WorxConnect, operated by ZimWorX, connects businesses with university-educated virtual/remote team members working full-time from our first-class global outsourcing campuses. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform and services.

We operate across multiple jurisdictions with candidates in Zimbabwe, Zambia, and Costa Rica, and clients in the United States, United Kingdom, and Canada. We comply with applicable data protection laws in all regions where we operate, including GDPR (UK/EU), CCPA (California), PIPEDA (Canada), and local data protection laws in Zimbabwe, Zambia, and Costa Rica.

How We Operate

WorxConnect is a professional talent platform operated by ZimWorX LLC. All candidates listed on our platform are employees of ZimWorX, not independent contractors. When you engage a candidate through our managed service:

  • ZimWorX remains the legal employer of all personnel
  • ZimWorX handles all payroll, taxes, and benefits for employees
  • You contract with ZimWorX for professional services via a B2B relationship
  • ZimWorX coordinates and manages all work arrangements between clients and employees

Compliance Assurance: This structure ensures compliance with employment laws in all jurisdictions where we operate (Zimbabwe, Zambia, Costa Rica) and where our clients are located (USA, UK, Canada).

Employment Relationship Clarification

For Clients:

When you engage talent through WorxConnect, you are entering into a business-to-business service agreement with ZimWorX, not hiring employees or contractors. ZimWorX is the sole employer of all personnel.

You are responsible for:

  • Communicating project requirements through ZimWorX representatives
  • Reviewing deliverables and providing feedback
  • NOT directing daily work methods, hours, or workplace conduct

For Candidates:

By registering as a candidate, you understand that if successfully placed, you will become an employee of ZimWorX, not an independent contractor. Your employment will be governed by a written team member agreement compliant with the laws of your country of residence (Zimbabwe, Zambia, or Costa Rica).

Information We Collect

Information You Provide to Us

When you create an account, browse our talent marketplace, or contact us, we collect information you voluntarily provide:

For Clients (Businesses Hiring Talent):

  • Account Information: Name, email address, phone number, job title, company name
  • Company Information: Company size, industry, website, business type, year founded
  • Hiring Preferences: Budget range, preferred regions, preferred roles, timeline, compliance requirements

For Candidates (Professionals Seeking Work):

  • Account Information: Name, email address, phone number
  • Professional Information: Professional title, experience level, skills, certifications, education, languages
  • Work Preferences: Availability, business center location, working hours, portfolio/resume
  • Profile Content: Bio, LinkedIn URL, website, location information

Information Automatically Collected

When you access our platform, we automatically collect certain technical information:

  • Device Information: IP address, browser type, device type, operating system
  • Usage Data: Pages viewed, time spent on pages, links clicked, search queries
  • Location Data: General geographic location based on IP address
  • Session Information: Login times, session duration, authentication tokens

How We Use Your Information

We use your personal information for the following purposes, based on our legitimate business interests, to fulfill our contract with you, or with your consent:

Platform Services

To operate our talent marketplace, manage your account, facilitate connections between clients and candidates through our managed service model, and provide customer support.

Talent Matching & Coordination

To match clients with suitable candidates, coordinate placements, verify candidate qualifications, and provide personalized recommendations based on your preferences and requirements.

Communication

To send you service-related notifications, respond to inquiries, provide updates about your account, and send marketing communications (only with your consent, which you can withdraw at any time).

Security & Fraud Prevention

To protect our platform, verify identities, detect and prevent fraud, ensure compliance with our Terms of Service, and maintain audit logs for security purposes.

Platform Improvement

To analyze usage patterns, improve our services, develop new features, conduct research, and enhance user experience based on aggregated, anonymized data.

Legal Compliance

To comply with applicable laws and regulations, respond to legal requests, enforce our agreements, and protect our legal rights and the rights of our users.

Important: Our Employment & Service Model

WorxConnect operates on a professionally managed service model. All candidates listed on our platform are employees of ZimWorX LLC, not independent contractors. When you engage talent through our service:

  • ZimWorX is the employer: We handle all team member agreements, payroll, taxes, and benefits
  • B2B relationship: Clients contract with ZimWorX for services, not directly with individuals
  • Managed coordination: All interactions are mediated through our Talent Acquisition team
  • Contractual framework: We provide Master Service Agreements (MSA), Statements of Work (SOW), and where applicable, Business Associate Agreements (BAA) for healthcare clients

Healthcare Compliance & Business Associate Agreements

For clients in the healthcare industry or those handling Protected Health Information (PHI), ZimWorX provides comprehensive compliance support to ensure adherence to HIPAA and other healthcare data protection regulations.

