or our internal data policies. We dispose of personal information in accordance with Steward Bank’s established policies and procedures.

9. Changes to this policy.

9.1 We reserve the right to modify this Privacy Policy Statement as and when required.

9.2 We will post any changes to our Privacy Policy Statement on our website: https://www.stewardbank.co.zw.

Any amendment or modification to this policy will take effect from the date of notification on the Steward Bank website.