Available Protocols · Compliance Architecture

Data Governance
& Privacy

How Epistemica collects, uses, stores and shares personal information across every service we operate — the entities responsible, the law that applies in each market, who processes data on our behalf, and the rights you can exercise.

Version 1.0 · Effective 26 August 2026 · Applies to all Epistemica services

1 · Who is responsible

Sarpong Wealth LLC (United States) is the data controller — the “responsible party” under POPIA — for the Epistemica services worldwide. Epistemica (Pty) Ltd is the South African operating entity.

Prince Kwasi Sarpong is the registered Information Officer under POPIA, registered with the South African Information Regulator, and is the contact point for every privacy question, request or complaint in this document.

Contact for all privacy matters: info@epistemica.co.za

2 · What this covers

Epistemica Global and Epistemica South Africa are the same company. This document applies to epistemicaglobal.com, epistemica.co.za, and every Epistemica service:

ServiceWhat it isAccounts?
epistemicaglobal.comThis websiteNo
epistemica.co.zaThe South African siteNo
Epistemica InštitútProgrammes and certificationYes
CognitioCognitive Growth Index assessmentYes
Cognitio StratAdversarial strategy reasoningYes
Cognitio ProbeProvenance and viva instrumentYes
VulaEpistemic Disruption QuotientYes
Cognitio EdCAPS-aligned schooling, Grades 3 to 12Yes — parent-created
SikaSmartFinancial MRI and adviser workspaceYes

Markets. Services are open in South Africa and the United States. Canada, Australia and New Zealand open 1 November 2026; the United Kingdom, Germany, France and the Netherlands open 1 December 2026. Where a market is not yet open, we do not accept sign-ups from it.

3 · What we collect

On this website

This site has no accounts, no analytics and no tracking cookies. We collect only what you type into one of two forms:

  • Contact form — your name, email address and message.
  • Instructor materials request — your name, institutional email address, institution, course or programme (optional), the case requested, which materials, and any notes you add.

Both are handled by Netlify Forms and emailed to info@epistemica.co.za. Our host also keeps standard server logs, including IP address, for security and abuse prevention.

In the services

  • You give us: name, email address, country, and the working material you enter or upload — assessment responses, documents, and, in SikaSmart, household and financial figures and any statements or fact sheets you upload for analysis.
  • Created for you: scores, indices, dossiers, reports and saved analyses.
  • Collected automatically: sign-in identifiers, usage and request logs, and technical data needed to operate and secure the service.

Financial information is not “special category” data under POPIA or the GDPR. Where a service offers optional demographic fields, they are collected only where lawful in your jurisdiction, only with your consent, and never required.

4 · Google user data & Limited Use

Several services offer Sign in with Google, provided through Firebase Authentication. This section documents that use in full, as required by the Google API Services User Data Policy.

What we access

Only your basic Google profile, under the email, profile and openid scopes: your email address, display name, profile image and Google account identifier. We request no other scopes. We do not access your Gmail, Drive, Calendar, Contacts or any other Google service.

How we use it

Solely to create and secure your account, to sign you in, to identify your work across sessions, and to contact you about the service. Your account and all records are keyed to the account identifier, not to your name.

How we store it

In Firebase Authentication and Google Cloud Firestore, in the us-west1 region, encrypted in transit and at rest.

Limited Use commitment

Epistemica’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We limit our use of Google user data to providing and improving user-facing features that are prominent in the Epistemica interface.
  • We do not transfer Google user data except to provide or improve those features with your consent, for security purposes, to comply with applicable law, or in connection with a merger or acquisition after obtaining your explicit prior consent.
  • We do not allow humans to read Google user data, except where you have given affirmative agreement, where it is necessary for security purposes such as investigating a bug or abuse, where it is necessary to comply with applicable law, or where the data is aggregated and used for internal operations.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not use Google user data to train, fine-tune or improve any artificial intelligence or machine learning model.

If we ever change how Google user data is used, we will update this document and ask you to consent to the change before the new use begins.

You can revoke our access at any time at myaccount.google.com/permissions. Revoking access removes sign-in; to delete the data already held, use the erasure route in section 10.

5 · Why we process it, and on what basis

PurposeBasis (GDPR / UK)Basis (POPIA)
Provide the service you asked forContractNecessary to perform a contract
Account security, abuse preventionLegitimate interestsLegitimate interests
Answering your enquiryLegitimate interestsConsent / legitimate interests
Optional demographic fieldsConsentConsent
Billing and tax recordsLegal obligationLegal obligation
Service emailsContractNecessary to perform a contract

We do not sell personal information, and we do not use it for behavioural advertising.

6 · AI processing

Our services use Google Vertex AI for inference only, inside our own Google Cloud projects in us-west1, reached through service-account credentials rather than an API key.

  • Your data is never used to train or fine-tune any model — ours, Google’s, or anyone else’s.
  • Content is sent for inference and the result is returned to you; it is not retained by the model.
  • Outputs are decision-support, not advice. Where a service touches a regulated field, a qualified human remains responsible for any decision.

7 · Who processes data on our behalf

These are our operators (POPIA s20–21) and processors (GDPR Art 28). Each works under a written data-processing agreement and only on our instruction.

