Privacy Policy
ScholarBridge is the data controller for personal data processed through ScholarBridge.
1. Who we are
ScholarBridge (--“we--”) operates ScholarBridge. We act as the data controller for the personal data you provide when creating an account and using the service.
2. Personal data we collect
- Account data: name, email address, password (hashed), login provider identifiers.
- Profile & academic context: university, faculty, qualification, modules, research stage, role (student / researcher / lecturer) and other information you enter during onboarding.
- Content: documents, drafts, prompts, chat messages, notes, presentations and other material you upload or generate.
- Usage & telemetry: pages viewed, features used, AI operations run, credits consumed, device/browser identifiers, IP address and error logs.
- Support communications: messages you send us for support.
Payment card data is collected directly by our payment provider (see §5) --- we never see or store it.
3. Why we process it (purposes and legal basis)
- Provide the service (contract performance): account creation, hosting your content, running AI operations.
- Personalise your experience (contract / legitimate interests): coaching recommendations, memory engine, readiness scoring.
- Security & fraud prevention (legitimate interests / legal obligation): abuse detection, rate limits, audit logs.
- Support (contract / legitimate interests): answering your enquiries.
- Service improvement (legitimate interests): aggregated analytics; we do not use your uploaded academic content to train foundation models.
- Marketing (consent): only where you opt in.
4. Who we share it with
- Hosting & infrastructure providers that store data and run the service on our behalf.
- AI model providers to process prompts and return outputs. Content is sent under terms that prohibit using it to train their models on identifiable data.
- Paddle.com --- our Merchant of Record for payments, subscription management, tax compliance and invoicing.
- Professional advisers (legal, accounting) where necessary.
- Authorities where required by law.
5. Payments
Payments are processed by Paddle.com. Paddle acts as an independent controller for payment data and follows its own privacy notice. We receive limited transaction metadata (order id, plan, amount, status) to grant access to paid features.
6. International transfers
Personal data may be processed outside South Africa, including in jurisdictions with different data-protection laws. Where transfers occur we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions where applicable.
7. Retention
We keep personal data for as long as your account is active and for a limited period afterwards, as set out in the Data Retention Policy. When it is no longer needed we delete or anonymise it.
8. Your rights
Subject to local law, you have the right to access, rectify, erase, restrict or object to processing of your personal data; to data portability; and to withdraw consent. In South Africa you may lodge a complaint with the Information Regulator; in the EEA/UK you may complain to your local supervisory authority. Contact arcn2027@gmail.com to exercise your rights. We aim to respond within one month.
9. Security
We use appropriate technical and organisational measures, including transport encryption, access controls, audit logs and role-based permissions. No system can be guaranteed 100% secure; report suspected issues to arcn2027@gmail.com.
10. Cookies
See our Cookie Policy.
11. Changes
We may update this Privacy Policy from time to time; material changes will be notified in-app or by email.