w2a← Back to w2a
LEGAL · DATA PROTECTION

Privacy Policy

Last updated: 1 August 2026 · Version 2.0
This policy is written to be understood, not to hide behind legal language. If anything is unclear, or you want to exercise a right described below, contact dpo@w2a.co.zw and a person will answer you.

1. Who we are

w2a is a platform operated by Pardus Solutions (Pvt) Ltd, a company registered in Zimbabwe. w2a lets organisations and individuals run services over WhatsApp, web portals and branded mobile apps — taking orders, accepting payments, registering people, issuing documents and capturing signatures.

General: info@w2a.co.zw · Data protection: dpo@w2a.co.zw · WhatsApp: +263 71 662 5470

2. Controller and processor

This distinction determines who is responsible for a particular processing activity.

SituationControllerw2a's role
You message a business, school, clinic or government department using w2aThat organisation — it decides what to ask and whyProcessor, acting on its instructions
You create a w2a account or visit this websitew2a / Pardus SolutionsController

If you gave your details to an organisation using w2a and want them corrected or deleted, that organisation normally decides. You may contact us and we will route the request and, where we can, assist.

3. What information we collect

From people using a w2a-powered service

  • WhatsApp phone number and display name.
  • Information sent in the conversation, including form answers, orders, files and photographs.
  • Transaction records such as orders, payments, receipts, invoices and documents.
  • Signature evidence where you sign a document.

From organisations and individuals with a w2a account

  • Name, organisation, email address, phone number and role.
  • Applications, forms, products, prices and configuration settings.
  • Integration credentials, encrypted at rest.
  • Usage and audit records such as sign-ins and consequential changes.

From this website

  • Standard server logs such as IP address, browser type and pages requested for security and troubleshooting.
  • No advertising trackers or third-party marketing cookies are used on this website.

We do not collect payment card numbers. Payments are processed by licensed providers; w2a receives the payment result and reference required to reconcile the transaction.

4. Why we process information and lawful basis

PurposeLawful basis
Delivering the service requested — answering messages, taking orders and issuing receiptsPerformance of a contract / your request
Messaging through WhatsAppConsent, where required
Transaction, tax and signature recordsLegal obligation and legitimate interest in accurate records
Security, fraud and abuse preventionLegitimate interest
Product improvementLegitimate interest using aggregated or de-identified information where appropriate

We do not sell personal information or share it with advertisers or data brokers for their own marketing.

5. WhatsApp, Meta and consent

w2a delivers messages through the WhatsApp Business Platform operated by Meta. Businesses using w2a must follow applicable Meta policies.

  • Opt-in comes first where required. w2a records consent where it is captured through the platform.
  • Users can stop messages by replying STOP or blocking the business number.
  • Business-initiated messages outside the applicable customer service window use Meta-approved templates where required.
  • Meta processes message delivery and WhatsApp use is also governed by Meta/WhatsApp's own policies.
  • w2a does not use customer conversations for advertising or sell them.

WhatsApp Business Messaging Policy ↗ · WhatsApp Privacy Policy ↗

6. Who we share information with

  • The organisation you contacted.
  • Meta / WhatsApp for message delivery.
  • Payment providers when you initiate a payment.
  • Infrastructure providers necessary to operate the service, under appropriate confidentiality obligations.
  • Law enforcement or regulators where legally required.

Each organisation's data is isolated from every other organisation's. One w2a customer cannot access another customer's records.

7. How we protect information

  • HTTPS/TLS encryption in transit.
  • Encryption at rest for credentials and integration secrets.
  • Role-based access controls.
  • Audit logging of consequential actions with actor and timestamp.
  • Tenant isolation at the data layer.
  • Least-privilege application database access.
  • Single-use, expiring links for sensitive actions such as signing.

No system is perfectly secure. We aim to reduce risk, detect problems quickly and communicate honestly if an incident affects you.

8. Retention

  • Conversation and transaction records: while the organisation's account is active and thereafter where required for tax, accounting or legal purposes.
  • Signature evidence: for the life of the underlying agreement where needed as evidence.
  • Account records: while the account is open and for a reasonable period afterwards.
  • Server logs: a short rolling window for security and diagnostics.

Organisations using w2a can export and delete their own records subject to applicable legal retention obligations.

9. Your rights

Under the Cyber and Data Protection Act [Chapter 12:07], applicable rights may include being informed about processing, access, correction, objection/withdrawal of consent and deletion where no overriding legal reason requires retention. You may also complain to the Data Protection Authority.

To exercise a right, email dpo@w2a.co.zw. We aim to respond within 30 days. Where the information belongs to an organisation using w2a, we will pass the request to that organisation and support it in responding.

10. Electronic signatures

Where you sign through w2a, the evidence may include the signature image, date/time, IP address, device/browser description, phone number to which the signing link was issued, exact document and consent wording, and cryptographic hashes of the document and signature. Signing links are single-use and time-limited, and captured signatures are not overwritten.

We describe the technical evidence captured; we do not give legal advice on whether a particular electronic signature satisfies a particular contract or statute.

11. Children

w2a is intended for adults and organisations. Where an organisation processes information about minors, such as a school registering learners, that organisation is responsible for the appropriate parental/guardian consent and safeguards. w2a does not knowingly collect children's information for its own purposes.

12. Storage and international transfers

w2a application data is hosted on servers managed for us in a secured facility. Some necessary sub-processors, notably Meta for WhatsApp message delivery, operate internationally. Where personal information crosses borders, the deployment must use a lawful transfer basis and appropriate safeguards under applicable law.

13. If something goes wrong

If a security breach affects personal information, we will notify affected organisations and, where required, the Data Protection Authority without undue delay, with information about what happened, what information was involved and the response taken.

14. Changes

We will update this policy when our practices change and revise the last-updated date. If a change materially affects rights, we will provide notice through the service where appropriate.

15. Contact and complaints

Data protection: dpo@w2a.co.zw
General: info@w2a.co.zw
Operator: Pardus Solutions (Pvt) Ltd, Harare, Zimbabwe

If you are not satisfied with our response, you may complain to the Data Protection Authority. In Zimbabwe that function is performed by POTRAZ under the Cyber and Data Protection Act [Chapter 12:07]. Current contact details are published by POTRAZ.

For corporate and public-sector buyers: w2a can provide a compliance pack covering security architecture, data flows, sub-processors, retention schedule and incident procedures, and can work through a security questionnaire or data processing agreement. Email dpo@w2a.co.zw.

© 2026 w2a · Pardus Solutions (Pvt) Ltd · Home · Terms