Zimo Clan — Decentralized Agricultural Finance Ecosystem
Effective Date: May 22, 2026 | Last Updated: May 22, 2026 | Version: 1.0
1. INTRODUCTION
Zimo Protocol Labs ("Zimo Clan," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you:
- Visit our website at https://zimoclan.com
- Use the Heraja Farm Intelligence App
- Participate in the Zimo Protocol as a Partner Farm or Digital Farmer
- Interact with our smart contracts on the Solana blockchain
- Contact our support team or engage with our community channels
This policy applies to all users globally, with specific provisions for residents of Nigeria, the European Union (GDPR), the United Kingdom, and other jurisdictions with applicable privacy laws.
By using our services, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use our services.
2. INFORMATION WE COLLECT
2.1 Information You Provide Directly
For Partner Farms (Farmers):
- Identity Information: Full name, date of birth, government ID number (NIN, voter's card, driver's license, passport), ID document copies
- Contact Information: Phone number, email address, home address, LGA, state
- Farm Information: Farm name, location, size, type of farming, photos, operational history
- Financial Information: Bank account details, mobile money wallet IDs, payment history
- Biometric Information: Facial geometry data from liveness verification (selfie checks)
- Application Materials: Documents uploaded during verification (land deeds, certificates, references)
For Digital Farmers (Web3 Participants):
- Identity Information: Name, government ID, proof of address (for KYC tiers)
- Contact Information: Email address, phone number
- Wallet Information: Solana wallet public address (NOT private keys — we never ask for these)
- Transaction Data: On-chain transaction history related to Zimo Protocol interactions
- KYC Documents: ID copies, selfies, proof of funds (for enhanced tiers)
For All Users:
- Communication Data: Emails, chat logs, support tickets, feedback forms
- Marketing Preferences: Newsletter subscriptions, notification settings
- Referral Information: Who referred you, who you referred
2.2 Information Collected Automatically
Technical Data:
- IP address, browser type and version, operating system
- Device type, screen resolution, language preferences
- Time zone, geolocation (approximate, based on IP)
- Referral source, pages visited, time spent on site
- Click patterns, scroll behavior, feature usage
Blockchain Data (Public by Design):
- Wallet addresses and transaction hashes
- Smart contract interactions (deposits, withdrawals, claims)
- Token balances and staking positions
- Governance votes and proposals
Important: Blockchain data is immutable and publicly visible. While wallet addresses are pseudonymous, transaction patterns can potentially be linked to identities. We cannot delete, modify, or restrict access to on-chain data.
App Usage Data:
- Login times and frequency
- Features used within the Heraja App
- Daily report submissions and patterns
- AI recommendation interactions
- Crash logs and performance metrics
Cookies and Similar Technologies:
- Session cookies (essential for functionality)
- Preference cookies (language, region settings)
- Analytics cookies (Google Analytics, Mixpanel)
- Advertising cookies (only with explicit consent)
2.3 Information from Third Parties
- Identity Verification Providers: NIMC (Nigeria), Jumio, Onfido, SumSub
- Blockchain Analytics: Chainalysis, Elliptic, TRM Labs (for compliance screening)
- Payment Processors: Paystack, Flutterwave, bank APIs
- Marketing Partners: Social media platforms, referral programs
- Public Sources: Government registries, sanctions lists, PEP databases
3. HOW WE USE YOUR INFORMATION
3.1 Primary Purposes
| Purpose | Legal Basis | Data Used |
|---|
| Identity Verification | Legal obligation, contract performance | ID documents, biometrics, KYC data |
| Farm Verification | Contract performance | Farm photos, location, operational data |
| Capital Allocation | Contract performance | Farm scores, production plans, wallet addresses |
| Payment Processing | Contract performance | Bank details, mobile money IDs, transaction history |
| Risk Assessment | Legitimate interest | Farm data, historical performance, credit checks |
| Fraud Prevention | Legal obligation | Transaction patterns, device fingerprints, behavioral data |
| Platform Security | Legitimate interest | Login attempts, IP addresses, suspicious activity |
| Customer Support | Contract performance | Communication history, account details, issue reports |
| Product Improvement | Legitimate interest | Usage analytics, feature engagement, crash reports |
| Marketing & Communications | Consent (withdrawable) | Email, phone, preferences |
| Legal Compliance | Legal obligation | All data as required by regulators |
| Research & Analytics | Legitimate interest (anonymized) | Aggregated, de-identified datasets |
3.2 Specific Uses for Farmers
- Daily Operations: Send reminders for reporting, weather alerts, AI recommendations
- Vet Coordination: Share health data with certified veterinarians for diagnosis
- Input Delivery: Share location and contact details with logistics partners
- Payment Distribution: Process earnings to your bank account or mobile wallet
- Performance Tracking: Calculate ZOU scores, farm ratings, and eligibility for expanded financing
3.3 Specific Uses for Digital Farmers
- Investment Management: Track pool performance, calculate returns, process claims
- Governance: Verify voting eligibility, weight votes by stake, execute decisions
- Compliance: Screen for sanctions, PEP status, suspicious transaction patterns
- Tax Reporting: Generate annual transaction summaries for your records
3.4 Automated Decision-Making
We use automated systems for:
- Farm Scoring: Algorithmic assessment of verification data (0–100 score)
- Risk Profiling: Transaction monitoring and anomaly detection
- KYC Tiers: Automatic classification based on documentation completeness
- Emission Calculations: ZOU-to-token conversion based on verified production data
Your Rights: You can request human review of any automated decision that significantly affects you (e.g., farm rejection, account suspension).
