1. Responsible Party & Operator Status
Under the Protection of Personal Information Act 4 of 2013 (POPIA) and the General Data Protection Regulation (GDPR):
- Customer as Responsible Party / Controller: The law firm, corporate legal department, or university faculty acts as the Responsible Party regarding personal information contained in uploaded litigation dockets, student records, and advocate evaluations.
- Jurisor as Operator / Processor: Jurisor processes personal information strictly on the mandate and instructions of the Customer in our capacity as an Operator under Section 1 of POPIA.
2. Categories of Information Processed
We process the following categories of data solely to provide the simulation service:
3. Zero Model Training & Confidentiality
All inference operations are executed under enterprise zero-data-retention terms, ensuring that prompt inputs and generated responses are processed statelessly and discarded immediately following response generation.
4. Technical & Organizational Safeguards (Section 19 POPIA)
Pursuant to Section 19 of POPIA, Jurisor maintains robust technical security measures to prevent loss, damage, or unauthorized access:
- Encryption in Transit: Mandatory TLS 1.3 for API endpoints and DTLS-SRTP 256-bit encryption for real-time voice streams.
- Encryption at Rest: Persistent database storage and archival stores are encrypted using industry-standard AES-256 with KMS key management.
- Logical Tenant Isolation: Strict multi-tenant boundaries ensure that data queries are cryptographically restricted to authorized tenant domains.
- Audit Logging: All simulation provisioning, administrative actions, and judicial assessments emit structured immutable audit records.
5. Cross-Border Data Flows & Sovereignty
In compliance with Section 72 of POPIA regarding transborder information flows:
Primary database storage and institutional records reside within South African data center regions (Cape Town / Johannesburg). Where global processing relays occur, transfers are governed by binding corporate agreements and Standard Contractual Clauses guaranteeing an equivalent level of data protection.
6. Data Subject Rights & Right-to-Erasure
Under POPIA Sections 23 and 24 and GDPR Articles 15-20, data subjects (advocates, students, and faculty) possess the right to:
- Request access to all simulation transcripts and judicial evaluations linked to their institutional profile.
- Request correction or deletion of inaccurate personal information.
- Execute a formal Right-to-be-Forgotten (RTBF) purge, permanently removing personal records in accordance with institutional data retention schedules.
7. Information Officer Contact Details
For statutory privacy inquiries, data subject access requests, or to execute a POPIA Operator Agreement, please contact our designated Information Officer: