Zergaw Hosting Privacy Policy

Zergaw Hosting - Client Management, Invoicing and Support Software

ZERGAW CLOUD - PRIVACY POLICY

This Privacy Policy outlines the explicit practices, lawful bases, architectural mechanisms, and governance frameworks governing the processing, hosting, transmission, and lifecycle management of Personal Data and Customer Enterprise Content across our cloud services ecosystem—including Infrastructure as a Service (IaaS), Software as a Service (SaaS), Security as a Service (SECaaS), Database as a Service (DBaaS), and Demand-Based ICT Infrastructure Solutions.

1. Regulatory Governance Architecture

This document establishes full legal alignment with federal legislation in the Federal Democratic Republic of Ethiopia and international privacy frameworks, forming a binding regulatory architecture:

  • Ethiopian Personal Data Protection Proclamation No. 1321/2024: Enforces primary statutory compliance regarding data subject rights, lawful processing principles, mandatory registration with regulatory authorities, data protection impact assessments (DPIAs), and domestic data residence mandates.
  • Computer Crimes Proclamation No. 958/2016: Governs requirements for illegal access prevention, data integrity protection, system security audits, criminal liability for data interception, and mandatory retention of communication access logs.
  • INSA Critical Mass Standards & ECA Cloud Directives: Complies with the cyber threat containment rules, incident reporting schedules, and infrastructure security baseline rules established by the Information Network Security Administration (INSA) and the Ethiopian Communications Authority (ECA).
  • International Security Standards (ISO/IEC 27001 & NIST CSF v1.1): Aligns technical safeguards with ISO/IEC 27001 (Information Security Management Systems), ISO/IEC 27018 (Code of practice for protection of personally identifiable information in public clouds), and the NIST Cybersecurity Framework across Identify, Protect, Detect, Respond, and Recover domains.
  • European Union General Data Protection Regulation (EU GDPR - Regulation 2016/679): Serves as the international benchmark for Data Controller versus Data Processor role allocation, data protection by design/default, and cross-border data transfer safeguards.

2. Definition of Roles: Data Controller vs. Data Processor

To establish transparency and contractual precision, ZERGAW CLOUD explicitly delineates legal roles under Proclamation No. 1321/2024 and international data protection standards:

2.1 ZERGAW CLOUD as Data Controller

ZERGAW CLOUD operates as a Data Controller with respect to account management information, customer identity metadata, billing and transaction histories, technical diagnostic telemetry, and direct support interactions. As Data Controller, ZERGAW CLOUD determines the purpose and lawful means of processing such administrative data.

2.2 ZERGAW CLOUD as Data Processor

ZERGAW CLOUD acts exclusively as a Data Processor regarding all Customer Content stored, executed, or processed within our cloud platforms. This includes data processed through hosted Enterprise Resource Planning (ERP) systems, Letter Tracking Systems, Attendance & Payroll Applications, Enterprise Document Management Systems, Cloud Storage Buckets, Corporate Email, and Virtual Private Servers (VPS). In this capacity, the enterprise client acts as the Data Controller, maintaining absolute ownership and authority over customer data definitions, access controls, and processing instructions.

3. Comprehensive Categories of Personal & Operational Data Processed

 

Data Classification Data Elements Collected Collection Mechanism Primary Statutory Purpose 
Account & Identity Metadata Full legal name, corporate title, legal entity designation, work email address, verified phone numbers, government identification details (for enterprise verification). Direct user input during account registration, service provisioning, or contract execution. Account establishment, legal identity verification, administrative communication, contractual execution.
Financial & Billing Records Payment logs, transaction identifiers, billing addresses, tax identification numbers (TIN), digital wallet references (e.g., Telebirr, CBE Birr), invoice histories. Automated payment gateway integration and financial reconciliation channels. Transaction processing, statutory tax reporting (Ethiopian Ministry of Revenue compliance), audit requirements.
System Telemetry & Access Logs IP addresses, MAC addresses, device identifiers, browser types, session timestamps, DNS query logs, API access logs, bandwidth utilization metrics. Automated background logging via hypervisors, cloud firewalls, load balancers, and gateway edge routers. System health monitoring, load balancing, DDoS attack mitigation, security breach audits under Proclamation No. 958/2016.
Tenant Application Content Customer-hosted databases, financial ledgers, employee records, internal communications, uploaded digital documents, encrypted backups. Customer upload, tenant application execution, API ingestion, automated server backups. Processing and hosting strictly based on tenant instructions and active service SLA agreements.

4. Lawful Bases for Processing Under Proclamation No. 1321/2024

In accordance with Article 5 of Ethiopian Personal Data Protection Proclamation No. 1321/2024, ZERGAW CLOUD executes all data processing activities exclusively under one or more of the following lawful bases:

  1. Explicit Legal Consent: Granted by data subjects or organizational representatives during service registration or opt-in verification.
  2. Performance of Contractual Obligations: Necessary to fulfill core Cloud Service Level Agreements (SLAs), deliver provisioning requirements, and maintain continuous service availability.
  3. Compliance with Statutory Obligations: Mandated by Ethiopian tax laws, telecom regulatory requirements, or lawful court directives issued by federal judicial bodies.
  4. Legitimate Technical & Operational Interests: Pursued to protect cloud infrastructure integrity, prevent cybercrime under Proclamation No. 958/2016, defend against malicious network activity, and maintain uninterrupted zero-trust edge protection.