4. HOW WE SHARE YOUR INFORMATION
4.1 Within Zimo Ecosystem
- Heraja Operations Team: Farm advisors, field agents, vet coordinators
- Zimo Protocol Labs: Engineering, compliance, executive teams
- Affiliated Entities: Heraja Agro Technologies, Zimo Foundation (future DAO)
All internal sharing is on a need-to-know basis with appropriate access controls.
4.2 Service Providers (Processors)
| Category | Provider | Purpose | Location |
|---|
| Cloud Infrastructure | Amazon Web Services (AWS) | Data storage, app hosting | Ireland (EU), USA |
| Identity Verification | Jumio, SumSub | KYC/AML checks | USA, EU |
| Blockchain Infrastructure | Solana Foundation | Node access, RPC | USA, EU, Asia |
| Analytics | Google Analytics, Mixpanel | Usage analytics | USA |
| Communication | Twilio, SendGrid | SMS, email notifications | USA |
| Payment Processing | Paystack, Flutterwave | Naira payments | Nigeria |
| Customer Support | Zendesk, Intercom | Ticket management | USA, EU |
| Security | Chainalysis, TRM Labs | Compliance screening | USA |
All processors are bound by Data Processing Agreements (DPAs) requiring:
- Processing only on our instructions
- Adequate security measures
- Confidentiality obligations
- Deletion/return of data upon contract termination
4.3 Partner Farms & Marketplace Participants
- Buyer-Seller Matching: Farm names, locations, product types, and quality grades are shared with potential buyers
- Logistics Coordination: Delivery addresses and contact details shared with transport providers
- Vet Services: Health data shared with certified veterinarians in our network
What We DON'T Share:
- Your full government ID number
- Your bank account details (except to payment processors)
- Your biometric data (except to verification providers)
- Your private keys or wallet seed phrases (we never have these)
4.4 Legal and Regulatory Disclosures
We may disclose information when required by:
- Court orders, subpoenas, or legal process
- Regulatory investigations (SEC, CBN, FATF, etc.)
- Law enforcement requests (with appropriate legal basis)
- Tax authorities (with proper documentation)
We will notify you of such disclosures unless prohibited by law.
4.5 Business Transfers
If Zimo Protocol Labs is acquired, merged, or undergoes asset sale:
- Your information may be transferred to the acquiring entity
- You will be notified of any change in data controller
- Your rights under this policy remain protected
4.6 Public and On-Chain Data
All transactions on the Solana blockchain are publicly visible and immutable. This includes:
- Wallet addresses
- Transaction amounts and timestamps
- Smart contract interactions
- Token transfers
We cannot control, restrict, or delete blockchain data. If you require privacy, consider using a separate wallet for Zimo interactions.
Public Profiles (Optional): Farm names and general locations (state-level) may appear on public leaderboards. You can opt out in your account settings.
5. DATA STORAGE AND SECURITY
5.1 Storage Locations
- Primary: AWS data centers in Ireland (EU) and USA
- Backup: Encrypted copies in multiple geographic regions
- Blockchain: Solana network (globally distributed validators)
5.2 Retention Periods
| Data Type | Retention Period | Reason |
|---|
| Identity documents | 7 years after account closure | Legal/regulatory compliance |
| Transaction records | 7 years | Tax and audit requirements |
| Farm operational data | 5 years after last activity | Historical analysis, dispute resolution |
| Communication logs | 3 years | Customer support, legal defense |
| Analytics data | 2 years (then anonymized) | Product improvement |
| Marketing data | Until consent withdrawn | Communication preferences |
| Biometric data | 3 years after verification | Fraud prevention, re-verification |
Early Deletion: You can request deletion of non-mandatory data at any time (see Section 8).