ProcessorWhat it handlesRegion
Google Cloud PlatformHosting, database, document storage, Vertex AI inference, buildus-west1 (USA)
Firebase (Google)Authentication and sign-in identityGoogle regions
NetlifyThis website; contact and materials form submissionsUSA / global CDN
BrevoTransactional emailEU
StripePayment and billing metadata, where billing is enabledUSA / EU
PlaidOptional bank-account connection in SikaSmart, only if you choose itUSA

We do not use AI vendors outside Google Cloud in the product runtime.

8 · International transfers

Personal information is processed in the United States (Google Cloud us-west1). Where information leaves your country we rely on the transfer mechanism appropriate to it — for South Africa, POPIA section 72 read with our processor agreements and your consent notice; for the European Economic Area and the United Kingdom, the EU-US Data Privacy Framework and/or Standard Contractual Clauses together with our processors’ own clauses. Data is encrypted in transit and at rest throughout.

9 · How long we keep it

RecordKept for
Account and the work saved in itWhile the account is open
After you erase your accountDeleted; backups age out within 90 days
Website form submissions24 months, then deleted
Billing and tax recordsAs tax law requires, typically 5–7 years
Security and access logsUp to 12 months

10 · Your rights

Wherever you are, you may ask us to access, correct, delete or export your personal information, to object to or restrict processing, and to withdraw consent at any time. Services with accounts provide “Download my data” and “Erase everything” directly in the interface; erasure removes the account, its records and its stored documents.

Where you areLawRegulator you may complain to
South AfricaPOPIAInformation Regulator (South Africa)
European Economic AreaGDPRYour national supervisory authority
United KingdomUK GDPR / DPA 2018Information Commissioner’s Office
CaliforniaCCPA / CPRACalifornia Privacy Protection Agency
CanadaPIPEDAOffice of the Privacy Commissioner of Canada
AustraliaPrivacy Act / APPsOffice of the Australian Information Commissioner
New ZealandPrivacy Act 2020Office of the Privacy Commissioner

We answer requests within 30 days. We never charge for a first request, and we will not discriminate against you for exercising any of these rights.

California. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months.

11 · Security

  • Encryption in transit (TLS) and at rest.
  • Every AI and database call is server-side; no API key is ever exposed in a browser.
  • Every request is authenticated and rate-limited per account.
  • Records are keyed to an account identifier, never to a person’s name.
  • Uploaded documents are private to the account that uploaded them.
  • No downloadable service-account keys exist anywhere in our infrastructure; services authenticate through workload identity.
  • Automated daily security scanning across all services, with alerting.

No system is perfectly secure. We state our controls plainly rather than promise absolute safety.

12 · Breach notification

If a breach affects your personal information we will notify the relevant regulator and you as the law requires — under POPIA section 22 as soon as reasonably possible, and under the GDPR and UK GDPR within 72 hours of becoming aware where the breach is reportable.

13 · Children

Most Epistemica services are for adults and require you to be 18 or older. Cognitio Ed is the exception — it is built for school-age learners, and this section governs it.

A child cannot open an account

There is no self-signup for learners. A parent or guardian registers, gives consent, and then adds each child under their own account; a child profile is not active until the adult publishes it. Where a school provides the service, the school does the same for its roster. We record who gave consent, when, and by what method, so the permission behind every child profile can be traced.

What we hold for a learner

Only what teaching requires: a display name, grade, subject selections, lesson and quiz progress, and work the learner produces in the app. We do not ask children for contact details, location or any demographic information. The account belongs to the adult, and the learner is a profile inside it.

What we never do

  • No advertising to children, and no profiling for advertising.
  • No sale or sharing of a child’s information.
  • No use of a child’s work to train, fine-tune or improve any AI model.

The adult stays in control

The parent, guardian or school can view everything held for a child, export it, correct it, or delete the profile and its records at any time from inside the app, or by writing to us. Withdrawing consent removes the profile.

This follows POPIA section 35, which requires the consent of a competent person before a child’s information is processed; the United States COPPA rule for children under 13, whose consent we take from the parent or guardian rather than the child; and FERPA where a school is the record-holder, in which case the school directs us and we act only on its instruction.

If you believe a child’s information reached us without the right adult’s permission, write to info@epistemica.co.za and we will delete it.

14 · Cookies & local storage

This website sets no tracking cookies and runs no analytics. The paper reader stores your chosen text size in your own browser’s sessionStorage; it never reaches us. Our hosts set strictly necessary cookies for security and load balancing. Services with accounts use a session cookie to keep you signed in.

15 · Changes

We will post any change here with a new version number and effective date. Where a change materially affects how we use personal information — including any change to how Google user data is used — we will notify you and, where consent is the basis, ask for it again before the change takes effect.

16 · Contact & complaints

Information Officer: Prince Kwasi Sarpong
Email: info@epistemica.co.za
Controller: Sarpong Wealth LLC (United States)
South African entity: Epistemica (Pty) Ltd

Write to us first — we would rather fix it. You may also complain directly to the regulator listed for your jurisdiction in section 10.