LEGAL & COMPLIANCE

Privacy Policy

Transparent data governance and confidentiality standards.

Effective Date: September 2026. ZIMA MDR is committed to the highest standards of data security, confidentiality, and data minimization.

1. Introduction & Scope

ZIMA MDR ("we", "our", or "us"), operating within the Mtengwa Strategic Advisory and BuruOps technology ecosystem, provides managed detection, threat intelligence, and incident response services. This Privacy Policy details how we collect, process, and protect information when you visit our website (zimamdr.com) or interact with our operational platforms.

2. Customer Telemetry & Security Logs

In our capacity as a Managed Detection & Response provider, we process system telemetry and security log events strictly under the direction of our client organisations as a Data Processor.

  • Telemetry Scope: Host execution events, system authentication logs, file integrity hashes, process trees, and network connection metadata necessary to detect adversary behavior.
  • Data Minimisation: We do not collect or inspect the contents of private communications, personal documents, or end-user media files.
  • Isolation & Encryption: All in-transit telemetry is secured using authenticated point-to-point encrypted tunnels with AES-256 and modern WireGuard cryptography. At-rest telemetry is encrypted using standard AES-256 cryptographic standards.

3. Website Inquiries & Contact Data

When you submit an inquiry or request a security briefing through our website, we collect your name, corporate email address, organisation name, phone number (if provided), and infrastructure context.

This information is used exclusively to evaluate your operational requirements, provide requested proposals, and communicate regarding services. We never sell, lease, or monetize your contact data to third parties.

4. Data Retention & Sovereignty

Depending on the chosen deployment model (Shared Managed, Dedicated Environment, or Customer-Hosted), customer security telemetry is retained according to mutually agreed contract schedules (typically 30, 90, or 365 days) after which it is securely purged. Under the Customer-Hosted model, raw data never leaves your infrastructure perimeter.

5. Your Rights Under GDPR & International Law

If you reside in the United Kingdom, European Union, or Canada, you possess rights to access, rectify, or request the erasure of your personal contact data. To exercise these rights, please contact our privacy officer at security@zimamdr.com.