SECTION 01
Purpose and Scope
This policy governs how TecHaven collects, processes, stores, transfers, and disposes of personal data and proprietary information. It applies to all data processed by TecHaven in the course of operating its digital marketplace, escrow system, delivery network, and associated services.
This policy applies to all directors, employees, contractors, foot agents, technology partners, and third-party service providers who handle TecHaven data in any form.
SECTION 02
Legal and Regulatory Framework
TecHaven complies with all applicable laws and regulations governing data protection and electronic commerce. The primary legal instruments governing our data practices are set out below.
| Statute / Regulation |
Relevance to TecHaven |
| Data Protection Act, 2024 (Malawi) |
The primary data protection legislation in Malawi. Establishes rights of data subjects and obligations of data controllers and processors. Mandates lawful bases for processing, consent requirements, data subject rights, and breach notification. TecHaven is a data controller under this Act. |
| Electronic Transactions and Cyber Security Act, 2016 (Act No. 33 of 2016) |
Governs electronic commerce, digital signatures, electronic records, and cybercrime. Sections 55–75 create criminal offences for unauthorised access, data interception, and destruction of electronic information. Requires platforms to maintain security of electronic transactions. |
| Communications Act, 2016 (Act No. 35 of 2016) |
Regulates electronic communications services. Requires service providers to protect the privacy of communications and notify subscribers of security breaches affecting their personal data. |
| Consumer Protection Act, 2003 (Malawi) |
Requires businesses to handle consumer information responsibly and to protect consumers from unfair practices including misuse of personal data in commercial transactions. |
| Financial Crimes Act, 2017 |
Requires secure retention of KYC and financial records. Data security measures must protect the confidentiality of AML-related records and STR filings. |
| GDPR (EU) — Extra-territorial applicability |
Where TecHaven processes data of persons located in the European Union (e.g. diaspora buyers), the General Data Protection Regulation may apply. TecHaven implements GDPR-compliant standards as a baseline to ensure international readiness. |
SECTION 03
Data Categories and Classification
TecHaven processes the following categories of data, classified by sensitivity level. Each classification carries specific handling requirements.
| Classification |
Examples |
Handling Requirement |
| Highly Confidential |
NID copies, TIN, KYC documents, escrow transaction records, STR filings, passwords |
Encrypted at rest and in transit. Access limited to Compliance and Finance. Never shared externally without legal basis. |
| Confidential |
Seller contact details, buyer addresses, order history, platform analytics, internal reports |
Encrypted in transit. Role-based access control. Not shared without a data sharing agreement. |
| Internal |
Internal communications, HR records, operational processes, pricing strategies |
Accessible to authorised staff only. Not for external distribution. |
| Public |
Product listings, marketing content, public website content |
Freely shareable. No special controls required. |
SECTION 04
Lawful Bases for Data Processing
Pursuant to the Data Protection Act, 2024, TecHaven processes personal data on the following lawful bases:
Contract
Processing necessary to fulfil purchase orders, escrow transactions, and delivery services contracted between TecHaven and its users.
Legal Obligation
Processing required by the Financial Crimes Act (KYC/AML records), tax law (TIN records), and court orders.
Legitimate Interests
Platform fraud prevention, transaction monitoring, and business analytics where not overridden by user rights.
Consent
Processing for marketing communications, profiling, and non-essential cookies — subject to explicit opt-in consent.
SECTION 05
Data Subject Rights
Under the Data Protection Act, 2024, users of TecHaven have the following rights regarding their personal data:
Right of Access
Request a copy of personal data held by TecHaven.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of personal data, subject to overriding legal retention obligations.
Right to Restriction of Processing
Object to certain types of processing of your personal data.
Right to Data Portability
Receive your personal data in a structured, commonly used, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
How to submit a request: All rights requests are acknowledged within
5 business days and fulfilled within
30 days. Submit your request to:
support@techavenmw.com
SECTION 06
Technical and Organisational Security Measures
6.1 Technical Controls
- All data in transit encrypted using TLS 1.2 or higher
- All sensitive data at rest encrypted using AES-256 or equivalent
- Multi-factor authentication (MFA) required for all administrative platform access
- Role-based access control (RBAC) — minimum necessary access principle enforced
- Regular automated vulnerability scanning of the TecHaven web and mobile application
- Web Application Firewall (WAF) deployed on all public-facing endpoints
- Database access logs maintained and reviewed weekly
- Automated backups performed daily with offsite replication
6.2 Organisational Controls
- All staff sign a data confidentiality agreement at commencement of employment or engagement
- Annual data protection training for all staff
- Background checks conducted on staff with access to Highly Confidential data
- Clean desk and screen lock policy enforced
- Acceptable Use Policy governing use of TecHaven devices and systems
- Incident response plan maintained and tested at least annually
SECTION 07
Data Breach Notification
In the event of a personal data breach, TecHaven shall take the following steps:
- Contain the breach immediately upon discovery and document all actions taken
- Assess the risk to data subjects within 24 hours
- Notify the relevant Data Protection Authority in Malawi within 72 hours of becoming aware of the breach where it is likely to result in a risk to individual rights, pursuant to the Data Protection Act, 2024
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Maintain a Breach Register documenting all incidents regardless of notification threshold
SECTION 08
Third-Party Data Sharing
TecHaven may share personal data with third parties only where one or more of the following conditions are met:
- The data subject has given explicit consent
- Sharing is required to fulfil a contractual obligation (e.g., delivery agents, payment processors)
- Sharing is required by law (e.g., FIA, court order, MRA audit)
- A Data Processing Agreement (DPA) is in place with the third party requiring them to maintain equivalent data protection standards
TecHaven does not sell personal data to third parties under any circumstances.
