Who is responsible for your information?
Fixa operates the Fixa website, MyFixa and the related trust-network services described in this Privacy Policy.
For data-protection purposes, Fixa determines why and how personal information is processed when you create an account, submit a job, apply as a professional, communicate with us or otherwise use the platform.
Current operating location: Harare, Zimbabwe.
When this Policy applies
This Privacy Policy applies to customers, prospective customers, independent professionals, professional applicants, website visitors and other people who interact with Fixa.
It applies to information collected through fixa.africa, MyFixa, Fixa OS, forms, email, WhatsApp, telephone calls, job documentation and related operational channels.
It should be read together with the Fixa Terms of Use.
Information we collect
The information Fixa collects depends on how you use the service.
- Identity and account information, such as your name, email address, telephone number and account identifier.
- Location information, such as suburb, property location, directions and service address.
- Job information, including the problem, requested outcome, trade category, urgency, budget and access details.
- Photographs, videos, measurements, receipts, completion evidence and other job documentation.
- Professional information, including profile details, trade, experience, qualifications, references, verification records and work history.
- Communications, including messages, support requests, complaint information, call notes and WhatsApp correspondence.
- Payment and transaction records, such as amounts, deposits, payment status, references and refund records.
- Reviews, ratings, comments and optional photographs submitted after a job.
- Legal acceptance records, including which version of a document you accepted and when.
- Technical information, including browser type, device type, IP address, session activity, page interactions and authentication events.
- Security and fraud-prevention information, including access logs, failed login attempts and account-risk signals.
Where the information comes from
Most personal information is provided directly by you. Fixa may also receive information from other people or systems involved in operating the service.
- Information entered into Fixa forms, accounts and dashboards.
- Information supplied through email, WhatsApp, telephone or in-person communication.
- Information supplied by an assigned professional about the progress or completion of a job.
- References, verification sources or documents supplied during professional vetting.
- Website, authentication, analytics and security technologies.
- Payment providers, banks, mobile-money providers or other payment channels where relevant.
- Publicly available information where reasonably necessary for verification, safety or fraud prevention.
Why Fixa uses personal information
Fixa processes personal information only where it has a defined operational, safety, legal or service-related purpose.
- To create, authenticate and manage customer and administrator accounts.
- To understand job requests and identify an appropriate professional.
- To coordinate appointments, access, scope, pricing and communication.
- To document job progress, completion, changes and customer approval.
- To process or coordinate payments, refunds, deposits and transaction records.
- To verify, assess and manage independent professionals.
- To provide customer support and respond to questions or complaints.
- To investigate workmanship concerns, safety incidents, fraud or misuse.
- To maintain the security, integrity and reliability of the platform.
- To administer reviews and protect the credibility of the trust network.
- To comply with legal, regulatory, accounting and record-keeping obligations.
- To understand how the website is used and improve the service.
- To communicate important updates about an account, job, policy or security matter.
Legal grounds for processing
Depending on the circumstances, Fixa processes information with your consent, because it is necessary to provide a requested service, to protect legitimate operational interests, to protect a person’s vital interests or to comply with legal obligations.
Where written consent is required for sensitive personal information, Fixa will request it separately.
You may withdraw consent where processing depends on consent. Withdrawal does not make earlier lawful processing invalid and may affect Fixa’s ability to continue providing a service.
Information shared during a job
A professional may receive the customer’s name, contact number, service location, job description, photographs, access information and other details needed to assess or complete the work.
Customers may receive the assigned professional’s name, profile information, trade, verification status, photograph and relevant job communication.
Neither side may use information obtained through Fixa for harassment, unrelated marketing, intimidation, discrimination or another unauthorised purpose.
Technology and service providers
Fixa uses third-party technology to operate the platform. These providers process information on Fixa’s behalf or provide services that involve personal information.
- Framer for website hosting and page delivery.
- Supabase for authentication, databases, storage and server-side functions.
- Resend and related email infrastructure for transactional and authentication emails.
- Google Analytics for website measurement and usage reporting.
- Microsoft Clarity for website interaction analysis, including session and interface behaviour.
- WhatsApp and Meta services where users communicate with Fixa through WhatsApp.
- Google services where operational documents, records or forms are used.
- Other carefully selected providers used for payments, security, support, communications or administration.
Cookies, analytics and session information
Fixa may use cookies, browser storage and similar technologies to keep users signed in, protect accounts, remember preferences and understand how the website performs.
Google Analytics and Microsoft Clarity may collect technical and interaction information such as page views, approximate location, browser details, clicks, scrolling and navigation patterns.
Where required, Fixa will request consent before activating non-essential analytics technologies. Browser settings may also allow you to block or delete cookies, although doing so may affect parts of the service.
Job photographs and property information
Job photographs and videos help Fixa understand the request, select a professional, document the scope, track progress and investigate concerns.
