Skip to content

Privacy Policy

Babel Shield — Sixees Labs Pty (Ltd)
Last Updated: 20 July 2026
Effective Date: 5 May 2026


1. Introduction

Sixees Labs Pty (Ltd) ("we", "us", "our", or "Sixees Labs") operates Babel Shield (the "Service"), a software-as-a-service content moderation platform accessible via our website and API. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our Service, or interact with us in any way.

We are committed to protecting your privacy and complying with applicable data protection laws, including the South African Protection of Personal Information Act, 2013 ("POPIA"), the European Union General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and other applicable privacy laws. Sixees Labs is established in South Africa, and Babel Shield operates within the Sixees Labs POPIA compliance framework; our Information Officer is registered with the Information Regulator (South Africa) and can be reached at the email address in Section 15.

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. For transactions processed through Paddle, Paddle acts as an independent data controller with respect to the personal data it collects during the checkout process. Please refer to Paddle's Privacy Policy for details on how Paddle processes your data.

If you have questions or concerns about this policy, please contact us at [email protected].


2. Information We Collect

Providing Personal Information through the Website is voluntary. If you choose not to provide the details requested in a form, we may be unable to respond to your enquiry or provide the materials or services you have asked for. Required fields, where they apply, are marked at the point of collection.

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Content Submitted to the Service

When you use the Babel Shield API or client libraries, you may submit content for moderation ("Submitted Content"). Submitted Content is processed in real time and moderation results are returned to you.

Real-time moderation is currently performed using a third-party AI provider (see Section 4.2). We retain Submitted Content for two purposes: (a) operating, securing, and improving the Service (for example, to debug failed requests, investigate abuse, and meet reasonable audit needs), and (b) keeping a sanitised copy that we may use in the future to train and evaluate our own moderation models. We do not currently train our own models on Submitted Content, but we retain a sanitised copy so that we are able to do so should we decide to; we describe this here so that this future use is disclosed at the point of collection. Section 8 sets out retention periods, and Sections 4 and 5 explain how we use and lawfully process this data.

Before Submitted Content is transmitted to our third-party AI providers, or retained by us as a sanitised copy (including any copy we may later use to train or evaluate our own models), it passes through an automated sanitisation pipeline. This pipeline detects a defined set of personal-data types and replaces each detected value with a fixed, irreversible, keyless placeholder label (for example, [PHONE]). The types it detects and redacts are: payment card numbers, United States Social Security numbers, telephone numbers, email addresses, and IP addresses (both IPv4 and IPv6). For email addresses, only the local part is removed and the domain is deliberately preserved as a spam signal, so an email address is partially redacted rather than removed entirely.

This is a data-minimisation measure, not anonymisation or pseudonymisation: although each transformation is irreversible and uses no recovery key, the content that remains is still personal data. The pipeline does not detect every kind of identifier. In particular, personal names, postal or physical addresses, dates of birth, and government identifiers other than United States Social Security numbers (such as passport, driving-licence, or national-identity numbers) are not automatically detected or redacted. Those identifiers, and any other personal data contained in the free-text content you submit, may therefore be transmitted to and retained by our third-party AI providers under their own terms (see Section 4.2).

Value-level sanitisation is enforced centrally at our API layer (as described above), so that it applies consistently however a request reaches us — whether through our client libraries or a direct API call. To reduce what reaches us in the first place, our client libraries also let you exclude fields likely to contain sensitive data (such as payment-card fields) so that they are never transmitted to the Service. We strongly encourage you to use these field-exclusion features, particularly for fields likely to contain sensitive or special-category data.

The retained sanitised copy is organised by customer account and request (not by the identity of the individual end-users whose data may appear within submitted content). This means we can locate the content associated with a given account, but we may be unable to locate content relating to a particular individual from that individual's identity alone. It does not mean the content is anonymous: because the sanitisation pipeline does not remove names or addresses, the retained copy may still contain personal data. Section 6 explains how we handle rights requests in that light.

Section 6 explains your rights, including how to object to any future use of Submitted Content for model training, and the practical limits of those rights in respect of the retained sanitised copy.


3. How We Use Your Information

We use the information we collect for the following purposes:


4. How We Share Your Information

We do not, and will never, sell your personal data or personal information, and we do not disclose it to third parties for their own independent purposes except as described in this policy. Retaining and, in future, using a sanitised copy of Submitted Content to train our own models is an internal use of that data by us — it is not a sale, and it does not involve disclosing that content to a third party for their own purposes. We share your information only in the following circumstances:

4.1 Paddle (Merchant of Record)

As our Merchant of Record, Paddle receives personal data necessary to process your payments, manage subscriptions, handle refunds, issue invoices, and provide customer support for billing-related inquiries. Paddle acts as an independent data controller for this data. See Paddle's Privacy Policy.

4.2 Third-Party AI Providers

To deliver content moderation, we transmit Submitted Content to third-party AI service providers for scoring. Before transmission, content passes through the sanitisation pipeline described in Section 2.3, which redacts a defined set of personal-data types but does not remove names, postal addresses, or other identifiers that may appear in free-text content. We currently use a single third-party AI provider, which processes API content under its standard terms; under those terms, such content may be retained for up to approximately 30 days for abuse-monitoring and security purposes before deletion. We do not use a zero-data-retention tier. These retention terms are set by the provider and may change, as described below. We also provide client-library features that let you exclude fields likely to contain sensitive data before they are sent to the Service (see Section 2.3).

