Privacy Statement
Supervision Board is a platform for managing postgraduate research supervision: draft submissions, supervisor feedback, revisions, milestones and related communication. This statement explains what personal information the platform processes, why, who it is shared with, and the rights you have. It is written with the South African Protection of Personal Information Act, 2013 (POPIA) in mind.
1. Who is responsible
Supervision Board is provided to universities and their students and staff. Your university decides which supervision records are kept and for what academic purpose, and is generally the responsible party for that information under POPIA. Supervision Board operates the platform and processes information on the university's behalf and in line with its instructions.
2. Information we process
- Account details: name, email address, role (student, supervisor, administrator), university, department, programme and, for students, a student number.
- Sign-in information: if you sign in with Microsoft (Office 365), your Microsoft account identifier, name and email address from your university directory.
- Academic work: draft documents you upload, their versions and change summaries, reference lists, and the results of reference checks.
- Supervision records: feedback comments and their type, your responses, annotations, rubric scores, review decisions, milestones, tasks, meeting notes and messages.
- Feedback activity: when feedback was issued, opened, responded to and resolved, so that supervision progress can be followed.
- Wellbeing check-ins (optional): if you choose to complete them, mood and stress ratings and whether you would like support. This can be sensitive; it is only used to help your supervisors support you.
- Profile information you choose to provide, which may include funding type, language preference, nationality group and disability-support needs, used for support and institutional reporting.
- Usage and security data: pages visited within the platform, sign-in times, IP address, and audit records of sensitive actions such as exports and administrator views.
We do not sell personal information and we do not use it for advertising.
3. How we use it
- To run the supervision process: delivering drafts to supervisors and feedback to students, tracking revisions and milestones, and sending notifications and emails about them.
- To show supervision progress: indicators such as feedback turnaround, response times and outstanding feedback. These are signals to support a conversation, not judgements of a student's ability or a supervisor's quality.
- To check references against public bibliographic records.
- To provide optional AI assistance (see section 4).
- To keep the platform secure, prevent misuse, and meet the university's record-keeping and governance obligations.
We process information because it is necessary to provide the service your university has arranged, to fulfil the university's legitimate academic purposes, to meet legal obligations, or, for optional features such as wellbeing check-ins, with your consent.
4. AI features
Some optional features use a large language model (Claude, provided by Anthropic) to help supervisors review drafts, summarise outstanding feedback, and help students understand feedback. When a feature is used, the relevant text (for example extracts of a draft or a feedback comment) is sent to the AI provider to generate a response.
- AI output is a suggestion. A supervisor reviews and edits it before anything reaches a student, and feedback that started from an AI suggestion is marked as AI-assisted.
- Names and student numbers are not included in the overviews generated about outstanding feedback.
- Each use of an AI feature is logged (who, which feature, when) so that AI assistance is transparent and auditable.
- Academic judgement, marks and decisions remain with people.
5. Signing in with Microsoft
If you choose Sign in with Office 365, Microsoft authenticates you and shares your basic profile (name, email address and account identifier) with Supervision Board so that we can match you to your existing account. We request only the permissions needed to sign you in and read your basic profile. We do not read your email, files, calendar or contacts. Microsoft's own processing is covered by the Microsoft Privacy Statement.
6. Who we share it with
Information is shared only as needed to provide the service:
- Within your university: your supervisors, and authorised staff such as programme coordinators, heads of department and research office staff, according to their role (see section 7).
- Service providers that help us run the platform, under confidentiality obligations: hosting and database services, email delivery, Microsoft (sign-in), Anthropic (AI features, when used), and CrossRef (reference-check queries contain the reference text only).
- Content delivery networks that serve fonts and interface libraries to your browser, which receive technical information such as your IP address.
- Where the law requires it, for example in response to a lawful request.
Some service providers may process information outside South Africa. Where that happens, we rely on providers that offer an adequate level of protection, as POPIA requires.
7. Who can see what
- Students see their own submissions, feedback and progress indicators.
- Supervisors see the students they actively supervise.
- Heads of department and faculty or institution administrators see anonymous totals only. Groups smaller than five students are hidden so individuals cannot be identified. An individual student's indicators are shown to such staff only while an escalation case they are handling is open, and every such view is recorded in an audit log.
- Exported supervision records are anonymised by default when exported by staff.
8. Cookies and browser storage
We use only what is needed for the platform to work: sign-in cookies and a sign-in token kept in your browser's local storage so that you stay signed in, plus small preferences such as whether a side panel is collapsed. We do not use advertising or cross-site tracking cookies. Signing out removes the sign-in token from your browser.
9. How long we keep it
Supervision records are kept for as long as you are registered and supervised, and afterwards for as long as your university's records-management and academic-integrity policies require. Information is then deleted or anonymised. Logs used for security and auditing are kept for a limited period appropriate to that purpose.
10. Security
Access is restricted by role, connections are encrypted, and sensitive actions are logged. No system is perfectly secure; if a security compromise affects your personal information, we and your university will notify you and the Information Regulator as POPIA requires.
11. Your rights
Under POPIA you may:
- ask whether we hold personal information about you and request a copy of it (students can also download their own supervision record from the platform);
- ask for information that is inaccurate, out of date or incomplete to be corrected;
- ask for information to be deleted or its processing restricted, where the law allows;
- object to processing, and withdraw consent for optional features such as wellbeing check-ins;
- lodge a complaint with the Information Regulator (South Africa).
Because your university is usually the responsible party, some requests are best made to your university's information officer, and we will help them respond.
12. Contact
You can also contact your university's information officer, or your supervisor or programme administrator.
We may update this statement when the platform or the law changes. The date at the top shows when it was last revised.