TECHAVEN Logo
TECHAVEN Logo Download app
Legal

Privacy & Data
Protection Policy

 Effective Date: 01/01/2026  Version 1.0  TecHaven, Malawi

This policy explains how TecHaven collects, uses, stores, and protects your personal data when you use our digital marketplace, escrow system, delivery network, and related services. We are committed to keeping your data safe and being transparent about how we use it.

Purpose and Scope

This policy governs how TecHaven collects, processes, stores, transfers, and disposes of personal data and proprietary information. It applies to all data processed by TecHaven in the course of operating its digital marketplace, escrow system, delivery network, and associated services.

This policy applies to all directors, employees, contractors, foot agents, technology partners, and third-party service providers who handle TecHaven data in any form.

Data Categories and Classification

TecHaven processes the following categories of data, classified by sensitivity level. Each classification carries specific handling requirements.

Classification Examples Handling Requirement
Highly Confidential NID copies, TIN, KYC documents, escrow transaction records, STR filings, passwords Encrypted at rest and in transit. Access limited to Compliance and Finance. Never shared externally without legal basis.
Confidential Seller contact details, buyer addresses, order history, platform analytics, internal reports Encrypted in transit. Role-based access control. Not shared without a data sharing agreement.
Internal Internal communications, HR records, operational processes, pricing strategies Accessible to authorised staff only. Not for external distribution.
Public Product listings, marketing content, public website content Freely shareable. No special controls required.

Lawful Bases for Data Processing

Pursuant to the Data Protection Act, 2024, TecHaven processes personal data on the following lawful bases:

Contract

Processing necessary to fulfil purchase orders, escrow transactions, and delivery services contracted between TecHaven and its users.

Legal Obligation

Processing required by the Financial Crimes Act (KYC/AML records), tax law (TIN records), and court orders.

Legitimate Interests

Platform fraud prevention, transaction monitoring, and business analytics where not overridden by user rights.

Consent

Processing for marketing communications, profiling, and non-essential cookies — subject to explicit opt-in consent.

Data Subject Rights

Under the Data Protection Act, 2024, users of TecHaven have the following rights regarding their personal data:

Right of Access

Request a copy of personal data held by TecHaven.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of personal data, subject to overriding legal retention obligations.

Right to Restriction of Processing

Object to certain types of processing of your personal data.

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

How to submit a request: All rights requests are acknowledged within 5 business days and fulfilled within 30 days. Submit your request to: support@techavenmw.com

Technical and Organisational Security Measures

6.1 Technical Controls

  • All data in transit encrypted using TLS 1.2 or higher
  • All sensitive data at rest encrypted using AES-256 or equivalent
  • Multi-factor authentication (MFA) required for all administrative platform access
  • Role-based access control (RBAC) — minimum necessary access principle enforced
  • Regular automated vulnerability scanning of the TecHaven web and mobile application
  • Web Application Firewall (WAF) deployed on all public-facing endpoints
  • Database access logs maintained and reviewed weekly
  • Automated backups performed daily with offsite replication

6.2 Organisational Controls

  • All staff sign a data confidentiality agreement at commencement of employment or engagement
  • Annual data protection training for all staff
  • Background checks conducted on staff with access to Highly Confidential data
  • Clean desk and screen lock policy enforced
  • Acceptable Use Policy governing use of TecHaven devices and systems
  • Incident response plan maintained and tested at least annually

Data Breach Notification

In the event of a personal data breach, TecHaven shall take the following steps:

  • Contain the breach immediately upon discovery and document all actions taken
  • Assess the risk to data subjects within 24 hours
  • Notify the relevant Data Protection Authority in Malawi within 72 hours of becoming aware of the breach where it is likely to result in a risk to individual rights, pursuant to the Data Protection Act, 2024
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms
  • Maintain a Breach Register documenting all incidents regardless of notification threshold

Third-Party Data Sharing

TecHaven may share personal data with third parties only where one or more of the following conditions are met:

  • The data subject has given explicit consent
  • Sharing is required to fulfil a contractual obligation (e.g., delivery agents, payment processors)
  • Sharing is required by law (e.g., FIA, court order, MRA audit)
  • A Data Processing Agreement (DPA) is in place with the third party requiring them to maintain equivalent data protection standards
TecHaven does not sell personal data to third parties under any circumstances.

