Privacy Policy
Babel Shield — Sixees Labs Pty (Ltd)
Last Updated: 20 July 2026
Effective Date: 5 May 2026
1. Introduction
Sixees Labs Pty (Ltd) ("we", "us", "our", or "Sixees Labs") operates Babel Shield (the "Service"), a software-as-a-service content moderation platform accessible via our website and API. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our Service, or interact with us in any way.
We are committed to protecting your privacy and complying with applicable data protection laws, including the South African Protection of Personal Information Act, 2013 ("POPIA"), the European Union General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and other applicable privacy laws. Sixees Labs is established in South Africa, and Babel Shield operates within the Sixees Labs POPIA compliance framework; our Information Officer is registered with the Information Regulator (South Africa) and can be reached at the email address in Section 15.
Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. For transactions processed through Paddle, Paddle acts as an independent data controller with respect to the personal data it collects during the checkout process. Please refer to Paddle's Privacy Policy for details on how Paddle processes your data.
If you have questions or concerns about this policy, please contact us at [email protected].
2. Information We Collect
Providing Personal Information through the Website is voluntary. If you choose not to provide the details requested in a form, we may be unable to respond to your enquiry or provide the materials or services you have asked for. Required fields, where they apply, are marked at the point of collection.
2.1 Information You Provide Directly
- Account Information: Name, email address, company name, and billing address when you register for the Service.
- Payment Information: Payment details are collected and processed directly by Paddle as our Merchant of Record. We do not collect, store, or have access to your credit card or payment instrument details.
- Communications: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken within the Service, timestamps, and session duration.
- Device and Browser Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Cookies and Tracking Technologies: We use cookies, web beacons, pixels, and similar technologies to track website traffic and trends, and to optimise conversions and UI/UX usage patterns via third-party analytics services. See Section 7 (Cookies) for more details.
- Log Data: Server logs that may include your IP address, access times, pages viewed, and referring URLs.
2.3 Content Submitted to the Service
When you use the Babel Shield API or client libraries, you may submit content for moderation ("Submitted Content"). Submitted Content is processed in real time and moderation results are returned to you.
Real-time moderation is currently performed using a third-party AI provider (see Section 4.2). We retain Submitted Content for two purposes: (a) operating, securing, and improving the Service (for example, to debug failed requests, investigate abuse, and meet reasonable audit needs), and (b) keeping a sanitised copy that we may use in the future to train and evaluate our own moderation models. We do not currently train our own models on Submitted Content, but we retain a sanitised copy so that we are able to do so should we decide to; we describe this here so that this future use is disclosed at the point of collection. Section 8 sets out retention periods, and Sections 4 and 5 explain how we use and lawfully process this data.
Before Submitted Content is transmitted to our third-party AI providers, or retained by us as a sanitised copy (including any copy we may later use to train or evaluate our own models), it passes through an automated sanitisation pipeline. This pipeline detects a defined set of personal-data types and replaces each detected value with a fixed, irreversible, keyless placeholder label (for example, [PHONE]). The types it detects and redacts are: payment card numbers, United States Social Security numbers, telephone numbers, email addresses, and IP addresses (both IPv4 and IPv6). For email addresses, only the local part is removed and the domain is deliberately preserved as a spam signal, so an email address is partially redacted rather than removed entirely.
This is a data-minimisation measure, not anonymisation or pseudonymisation: although each transformation is irreversible and uses no recovery key, the content that remains is still personal data. The pipeline does not detect every kind of identifier. In particular, personal names, postal or physical addresses, dates of birth, and government identifiers other than United States Social Security numbers (such as passport, driving-licence, or national-identity numbers) are not automatically detected or redacted. Those identifiers, and any other personal data contained in the free-text content you submit, may therefore be transmitted to and retained by our third-party AI providers under their own terms (see Section 4.2).
Value-level sanitisation is enforced centrally at our API layer (as described above), so that it applies consistently however a request reaches us — whether through our client libraries or a direct API call. To reduce what reaches us in the first place, our client libraries also let you exclude fields likely to contain sensitive data (such as payment-card fields) so that they are never transmitted to the Service. We strongly encourage you to use these field-exclusion features, particularly for fields likely to contain sensitive or special-category data.
The retained sanitised copy is organised by customer account and request (not by the identity of the individual end-users whose data may appear within submitted content). This means we can locate the content associated with a given account, but we may be unable to locate content relating to a particular individual from that individual's identity alone. It does not mean the content is anonymous: because the sanitisation pipeline does not remove names or addresses, the retained copy may still contain personal data. Section 6 explains how we handle rights requests in that light.
Section 6 explains your rights, including how to object to any future use of Submitted Content for model training, and the practical limits of those rights in respect of the retained sanitised copy.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, and maintain the Babel Shield platform and API.
- Account Management: To create and manage your account, process subscriptions, and communicate account-related information.
- Payment Processing: To facilitate transactions through Paddle as our Merchant of Record.
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical support.
- Service Improvement and Model Development: To analyse usage patterns and improve our Service, and to retain a sanitised copy of Submitted Content that we may use in the future to train and evaluate our own moderation models. Any Submitted Content retained for, or later used in, model training is sanitised as described in Section 2.3.
- Analytics and Optimisation: To track website traffic and trends, optimise conversions, and understand UI/UX usage patterns using cookies and third-party analytics services.
- Security: To detect, prevent, and address fraud, abuse, security risks, and technical issues.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Marketing Communications: To send you information about our services, updates, and promotional content where you have consented to receive such communications or where otherwise permitted by law. You may opt out at any time.
4. How We Share Your Information
We do not, and will never, sell your personal data or personal information, and we do not disclose it to third parties for their own independent purposes except as described in this policy. Retaining and, in future, using a sanitised copy of Submitted Content to train our own models is an internal use of that data by us — it is not a sale, and it does not involve disclosing that content to a third party for their own purposes. We share your information only in the following circumstances:
4.1 Paddle (Merchant of Record)
As our Merchant of Record, Paddle receives personal data necessary to process your payments, manage subscriptions, handle refunds, issue invoices, and provide customer support for billing-related inquiries. Paddle acts as an independent data controller for this data. See Paddle's Privacy Policy.
4.2 Third-Party AI Providers
To deliver content moderation, we transmit Submitted Content to third-party AI service providers for scoring. Before transmission, content passes through the sanitisation pipeline described in Section 2.3, which redacts a defined set of personal-data types but does not remove names, postal addresses, or other identifiers that may appear in free-text content. We currently use a single third-party AI provider, which processes API content under its standard terms; under those terms, such content may be retained for up to approximately 30 days for abuse-monitoring and security purposes before deletion. We do not use a zero-data-retention tier. These retention terms are set by the provider and may change, as described below. We also provide client-library features that let you exclude fields likely to contain sensitive data before they are sent to the Service (see Section 2.3).
We do not provide Submitted Content to third-party AI providers for the purpose of training their models, and we select providers whose published terms are consistent with this. However, third-party AI providers process content under their own terms and privacy policies, which they may amend from time to time, and we cannot control or guarantee what those providers do with content once it leaves our systems. Any training and evaluation of Babel Shield's own models would be carried out by us, not by our third-party AI providers, using the retained sanitised copy described in Section 2.3.
4.3 Analytics and Optimisation Services
We use third-party analytics and conversion optimisation services that collect data through cookies and similar technologies to help us understand website traffic, usage trends, and user experience patterns.
4.4 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.5 Business Transfers
If Sixees Labs is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
4.6 With Your Consent
We may share your information with other parties when you have given us explicit consent to do so.
5. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases:
- Performance of a Contract: Processing necessary to deliver the Service you have subscribed to, including real-time moderation of Submitted Content.
- Legitimate Interests: Processing for our legitimate business interests, such as improving the Service, ensuring security, conducting analytics, and retaining a sanitised copy of Submitted Content for the possible future training and evaluation of our own moderation models. We rely on legitimate interests for retaining that copy and for any future model training on the basis that (i) before it is retained or used, Submitted Content passes through the sanitisation pipeline described in Section 2.3, which redacts a defined set of personal-data types and reduces (but does not eliminate) directly identifying data, (ii) any models we develop would be used only to operate and improve the Service, (iii) we provide an effective right to object (see Section 6), and (iv) the retained copy is organised by customer account and request, not by the identity of the individual end-users whose data may appear within submitted content. We have carried out and maintain a balancing assessment for this processing, and you may ask us for a summary of it.
