Available Protocols · Compliance Architecture
How Epistemica collects, uses, stores and shares personal information across every service we operate — the entities responsible, the law that applies in each market, who processes data on our behalf, and the rights you can exercise.
Version 1.0 · Effective 26 August 2026 · Applies to all Epistemica services
Sarpong Wealth LLC (United States) is the data controller — the “responsible party” under POPIA — for the Epistemica services worldwide. Epistemica (Pty) Ltd is the South African operating entity.
Prince Kwasi Sarpong is the registered Information Officer under POPIA, registered with the South African Information Regulator, and is the contact point for every privacy question, request or complaint in this document.
Contact for all privacy matters: info@epistemica.co.za
Epistemica Global and Epistemica South Africa are the same company. This document applies to epistemicaglobal.com, epistemica.co.za, and every Epistemica service:
| Service | What it is | Accounts? |
|---|---|---|
| epistemicaglobal.com | This website | No |
| epistemica.co.za | The South African site | No |
| Epistemica Inštitút | Programmes and certification | Yes |
| Cognitio | Cognitive Growth Index assessment | Yes |
| Cognitio Strat | Adversarial strategy reasoning | Yes |
| Cognitio Probe | Provenance and viva instrument | Yes |
| Vula | Epistemic Disruption Quotient | Yes |
| Cognitio Ed | CAPS-aligned schooling, Grades 3 to 12 | Yes — parent-created |
| SikaSmart | Financial MRI and adviser workspace | Yes |
Markets. Services are open in South Africa and the United States. Canada, Australia and New Zealand open 1 November 2026; the United Kingdom, Germany, France and the Netherlands open 1 December 2026. Where a market is not yet open, we do not accept sign-ups from it.
This site has no accounts, no analytics and no tracking cookies. We collect only what you type into one of two forms:
Both are handled by Netlify Forms and emailed to info@epistemica.co.za. Our
host also keeps standard server logs, including IP address, for security and abuse prevention.
Financial information is not “special category” data under POPIA or the GDPR. Where a service offers optional demographic fields, they are collected only where lawful in your jurisdiction, only with your consent, and never required.
Several services offer Sign in with Google, provided through Firebase Authentication. This section documents that use in full, as required by the Google API Services User Data Policy.
Only your basic Google profile, under the email, profile and
openid scopes: your email address, display name,
profile image and Google account identifier. We request no
other scopes. We do not access your Gmail, Drive, Calendar, Contacts or any other Google service.
Solely to create and secure your account, to sign you in, to identify your work across sessions, and to contact you about the service. Your account and all records are keyed to the account identifier, not to your name.
In Firebase Authentication and Google Cloud Firestore, in the us-west1 region,
encrypted in transit and at rest.
Epistemica’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
If we ever change how Google user data is used, we will update this document and ask you to consent to the change before the new use begins.
You can revoke our access at any time at myaccount.google.com/permissions. Revoking access removes sign-in; to delete the data already held, use the erasure route in section 10.
| Purpose | Basis (GDPR / UK) | Basis (POPIA) |
|---|---|---|
| Provide the service you asked for | Contract | Necessary to perform a contract |
| Account security, abuse prevention | Legitimate interests | Legitimate interests |
| Answering your enquiry | Legitimate interests | Consent / legitimate interests |
| Optional demographic fields | Consent | Consent |
| Billing and tax records | Legal obligation | Legal obligation |
| Service emails | Contract | Necessary to perform a contract |
We do not sell personal information, and we do not use it for behavioural advertising.
Our services use Google Vertex AI for inference only, inside our own Google
Cloud projects in us-west1, reached through service-account credentials rather than
an API key.
These are our operators (POPIA s20–21) and processors (GDPR Art 28). Each works under a written data-processing agreement and only on our instruction.
| Processor | What it handles | Region |
|---|---|---|
| Google Cloud Platform | Hosting, database, document storage, Vertex AI inference, build | us-west1 (USA) |
| Firebase (Google) | Authentication and sign-in identity | Google regions |
| Netlify | This website; contact and materials form submissions | USA / global CDN |
| Brevo | Transactional email | EU |
| Stripe | Payment and billing metadata, where billing is enabled | USA / EU |
| Plaid | Optional bank-account connection in SikaSmart, only if you choose it | USA |
We do not use AI vendors outside Google Cloud in the product runtime.