Cross-Border Data Transfers

Where TecHaven transfers personal data outside Malawi (e.g., to cloud service providers or international payment processors), it shall ensure that:

  • The recipient country provides an adequate level of data protection as recognised by Malawian authorities
  • Appropriate safeguards are in place (Standard Contractual Clauses or equivalent)
  • The transfer is documented and subject to the organisation's data transfer impact assessment

Retention and Disposal

Personal data shall be retained only for as long as necessary for the purpose for which it was collected, or as required by law.

Data Type Retention Period Legal Basis
KYC documents and transaction records Minimum 5 years Financial Crimes Act, 2017
Tax and financial records Minimum 7 years Taxation Act, Malawi
Customer order history and communications 3 years from last transaction Contractual / Legitimate Interest
Marketing consent records Duration of consent + 1 year Data Protection Act, 2024

Upon expiry of retention periods, data shall be securely deleted or anonymised. Physical documents shall be shredded. Electronic records shall be overwritten or cryptographically erased.

Data Protection Officer

TecHaven has appointed a Data Protection Officer (DPO) responsible for:

  • Advising on data protection obligations under applicable law
  • Monitoring compliance with this policy
  • Acting as the point of contact for data subjects and regulatory authorities
  • Conducting and coordinating data protection impact assessments (DPIAs)

Data Protection Officer

support@techavenmw.com

+265 983 78 06 56

Cookies and Tracking Technologies

TecHaven uses cookies and similar tracking technologies on our website and mobile application to improve your experience and deliver our services securely and efficiently.

Cookie Type Purpose Legal Basis
Strictly Necessary Enable core platform functionality, security, and your login session Contract / Legitimate Interest (cannot be disabled)
Functional Remember your preferences, language, and settings between visits Consent
Analytics Understand how users interact with our platform so we can improve it Consent
Marketing Deliver personalised advertisements and measure campaign effectiveness Consent

You may manage your cookie preferences at any time via our Cookie Settings. Withdrawing consent for non-essential cookies will not affect your ability to use the core platform.

Automated Decision-Making and Profiling

TecHaven may use automated systems to support the following activities:

  • Fraud detection: Automated monitoring of transaction patterns to flag potentially fraudulent activity for human review
  • Seller verification: Automated checks against submitted KYC documents during the onboarding process
  • Product recommendations: Personalised product suggestions based on your browsing and purchase history

No decision that produces a significant legal or similarly significant effect on you will be made solely by automated means without the possibility of human review. Where such automated decisions occur, you have the right to request that a member of staff reviews the outcome. To exercise this right, contact our Data Protection Officer.

Children's Privacy

TecHaven's platform is intended for users aged 18 years and above. We do not knowingly collect or process personal data from children under the age of 18.

If you believe that a child under 18 has provided us with personal data without verifiable parental or guardian consent, please contact our Data Protection Officer immediately. We will promptly investigate and, where confirmed, delete any such data.

Parents and guardians who become aware that their child has submitted personal data to TecHaven without consent should contact us at support@techavenmw.com.

Changes to This Policy

This policy shall be reviewed annually or upon any material change in applicable data protection law or TecHaven's data processing activities. When we make significant changes, we will:

  • Post the updated policy on this page with a revised effective date
  • Notify registered users by email at least 14 days before changes take effect
  • Where required by law, seek fresh consent for any new or materially different processing activities

Your continued use of TecHaven's services after the effective date of a revised policy constitutes acceptance of the updated terms, except where fresh consent is legally required.

This policy was last reviewed on [REVIEW DATE — 12 months from effective date].

Contact Us

If you have any questions about this policy, wish to exercise your data subject rights, or need to report a data protection concern, please reach out through the following channels:

Data Protection Officer

support@techavenmw.com

+265 983 78 06 56

Registered Address

Techaven
Reg. No. BRNKGS4J55

Falls Estate, Lilongwe, Malawi

You also have the right to lodge a complaint with the relevant Data Protection Authority in Malawi if you believe your personal data has been processed unlawfully or without a valid legal basis.

Approved by: Chifundo Chiwaya, TecHaven

Document Type: Compliance Policy  |  Version: 1.0  |  Company: Techaven, Reg. No. BRNKGS4J55