Business Associate Agreements (BAA)

When ZimWorX employees access, process, or transmit Protected Health Information (PHI) on behalf of healthcare clients, ZimWorX enters into a Business Associate Agreement (BAA) as required by HIPAA (45 CFR §§ 164.308, 164.310, and 164.312).

Our BAA Commitments Include:

  • HIPAA Security Rule compliance: Administrative, physical, and technical safeguards to protect PHI
  • Limited use and disclosure: PHI used only for services provided to the covered entity
  • Employee training: All ZimWorX employees handling PHI receive HIPAA training and certification
  • Breach notification: Notification to covered entity of any PHI breach within required timeframes
  • Right to audit: Covered entities may audit our HIPAA compliance upon reasonable request
  • Data return/destruction: PHI returned or destroyed at contract termination as directed by covered entity

Requesting a BAA

If your organization is a HIPAA-covered entity or business associate and requires a BAA before engaging our services, please contact us during the onboarding process. We will provide our standard BAA template or review your BAA for execution.

Note for Non-Healthcare Clients: If you do not handle PHI or are not subject to HIPAA, a BAA is not required. However, all ZimWorX services include robust data protection measures regardless of your industry, as outlined in this Privacy Policy.

Sharing and Disclosure of Information

We respect your privacy and do not sell your personal information. We share your information only in the following limited circumstances:

Within Our Organization

Your information is shared with our Talent Acquisition team, account managers, and administrative staff who need access to provide services, coordinate placements, and support your account.

Limited Client-Candidate Information Sharing

As part of our managed service model:

  • Clients see: Candidate first name and last initial, professional title, skills, experience, business center location, and portfolio/work samples (no direct contact information)
  • Candidates see: General industry/role requirements, company size range, and project details after being matched (no client contact information)

Privacy Protection: Email addresses, phone numbers, and full names are never shared directly between clients and candidates. All coordination occurs through ZimWorX representatives.

Service Providers

We work with trusted third-party service providers who assist us in operating our platform. These providers are contractually obligated to protect your data and use it only for the services they provide to us:

  • Cloud Hosting: Infrastructure and data storage providers
  • Email Services: To send transactional and marketing emails
  • Analytics: To understand platform usage and improve services
  • Scheduling Tools: For discovery calls and consultations

Legal Requirements

We may disclose your information when required by law, in response to legal proceedings, to protect our rights, or to ensure the safety of our users and platform.

Business Transfers

If ZimWorX is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

Your Privacy Rights

Depending on your location, you have certain rights regarding your personal information. We honor these rights globally:

Right to Access

Request a copy of your personal information we hold about you.

Right to Rectification

Correct inaccurate or incomplete information in your profile.

Right to Erasure

Request deletion of your account and personal data ("right to be forgotten").

Right to Data Portability

Download your data in a machine-readable format (JSON or CSV).

Right to Object

Object to certain processing of your data, including marketing communications.

Right to Restrict Processing

Request that we limit how we use your data while you contest its accuracy or lawfulness.

How to Exercise Your Rights

You can exercise most of these rights directly from your account settings in your profile page. For additional requests or assistance, contact our Data Protection team:

Email: privacy@zimworx.com

Mail: ZimWorX Data Protection Officer, Argyle, Texas, USA

We will respond to your request within 30 days (or as required by applicable law).

California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to opt-out of the "sale" of your personal information. We do not sell your personal information and have not done so in the past 12 months.

Data Security

We take the security of your personal information seriously and implement industry-standard measures to protect it:

Encryption

All data transmission is encrypted using TLS/SSL. Passwords are hashed using industry-standard bcrypt algorithms.

Access Controls

Role-based access control (RBAC) ensures only authorized personnel can access sensitive data.

Audit Logging

Comprehensive audit trails track all access to personal data for security and compliance purposes.

Secure Infrastructure

Our platform is hosted on secure, enterprise-grade cloud infrastructure with regular security updates.