Personal information is processed in the United States (Google Cloud
us-west1). Where information leaves your country we rely on the transfer mechanism
appropriate to it — for South Africa, POPIA section 72 read with our processor agreements
and your consent notice; for the European Economic Area and the United Kingdom, the EU-US Data
Privacy Framework and/or Standard Contractual Clauses together with our processors’ own
clauses. Data is encrypted in transit and at rest throughout.
| Record | Kept for |
|---|---|
| Account and the work saved in it | While the account is open |
| After you erase your account | Deleted; backups age out within 90 days |
| Website form submissions | 24 months, then deleted |
| Billing and tax records | As tax law requires, typically 5–7 years |
| Security and access logs | Up to 12 months |
Wherever you are, you may ask us to access, correct, delete or export your personal information, to object to or restrict processing, and to withdraw consent at any time. Services with accounts provide “Download my data” and “Erase everything” directly in the interface; erasure removes the account, its records and its stored documents.
| Where you are | Law | Regulator you may complain to |
|---|---|---|
| South Africa | POPIA | Information Regulator (South Africa) |
| European Economic Area | GDPR | Your national supervisory authority |
| United Kingdom | UK GDPR / DPA 2018 | Information Commissioner’s Office |
| California | CCPA / CPRA | California Privacy Protection Agency |
| Canada | PIPEDA | Office of the Privacy Commissioner of Canada |
| Australia | Privacy Act / APPs | Office of the Australian Information Commissioner |
| New Zealand | Privacy Act 2020 | Office of the Privacy Commissioner |
We answer requests within 30 days. We never charge for a first request, and we will not discriminate against you for exercising any of these rights.
California. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months.
No system is perfectly secure. We state our controls plainly rather than promise absolute safety.
If a breach affects your personal information we will notify the relevant regulator and you as the law requires — under POPIA section 22 as soon as reasonably possible, and under the GDPR and UK GDPR within 72 hours of becoming aware where the breach is reportable.
Most Epistemica services are for adults and require you to be 18 or older. Cognitio Ed is the exception — it is built for school-age learners, and this section governs it.
There is no self-signup for learners. A parent or guardian registers, gives consent, and then adds each child under their own account; a child profile is not active until the adult publishes it. Where a school provides the service, the school does the same for its roster. We record who gave consent, when, and by what method, so the permission behind every child profile can be traced.
Only what teaching requires: a display name, grade, subject selections, lesson and quiz progress, and work the learner produces in the app. We do not ask children for contact details, location or any demographic information. The account belongs to the adult, and the learner is a profile inside it.
The parent, guardian or school can view everything held for a child, export it, correct it, or delete the profile and its records at any time from inside the app, or by writing to us. Withdrawing consent removes the profile.
This follows POPIA section 35, which requires the consent of a competent person before a child’s information is processed; the United States COPPA rule for children under 13, whose consent we take from the parent or guardian rather than the child; and FERPA where a school is the record-holder, in which case the school directs us and we act only on its instruction.
If you believe a child’s information reached us without the right adult’s permission, write to info@epistemica.co.za and we will delete it.
This website sets no tracking cookies and runs no analytics. The paper reader
stores your chosen text size in your own browser’s sessionStorage; it never
reaches us. Our hosts set strictly necessary cookies for security and load balancing. Services
with accounts use a session cookie to keep you signed in.
We will post any change here with a new version number and effective date. Where a change materially affects how we use personal information — including any change to how Google user data is used — we will notify you and, where consent is the basis, ask for it again before the change takes effect.
Information Officer: Prince Kwasi Sarpong
Email: info@epistemica.co.za
Controller: Sarpong Wealth LLC (United States)
South African entity: Epistemica (Pty) Ltd
Write to us first — we would rather fix it. You may also complain directly to the regulator listed for your jurisdiction in section 10.