SECTION 09
Cross-Border Data Transfers
Where TecHaven transfers personal data outside Malawi (e.g., to cloud service providers or international payment processors), it shall ensure that:
- The recipient country provides an adequate level of data protection as recognised by Malawian authorities
- Appropriate safeguards are in place (Standard Contractual Clauses or equivalent)
- The transfer is documented and subject to the organisation's data transfer impact assessment
SECTION 10
Retention and Disposal
Personal data shall be retained only for as long as necessary for the purpose for which it was collected, or as required by law.
| Data Type |
Retention Period |
Legal Basis |
| KYC documents and transaction records |
Minimum 5 years |
Financial Crimes Act, 2017 |
| Tax and financial records |
Minimum 7 years |
Taxation Act, Malawi |
| Customer order history and communications |
3 years from last transaction |
Contractual / Legitimate Interest |
| Marketing consent records |
Duration of consent + 1 year |
Data Protection Act, 2024 |
Upon expiry of retention periods, data shall be securely deleted or anonymised. Physical documents shall be shredded. Electronic records shall be overwritten or cryptographically erased.
SECTION 11
Data Protection Officer
TecHaven has appointed a Data Protection Officer (DPO) responsible for:
- Advising on data protection obligations under applicable law
- Monitoring compliance with this policy
- Acting as the point of contact for data subjects and regulatory authorities
- Conducting and coordinating data protection impact assessments (DPIAs)
SECTION 12
Cookies and Tracking Technologies
TecHaven uses cookies and similar tracking technologies on our website and mobile application to improve your experience and deliver our services securely and efficiently.
| Cookie Type |
Purpose |
Legal Basis |
| Strictly Necessary |
Enable core platform functionality, security, and your login session |
Contract / Legitimate Interest (cannot be disabled) |
| Functional |
Remember your preferences, language, and settings between visits |
Consent |
| Analytics |
Understand how users interact with our platform so we can improve it |
Consent |
| Marketing |
Deliver personalised advertisements and measure campaign effectiveness |
Consent |
You may manage your cookie preferences at any time via our Cookie Settings. Withdrawing consent for non-essential cookies will not affect your ability to use the core platform.
SECTION 13
Automated Decision-Making and Profiling
TecHaven may use automated systems to support the following activities:
- Fraud detection: Automated monitoring of transaction patterns to flag potentially fraudulent activity for human review
- Seller verification: Automated checks against submitted KYC documents during the onboarding process
- Product recommendations: Personalised product suggestions based on your browsing and purchase history
No decision that produces a significant legal or similarly significant effect on you will be made solely by automated means without the possibility of human review. Where such automated decisions occur, you have the right to request that a member of staff reviews the outcome. To exercise this right, contact our Data Protection Officer.
SECTION 14
Children's Privacy
TecHaven's platform is intended for users aged 18 years and above. We do not knowingly collect or process personal data from children under the age of 18.
If you believe that a child under 18 has provided us with personal data without verifiable parental or guardian consent, please contact our Data Protection Officer immediately. We will promptly investigate and, where confirmed, delete any such data.
Parents and guardians who become aware that their child has submitted personal data to TecHaven without consent should contact us at support@techavenmw.com.
SECTION 15
Changes to This Policy
This policy shall be reviewed annually or upon any material change in applicable data protection law or TecHaven's data processing activities. When we make significant changes, we will:
- Post the updated policy on this page with a revised effective date
- Notify registered users by email at least 14 days before changes take effect
- Where required by law, seek fresh consent for any new or materially different processing activities
Your continued use of TecHaven's services after the effective date of a revised policy constitutes acceptance of the updated terms, except where fresh consent is legally required.
This policy was last reviewed on [REVIEW DATE — 12 months from effective date].
SECTION 16
Contact Us
If you have any questions about this policy, wish to exercise your data subject rights, or need to report a data protection concern, please reach out through the following channels:
You also have the right to lodge a complaint with the relevant Data Protection Authority in Malawi if you believe your personal data has been processed unlawfully or without a valid legal basis.
Approved by: Chifundo Chiwaya, TecHaven
Document Type: Compliance Policy | Version: 1.0 | Company: Techaven, Reg. No. BRNKGS4J55