We do not provide Submitted Content to third-party AI providers for the purpose of training their models, and we select providers whose published terms are consistent with this. However, third-party AI providers process content under their own terms and privacy policies, which they may amend from time to time, and we cannot control or guarantee what those providers do with content once it leaves our systems. Any training and evaluation of Babel Shield's own models would be carried out by us, not by our third-party AI providers, using the retained sanitised copy described in Section 2.3.

4.3 Analytics and Optimisation Services

We use third-party analytics and conversion optimisation services that collect data through cookies and similar technologies to help us understand website traffic, usage trends, and user experience patterns.

4.4 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.5 Business Transfers

If Sixees Labs is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

4.6 With Your Consent

We may share your information with other parties when you have given us explicit consent to do so.


5. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data on the following legal bases:

Where you are an API customer submitting third-party end-user content to the Service, you are responsible for ensuring you have an appropriate legal basis to provide that content to us for the purposes described in this policy, including retention of a sanitised copy and any future model training following sanitisation, and for providing any notices required to your own users.


6. Your Privacy Rights

6.1 Rights Under GDPR (EEA and UK Residents)

If you are located in the EEA or UK, you have the following rights:

These rights apply to the personal data we hold about you, including account data, operational copies of Submitted Content, and the retained sanitised copy of Submitted Content. Two practical limits apply:

To exercise these rights, make a data subject request or contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

API customers can opt out, at the account level, of having their Submitted Content retained for or used in model training and evaluation by emailing [email protected]. Once an opt-out is in effect, Submitted Content received from that account thereafter will not be retained for, or used in, model training. For content already held in the retained sanitised copy, it remains associated with your account, and on request we can locate and delete it.

6.2 Rights Under CCPA (California Residents)

If you are a California resident, you have the following rights under the CCPA:

The same two practical limits described under Section 6.1 apply to these rights: stored content is keyed to the customer account and request rather than to individual end-users, so requests are handled as described in Section 6.1 (we do not claim this content is deidentified — it may still contain identifiers); and individual contributions cannot practicably be isolated or removed from any trained model parameters. We will action your request in respect of all personal information we can identify as relating to you.

To exercise these rights, make a data subject request or contact us at [email protected]. We will verify your identity and respond within 45 days.

6.3 Rights Under POPIA (South Africa)

If you are in South Africa, or your personal information is otherwise processed under POPIA, you have the following rights as a data subject:

The same two practical limits described in Section 6.1 apply: stored content is keyed to the customer account and request rather than to individual end-users, so requests are handled as described in Section 6.1; and individual contributions cannot practicably be isolated or removed from any trained model parameters. We do not treat this content as deidentified.

To exercise these rights, contact our Information Officer at [email protected] or make a data subject request. You also have the right to lodge a complaint with the Information Regulator (South Africa). Complaints must be made in writing on the prescribed form:


7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website to:

Managing Cookies

You can manage your cookie preferences through:

Analytics and marketing cookies are off by default and load only after you accept. If your browser or device sends a Global Privacy Control (GPC) or Do Not Track signal, we do not load Google Analytics at all — no analytics scripts or cookies are set, regardless of the banner.

Please note that disabling certain cookies may affect the functionality of our website.

For more information about the specific cookies we use, please refer to our Cookie Banner or contact us at [email protected].


8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.

When data is no longer needed, we securely delete or anonymise it.


9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

While we take reasonable steps to protect your data, no method of transmission over the Internet or electronic storage is completely secure.


10. International Data Transfers

Sixees Labs is established in South Africa. We operate three separate regional instances of the Service — in South Africa, the European Union, and the United States — and personal data submitted to a given instance is stored within that instance's region. The only routine flow of Submitted Content out of its region is the real-time API call to our third-party AI provider; we do not control where that provider processes or retains the content it receives (see Section 4.2). Any training and evaluation of our own models, if and when we carry it out, would take place within the region in which the data is held.

Where we transfer personal data from the EEA or UK to a country that has not been recognised by the European Commission (or, for UK data, the UK Government) as providing an adequate level of protection, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognised transfer mechanisms, and we apply supplementary measures where required.

Where personal information is transferred out of South Africa under POPIA, we do so only on a basis permitted by section 72 of POPIA — in particular, where the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection, where the transfer is necessary for the performance of our contract with you (or a contract concluded in your interest), or with your consent.


11. Children's Privacy

The Service is not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). Under POPIA, a child is a person under 18, and we do not knowingly process the personal information of a child without the consent of a competent person (such as a parent or guardian). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will promptly delete it.


12. Third-Party Links

Our website or Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page, and where appropriate, by sending you a notification via email or through the Service. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.


14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Sixees Labs Pty (Ltd)
Email: [email protected]

For payment, billing, or refund inquiries, please contact Paddle directly at https://paddle.net or via [email protected].


15. Information Officer and Data Protection Contact

Our Information Officer, appointed under POPIA and registered with the Information Regulator (South Africa), is also our point of contact for GDPR and other data protection matters. If you have concerns about our data processing that we have not adequately addressed, you may contact them at [email protected]. You also have the right to complain to your local data protection authority or, in South Africa, to the Information Regulator (see Section 6.3).