- Avoid including identity documents, passwords, security codes, private messages or unrelated personal possessions.
- Avoid photographing people unless their presence is genuinely relevant and they have been informed.
- Property photographs will not be used for public marketing in an identifiable form without appropriate permission.
- Fixa may use de-identified or aggregated job information for training, reporting and service improvement.
Sensitive personal information
Fixa does not ordinarily need health, biometric, genetic, political, religious or other highly sensitive personal information to arrange a job.
Please do not submit sensitive information unless it is genuinely necessary for safety, accessibility, identity verification or another clearly explained purpose.
Where sensitive information must be processed, Fixa will apply additional safeguards and obtain written consent where required.
Processing outside Zimbabwe
Some of Fixa’s technology providers operate infrastructure outside Zimbabwe. Personal information may therefore be stored or processed in countries such as the United Kingdom, European Union member states, the United States or other locations where the relevant provider operates.
Fixa will take reasonable steps to use providers and arrangements that offer appropriate safeguards for international data transfers.
Where required, transfers will be based on consent, contractual necessity, legal requirements or another permitted transfer mechanism.
How Fixa protects information
Fixa uses reasonable technical and organisational measures designed to protect personal information against unauthorised access, alteration, loss, misuse or disclosure.
- Passwordless authentication and secure access links.
- Role-based administrator access and database access controls.
- Restricted access to internal systems and records.
- Logging and review of important authentication and system events.
- Use of reputable hosting and infrastructure providers.
- Storage and database security settings appropriate to the type of information.
- Internal procedures for investigating suspected security incidents.
How long information is kept
Fixa retains personal information only for as long as reasonably necessary for the purpose for which it was collected or for a related legal, safety, accounting, dispute-resolution or fraud-prevention purpose.
- Active account information is normally retained while the account remains active.
- Job, transaction, acceptance and dispute records may be retained after completion to support warranties, complaints, accounting and legal obligations.
- Professional verification records may be retained while the professional remains active and for a reasonable period afterwards.
- Security and technical logs are generally retained for shorter operational periods unless needed for an investigation.
- Marketing preferences are retained until you unsubscribe or the record is no longer needed.
- Information may be anonymised instead of deleted where it can no longer reasonably identify a person.
Your data-protection rights
Subject to applicable law and reasonable identity verification, you may ask Fixa to:
- Explain whether and how your personal information is being used.
- Provide access to personal information held about you.
- Correct information that is inaccurate, incomplete, false or misleading.
- Delete false or misleading information and consider other valid deletion requests.
- Object to all or part of certain processing.
- Withdraw consent where consent is the basis for processing.
- Object free of charge to direct-marketing use of your information.
- Request human review where a significant decision has been based solely on automated processing.
Making a privacy request
Send privacy requests to hello@fixa.africa or use Fixa’s official contact channel.
Include your name, account email or telephone number, the nature of the request and any relevant job reference.
Fixa may request reasonable proof of identity before releasing, correcting or deleting personal information. This helps prevent another person from gaining access to your records.
A request may be limited where disclosure would expose another person’s information, interfere with a legal obligation, prejudice an investigation or otherwise be restricted by law.
Marketing communications
Fixa may send operational messages about accounts, jobs, security, payments, policies and support. These messages are part of providing the service and are not ordinary marketing.
Promotional messages will be sent only where permitted. You may opt out of direct marketing at any time using the unsubscribe method provided or by contacting Fixa.
Children
Fixa’s customer and professional services are intended for adults aged 18 and over.
A child should not create an account, submit a job or apply as a professional without an authorised parent or legal guardian.
Where Fixa learns that a child’s information has been collected improperly, it will take reasonable steps to restrict or remove it.
Automated processing
Fixa may use rules or system-assisted tools to organise job requests, flag risk, detect misuse or assist with matching.
Fixa does not intend to make decisions producing serious legal or similarly significant effects solely through automated processing without appropriate consent, legal authority or human review.
Security incidents
If Fixa becomes aware of a security incident affecting personal information, it will investigate, contain and document the incident.
Fixa will notify the relevant authority and affected people where required by applicable law and where the incident creates a material risk to their rights or safety.
Complaints
Please raise a privacy concern with Fixa first so it can be investigated and addressed.
You may also lodge a complaint with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), which is Zimbabwe’s designated Data Protection Authority.
Using Fixa’s internal complaint process does not remove a legal right to approach the regulator or another competent authority.
Changes to this Policy
Fixa may update this Privacy Policy as the platform, technology, service providers or legal requirements change.
The current effective date and version will be shown at the top of this page.
Where a change materially affects how personal information is used, Fixa may provide additional notice or request new consent where appropriate.
Contact Fixa
Privacy questions and requests can be sent to hello@fixa.africa.
You can also contact Fixa through the official contact details published on fixa.africa.