Privacy notice
This explains what BiasLens collects about you, why, where it is kept, how long for, and what you can ask us to do about it. It is written to be read before you decide whether to use the platform, not after.
Last updated 17 August 2026.
What BiasLens assesses — and what it does not
BiasLens assesses systems, not people. It is a tool for examining whether an AI or automated decision-making system produces unfair outcomes. It is not, and will not become, a tool for monitoring, profiling, scoring or evaluating individual employees.
Specifically, BiasLens does not:
- ingest employee-level records, prompts, messages or activity logs;
- build behavioural profiles of individual workers;
- produce risk scores attached to a named or identifiable person;
- support productivity surveillance or performance monitoring.
Where BiasLens analyses group outcomes, it applies minimum-population thresholds: results for very small groups are marked as indicative only or suppressed entirely. This is because small groups produce statistically unreliable results, and because a small cell in a report can make an individual indirectly identifiable even when no names or identifiers are held. Removing identifiers does not, by itself, remove re-identification risk.
This is a deliberate design boundary rather than a current limitation. If BiasLens later receives governance data from other enterprise systems, it will request the least identifiable data capable of answering the question, and this boundary will continue to apply.
1. Who is responsible
BeAccessible is the responsible party for personal information collected through BiasLens. Under the Protection of Personal Information Act, the head of a private body is its Information Officer. For BeAccessible that is Fadila Lagadien.
All privacy matters: hello@beaccessible.co.za
You do not need an account to contact us, and you do not need an account to read this page.
2. What we collect
Only what is needed to run the service.
Your account
- Email address
- Your name, as you enter it
- The role you choose, which changes the guidance you see
- Your organisation name, if you provide one
What you create
- Your answers to the assessment questions
- The AI system profiles and risk classifications you build
- Anything you add to an evidence log, including files you attach
- The documents BiasLens generates for you
What you ask BiasLens Guide
BiasLens Guide is a public informational assistant. When you send a message to BiasLens Guide, the text of that Guide conversation is sent to the AI service used to generate the answer. The Guide is deliberately separated from the private assessment environment: it does not read your account, assessment answers, evidence files or private fairness data.
Please do not put employee, applicant, health, disability, identification, credential or other sensitive person-level information into BiasLens Guide.
Technical
- A sign-in cookie, so the platform knows it is still you as you move between pages
- A record of sensitive actions such as deletions and role changes, kept so that changes to an assessment can be accounted for
3. Why we collect it
- To provide the service you asked for. We cannot run an assessment without the answers to it.
- To answer a BiasLens Guide question. Guide messages are processed only so the public assistant can generate a response to the question you chose to submit.
- To support you when something goes wrong. See section 10 on who at BeAccessible can see your work.
- To keep the platform secure and accountable. Access is by invitation only, and significant changes are logged.
That is the whole of it. We do not profile you, we do not advertise to you, and we do not sell or share your information for anyone else's commercial purposes.
4. Sensitive information, and information about other people
Bias assessments touch subjects POPIA calls special personal information: disability, race, health, religion, sex, and similar. This is unavoidable — you cannot test a system for discrimination without naming the grounds it might discriminate on.
Most of the platform does not need identifiable data. The Fairness Metrics Calculator works on counts — how many people in a group, how many received a positive outcome. It never needs to know who they were. Please keep it that way wherever you can.
If you upload information about other people — for example records attached to an evidence log — you remain the responsible party for that information. BeAccessible processes it on your behalf and for no other purpose. Only upload what you genuinely need, and remove it when you no longer need it.
Do not submit that information to BiasLens Guide. The public Guide only needs a general description of the system, workflow, decision context or evidence question.
5. Where your information is stored
Your assessment data is stored in the United Kingdom, not in South Africa. Our database is hosted in London.
POPIA treats this as a transfer of personal information outside the Republic, so we are telling you plainly rather than leaving it to be discovered. The transfer happens because it is necessary to provide the service you have asked for, and our agreements with our providers require them to protect the information.
For anyone in the EU or EEA: the United Kingdom holds a European Commission adequacy decision, renewed in December 2025, so information may move there without additional safeguards for the period it runs.
6. Who else handles it
These service providers process information on our behalf for the functions described below:
- Supabase — accounts, sign-in and the database. This is where your assessments live.
- Vercel — hosting and the AI gateway used by the public BiasLens Guide. Vercel serves the pages to your browser and routes Guide requests to the selected AI model.
- OpenAI — the AI model provider used to generate public BiasLens Guide responses. Only the Guide conversation submitted to that feature is sent for model processing; private assessment content is not connected to the Guide route.
- Resend — sending the emails we send you, such as invitations and sign-in links.