Data Breach Notification

In the unlikely event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours (or as required by applicable law), providing information about the breach, affected data, and steps we're taking to address it.

International Data Transfers

As a global platform connecting candidates in Zimbabwe, Zambia, and Costa Rica with clients in the United States, United Kingdom, and Canada, we transfer personal data across international borders.

Our Safeguards

We ensure that all international data transfers are protected by appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs): EU-approved contract terms for data transfers
  • Transfer Impact Assessments: Evaluating risks for international transfers
  • Encryption: All data is encrypted during transfer and at rest
  • Data Minimization: We transfer only necessary information for service provision

🇿🇼 🇿🇲 🇨🇷 Candidate Data

Data from Zimbabwe, Zambia, and Costa Rica may be transferred to our US-based systems for processing and client matching.

🇺🇸 🇬🇧 🇨🇦 Client Data

Data from USA, UK, and Canada is processed on servers with appropriate data protection certifications.

🔐 Your Protection

Regardless of location, your data receives the highest level of protection under applicable laws.

Data Retention

We retain your personal information only for as long as necessary to provide our services and comply with legal obligations:

Active Accounts

Indefinite

Your account information is retained while your account is active and for legitimate business purposes.

Inactive Accounts

2-3 Years

Accounts with no login activity for 2 years receive a warning. After 3 years, inactive accounts may be deleted.

Deleted Accounts

30-90 Days

When you delete your account, most data is immediately removed. Some data may be retained for 30-90 days for backup purposes.

Audit Logs

1-7 Years

Security and audit logs are retained for 1 year (standard) to 7 years (account deletions) for compliance and security purposes.

Session Data

30 Days

Authentication tokens and session data expire automatically and are cleaned up within 30 days.

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. You can control cookie preferences through our cookie consent banner and your browser settings.

Necessary

Essential for platform functionality, authentication, and security. Cannot be disabled.

Examples: Session tokens, security cookies, user preferences

Analytics

Help us understand how users interact with our platform to improve services.

Examples: Page views, time on site, click patterns

Marketing

Used for third-party services like Calendly and personalized content.

Examples: Calendly embed, remarketing pixels

Manage Your Cookie Preferences

You have control over which cookies we use. Update your preferences at any time:

Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@zimworx.com and we will promptly delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will notify you via email or prominent notice on our platform
  • Your continued use of our services after changes indicates acceptance of the updated policy

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Contact Us About Privacy

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer

Status

Designated Data Protection Officer

Registered with POTRAZ (Zimbabwe)

Email

dpo@zimworx.com

Alternative: privacy@zimworx.com

Office

ZimWorX LLC
Argyle, Texas, USA

General Inquiries

Response Time: We aim to respond to all privacy-related inquiries within 30 days (or as required by applicable law). For urgent matters, please indicate "URGENT" in your subject line.

Jurisdiction-Specific Information

🇬🇧 🇪🇺United Kingdom & European Union (GDPR)

For UK and EU residents, we process your data in accordance with the UK GDPR and EU GDPR. You have specific rights including:

  • • Right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or your local supervisory authority
  • • Right to withdraw consent at any time (where processing is based on consent)
  • • Right to automated decision-making opt-out (we don't currently use automated decision-making)

Legal Basis: We process your data based on contract performance, legitimate interests, legal obligations, and your consent where applicable.

🇺🇸California Residents (CCPA/CPRA)

California residents have specific rights under the CCPA/CPRA:

  • • Right to know what personal information we collect, use, disclose, and sell
  • • Right to delete personal information (with certain exceptions)
  • • Right to opt-out of the "sale" or "sharing" of personal information (we do not sell your information)
  • • Right to correct inaccurate personal information
  • • Right to limit use of sensitive personal information
  • • Right to non-discrimination for exercising your rights

Shine the Light Law

California residents can request information about disclosures of personal information to third parties for their direct marketing purposes once per calendar year.

🇨🇦Canada (PIPEDA)

For Canadian residents, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:

  • • Access your personal information we hold
  • • Challenge the accuracy and completeness of your information
  • • Withdraw consent at any time (subject to legal restrictions)
  • • File a complaint with the Office of the Privacy Commissioner of Canada

We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.

🇿🇼Zimbabwe (Data Protection Act 2021)

For residents of Zimbabwe, we comply with the Data Protection Act [Chapter 11:12] of 2021 and regulations issued by the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).