5. Technical & Organizational Data Protection Safeguards (Z-CARE Framework)

ZERGAW CLOUD protects data through our proprietary multi-tenant security architecture known as the Z-CARE Framework, enforcing defense-in-depth security measures across six layers:

The Z-CARE Security Layers:

  • Layer 1 — Physical Infrastructure Security: Co-located and dedicated tier III data center facilities within Addis Ababa (including ICT Park, Bole, and Legahar sites) featuring biometric access controls, 24/7 CCTV tracking, redundant power (dual UPS + generator backup), and automated fire suppression.
  • Layer 2 — Network & Edge Security: Enterprise DDoS mitigation, automated web application firewalls (WAF), stateful inspection firewalls, perimeter intrusion prevention systems (IPS), and isolated VPC routing.
  • Layer 3 — Hypervisor & Virtualization Isolation: Strict kernel-level tenant segregation preventing cross-VM side-channel attacks, resource leaks, or unauthorized memory inspection across shared multi-tenant hosts.
  • Layer 4 — Cryptographic Data Protection: All data in transit is encrypted using TLS 1.3, WireGuard, or IPsec (256-bit encryption key strength). All persistent storage volumes, snapshots, and backups are encrypted at rest using AES-256 standards with hardware security module (HSM) key isolation.
  • Layer 5 — Identity & Access Management (IAM): Zero-Trust Identity verification enforcing role-based access control (RBAC), multi-factor authentication (MFA), strict session timeouts, and privilege escalation logging.
  • Layer 6 — Security Operations Center (SOC) Governance: Continuous 24/7 real-time monitoring via automated SIEM tools, proactive vulnerability threat hunting, software patching workflows, and rapid incident isolation response.

6. Data Sovereignty & Geographic Residency Controls

To support national cloud autonomy and full compliance with Article 42 of Ethiopian Personal Data Protection Proclamation No. 1321/2024, ZERGAW CLOUD guarantees strict domestic data residency:

  • 100% In-Country Storage: All primary enterprise databases, backups, system state logs, customer personal data, and disaster recovery nodes operate within certified data center facilities located inside the Federal Democratic Republic of Ethiopia (Addis Ababa region).
  • Cross-Border Transfer Restrictions: ZERGAW CLOUD does not transfer, route, or backup customer personal data outside the borders of Ethiopia unless explicitly requested by the Data Controller through specific cross-border configuration instructions, and provided that such transfer satisfies all lawful criteria and regulatory approvals established by the national supervisory authority.

7. Data Retention, Audit Logging, & Certified Destruction Schedules

7.1 Statutory Activity Logging Mandates

Pursuant to Article 50 of Proclamation No. 1321/2024 and provisions within Computer Crimes Proclamation No. 958/2016, ZERGAW CLOUD maintains automated, tamper-proof system security logs. These access logs track system entry, record modifications, administrative overrides, data transfers, and account deletions for a mandatory retention period of no less than two (2) years to facilitate forensic security analysis and legal compliance.

7.2 Data Destruction Standards

Upon contract expiration, service termination, or receipt of a formal data erasure instruction from a Data Controller, ZERGAW CLOUD follows strict data destruction protocols. Storage blocks are zero-filled, overwritten, and sanitized using NIST SP 800-88 Rev. 1 media sanitization standards. Physical media retiring from service undergoes total degaussing or physical shredding.

8. Statutory Data Subject Rights

In accordance with Chapter 3 of Proclamation No. 1321/2024, individual data subjects whose information is controlled directly by ZERGAW CLOUD hold statutory rights. Requests may be exercised by contacting our Data Protection Officer:

  • Right of Access & Confirmation: The right to obtain official confirmation of whether personal data is being processed, along with detailed records regarding processing scope, source data, and receiving parties.
  • Right to Rectification: The right to require immediate correction or updating of incomplete or inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): The right to request permanent deletion of personal data where retention is no longer necessary for contractual execution, statutory compliance, or legitimate operational purposes.
  • Right to Object & Restrict Processing: The right to object to specific automated processing, direct marketing outreach, or discretionary profiling activities.
  • Right to Withdrawal of Consent: The right to withdraw processing consent at any time without compromising the lawfulness of historical processing executed prior to revocation.
  • Right to File Regulatory Complaints: The right to lodge administrative grievances directly with ZERGAW CLOUD's Privacy Office or elevate unresolved matters to the Ethiopian Communications Authority (ECA) or national supervisory board.

9. Mandatory Data Breach Notification Workflow

ZERGAW CLOUD maintains an incident management framework compliant with INSA standards and national data protection laws. In the event of a confirmed security breach compromising personal data or customer content integrity:

  1. Regulatory Escalation: ZERGAW CLOUD will notify the Ethiopian Communications Authority (ECA) and relevant security agencies within 72 hours of technical confirmation.
  2. Data Controller & Subject Communication: Impacted enterprise clients and affected data subjects will receive timely notification outlining the nature of the breach, estimated impact, affected data categories, and immediate corrective steps implemented.
  3. Mitigation & Remediation: Immediate execution of system isolation, key rotation, patch deployment, and post-incident security reporting.

10. Contact Details

For inquiries regarding this Privacy Policy, compliance audits, or data subject rights requests, contact our privacy governance team:

Physical Office: HQ, ICT Park, ZERGAW Building, Addis Ababa, Ethiopia

Official Email: hello@zergaw.com / support@zergaw.com

Telephone Contact: +251 932 414 243 / +251 116 39 33 03

Customer Shortcode: 9892

Corporate Web Portal: www.zergaw.com

© 2026 Zergaw Cloud. All rights reserved.