1.Introduction
Harvest House International Church ("HHI", "the Church", "we", "us") is committed to protecting the privacy and security of your personal information in line with the Cyber and Data Protection Act [Chapter 12:07] and Statutory Instrument 155 of 2024 ("the CDPA"). HHI operates as a single legal persona, distinct from its members, with its principal area of operation in Zimbabwe and a network of local assemblies. This notice explains how we collect and use personal information belonging to our members, visitors, event attendees, children, donors, volunteers, and staff, across every assembly operating under the HHI name.
HHI holds a Tier 3 Data Controller Licence, approved by the Data Protection Authority of Zimbabwe (POTRAZ) on 17 September 2026, covering the personal data processing carried out by every assembly, department and ministry operating under the HHI name.
2.What is Personal Information?
Personal information is any information relating to an identified or identifiable living individual. In the course of church life, this may include:
- Personal identifiers: full name, home address, phone number, and email address
- Demographic data: date of birth, gender, marital status, family status, economic status and profession
- Church-specific data: year of repentance, year of joining, zone, church groups, departments/ministries, church position, languages spoken
- Attendance and engagement data: visit and event attendance, small-group and volunteer participation
- Giving records: tithe and offering information
- Sensitive information: religious beliefs and practice (inherent to church membership), prayer or counselling requests, health or family circumstances voluntarily disclosed
2.1 Sensitive Information
Attendance, religious choices, and prayer or counselling requests may reveal sensitive personal information. We process this information only for the stated purposes and with your written consent or another documented lawful basis. Where you submit a prayer or follow-up request, we ask that you give only the minimum information needed - sensitive matters (such as detailed medical, financial or family circumstances) should be discussed privately with an authorised pastoral-care representative rather than recorded on a form.
2.2 Data of Minors
Where a visitor or member is under the age of 18, we collect their information only with the written authorisation of a parent or legally recognised guardian, who confirms their authority and consents on the child's behalf. We explain the relevant form to the child in language appropriate to their age, and consent is reviewed when the member turns 18.
3.What Personal Information We Collect
We collect personal information directly from you, primarily through our standardised church forms:
- Visitors Card - completed by first-time and returning visitors, and attendees at church events
- Member Registration Form - completed by those who join HHI as members
- Volunteer and staff onboarding records, including a signed Confidentiality and Non-Disclosure Agreement for anyone granted access to our church management system
- Ongoing records of your engagement with the Church - attendance, ministry involvement, and giving
4.How We Use Your Personal Information
HHI processes personal information only for legitimate ministry, administrative and legal purposes, including:
- Recording your visit and responding to any request you make
- Administering membership and coordinating the ministries and church groups you select
- Providing pastoral follow-up and care that you request
- Protecting children through parental/guardian authorisation and safeguarding practice
- Sending communications only where you have chosen to receive them (call, SMS, WhatsApp or email)
- Financial administration of tithes, offerings and stewardship reporting
- Church governance and statutory record-keeping required by our Constitution
- Complying with the CDPA and other applicable legal or regulatory requirements
5.Lawful Basis for Processing
We rely on different lawful bases depending on the nature of the processing:
- Consent - for optional communications, and for sensitive information such as prayer or counselling requests, which we only process with your express written consent. You may withdraw consent at any time without affecting membership.
- Parental/guardian consent - for the information of a visitor or member under the age of 18.
- Contractual/constitutional necessity - for core membership and volunteer/staff administration.
- Legal obligation - for financial, governance and licensing records required under Zimbabwean law and HHI's Constitution.
- Legitimate interest - for day-to-day church administration that does not override your rights and freedoms.
7.Transfer of Personal Information Outside Zimbabwe
Some of our systems and service providers - including the DiscipleSoft platform and any cloud hosting or communication services it uses - may store or process personal information outside Zimbabwe. Where this occurs, HHI ensures that: (1) the transfer complies with the CDPA and its regulations; (2) appropriate safeguards are in place, such as the Data Processing Agreement with DiscipleSoft; and (3) any third-party provider meets security and privacy standards equivalent to those required in Zimbabwe.
8.Your Rights as a Data Subject
You have the right to:
- Be informed about the collection and use of your personal information
- Access your personal information, or request a copy of it
- Request correction of any inaccurate or incomplete personal information
- Request deletion of your personal information in certain circumstances
- Object to certain processing, or withdraw consent at any time
Withdrawing consent does not affect the lawfulness of processing already carried out, and will not affect your membership. To exercise any of these rights, please contact our Data Protection Officer using the details in Section 11. We will respond within 30 days.
8.1 The Role of the Regulator
The Data Protection Authority of Zimbabwe, administered by POTRAZ, is responsible for overseeing and enforcing compliance with the CDPA. If you believe HHI has not handled your personal information in line with the law, you may lodge a complaint directly with POTRAZ.
9.Data Security
HHI protects personal information through a combination of technical and organisational measures, including:
- Role-based, least-privilege access to DiscipleSoft and other church systems
- A signed Confidentiality and Non-Disclosure Agreement for every volunteer or staff member granted system access
- Audit trails, access logs and backups within DiscipleSoft
- Secure physical storage of paper forms and files
9.1 Data Breach Response
If a data breach occurs that may affect you, HHI will act quickly to investigate, contain the issue and reduce potential harm. In line with the CDPA: we will notify POTRAZ without undue delay upon becoming aware of a breach; where the breach poses a risk to your rights, we will inform affected individuals as soon as reasonably possible; and we will take corrective action to prevent recurrence.
10.Data Retention
HHI keeps personal information only for as long as necessary for ministry, administrative, legal or regulatory purposes, in line with our Data Retention Schedule. Visitor information is generally retained until you become a member, or securely destroyed/anonymised after a defined period. Membership, financial, and governance records are retained for longer periods to meet our statutory and constitutional obligations. Full retention periods are set out in the HHI Retention Schedule, available on request from the Data Protection Officer.
11.Data Protection Officer & Contact Details
If you have any questions, concerns or requests regarding this Privacy Notice or how HHI handles your personal information, please contact us on the below details:
- DPO Email: dpo@harvesthouseint.org
- Chief Compliance Officer: compliance@harvesthouseint.org
- Postal Address: Stand No. 19742, Selbourne Park, Bulawayo, Zimbabwe
In the event that you contact us and you are not satisfied with our response or believe that we have infringed on your rights, you may also lodge a complaint with the Data Protection Authority, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) via their website https://www.potraz.gov.zw
12.Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. Any material changes will be posted on our website, with an updated version date.
13.Version Control
| Version | Author | Description |
|---|---|---|
| Version 1.0 (17 September 2026) | DPO | Initial draft |