- Consent: Where you have given explicit consent, such as for marketing communications or non-essential cookies.
- Legal Obligation: Where processing is necessary to comply with applicable law.
Where you are an API customer submitting third-party end-user content to the Service, you are responsible for ensuring you have an appropriate legal basis to provide that content to us for the purposes described in this policy, including retention of a sanitised copy and any future model training following sanitisation, and for providing any notices required to your own users.
6. Your Privacy Rights
6.1 Rights Under GDPR (EEA and UK Residents)
If you are located in the EEA or UK, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Restriction: Request that we restrict processing of your data under certain circumstances.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests, including the retention of Submitted Content for, and any use of it in, model training and evaluation.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
These rights apply to the personal data we hold about you, including account data, operational copies of Submitted Content, and the retained sanitised copy of Submitted Content. Two practical limits apply:
- We key stored content by customer account and request, not by the identity of individual end-users. If you are one of our account holders, we can locate the Submitted Content associated with your account and action your request in respect of it. We do not, however, maintain an index by the identity of the individual end-users whose personal data may appear within Submitted Content. If you are such an individual — for example, your details were submitted through a website that uses Babel Shield — we may be unable to locate that content from your identity alone; you can ask the operator of that website (our customer, who is responsible for that content), or provide us with enough detail (the website or domain, the content, and the approximate date) for us to make reasonable efforts to locate it. This is consistent with Article 11 GDPR, which addresses processing that does not require us to identify a data subject. We do not claim this content is anonymous — it may still contain names, addresses, or other identifiers.
- Trained model parameters (if and when we train our own models) are not a stored copy of the training data, and individual contributions cannot practicably be isolated or removed from them.
To exercise these rights, make a data subject request or contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
API customers can opt out, at the account level, of having their Submitted Content retained for or used in model training and evaluation by emailing [email protected]. Once an opt-out is in effect, Submitted Content received from that account thereafter will not be retained for, or used in, model training. For content already held in the retained sanitised copy, it remains associated with your account, and on request we can locate and delete it.
6.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the CCPA:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the purposes, and the third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected from you.
- Right to Correct: Request correction of inaccurate personal information we maintain about you.
- Right to Opt Out of Sale or Sharing: We do not, and will never, sell your personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA. Because we do not sell or share personal information, there is nothing for you to opt out of.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
The same two practical limits described under Section 6.1 apply to these rights: stored content is keyed to the customer account and request rather than to individual end-users, so requests are handled as described in Section 6.1 (we do not claim this content is deidentified — it may still contain identifiers); and individual contributions cannot practicably be isolated or removed from any trained model parameters. We will action your request in respect of all personal information we can identify as relating to you.
To exercise these rights, make a data subject request or contact us at [email protected]. We will verify your identity and respond within 45 days.
6.3 Rights Under POPIA (South Africa)
If you are in South Africa, or your personal information is otherwise processed under POPIA, you have the following rights as a data subject:
- Access: Request confirmation of, and a record of, the personal information we hold about you (POPIA section 23).
- Correction and Deletion: Request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or obtained unlawfully (POPIA section 24).
- Objection: Object, on reasonable grounds relating to your particular situation, to processing based on our legitimate interests, including the retention of Submitted Content for, and any use of it in, model training (POPIA section 11(3)).
- Direct Marketing: Object to the processing of your personal information for direct marketing at any time.
- Automated Decision-Making: Not be subject to a decision based solely on the automated processing of your personal information that has legal or similarly significant effects, subject to the exceptions in POPIA section 71.
The same two practical limits described in Section 6.1 apply: stored content is keyed to the customer account and request rather than to individual end-users, so requests are handled as described in Section 6.1; and individual contributions cannot practicably be isolated or removed from any trained model parameters. We do not treat this content as deidentified.
To exercise these rights, contact our Information Officer at [email protected] or make a data subject request. You also have the right to lodge a complaint with the Information Regulator (South Africa). Complaints must be made in writing on the prescribed form:
- Website: https://inforegulator.org.za
- Complaints email: [email protected]
- Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website to:
- Essential Cookies: Enable core website functionality (session management, security).
- Analytics Cookies: Track website traffic, page views, and usage trends to help us improve the Service.
- Marketing and Optimisation Cookies: Used by third-party services to optimise conversions, analyse UI/UX usage patterns, and deliver relevant content.
