Minerva is committed to protecting your privacy. This commitment reflects the value we place on earning and keeping
the trust of our employees, customers, clients, business partners and others who share their personal information with
us directly or indirectly.
This Privacy Notice explains Minerva’s information processing practices as a Data Controller and/or Data Processor
as defined in the Cyber and Data Protection Act [Chapter12:07] and its Regulations. This Notice applies to any personal
information you provide to Minerva and any personal information we collect from other sources, unless you are provided
with a more specific privacy statement at the time of data collection.
Throughout this Notice, “Minerva” refers to Minerva Risk Advisors, including its affiliated companies (Minerva Risk
Solutions, Minerva Benefits Consulting, Minerva Reinsurance and Healthcare Benefits Consulting) also referred to as
“we,” “us,” or “our”. Personal information is collected by Minerva and we are responsible for its processing as a data
controller. Minerva entities also provide services to our clients as a processor. Where this is the case, we will process
your personal information in line with our legal obligations and contractual commitments with our clients.
The personal information we collect varies depending upon the nature of our services. This Notice provides an overview
of the categories of personal information we collect and the purposes for which we use it. More information about the
personal information collected for each of our services, together with the purpose and legal basis for collecting the
information, may be provided to you in separate privacy notices relevant to the applicable services.
Minerva collects information directly from you when you:
• Request a service from us.
• Visit a Minerva site or attend a Minerva event;
• Apply for a job position at Minerva.
• Contact us with a complaint or query;
• Engage with us over social media;
• Register with or use any of our websites or applications; or
• Any other ways not listed above.
You are required to provide any personal information we reasonably require (in a form acceptable to us) to meet our
obligations in connection with the services we provide to you, including any legal and regulatory obligations.
Where you provide personal information to Minerva about third-party individuals (e.g., information about your spouse,
child(ren), dependents or next of kin we may require you to provide explicit consent on their behalf.
In some instances, we automatically collect certain types of information when you visit our websites and
through e-mails that we may exchange. Automated technologies may include the use of web server logs to
collect IP addresses and “cookies”.
When we provide the services to our clients, we may collect personal information from our clients about you,
such as your name, contact details, date of birth, gender, marital status, financial details, employment details,
and benefit coverage. We may also collect (in each case as strictly relevant to the services we provide)
sensitive personal data information about you, such as race, health information in relation to life, biometric,
images, professional liability or employee benefit programs sponsored by your employer. or criminal history—
as defined under the Act. Such sensitive personal information is processed only after obtaining written
consent from you.
Basic personal details, such as your name, address, contact details, date of birth, age, gender and marital status.
i. Identification Data such as National Identification Number, pension scheme reference number.
ii. Demographic details, such as information about your age, gender, race, marital status, lifestyle, and insurance
requirements;
iii. Employment data such as role, employment status (such as full/part time, contract), salary/income
information, employment benefits, and employment history.
iv. Health data such as information about your health status and medical records and medical claims.
v. Financial data such as bank account details, salary, tax code, third-party deductions, bonus payments, benefits
and entitlement data;
vi. Claims details such as information about any claims concerning you
vii. Your marketing preferences;
viii. Online information: e.g., information about your visits to our websites;
ix. Events information such as information about your interest in and attendance at our events, including
provision of feedback forms;
x. Social media information such as interactions (e.g., likes, mentions, posts or any content shared about us)
with our social media presence
xi. Biometric Data: includes fingerprint recognition, facial recognition
xii. Usage & Marketing preference Data: Information on how you use our services and products and preferences
in receiving marketing communications.
The following is a summary of the purposes for which we use personal information.
• To provide our insurance, reinsurance, pensions and retirement, health, and data and analytics services,
• To communicate about your policy, your claims and your other inquiries.
• To carry out Minerva’s regulatory and compliance obligations, for example “Know Your Customer” checks
and screening, as per IPEC regulations
• To address inquiries and complaints,
• To administer claims and benefits.
• To confirm and verify evidence of continued existence for pensioners.
• To communicate with our clients,
• To share marketing material such as newsletters, promotional material and other marketing
communications, if you sign up for our newsletters. You can opt out at any time.
• To invite our clients to events, including arranging and administering those events.
• To maintain and improve processes used in providing the services.
Our websites are not directed to children, and we do not knowingly collect personal information from children on our
websites.
Certain Minerva solution lines may process data related to children, such as their date of birth, address, and other
identifiable information. This information is not collected directly from children, but from other parties such as from our
client or directly from you as the parent or guardian of the child (e.g., so that the child may be named a beneficiary to
an insurance policy or pension plan).In that case, we will put in place mechanisms to obtain parental consent for the
processing of children’s data. We may request evidence to verify parental authority presented by the alleged parent or
guardian over the child.
How long we retain your personal information depends on the purpose for which it was obtained and its nature. We will
keep your personal information for the period necessary to fulfil the purposes described in this Notice unless a longer
retention period is permitted. Your personal information will be securely destroyed when it is no longer required.