Our POTRAZ Registration

Data Controller: ZimWorX LLC
Data Protection Officer: Melinda Green
Status: Registered with POTRAZ
Contact: dpo@zimworx.com

Your Rights Under Zimbabwe Data Protection Act:

  • Right to be informed: Transparent information about how we process your data
  • Right to access: Request a copy of your personal data we hold
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data
  • Right to restriction: Limit how we process your data in certain circumstances
  • Right to object: Object to processing based on legitimate interests
  • Right to data portability: Receive your data in a machine-readable format

Cross-Border Data Transfers:

As a Zimbabwean candidate working with ZimWorX, your personal data may be transferred from Zimbabwe to the United States for processing and service delivery. We ensure adequate protection through:

  • Standard Contractual Clauses: Legal agreements approved for international transfers
  • Transfer Impact Assessments: Regular evaluation of transfer safeguards
  • Your explicit consent: During registration, you consent to international transfers
  • Encryption: All data encrypted during transfer and at rest
  • Security measures: Technical and organizational safeguards per POTRAZ requirements

Data Breach Notification:

In the unlikely event of a data breach affecting your personal information, we will notify POTRAZ within 72 hours as required by law. If the breach poses a high risk to your rights and freedoms, we will also notify you directly without undue delay.

Lodge a Complaint with POTRAZ

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ):

POTRAZ
Corner Samora Machel Avenue & Hampton Road
P.O. Box CY 2502, Causeway
Harare, Zimbabwe

Email: info@potraz.gov.zw
Phone: +263 242 785 380-4
Website: www.potraz.gov.zw
🇿🇲Zambia (Data Protection Act 2021)

For residents of Zambia, we comply with the Data Protection Act No. 3 of 2021 and regulations issued by the Zambia Information and Communications Technology Authority (ZICTA).

Your Rights Under Zambian Data Protection Law:

  • Right to information: Know how your personal data is being processed
  • Right to access: Obtain a copy of your personal data we hold
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data
  • Right to data portability: Receive your data in a structured format
  • Right to object: Object to processing for certain purposes

Cross-Border Data Transfers:

Your personal data may be transferred from Zambia to the United States for processing. We ensure protection through:

  • Your explicit consent for international transfers during registration
  • Adequate safeguards and contractual protections
  • Encryption and security measures compliant with ZICTA requirements

Lodge a Complaint with ZICTA

If you believe your data protection rights have been violated, contact:

Zambia Information and Communications Technology Authority (ZICTA)
P.O. Box 36871
Lusaka, Zambia

Email: info@zicta.zm
Phone: +260 211 254 070
🇨🇷Costa Rica (Ley 8968) / Costa Rica Law

🇪🇸 En Español

Para residentes de Costa Rica, cumplimos con la Ley 8968 de Protección de la Persona Frente al Tratamiento de sus Datos Personales:

  • Derecho de acceso: Conocer qué datos personales suyos están siendo procesados
  • Derecho de rectificación: Corregir datos inexactos o incompletos
  • Derecho de supresión: Solicitar la eliminación de sus datos personales
  • Derecho de oposición: Oponerse al procesamiento de sus datos
  • Derecho a la portabilidad: Recibir sus datos en formato estructurado
Transferencias Internacionales:

Sus datos pueden ser transferidos a Estados Unidos. Garantizamos la protección mediante:

  • Su consentimiento explícito para transferencias internacionales
  • Cláusulas contractuales estándar y salvaguardas adecuadas
  • Medidas de encriptación y seguridad

Presentar una Queja

Agencia de Protección de Datos de los Habitantes (PRODHAB)
San José, Costa Rica

Email: info@prodhab.go.cr
Sitio web: www.prodhab.go.cr

🇬🇧 In English

For Costa Rican residents, we comply with Law 8968 on the Protection of Individuals with Regard to the Processing of their Personal Data:

  • Right of access: Know what personal data is being processed
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data
  • Right to object: Object to data processing
  • Right to data portability: Receive your data in a structured format

We provide privacy notices and support in both English and Spanish for Costa Rican residents.

Questions About Your Privacy?

We're here to help. Contact our Data Protection team or visit your account settings to manage your privacy preferences.