ZaTafa Research AI policy

Privacy policy

This template describes how a production ZaTafa Research AI deployment should handle research data. It must be reviewed against local law and institutional governance before use with identifiable health information.

Last updated: 15 July 2026

Data minimisation

Users should upload only the variables required for the approved research objectives. The application scans column names and values for potential direct identifiers and asks the user to remove or mask them before analysis.

Storage and access

Production data must be encrypted in transit and at rest. Access is limited by project role, and each access or change is recorded in an audit log. Retention periods are controlled by the organisation and subscription plan.

Payments

Subscription checkout is hosted by Flutterwave. ZaTafa records the payment reference, selected plan, amount, currency, status and account-linking email, but does not receive or store card numbers, PINs or mobile-money credentials.

Artificial intelligence

Only dataset structure, variable metadata and approved aggregate outputs should be sent to the AI service by default. Raw record-level data must not be used to train external AI models.

Researcher responsibilities

The researcher remains responsible for ethical approval, lawful processing, data-quality decisions, statistical judgment and the final interpretation of findings.