Managing Cookies
You can manage your cookie preferences through:
- The cookie consent banner displayed on your first visit to our website.
- The Manage cookies link in the footer of every page, which is always available so you can change or withdraw your choice at any time — as easily as you gave it.
- Your browser settings (most browsers allow you to block or delete cookies).
Analytics and marketing cookies are off by default and load only after you accept. If your browser or device sends a Global Privacy Control (GPC) or Do Not Track signal, we do not load Google Analytics at all — no analytics scripts or cookies are set, regardless of the banner.
Please note that disabling certain cookies may affect the functionality of our website.
For more information about the specific cookies we use, please refer to our Cookie Banner or contact us at [email protected].
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
- Account Data: Retained for the duration of your account and for a reasonable period thereafter to comply with legal obligations and resolve disputes.
- Usage and Analytics Data: Retained in aggregated or anonymised form for analytical purposes.
- Submitted Content (operational copy): Retained for a period that depends on your subscription plan, as set out on our pricing page, and which we may adjust at our discretion, to support debugging, abuse investigation, and security review. After that period, operational copies are deleted.
- Submitted Content (retained sanitised copy): Following sanitisation as described in Section 2.3, a copy of Submitted Content is retained — organised by customer account and request rather than by individual end-user identity — for operating and improving the Service and for the possible future training and evaluation of our own models. This copy may still contain personal data (such as names and addresses). We retain it for as long as it remains necessary for those purposes, review it periodically, and prune data that is no longer needed. If you object to, or opt out of, its use for model training, we handle that as described in Section 6.
- Trained Models: If and when we train our own models, the resulting model parameters are retained as part of the Service. Model parameters are not a stored copy of the input data, but information learned from training data is intrinsically embedded in them.
- Anonymised, Aggregated, and Other Non-Identifiable Derivatives: Derivatives of Submitted Content that are anonymised, aggregated, or otherwise no longer identifiable (such as benchmark statistics and model performance metrics) may be retained indefinitely.
When data is no longer needed, we securely delete or anonymise it.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest for stored Submitted Content and the retained sanitised copy.
- Access controls and authentication mechanisms, with access to the retained sanitised copy restricted to authorised personnel.
- Regular security reviews and monitoring.
- Server-side, API-layer sanitisation of a defined set of personal-data types before Submitted Content is transmitted to third-party providers or retained as a sanitised copy, together with client-library features that let you exclude fields likely to contain sensitive data before they are sent to the Service.
While we take reasonable steps to protect your data, no method of transmission over the Internet or electronic storage is completely secure.
10. International Data Transfers
Sixees Labs is established in South Africa. We operate three separate regional instances of the Service — in South Africa, the European Union, and the United States — and personal data submitted to a given instance is stored within that instance's region. The only routine flow of Submitted Content out of its region is the real-time API call to our third-party AI provider; we do not control where that provider processes or retains the content it receives (see Section 4.2). Any training and evaluation of our own models, if and when we carry it out, would take place within the region in which the data is held.
Where we transfer personal data from the EEA or UK to a country that has not been recognised by the European Commission (or, for UK data, the UK Government) as providing an adequate level of protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognised transfer mechanisms, and we apply supplementary measures where required.
Where personal information is transferred out of South Africa under POPIA, we do so only on a basis permitted by section 72 of POPIA — in particular, where the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection, where the transfer is necessary for the performance of our contract with you (or a contract concluded in your interest), or with your consent.
11. Children's Privacy
The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). Under POPIA, a child is a person under 18, and we do not knowingly process the personal information of a child without the consent of a competent person (such as a parent or guardian). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will promptly delete it.
12. Third-Party Links
Our website or Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page, and where appropriate, by sending you a notification via email or through the Service. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Sixees Labs Pty (Ltd)
Email: [email protected]
For payment, billing, or refund inquiries, please contact Paddle directly at https://paddle.net or via [email protected].
15. Information Officer and Data Protection Contact
Our Information Officer, appointed under POPIA and registered with the Information Regulator (South Africa), is also our point of contact for GDPR and other data protection matters. If you have concerns about our data processing that we have not adequately addressed, you may contact them at [email protected]. You also have the right to complain to your local data protection authority or, in South Africa, to the Information Regulator (see Section 6.3).