Is Paperpal GDPR compliant? What universities should check
Paperpal is an AI writing assistant built for academic manuscripts, used by researchers on their own and increasingly licensed by universities and libraries. This page sets out what its publisher, Cactus Communications, publicly documents and what a DPO or librarian should clarify before an institutional licence.
Short answer
Paperpal is published by Cactus Communications, a group with entities in Singapore, India, Japan, China, South Korea, Denmark, the UK and the US; the Paperpal site names Cactus Communications Services Pte Ltd in Singapore, and the terms of use are governed by Singapore law. It is sold as Free, Prime and Pro plans for individuals, plus institutional licences. Paperpal states that user content is never used to train its AI on any plan, and it holds ISO/IEC 27001 and ISO/IEC 42001 certification, but its linked privacy policy says data is hosted in Singapore, India, the USA or Japan, and we found no public subprocessor list or Paperpal-specific DPA. Whether a university can use Paperpal depends on the processing agreement and transfer safeguards it can obtain for an institutional licence, and on what research and student data users upload.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI writing support with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Paperpal documents publicly
Everything below comes from Paperpal's own pages, the Cactus privacy policy and terms of use that Paperpal links to, the Editage trust centre run by the same group, and the official Data Privacy Framework List, all read on 7 October 2026. Paperpal URLs such as /privacy-policy returned "page not found"; the site footer links to the Cactus policies instead.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Paperpal pages name Cactus Communications Services Pte Ltd, 20 McCallum Street, Singapore. The Cactus privacy policy (version 4, 21 August 2024) covers group entities in Singapore, India, Japan, China, South Korea, Denmark, the UK and the US and names a Data Protection Officer. The terms of use are governed by Singapore law with arbitration in Singapore. Not found publicly An EU representative or EU contracting entity for Paperpal: not found in public documentation (checked 7 October 2026). | [1], [3], [4] |
| Where data is stored and processed | Plan-dependent The privacy policy says personal information is transferred to a third-party cloud provider in Singapore, India, the USA or Japan for hosting and back-up. Paperpal says data sits in SSAE 18/SOC 1 certified facilities with backups across multiple regions, and its universities page lists the SOC reports of AWS, Google Cloud and Azure. An EU hosting option: not found in public documentation (checked 7 October 2026). | [1], [2], [3] |
| Data processing agreement | Not found publicly The privacy policy says that when Cactus is a processor it acts on the controller's instructions under a controller/processor agreement, deletes or returns data at the end of the service, and allows audits. A published Paperpal DPA or template: not found in public documentation (checked 7 October 2026). | [3] |
| Subprocessors | Not found publicly The terms say Paperpal uses machine learning models, generative AI and third-party services chosen at Cactus's discretion, and the universities page says Paperpal uses a variety of AI models alongside its own. A public subprocessor list naming the AI and hosting providers: not found in public documentation (checked 7 October 2026). | [2], [4] |
| International transfers | Plan-dependent The privacy policy says data may be transferred to affiliates and service providers in other countries, that "specific requirements may apply" to such transfers, and that by using the services users agree to transfers where consent is required. Named mechanisms such as SCCs: not found in the policy. We found no entry for Cactus Communications or Paperpal on the official DPF List. | [3], [6] |
| AI model training on customer content | Documented Paperpal states that documents, uploads and personal information are never used to train its AI models, on every plan including Free, and that its own models are trained on independent scholarly datasets. | [1], [2] |
| Retention and deletion | Documented Documents you create and files uploaded for plagiarism checks can be deleted at any time; files uploaded for Journal Fit checks are deleted automatically after 90 days; PDFs uploaded to chat are deleted on demand; personal data is kept while the account is active and as legally required. For institutional accounts, Paperpal says all data is purged on request at account closure, quoting a minimum 14-day turnaround. Account deletion is requested by email. | [1] |
| Security certifications | Documented ISO/IEC 27001:2022 for the information security management system, ISO/IEC 42001:2023 for the AI management system, and CSA STAR Level 1. Paperpal also states alignment with the GDPR, PECR and FERPA. The universities page still refers to ISO/IEC 27001:2013. | [1], [2], [5] |
| Institution and enterprise controls | Plan-dependent Institutional licences come with a central dashboard to monitor licences and active users, onboard and reassign users. Single sign-on and admin control over individual AI features: not found in public documentation (checked 7 October 2026). | [2] |
What this means for a university
Validemic's analysisStrengths first. Paperpal makes a clear, plan-independent commitment not to train on user content, including on the free plan, which many writing tools do not offer to individual users [1]. It documents retention by data type, with automatic deletion for Journal Fit uploads, and holds ISO/IEC 27001 and ISO/IEC 42001 certificates [1]. For researchers who mainly want language editing of their own manuscripts, those are meaningful protections.
