Licensing & Policies
Track POTRAZ certificate expiry and policy review cycles with automatic status flags, so nothing lapses without warning.
Learn moreEleven compliance modules per client company, one login for you and your team.
Track POTRAZ certificate expiry and policy review cycles with automatic status flags, so nothing lapses without warning.
Learn moreLog incidents and data subject requests with full status workflows, owners, deadlines and a complete response history.
Learn moreCDPA-aligned templates you can adapt per client, with pre-population, risk scoring and formal company sign-off.
Learn moreRun staff awareness training with a built-in exam engine: retries, cooldowns, CSV question upload and certificates.
Learn moreGive each client login exactly the modules they need to edit; everything else stays safely view-only.
Learn morePull compliance scores, tickets and breach data into your own dashboards and client portals with a personal API key.
Learn moreFour steps, and most practices are running live client work on day one.
Register your DPO account, choose a plan and invite the colleagues who work alongside you.
Each company gets its own workspace, its own documents and its own compliance percentage.
Licensing, breaches, ROPA, DPIA, policies, training and audits, all tracked with owners and due dates.
Export a defensible record of everything done on each client's behalf, ready for the board or the regulator.
Data Trust was built for the people who actually carry the compliance workload: independent Data Protection Officers and the in-house teams supporting them across Zimbabwe.
Instead of scattered spreadsheets and buried email trails, every client company gets its own workspace, its own compliance percentage, and an auditable record of everything done on its behalf. When a regulator asks what you did and when you did it, the answer is already documented.
Our aim is simple: make it straightforward to meet Cyber and Data Protection Act and GDPR obligations without a large compliance department, so a single DPO or a small advisory team can confidently serve any number of client companies.
Three statements that decide what we build and how we work with every client.
We want to see a business landscape where protecting personal information is ordinary practice rather than a scramble before an inspection, where every organisation, from a five-person startup to a national bank, can show exactly how it safeguards the people it serves.
Our mission is to give independent Data Protection Officers and lean in-house teams the tools, templates and evidence trail they would otherwise need a whole department to maintain, so meeting the Cyber and Data Protection Act becomes a routine, affordable part of doing business.
Our goal is to become the standard workspace for data protection work in the region: continually widening our module coverage, keeping our templates current with every regulatory update, and supporting our clients so well that their compliance percentage never has to be explained twice.
Whichever kind of practice you run, the same platform scales with you.
Serve multiple client companies from one login: track POTRAZ licensing, breaches and ROPA/DPIA per client, and show each of them their own compliance percentage.
Act as the named DPO for a group of subsidiaries. Give each one a scoped login so their team can complete their own ROPA while you retain oversight and sign-off.
Layer data protection advisory onto existing client relationships: log advisory notes, run audits, and keep an auditable record of every recommendation given.
Meet CDPA breach-notification and staff-training obligations with a documented exam trail, incident workflow and policy review schedule your regulator can see.
Our clients handle sensitive information, so these accounts are shared anonymously at their request.
I was running six client companies out of three spreadsheets and a shared inbox. Now each one has its own workspace and I can answer "where are we on this?" in about four seconds instead of half an afternoon.
The breach workflow is the part that earned its keep. We logged an incident, assigned it, and had the whole notification timeline documented without anyone having to remember what the Act requires.
Getting staff through data protection training used to be an annual argument. The exam engine handles retries and records who passed, so I just check the dashboard and move on.
Names and companies withheld at our clients' request, in keeping with our own confidentiality commitments.
All plans include a free trial. No setup fees, no long contracts, cancel anytime.
The things practitioners ask us most. If your question is not here, just send it through.
No. The platform is built around the way an independent Data Protection Officer works, but in-house compliance teams, legal firms and IT security providers use it just as effectively. If you are working towards POTRAZ registration, the licensing module will help you keep that process on track too.
Yes. The ROPA and DPIA templates, breach notification workflow and policy review cycles are all built around the CDPA and its requirements. The same records also map onto GDPR obligations, which matters if any of your clients process data belonging to people in Europe.
That depends on your plan. Entry plans cover a single company, and higher plans move up to unlimited. You can change plan at any time as your practice grows, and your existing data carries across untouched.
They can. Each client company can be given sub-accounts with granular permissions, so their staff can complete their own ROPA entries or training while everything else stays view-only. You keep oversight and final sign-off.
It is derived from the status of each module for that company: what has been completed, what is outstanding and what has lapsed. Because every item is visible underneath the score, you can always explain exactly how the number was reached.
Data is held on encrypted connections, access is scoped per account, and every action is logged with a user and a timestamp. We hold ourselves to the same standards we help our clients meet, our privacy policy sets out the detail.
Nothing is deleted. Your account moves to a read-only state until you choose a plan, so you keep access to everything you have recorded and can pick up exactly where you left off.
Yes. You can export your records, and the read-only REST API lets you pull compliance scores, tickets, breaches, ROPA and DPIA data into your own reporting tools with a personal API key.
We do. Every plan includes support, and we run onboarding sessions and monthly CDPA practitioner workshops. Larger rollouts can have dedicated onboarding arranged as part of a custom plan.
Payments are processed through Paynow, which covers local mobile money and card options. For annual or custom arrangements, get in touch and we will invoice you directly.
Still have a question?
Ask us directlyFranchise networks, regulators and larger practices sometimes need a bespoke rollout. Tell us what you're running and we'll design a plan around it.
Questions about pricing, onboarding, or the platform itself. We usually reply within a business day.