Governance — Sable Foundry

Governance

How Sable Foundry collects, protects and releases Zimbabwean voice data. Written to be audited: by contributors, by licensees, by regulators, and by the judges of the AI4I Challenge.

§1

Lawful basis & classification

Voice recordings with demographic attributes are personal data. We treat them as such under Zimbabwe's Data Protection Act [Chapter 12:07], with informed consent as the lawful basis for all collection and processing. Data is classified at collection as personal — raw audio and contributor records — and released only in pseudonymised form under licence terms. Identity and payment records are held separately from the corpus under stricter access control and are never part of any release.

IN TRANSIT + AT REST TLS everywhere; encrypted storage; encrypted, restore-tested backups.
ROLE-BASED ACCESS Transcribers see audio without identity data; two named admins hold the identity key, with access logging.
RETENTION Unvalidated submissions deleted after 90 days; identity records kept only as long as payment and law require.
§3

Dual release model

COMMERCIAL RELEASE Licensed to institutions Contract terms prohibit re-identification, surveillance use and re-sale, with audit rights and termination clauses. Revenue in foreign currency finances contributor payments — a first call on revenue at a fixed published share.
OPEN RELEASE 20% to the commons, CC BY 4.0 A fifth of validated hours, from contributors with specific open-release consent, free for education and research. Where a subset presents elevated risk, it moves to controlled access rather than open release.
§4

Prohibited uses — in every licence

{{ p.title }} {{ p.body }}

Voice-cloning research use of the scripted subset is permitted only for contributors who gave specific, separate consent for that purpose.

§5

Risk register

RISKMITIGATION
{{ r.risk }} {{ r.mitigation }}
§6

Bias & representativeness register

The corpus is built to a representativeness plan, not to convenience. Deviations beyond 10 percentage points from target trigger corrective recruitment. Gaps that cannot be closed within a release are disclosed in the metadata card — never left silent.

RISKCHECKMITIGATION
{{ b.risk }} {{ b.check }} {{ b.mitigation }}
§7

Named stewardship, from day one

{{ s.initials }} {{ s.role }} {{ s.body }}

The data steward is the accountable contact named on every metadata card. Post-challenge, stewardship transfers into a locally incorporated entity, and the open subset is mirrored to a public repository so the commons never depends on a single server.