Privacy Policy
What personal information we collect, why, and the rights you have over it — including under GDPR, POPIA, and CCPA where applicable.
1. Introduction
This Privacy Policy explains how SizaPoint collects, uses, shares, and protects personal information when you use our website and workspace. We aim to meet the requirements of major data protection frameworks that may apply to our users, including the EU/UK General Data Protection Regulation (GDPR), South Africa's Protection of Personal Information Act (POPIA), and the California Consumer Privacy Act (CCPA/CPRA).
2. Information We Collect
- Account information: name, email address, institution and academic level (if provided), and authentication credentials.
- Content you provide: documents, notes, and prompts you upload or type into the workspace.
- Usage information: feature usage, AI credit consumption, and device/browser information, collected to operate and improve the Service.
- Security sessions: when you sign in we record browser, operating system, approximate location (from IP), and last activity so you can review active devices and sign out remotely. We email you when a new device signs in.
- Billing information: plan and payment status, handled by a PCI-compliant payment processor — we do not store your full card details ourselves.
- Communications: messages you send us through the contact form or support channels.
3. How We Use Information
- To provide, maintain, and personalise the workspace and its AI features.
- To process payments and manage subscriptions.
- To communicate with you about your account, security, and — where you've opted in — product updates.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
4. How AI Features Process Your Content
When you use an AI-powered tool, the relevant portion of Your Content is sent to a third-party AI model provider under contract solely to generate the requested output (for example, a summary, outline, or grammar suggestion). We do not permit AI providers to use your content to train their general-purpose models.
5. Documents You Upload for Processing
- When you upload a document (for example, an assignment, dissertation, or thesis) to Document Studio or another document tool, we store the original file, any working copies, and the corrected output so we can process your request and let you download the result.
- These files are processed only to provide the feature you asked for — analysing and correcting formatting, structure, headings, numbering, captions, citations, references, and consistency — and to show you what changed.
- Files are stored in encrypted cloud storage. We keep the original alongside the corrected version so the change is auditable and never destructive; we do not overwrite your uploaded file.
- Where a document tool uses AI to interpret ambiguous content (for example, whether a heading is really a heading), the relevant portion is sent to a contracted AI provider solely to generate that result. AI providers are contractually prohibited from using your documents to train their general-purpose models, and we do not use your uploaded documents to train models.
- Uploaded documents and their processed outputs are retained while your account is active and deleted when you delete the item, or when your account is deleted, subject to the limited retention described below. Guest "Try" document sessions are not retained after the session ends.
6. Legal Bases for Processing (where GDPR/POPIA apply)
- Performance of a contract — to provide the Service you've signed up for.
- Consent — for optional communications such as the newsletter, and for non-essential cookies.
- Legitimate interests — for security, fraud prevention, and service improvement, balanced against your rights.
- Legal obligation — where we must retain or disclose information to comply with the law.
7. Sharing of Information
We do not sell your personal information. We share information only with service providers who process it on our behalf under contract (for example, cloud hosting, email delivery, and payment processing), with your institution where you've joined an institutional workspace, or where required by law.
8. International Data Transfers
Where personal information is transferred across borders, we rely on recognised transfer mechanisms such as Standard Contractual Clauses, and we require service providers to apply protections consistent with this Policy.
9. Data Retention
We retain account and content data for as long as your account is active, plus a limited period afterward to comply with legal, accounting, or security requirements. Guest "Try" sessions are not retained after the session ends.
10. Your Rights
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your account and associated data.
- Object to or restrict certain processing, and withdraw consent at any time.
- Request a portable copy of your data.
- Lodge a complaint with your local data protection authority.
11. Children's Privacy
The Service is intended for students at secondary and tertiary education level and above. We do not knowingly collect personal information from young children without the consent required by applicable law.
12. Security
We use industry-standard cloud infrastructure with encryption in transit and at rest, access controls limiting who can view your data, and secure, hashed storage of authentication credentials. See our Security & Data Protection page for more detail.
13. Changes to this Policy
We will update the effective date and version at the top of this page whenever this Policy changes, and provide direct notice of material changes where required by law.
14. Contact and How to Exercise Your Rights
For privacy questions or to exercise any of the rights above, email our privacy team at privacy@sizapoint.com, or use our Contact page under the "General enquiry" topic. We aim to respond within the timeframes required by applicable law.
SizaPoint operates from South Africa and is the responsible party for your personal information under POPIA. Our Information Officer can be reached at privacy@sizapoint.com. If you are in the EU or UK, you may contact the same address for GDPR / UK GDPR matters; where we are legally required to appoint an EU or UK representative under Article 27 GDPR, that representative's details will be published on this page.
You also have the right to lodge a complaint with a supervisory authority — in South Africa, the Information Regulator (inforegulator.org.za); in the EU/UK, your local data protection authority.
Have a question about this document? Contact us.