These providers operate internationally, which means information may be handled outside South Africa. We have not independently audited their internal practices and we will not claim otherwise.
7. What we do not do
Private BiasLens assessment content is not sent to BiasLens Guide or to the Guide's AI model. The assessment calculations remain arithmetic, the compliance mapping is a fixed set of rules, and assessment documents are assembled from the information entered into those workflows. BiasLens Guide is a separate, public AI-assisted information feature and receives only the conversation a visitor deliberately submits to the Guide.
We also do not:
- Run advertising or marketing trackers on the platform
- Use analytics that follow you across the web
- Sell, rent or share your information for commercial purposes
- Make automated decisions about you
BiasLens assesses systems, not people
This one matters enough to state on its own. BiasLens is not, and will not become, a tool for monitoring, profiling or scoring individual employees. It examines whether a system produces unfair outcomes. It does not examine the people using that system.
That means BiasLens does not:
- Take in employee-level records, prompts, messages or activity logs
- Build behavioural profiles of individual workers
- Produce a risk score attached to a named or identifiable person
- Support productivity surveillance or performance monitoring
Where BiasLens compares outcomes between groups, it applies minimum population thresholds. Results for very small groups are marked indicative only, and groups below the reporting threshold are suppressed entirely. Two reasons, both important: small numbers produce unreliable results, and a small group in a report can make an individual indirectly identifiable even when we hold no names. Removing names does not, by itself, remove the risk of someone being recognised.
This is a design boundary, not a temporary limitation. If BiasLens ever receives governance data from other systems in your organisation, it will ask for the least identifiable information capable of answering the question — and this boundary will still apply.
8. How long we keep it
- While your account is open — your account details and your assessments are kept so you can carry on using them.
- When you ask us to delete — your account, your assessments and any files you uploaded are removed within 30 days.
- You can delete individual assessments yourself at any time, without asking us.
- Our audit record survives, without you in it. The log of significant actions is kept, but the entry no longer identifies who performed them. What happened remains accountable; who did it does not stay attached to a deleted person.
BiasLens Guide conversations are not written into the private BiasLens assessment database by the Guide feature.
9. How it is protected
- All traffic is encrypted in transit using HTTPS.
- Row-level security is enforced in the database itself, not only in the application. One ordinary user cannot read another ordinary user's records, and this is enforced below the application rather than by it.
- Accounts are created by invitation only. Public sign-up is switched off at the database, not merely hidden in the interface.
- Sensitive actions such as deletions and role changes are logged.
- You control your own exports.
- BiasLens Guide is kept outside the authenticated assessment data path and has no code connection to assessment records or uploaded evidence.
10. Who at BeAccessible can see your work
Administrator accounts at BeAccessible can read the assessments held on the platform, including yours. We are telling you this plainly because a privacy notice that implied nobody could would be untrue.
This access exists so that we can:
- Help you when something has gone wrong with an assessment
- Investigate a fault or a security concern
- Respond to a request or a complaint you have made
It is limited to named administrator accounts, not to anyone who happens to work with us. It is not used to review your work, to judge it, or for any commercial purpose. If you would prefer we did not look at a particular assessment while helping you, say so and we will work around it.
You can ask us at any time whether an administrator has accessed your records, and we will tell you.
11. Your rights
You can ask us to:
- Tell you what personal information we hold about you
- Correct anything that is wrong
- Delete your account and everything in it
- Give you a copy of your data in a usable format
- Stop processing your information, or object to how we are doing it
Email hello@beaccessible.co.za. We will reply within two working days and act within 30 days. There is no charge, and you do not have to explain why you are asking.
If you cannot use email, or need this notice in large print, plain text, audio, or read aloud to you, tell us through any channel that works for you and we will arrange it at no cost.
12. Cookies
BiasLens sets a cookie so that you stay signed in as you move between pages. That is what it is for and that is all it does.
There are no advertising cookies and no cross-site tracking. Because the cookie is strictly necessary to provide a service you have asked for, we do not interrupt you with a consent banner for it.
13. If you want to complain
Please raise it with us first at hello@beaccessible.co.za, but you are not obliged to.
- South Africa — the Information Regulator. Complaints go on Form 5 through the Regulator's eServices portal, or by email to POPIAComplaints@inforegulator.org.za. Offices at Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191.
- United Kingdom —the Information Commissioner's Office.
- European Union or EEA — the data protection supervisory authority for your country. We will help you identify the right one if you ask.
14. Changes to this notice
We update this notice whenever what we do with your information changes, and we review it at least every six months. The date at the top of the page tells you when it last changed. If a change materially affects you, we will tell you rather than rely on you noticing.