Privacy Policy

Comprehensive data protection for Africa's most advanced academic integrity platform

DPA 2021 Compliant Zambian Data Storage 84 Institutions AWS Enterprise Security 6 Academic Systems

PeakChecker v4.8.1 Integrated Academic Edition | Last Updated: January 7, 2026

Data Protection Act 2021 Compliance

This Privacy Policy implements Zambia's Data Protection Act No. 3 of 2021. PeakChecker v4.8.1 operates as a registered Data Controller with 6 integrated academic systems, all personal data stored on Zambian/AWS servers with complete storage abstraction.

1. Introduction & Scope

This Privacy Policy governs how PeakChecker v4.8.1 Integrated Academic Edition collects, processes, stores, and protects personal data in compliance with Zambia's Data Protection Act No. 3 of 2021. Our platform serves 84 Zambian educational institutions with 6 integrated academic systems, genuine AI detection using 3 ML models, complete storage abstraction, and AWS scalability.

Platform Scope: PeakChecker v4.8.1 processes academic data for legitimate educational purposes including AI detection, plagiarism analysis, cross-institution detection, citation verification, academic style analysis, unified processing, and educational focus across Zambian educational institutions.

2. Data Controller Information

2.1 PeakChecker as Data Controller

PeakChecker operates as a Data Controller as defined in Section 2 of the Data Protection Act 2021. We determine the purposes and means of processing personal data for academic integrity verification across 6 integrated systems.

Registration Status

DPA Registration: Pending (Section 19)

Controller Type: Academic Platform

Jurisdiction: Republic of Zambia

Data Location

Primary Storage: AWS Africa Region

Compliance: Section 70 DPA 2021

Local Storage: Complete abstraction layer

3. Data We Collect

We collect and process the following categories of personal data for legitimate academic purposes across 6 integrated systems:

Identity & Account Data
  • Full name and institutional identification
  • Institutional email address (domain-verified)
  • Academic role (student, educator, administrator)
  • Institution affiliation (84 pre-loaded options)
  • Account credentials (encrypted)
  • Student numbers and academic identifiers
Academic Content Data
  • Submitted documents (PDF, DOCX, TXT) up to 200,000+ characters
  • AI detection analysis results (3 ML models)
  • Plagiarism comparison data (Crossref API)
  • Cross-institution academic comparisons
  • Citation verification results
  • Academic style analysis findings
  • Educational improvement guidance
Academic Activity Data
  • Submission timestamps and quotas
  • Course enrollment information
  • Academic performance metrics
  • Platform usage patterns across 6 systems
  • Institution compliance data
  • Cross-institution comparison history
  • Educational focus engagement
Technical & System Data
  • IP addresses (for security)
  • Browser and device information
  • AWS storage abstraction metrics
  • API usage statistics across 280+ endpoints
  • Celery task processing logs
  • System performance metrics
  • Field-agnostic calibration data
Data Minimization: We follow Section 12(1)(c) of the Data Protection Act - collecting only data that is adequate, relevant, and limited to what's necessary for integrated academic integrity verification.

4. Integrated Academic Systems Data Processing

4.1 Six Integrated Academic Systems

PeakChecker v4.8.1 processes data through six integrated academic systems, each with specific data protection considerations:

Cross-institution Detection

Compares submissions across 84 Zambian universities while maintaining institutional privacy boundaries.

Citation Verification

Verifies citations using real-time Crossref API while protecting bibliographic metadata.

Academic Style Analysis

Analyzes Zambian academic standards while protecting individual writing styles.

AI Detection (3 ML Models)

Processes through 3 ML models for genuine detection with field-agnostic calibration.

Plagiarism Detection

Uses Crossref API and intelligent simulation with data minimization principles.

Educational Focus System

Provides improvement guidance while protecting student academic performance data.

4.2 Unified Document Processing

Centralized Processing: All 6 academic systems are coordinated through our unified document processor (document_processor.py) which implements consistent data protection across all processing stages while maintaining system separation where required.

