ZaTafa Research AI policy
Privacy policy
This template describes how a production ZaTafa Research AI deployment should handle research data. It must be reviewed against local law and institutional governance before use with identifiable health information.
Last updated: 15 July 2026
Data minimisation
Users should upload only the variables required for the approved research objectives. The application scans column names and values for potential direct identifiers and asks the user to remove or mask them before analysis.
Storage and access
Production data must be encrypted in transit and at rest. Access is limited by project role, and each access or change is recorded in an audit log. Retention periods are controlled by the organisation and subscription plan.
Payments
Subscription checkout is hosted by Flutterwave. ZaTafa records the payment reference, selected plan, amount, currency, status and account-linking email, but does not receive or store card numbers, PINs or mobile-money credentials.
Artificial intelligence
Only dataset structure, variable metadata and approved aggregate outputs should be sent to the AI service by default. Raw record-level data must not be used to train external AI models.
Researcher responsibilities
The researcher remains responsible for ethical approval, lawful processing, data-quality decisions, statistical judgment and the final interpretation of findings.