Healing relationships. Strengthening families. Building legacy marriages.
Your privacy matters

Privacy Policy

How Roots of Love Therapy handles personal information with care, transparency and respect for the sensitive nature of relationship support.

Effective: 21 August 2026 Last reviewed: 21 August 2026

Plain-language commitment: we collect only what we reasonably need, use it for clear purposes, limit who can access it, and treat relationship and wellbeing information as particularly sensitive.

1. Who we are and the scope of this policy

Roots of Love Therapy (“Roots of Love”, “we”, “us” or “our”) provides relationship education, assessments, counselling and therapeutic support. This policy applies to personal information processed through rootsoflovetherapy.com, enquiries, bookings, assessments, communications, programs and therapy-related administration.

For purposes of Zimbabwean data-protection law, the person or legal entity operating Roots of Love Therapy and deciding why and how personal information is processed is the data controller. The organisation's final registered name, physical address and Data Protection Officer or privacy representative details should be inserted here once formally confirmed.

2. Personal information we may collect

The information collected depends on how you interact with us and may include:

  • Identity and contact information: your name, email address, telephone number, location and preferred contact method.
  • Booking and service information: the service you are seeking, availability, appointment history and administrative correspondence.
  • Relationship and household information: relationship status, family context, concerns, goals and information you choose to share about a partner or family member.
  • Sensitive and health-related information: emotional wellbeing, mental or physical health, faith or beliefs, sex life, trauma, safety concerns and therapy notes where relevant to professional care.
  • Payment and transaction information: invoices, payment status and limited transaction records. Full card details should be processed by an authorised payment provider rather than stored by us.
  • Technical information: IP address, browser and device type, pages visited, timestamps, referral source and basic security logs if analytics, hosting or security tools are enabled.
  • Communications: emails, messages, contact-form entries, feedback and complaints.

Information about another person

If you provide information about your partner, child or another person, please share only what is reasonably necessary and, where appropriate, let them know that you have shared it. Information given by one partner may be relevant to couples work, but the treatment of private disclosures must also be governed by the therapy agreement agreed at intake.

The couples check-in

The public website check-in is currently a reflective frontend tool. Answers are scored within your browser and are not submitted to or stored by Roots of Love. If an account-based or clinician-reviewed assessment is introduced later, we will explain what is collected, why, who can see it and how long it is retained before collection begins.

3. How we use personal information

We may use information to:

  • respond to enquiries and recommend an appropriate starting point;
  • schedule, deliver and administer sessions, assessments and programs;
  • maintain professional records and continuity of care;
  • communicate about appointments, service changes and relevant follow-up;
  • process payments, issue receipts and meet accounting obligations;
  • protect clients, practitioners, systems and other people from harm, fraud or misuse;
  • improve services using aggregated or appropriately de-identified learning;
  • meet professional, ethical, regulatory and legal duties; and
  • send optional educational or marketing communications where you have chosen to receive them.

We do not sell personal information. We do not use therapy information for targeted advertising. We will not make a decision producing legal or similarly significant effects solely through an automated quiz score.

4. Grounds for processing

Depending on the activity and applicable law, processing may be based on your informed consent, steps requested before entering a service agreement, performance of that agreement, compliance with a legal or professional obligation, protection of vital interests, or a legitimate purpose that does not unfairly override your rights. Sensitive information receives additional protection and will be processed only where an appropriate legal basis and safeguards apply.

You may withdraw consent where consent is the basis for processing. Withdrawal does not invalidate earlier lawful processing and may not require deletion where information must be kept for another lawful reason.

5. Therapy confidentiality

Privacy law and therapeutic confidentiality overlap but are not identical. Information shared in therapy is treated as confidential and accessed only by authorised people who need it for care or administration. Before services begin, clients should receive a separate informed-consent and therapy agreement explaining record keeping, couples-confidentiality expectations, communication boundaries, emergencies, supervision and the specific limits of confidentiality.

Confidentiality may be limited where disclosure is required or permitted by law, ordered by a competent authority, necessary to address a serious and imminent safety concern, required to report certain forms of abuse, or needed to establish or defend a legal claim. The exact limits depend on the circumstances and applicable professional duties.