6. How We Use Your Data Across 6 Systems

6.1 Integrated Academic Purposes

  • AI Detection: Process through 3 ML models with field-agnostic calibration (65-85% range)
  • Plagiarism Analysis: Compare against academic databases using Crossref API
  • Cross-institution Detection: Analyze across 84 Zambian universities while protecting privacy
  • Citation Verification: Validate references using real-time academic databases
  • Academic Style Analysis: Assess Zambian academic writing standards
  • Educational Focus: Provide specific improvement guidance for academic writing

6.2 Platform & AWS Operations

  • Account Management: Verify institutional access and roles across 84 institutions
  • AWS Security: Protect data with S3, RDS, and ElastiCache security measures
  • Service Improvement: Enhance 6 academic systems and ML models
  • Storage Abstraction: Manage Local/S3 storage with automatic fallback
  • Performance Scaling: Support thousands of concurrent documents on AWS
  • Compliance: Meet legal obligations under DPA 2021 and AWS best practices

Purpose Limitation: We follow Section 12(1)(b) of the Data Protection Act - data is collected for explicit, specified, legitimate academic purposes across 6 integrated systems and not processed incompatibly with those purposes.

7. Data Security & AWS Infrastructure (Section 47 DPA)

7.1 AWS Security Measures Implemented

We implement comprehensive AWS security measures in compliance with Section 47 of the Data Protection Act 2021:

AWS Infrastructure Security
  • AWS S3 bucket encryption with KMS keys
  • RDS PostgreSQL Multi-AZ with encryption at rest
  • ElastiCache Redis with in-transit encryption
  • CloudFront CDN with TLS 1.3
  • AWS WAF protection against threats
  • VPC security groups and NACLs
Application Security
  • Complete storage abstraction layer
  • Automatic Local/S3 fallback system
  • AES-256 encryption for all academic data
  • Role-based access controls (24 tables)
  • Regular penetration testing
  • Celery task queue security

7.2 Storage Abstraction Layer

Complete Storage Abstraction: PeakChecker v4.8.1 implements a complete storage abstraction layer that seamlessly handles both local storage and AWS S3 with automatic fallback. All academic data is protected with consistent encryption regardless of storage backend.

7.3 Breach Notification (Section 49 DPA)

24-Hour Notification Commitment: In compliance with Section 49(1) of the Data Protection Act, we will notify the Data Protection Commissioner within 24 hours of any security breach affecting personal data across any of the 6 academic systems. Affected users will be notified as soon as practicable per Section 49(3).

8. Your Data Subject Rights (Sections 58-66 DPA)

Under the Data Protection Act 2021, you have the following rights regarding your personal data across 6 academic systems:

Right of Access (Section 58)

Request confirmation and access to your personal data processed by PeakChecker across all 6 systems.

Response: 30 days
Right to Rectification (Section 59)

Request correction of inaccurate or incomplete personal data across all systems.

Immediate action
Right to Erasure (Section 60)

Request deletion under specific conditions (subject to academic retention requirements).

Case-by-case
Right to Object (Section 61)

Object to processing of your personal data based on legitimate interests.

30 days review
Right to Portability (Section 62)

Receive your data in structured, commonly used format for transfer to another controller.

Available
Right to Restrict (Section 63)

Restrict processing of your data under specific circumstances.

Available
Exercising Your Rights:

To exercise any of these rights across all 6 academic systems, contact our Data Protection Officer at dpo@peakchecker.com or use the integrated rights portal in your account dashboard. We will respond within 30 days as required by the Data Protection Act.

9. Data Retention (Section 51 DPA)

9.1 Retention Periods Across Systems

We retain personal data only as long as necessary for its purpose across 6 academic systems, plus at least one year as required by Section 51(1) of the Data Protection Act:

Data Type Retention Period System(s) Legal Basis
Academic Submissions Purpose + 1 year (min 2 years) All 6 Systems Section 51(1) DPA
Cross-institution Data 3 years for academic reference Cross-institution Detection Academic standards
Citation Verification 2 years for academic integrity Citation Verification Educational requirements
AI Detection Results 7 years for academic reference AI Detection System Educational standards
User Accounts (Active) While active + 1 year All Systems Section 51(1) DPA
AWS S3 Backups 90 days with encryption Storage Abstraction Disaster recovery
System Logs 12 months for security All Systems Section 47 DPA
Secure Deletion: After retention periods expire, we securely delete or anonymize personal data across all systems. AWS S3 backups are retained for disaster recovery only and are encrypted with KMS with restricted access. Local storage data is securely erased.

