Privacy Policy
Last updated: 17 September 2026
1. Introduction
Rudolph & Timba Legal Practitioners (“the Firm“, “we“, “us” or “our“) is committed to delivering quality legal services with integrity and professionalism, and that commitment extends to how we handle your personal information. This Privacy Policy explains what personal information we collect, how we use and protect it, and the rights available to you.
This Policy applies to personal information collected through our website at www.rudolphtimba.com, through our provision of legal services, and through any other interaction you have with the Firm.
We process personal information in accordance with the Cyber and Data Protection Act [Chapter 12:07] and any other applicable law of Zimbabwe.
2. Who is responsible for your information
The Firm is the data controller in respect of the personal information described in this Policy. If you have any questions, you may contact us at info@rudolphtimba.com or using the details in section 15.
3. The information we collect
Depending on your relationship with us, we may collect and process the following categories of personal information:
Information you provide to us
- Identifying details such as your name, national identity or passport number, date of birth and nationality;
- Contact details such as your postal address, email address and telephone number;
- Information relevant to your matter, which may include financial, employment, family, commercial, property or other information necessary to advise and represent you;
- Correspondence and communications between you and the Firm.
Information collected automatically
- When you visit our website, we may collect technical data such as your IP address, browser type, device information, pages visited and the dates and times of your visits, including through cookies and similar technologies (see section 11).
Information from third parties
- We may receive information about you from other parties, such as opposing parties, courts and tribunals, regulators, public registries, other professional advisers, credit reference agencies, and persons who instruct us on your behalf.
Sensitive personal information
- Some matters require us to process sensitive personal information (for example information relating to health, criminal records, political or religious beliefs, or biometric data). We only process such information where it is necessary for your matter and permitted by law.
4. How we use your information
We use personal information for the following purposes:
- To provide legal advice and representation and to carry out your instructions;
- To communicate with you and manage our relationship with you;
- To perform client due diligence, conflict-of-interest checks, and anti-money-laundering and “know your client” verification as required by law;
- To manage our accounts, invoicing and the recovery of fees;
- To operate, maintain and improve our website;
- To comply with our legal, regulatory and professional obligations;
- To establish, exercise or defend legal claims; and
- For any other purpose disclosed to you at the time the information is collected, or to which you consent.
5. Lawful basis for processing
We process personal information where:
- it is necessary for the performance of our engagement with you or to take steps at your request before entering into an engagement;
- it is necessary to comply with a legal or regulatory obligation;
- it is necessary for the purposes of our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests;
- it is necessary to protect the vital interests of a person; or
- you have given your consent.
6. Confidentiality and legal professional privilege
As legal practitioners, we owe you a duty of confidentiality, and much of the information we hold is subject to legal professional privilege. Nothing in this Policy diminishes those protections. We will not disclose privileged or confidential information except where you authorise us to do so, or where we are permitted or required to do so by law or by our professional obligations.
7. When we share your information
We do not sell your personal information. We may share it with:
- Courts, tribunals and opposing parties, where necessary to conduct your matter;
- Regulators and professional bodies, including the Law Society of Zimbabwe, and law-enforcement or government authorities where required;
- Third parties instructed on your matter, such as advocates, experts, translators, notaries, foreign lawyers and other professional advisers;
- Service providers who support our operations (for example IT, document management, secure storage and archiving providers), under obligations of confidentiality and data protection;
- Other parties where you have consented, or where disclosure is otherwise required or permitted by law.
8. Cross-border transfers
Where we transfer personal information outside Zimbabwe — for example to instruct foreign lawyers or to use service providers located abroad — we take reasonable steps to ensure that the information is protected to a standard consistent with the Cyber and Data Protection Act [Chapter 12:07] and this Policy.
9. Data security
We maintain appropriate technical and organizational measures to protect personal information against unauthorized access, loss, misuse, alteration or disclosure. These include access controls, secure storage, confidentiality obligations for our personnel, and our internal systems of teamwork and peer-review. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. How long we keep your information
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, including to provide our services, to comply with our legal, regulatory and professional obligations, and to establish or defend legal claims. Our retention periods reflect the requirements applicable to legal practitioners in Zimbabwe, including obligations relating to client files and accounting records. When information is no longer required, we securely destroy or anonymise it.
11. Cookies and website analytics
Our website may use cookies and similar technologies to enable core functionality, remember your preferences, and understand how the site is used. You can set your browser to refuse some or all cookies, though parts of the site may not function properly as a result.
12. Your rights
Subject to applicable law and to our duties of confidentiality and privilege, you may have the right to:
- request access to the personal information we hold about you;
- request the correction of inaccurate or incomplete information;
- request the deletion of your information in certain circumstances;
- object to, or request that we restrict, certain processing;
- request the transfer of your information; and
- withdraw any consent you have given, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at info@rudolphtimba.com. We may need to verify your identity before acting on a request. Some rights may be limited where the information is subject to privilege, or where retention is required by law.
13. Children
Our website is not directed at children, and we do not knowingly collect personal information from children except where necessary in the course of a matter and permitted by law.
14. Changes to this Policy
We may update this Policy from time to time. The current version will always be available on our website, and the “Last updated” date above indicates when it was last revised. Material changes will be brought to your attention where appropriate.
15. Contact us and complaints
If you have any questions about this Policy or wish to exercise your rights, please contact:
Rudolph & Timba Legal Practitioners [1 Maasdorp Avenue Alexandria Park Harare] Email: info@rudolphtimba.com
If you are not satisfied with how we have handled your personal information, you may lodge a complaint with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), which acts as the Data Protection Authority under the Cyber and Data Protection Act [Chapter 12:07].