6. When information may be shared

We disclose only what is reasonably necessary and may share information with:

  • authorised practitioners, administrative staff or professional supervisors bound by confidentiality;
  • technology providers supporting secure hosting, email, scheduling, video sessions, forms, record systems, backups or cybersecurity;
  • payment processors, accountants, auditors and professional advisers;
  • another healthcare professional where you request or authorise coordinated care;
  • regulators, courts, law-enforcement bodies or safeguarding authorities where lawfully required; and
  • a successor organisation during a properly managed reorganisation, subject to confidentiality and data-protection safeguards.

Service providers should act under written instructions, use information only for the agreed service and apply appropriate confidentiality and security measures.

7. Processing outside Zimbabwe

Some technology providers may store or support information outside Zimbabwe. Before using such services for identifiable or sensitive information, we will assess the destination, contractual protections and other safeguards required for lawful transborder data flows. Clients should be told when a core clinical platform routinely stores their information in another country.

8. How long we keep information

We keep information only for as long as reasonably necessary for the purpose collected and to meet legal, tax, insurance, safeguarding and professional-record obligations. Retention periods differ by record type and may be suspended where a complaint, safety issue or legal claim requires preservation.

To be finalised before collecting clinical data: Roots of Love should approve a written retention schedule covering enquiries that do not become clients, adult clinical records, records involving minors, assessment results, payment records, consent forms, security logs and marketing preferences. When retention ends, information should be securely deleted, destroyed or irreversibly de-identified.

9. How we protect information

We use proportionate organisational and technical measures designed to protect information against accidental loss, unauthorised access, alteration, disclosure or destruction. These should include role-based access, strong authentication, secure device configuration, encrypted transmission, protected backups, confidentiality commitments, vendor review, staff training and an incident-response process.

No method of electronic storage or transmission is completely secure. If a personal-data breach creates a material risk, we will investigate, contain it, document it and notify the Data Protection Authority and affected people where required.

10. Your data-protection rights

Subject to applicable law and any valid exceptions, you may ask to:

  • be informed about how your information is used;
  • access personal information held about you;
  • correct information that is inaccurate, incomplete, false or misleading;
  • object to all or part of certain processing;
  • request deletion where there is no lawful reason to retain the information;
  • withdraw consent where processing relies on consent; and
  • raise a concern about unfair, unlawful or non-transparent processing.

To protect confidentiality, we may need to verify your identity. In couples or family records, access rights may need to be balanced against another person's privacy and information cannot automatically be disclosed merely because it appears in a shared record.

11. Children's information

The public website and couples check-in are not directed to children under 18. We do not knowingly invite a child to submit personal information through the public contact form without appropriate adult involvement. If services for a child or family are introduced, we will use age-appropriate notices, confirm the correct consent or other legal authority, prioritise the child's best interests and apply data protection by design and by default.

12. Cookies, analytics and external links

The website may use essential cookies needed for security, session continuity and basic operation. Non-essential analytics, advertising or embedded-media cookies should remain disabled until a consent tool is implemented where required. A cookie notice should identify each cookie, provider, purpose and duration.

Links to WhatsApp, social networks, payment providers or other websites take you to services controlled by third parties. Their privacy practices are governed by their own notices, and you should review them before sharing sensitive information.

13. Privacy questions, requests and complaints

Contact our privacy representative at info@rootsoflovetherapy.com with the subject “Privacy Request”. Please do not include therapy details in the first email. We will acknowledge the request, verify identity where necessary and respond within the period required by applicable law.

If you believe your information has been handled improperly, please contact us first so we can investigate. You may also lodge a complaint with the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ), the Data Protection Authority designated under Zimbabwe's Cyber and Data Protection Act.

14. Changes to this policy

We may update this policy when services, technology, professional requirements or law change. The revised version will be posted here with a new “last reviewed” date. If a change materially affects how existing sensitive information is used, we will provide additional notice and seek consent where required.

Important: This policy describes intended privacy practices and does not replace the separate informed-consent, therapy, safeguarding and emergency policies used in professional care.