10. Data Sharing & AWS Transfers

10.1 AWS Data Processors

We engage AWS services as trusted processors who implement appropriate security measures. All AWS services operate under strict data processing agreements compliant with DPA 2021 requirements and AWS shared responsibility model.

10.2 Zambian Data Storage with AWS (Section 70 DPA)

AWS Africa Region Compliance: In compliance with Section 70(1) of the Data Protection Act, all personal data is processed and stored on AWS Africa (Cape Town) Region servers. Our complete storage abstraction layer ensures data protection regardless of storage backend, with Zambian legal jurisdiction maintained.

10.3 Integrated Academic System Sharing

Data sharing between our 6 integrated academic systems follows strict internal controls:

  • Unified document processor coordinates data flow between systems
  • Role-based access controls limit data access to necessary personnel
  • Encryption maintained during all inter-system transfers
  • Audit logging of all cross-system data access

10.4 Non-Disclosure (Section 53 DPA)

We do not disclose personal data to third parties except:

  • With your explicit consent per Section 53(2) for specific purposes
  • To your educational institution for academic integrity purposes
  • When required by Zambian law or legal process
  • To prevent threats to national security or investigate crimes
  • To Crossref API for citation verification (minimal metadata only)

11. Contact & Data Protection Officer

Data Protection Officer

Email: dpo@peakchecker.com

Focus: DPA 2021 compliance across 6 academic systems

Responsibilities: Rights requests, compliance monitoring, breach response, AWS security oversight

Response Time: Within 72 hours for rights requests

AWS & Technical Support

Email: peakchecker.team@gmail.com

Phone: +260 964 251 033

Hours: Mon-Fri, 07:00-17:00 GMT+2

AWS Support: 24/7 infrastructure monitoring

Focus: Platform access, technical issues, academic support across 6 systems

Complaints: If you have concerns about our data handling across any of the 6 academic systems, contact our DPO first. You may also lodge a complaint with the Zambian Data Protection Commissioner per Section 68 of the Data Protection Act.

12. Policy Updates

We may update this Privacy Policy to reflect changes in:

  • Zambian data protection laws and regulations
  • PeakChecker v4.8.1+ features and 6 academic systems
  • AWS security requirements and best practices
  • Storage abstraction layer enhancements
  • Institutional requirements from 84 partner institutions
  • Field-agnostic calibration and ML model improvements
Notification: Significant changes will be communicated to institutional administrators and users via email and platform notifications. Continued use of PeakChecker v4.8.1 constitutes acceptance of updated policies.
PeakChecker v4.8.1 Integrated Academic Edition Specifications

Infrastructure: AWS Africa Region | Complete Storage Abstraction | Local/S3 Fallback

AI Systems: 3 ML Models | Field-agnostic Calibration | 65-85% Academic Range

Institutions: 84 Zambian Universities | Cross-institution Detection

Academic Systems: 6 Integrated Systems | Unified Document Processor

Database: 24 PostgreSQL Tables | 280+ API Endpoints | 32 Email Templates

Security: AWS WAF | S3 Encryption | DPA 2021 Compliance

Acknowledgement & Consent

By using PeakChecker v4.8.1 Integrated Academic Edition, you acknowledge that you have read and understood this Privacy Policy. You consent to the lawful processing of your personal data for academic integrity purposes across 6 integrated systems as described herein, in compliance with Zambia's Data Protection Act No. 3 of 2021 and AWS best practices.

PeakChecker v4.8.1 Integrated Academic Edition: 84 Zambian Institutions | 6 Integrated Academic Systems | 3 ML Models with Field-agnostic Calibration | Complete AWS Storage Abstraction | Crossref API Integration | Zambian Academic Style Analysis | 280+ API Endpoints | 24 Database Tables | AWS Africa Region Infrastructure

Compliance Framework: Data Protection Act No. 3 of 2021 | AWS Shared Responsibility Model | Zambian Jurisdiction | 84 Institutional Agreements | Enterprise Security Standards | Complete Storage Abstraction

Data Protection Act 2021 References: Sections 12 (Principles), 13 (Legal Basis), 15 (Consent), 47 (Security), 49 (Breach), 51 (Retention), 58-66 (Rights), 70 (Localization) - Applied across 6 Integrated Academic Systems

PeakChecker v4.9.2 QUOTA ENFORCED