We generally share your personal information with the following categories of recipients where necessary to offer,
administer and manage the services provided to you:
• Service Providers Third-party vendors, where we outsource our processing operations to suppliers that
provide services on our behalf including Auditors
• Affiliates: Companies related to us by common ownership or control.
• Law enforcement bodies, when required to do so by law, legal process or regulation
• Transborder Data Transfers some of our service providers may be located outside Zimbabwe and your data may be transferred/processed internationally Any transfer of data across the Zimbabwean borders is done in
accordance with the Cyber and Data Protection Act and the Regulations.
We implement industry-standard encryption and technical and organisation security controls to safeguard your data.
Your information is retained only for as long as necessary for legal and business purposes. These measures are to
protect your personal information from unauthorized access, use or disclosure in accordance with the Act.
We conduct risk assessments, and report breaches to POTRAZ within 24 hours—and notify affected individuals within
72 hours if there’s a high risk.
• Right to Access your personal information which Minerva holds about you.
• Right to Correction of your personal information where it is inaccurate or out of date.
• Right to be Deletion if your data is no longer necessary for the purpose for which it was collected, and there is no other legal ground fo processing the data or where data is inaccurate
• Right to Object to the processing of all or part of your personal information
• Right to be informed of the use to which we use your personal information
When you exercise these rights, we may need to ask you for additional information to confirm your identity, before
disclosing information to you or responding to your request. You can exercise your rights by contacting us.
Where a decision is taken solely by automated means involving the use of your personal information, you have the
right to challenge the decision and ask us to reconsider the matter, with human intervention. If you wish to exercise this
right, you should contact us.
We maintain internal policies, documented procedures, and logs to demonstrate compliance with data protection
obligations, including regular audits and risk assessments.
If you have any questions, would like further information about our privacy, would like to withdraw consent or would like
to make a complaint about the handling of your personal information, please contact us at:
Attention: The Data Protection Officer
Address: Minerva House
Block 2 Kenilworth Gardens
1 Kenilworth Road
Newlands,Harare
Email: dpo@minerva.co.zw
Telephone: +263(242)776900-1 / 779962-70
We may update this Notice from time to time. When we do, we will post the current version on this site, and we will
revise the version date. We encourage you to periodically review this Notice so that you will be aware of our privacy
practices. This Notice was last updated on 1 August 2025
As custodians of our clients’ personal information, we at Minerva Risk Advisors and its associated business units
acknowledge the trust you place in us. In line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the
following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within Minerva Risk Advisors understand and comply with
data protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice.
Name: Lydia Tanyanyiwa
Title: Group CEO
Signature & Date:
Healthcare Benefits Consulting Data Privacy Pledge
As custodians of our clients’ personal information, we at Minerva Healthcare acknowledge the trust you place in us. In
line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within Healthcare Benefits Consulting understand and
comply with data protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice.
Name: Nicholas Chekera
Title: General Manager
Signature & Date:
Minerva Risk Solutions Data Privacy Pledge
As custodians of our clients’ personal information, we at Minerva Risk Solutions acknowledge the trust you place in us.
In line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within Minerva Risk Solutions understand and comply with
data protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice
Name: Solomon Mavuka
Title: Managing Director
Signature & Date:
Minerva Benefits Consulting Data Privacy Pledge
As custodians of our clients’ personal information, we at Minerva Benefits Consulting acknowledge the trust you place
in us. In line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within this Business Unit understand and comply with data
protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice.
Name: Godwin Mudiwa
Title: Managing Director
Signature & Date:
Minerva Reinsurance Data Privacy Pledge
As custodians of our clients’ personal information, we at Minerva Reinsurance acknowledge the trust you place in us.
In line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within this Business Unit understand and comply with data
protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice.
Name: Madonna Katoma
Title: General Manager
Signature & Date:
Equiva Actuaries & Partners Data Privacy Pledge
As custodians of our clients’ personal information, we at Equiva Actuaries acknowledge the trust you place in us. In
line with the Cyber and Data Protection Act [Chapter 12:07], we pledge the following:
1. Respect & Confidentiality
We will treat all client data with the highest degree of respect, confidentiality, and professionalism.
2. Lawful & Transparent Processing
We will collect, use, and retain personal information only for lawful business purposes, in a manner that is
transparent and consistent with Minerva’s Privacy Notice.
3. Security & Safeguards
We will apply strong technical, physical, and organisational safeguards to protect client information from
unauthorized access, loss, or misuse.
4. Accountability
We accept responsibility for ensuring that all staff within this Business Unit understand and comply with data
protection policies, procedures, and legal requirements.
5. Client Rights
We will respect and uphold your rights to access, correct, restrict, or request deletion of your personal
information.
6. Prompt Reporting
In the event of any suspected or actual data breach, we will promptly escalate and cooperate with Minerva’s
Data Protection Officer to ensure legal reporting timelines are met.
7. Continuous Improvement
We will continuously review and improve our processes to strengthen data protection, guided by client
expectations, regulatory requirements, and industry best practice.
Name: Shadreck Majoni
Title: Head Actuarial Consultant
Signature & Date:
WhatsApp us