01
Scope and accountability
This policy applies to LOGAM websites, mobile applications, listener participation, support channels, memberships, bookings, advertising enquiries, program submissions and other digital services operated by LOGAM Radio Station Limited. LOGAM is responsible for determining why and how personal data is used within these services and aims to process only information reasonably necessary for legitimate station, contractual, consent-based, security, legal or public-interest purposes.
02
Information we collect
Depending on the feature used, LOGAM may process account and profile details, name, email address, telephone or WhatsApp contact, membership or booking details, support messages, listener comments, call-in requests, consent records, payment confirmation references, device identifiers used for security, IP-derived or session security records, and technical service logs. LOGAM does not intentionally request unnecessary sensitive personal information.
03
Why we use information
Personal data may be used to provide streaming and account services, manage programs and memberships, process bookings and support requests, moderate listener participation, communicate service information, prevent abuse and fraud, maintain audit and security controls, comply with lawful financial or regulatory duties, protect legal rights, and improve service reliability. Optional marketing or promotional communication should be based on an appropriate lawful basis and users may object or withdraw optional consent where applicable.
04
No sale of personal data
LOGAM does not sell, rent, trade or broker personal data to advertisers, data brokers or other third parties for their independent commercial use. Personal information may be disclosed only where needed to operate or protect the service through authorised processors or professional advisers, where the user has validly authorised the disclosure, or where disclosure is required or permitted by applicable law.
05
Third-party processors and disclosure
LOGAM may use hosting, streaming, payment, communications, email, professional-advisory or technology providers that process limited data for LOGAM under appropriate instructions and safeguards. LOGAM seeks to minimise disclosed data and restrict provider access to what is necessary. Where applicable law requires notice, consent, contractual safeguards or other conditions before disclosure or cross-border processing, LOGAM will apply those conditions.
06
Security safeguards and encryption
LOGAM protects production traffic with HTTPS/TLS, uses secure one-way password hashing, role-based access control, privileged-account multi-factor authentication, server-side validation, rate limiting, audit logging and controlled backups. Provider API keys and designated application secrets are encrypted at rest and are not exposed to public clients. Other personal records are protected by database, server and application access controls and appropriate technical and organisational safeguards. LOGAM does not represent that every individual database field is separately encrypted at rest unless that control is actually implemented for that field.
07
Retention and deletion
LOGAM retains records only for as long as reasonably required for the service, a legitimate operational purpose, legal or regulatory compliance, accounting, security investigation, audit, fraud prevention or dispute handling. When information is no longer required, LOGAM may securely delete, anonymise or archive it in accordance with applicable retention duties and backup cycles.
08
Your data-protection rights
Subject to applicable law and reasonable identity verification, a data subject may ask whether LOGAM processes personal data about them, request access, correction or completion of inaccurate data, request erasure where the legal conditions are met, object to certain processing, request restriction where available, withdraw optional consent, and request portability where applicable. A request may be limited where another written law, legal claim, security need, rights of another person or mandatory retention duty lawfully requires continued processing.
09
Cross-border access and processing
LOGAM is an online radio service that may be accessed internationally. Cross-border processing or transfers must be handled in accordance with the Zambia Data Protection Act and any other applicable transfer requirements. LOGAM will not treat the mere fact that a listener is abroad as permission to disregard Zambian data-protection obligations. GDPR is referenced only where its own territorial and material scope applies.
10
Children and vulnerable users
LOGAM applies heightened care where children or vulnerable persons are involved. Children should not submit payment, call-in, account or sensitive information without appropriate parent or guardian involvement where required. Content or conduct that exploits, threatens, grooms, sexually abuses or otherwise endangers a child is prohibited and may be removed, preserved as evidence and reported where lawfully required.
11
Security incidents and notification
LOGAM maintains incident-response procedures for suspected unauthorised access, misuse, disclosure or loss of personal data. Where a personal-data breach triggers notification duties under applicable law, LOGAM will notify the competent authority and affected data subjects within the legally required time and manner.
12
Privacy requests and complaints
Privacy questions and data-rights requests can be submitted through the official Help & Support or contact channels published by LOGAM. Requests should provide enough information for safe identity verification. A data subject may also exercise complaint rights available under the Zambia Data Protection Act with the competent Data Protection Commissioner.
13
Policy changes
LOGAM may update this policy when services, technology, legal requirements or operational practices change. The published version and effective date shown by LOGAM are the authoritative current policy. Material changes should be communicated through an appropriate station channel where reasonably necessary.
14
Your data-protection rights
Subject to applicable law and reasonable identity verification, a data subject may ask whether LOGAM processes personal data about them, request access, correction or completion of inaccurate data, request erasure where the legal conditions are met, object to certain processing, request restriction where available, withdraw optional consent, and request portability where applicable. A request may be limited where another written law, legal claim, security need, rights of another person or mandatory retention duty lawfully requires continued processing.
β
Legal framework
LOGAM applies these laws and standards only to the extent they lawfully govern the relevant service, processing activity, user or jurisdiction.
Zambia Data Protection Act, No. 3 of 2021Zambia Electronic Communications and Transactions Act, No. 4 of 2021Zambia Cyber Security Act, No. 3 of 2025Zambia Cyber Crime Act, No. 4 of 2025Zambia Children's Code Act, No. 12 of 2022 where children are concernedRegulation (EU) 2016/679 (GDPR) only where its territorial/material scope appliesOther applicable written law in a jurisdiction that lawfully governs the relevant processing activity
Legal note: This published station policy explains LOGAM's operational commitments. It does not replace case-specific advice from a qualified legal practitioner or an order of a competent authority.