5.3 Security Measures
Technical Safeguards:
- Encryption at Rest: AES-256 encryption for all stored data
- Encryption in Transit: TLS 1.3 for all network communications
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA)
- API Security: Rate limiting, input validation, OAuth 2.0
- Blockchain Security: Multi-sig treasury, timelocked upgrades, audited smart contracts
Organizational Safeguards:
- Employee background checks
- Regular security training
- Confidentiality agreements
- Incident response plan
- Annual third-party security audits
Breach Notification:
If we discover a data breach affecting your personal information, we will:
- Contain and investigate the breach within 24 hours
- Notify affected users within 72 hours of discovery
- Report to relevant regulators within required timeframes
- Provide guidance on protective measures
6. BLOCKCHAIN-SPECIFIC PRIVACY CONSIDERATIONS
6.1 Public Nature of Blockchain
The Solana blockchain is a public, distributed ledger. This means:
- Anyone can view transaction history for any wallet address
- We cannot delete transaction records (they are immutable)
- Pseudonymity, not anonymity: While wallet addresses don't show your name, transaction patterns can potentially be analyzed to infer identities
6.2 What We Can and Cannot Control
| Aspect | Our Control | Your Control |
|---|
| Transaction data on-chain | None (immutable) | Use fresh wallet for each interaction |
| Wallet address linkage | None | Don't publicly associate wallet with identity |
| Off-chain personal data | Full (stored in our databases) | Request deletion (subject to legal retention) |
| KYC verification records | Full (with legal retention) | Request access, correction, or deletion |
| App usage data | Full | Adjust privacy settings, opt out of analytics |
6.3 Privacy Best Practices for Users
- Use a dedicated wallet for Zimo interactions (don't reuse your main wallet)
- Don't publicly link your wallet address to your real identity
- Use privacy tools when required (e.g., confidential transfers when available)
- Review transaction history regularly for unauthorized activity
7. INTERNATIONAL DATA TRANSFERS
7.1 Transfer Mechanisms
Your data may be transferred to countries outside your residence, including:
- Nigeria (primary operations)
- United States (cloud infrastructure, service providers)
- European Union (cloud infrastructure, identity verification)
- Singapore (blockchain infrastructure)
We ensure adequate protection through:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions where recognized by relevant authorities
- Data Processing Agreements with all subprocessors
7.2 Nigerian Data Protection Regulation (NDPR)
For Nigerian residents, we comply with the NDPR 2019:
- Data processed lawfully, fairly, and transparently
- Collected for specified, explicit, and legitimate purposes
- Adequate, relevant, and limited to what is necessary
- Accurate and kept up to date
- Retained only as long as necessary
- Processed securely
8. YOUR RIGHTS
8.1 General Rights (All Users)
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data, subject to legal retention requirements.
- Right to Restrict Processing: Request limited use of your data in specific circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time (does not affect prior lawful processing).
- Right to Complain: Lodge a complaint with your local data protection authority.
8.2 Specific Rights for Nigerian Residents (NDPR)
- Right to request information about data processing
- Right to request cessation of processing that causes distress
- Right to prevent processing for direct marketing
- Right to compensation for damages from data breaches
8.3 Specific Rights for EU/UK Residents (GDPR/UK GDPR)
- Right to be informed (this Privacy Policy)
- Right of access (Subject Access Request)
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
To Exercise Your Rights:
- Email: privacy@zimoclan.com
- Subject: "Data Rights Request — [Your Name]"
- Include: Proof of identity (ID copy), specific request, wallet address (if applicable)
- Response time: 30 days (may extend to 60 days for complex requests)
8.4 Limitations on Rights
We may refuse requests that:
- Are manifestly unfounded or excessive
- Jeopardize others' rights or freedoms
- Conflict with legal obligations (e.g., tax retention laws)
- Impair fraud prevention or security measures
9. COOKIES AND TRACKING
9.1 What We Use
| Cookie Type | Purpose | Duration | Required? |
|---|
| Essential | Login sessions, security, preferences | Session / 1 year | Yes |
| Functional | Language, region, app settings | 1 year | No |
| Analytics | Google Analytics, Mixpanel | 2 years | No |
| Marketing | Ad conversion tracking | 90 days | No |
9.2 Your Choices
- Browser Settings: Block all cookies (may break functionality)
- Cookie Banner: Choose which categories to accept on first visit
- Opt-Out Links:
9.3 Do Not Track
We honor browser "Do Not Track" signals for analytics and marketing cookies. Essential cookies remain active for platform functionality.
10. CHILDREN'S PRIVACY
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
If we discover that a child under 18 has provided personal information:
- We will delete the information immediately
- We will terminate the associated account
- Parents/guardians can contact us at privacy@zimoclan.com
11. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically to reflect:
- New features or services
- Legal or regulatory changes
- Changes in data processing practices
- Security improvements
Notification:
- Material changes: Email notification + banner on website (30 days notice)
- Minor changes: Updated date at top of policy
- Continued use after changes = acceptance of revised policy
Archive: Previous versions available upon request.
12. CONTACT US
Data Protection Officer:
For Data Rights Requests:
For General Privacy Questions:
For Regulatory Inquiries:
Effective Date: May 22, 2026
By using Zimo Clan services, you acknowledge that you have read and understood this Privacy Policy.
Copyright 2026 Zimo Ecosystem. All rights reserved.