The open questions are contractual. Article 28 GDPR requires a binding contract with any processor that sets out instructions, confidentiality, subprocessor rules and deletion [7]. The Cactus privacy policy describes acting as a processor under a controller/processor agreement [3], but we could not find a Paperpal DPA or subprocessor list online. A university licence should not start until the DPO has the agreement and the list of AI and hosting providers in hand.
Transfers need a named mechanism. The privacy policy names hosting in Singapore, India, the USA or Japan [3]. The European Commission recognises Japan as adequate, and the United States only for organisations in the EU-US Data Privacy Framework; Singapore and India are not on its list [6]. We found no DPF listing for Cactus [8]. Under Article 46 GDPR, transfers without an adequacy decision need appropriate safeguards such as SCCs [7]. The policy's reliance on user agreement to transfers resembles the explicit-consent derogation in Article 49, which applies only in the absence of adequacy or safeguards and is titled "Derogations for specific situations" [7]. A university should not rely on users' consent for a licensed service; it should ask Cactus which SCC modules apply and for a transfer impact assessment.
Research data is the main risk. Manuscripts can include participant quotes, clinical details or case descriptions. Uploading them to an editing service is processing of research participants' personal data, sometimes of special category data. Article 35 GDPR requires a DPIA where processing using new technologies is likely to result in a high risk [7]. A library-wide licence for researchers, where health or interview data may be uploaded, is the kind of use many DPOs will want to assess, and research ethics approvals may restrict which services participants' data may go to.
Students and individual researchers. Someone who signs up on their own uses Paperpal under Cactus's terms, governed by Singapore law [4]. If the university recommends or requires Paperpal for coursework or theses, it is steering that processing and should provide a licensed route with a contract, rather than leaving students to accept consumer terms.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Paperpal before approving it
- Which Cactus entity contracts with an EU university, and can you provide your data processing agreement for institutional licences?
- In which countries are documents, uploads and chat PDFs from our users stored and processed, including backups? Is EU hosting available?
- Which transfer mechanism covers transfers from the EU to Singapore, India and the United States: SCCs (which modules), or something else? Can you share a transfer impact assessment?
- Who are your subprocessors, including the third-party AI model providers, and do they keep or train on prompts or documents?
- How will you notify us of new subprocessors, and can we object?
- Is your no-training commitment written into the institutional contract, not only the website?
- Who is your representative in the EU under Article 27 GDPR, if any?
- Does the institutional plan support single sign-on and let admins disable specific AI features?
- Can we receive the ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certificates with their scope statements and the latest penetration test summary?
The EU AI Act angle
Regulation (EU) 2024/1689, the AI Act, has applied in stages [9]. Article 4 on AI literacy has applied to deployers since 2 February 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, replaced Article 4: providers and deployers must take measures to support the AI literacy of their staff, without guaranteeing a specific level for any individual [10], [11]. A university that licenses Paperpal is a deployer.
Language editing and manuscript checks are normally not high-risk uses. That would change only if the university used Paperpal to evaluate learning outcomes or to monitor students during tests, which are among the education uses in Annex III point 3 [9]. After the Omnibus, the Annex III high-risk rules apply from 2 December 2027 [10], [11]. Chapter V obligations for general-purpose AI models have applied since 2 August 2025 and sit with the model providers, not with the university [9]. Because Paperpal does not name its third-party model providers publicly, a university cannot check whether they have signed the General-Purpose AI Code of Practice; Cactus and Paperpal do not appear on the European Commission's signatory list [12].
Sources
- Paperpal, Data Security: Secure AI Writing Tool for Researchers (including FAQ), retrieved 7 October 2026.
- Paperpal, Paperpal for Universities, retrieved 7 October 2026.
- Cactus Communications, Privacy Policy (version 4, effective 21 August 2024), retrieved 7 October 2026.
- Cactus Communications, Terms of Use, retrieved 7 October 2026.
- Cactus Communications, Trust Editage (certifications for the Cactus group), retrieved 7 October 2026.
- European Commission, Data protection adequacy for non-EU countries, retrieved 7 October 2026.
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28, 35, 46 and 49, retrieved 7 October 2026.
- U.S. Department of Commerce, Data Privacy Framework List (searched for "Cactus" and "Paperpal"), retrieved 7 October 2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal L, 12 July 2024, Articles 4 and 113 and Annex III, retrieved 7 October 2026.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal L, 24 July 2026, retrieved 7 October 2026.
- European Commission, AI Act (application timeline), retrieved 7 October 2026.
- European Commission, The General-Purpose AI Code of Practice (signatories), retrieved 7 October 2026.
About this page
We read Paperpal's public data security and universities pages, the Cactus Communications privacy policy and terms of use linked from Paperpal, the Editage trust centre, the official Data Privacy Framework List and the EU legal texts on 7 October 2026. Where we write "not found in public documentation", we looked and did not find it; that does not mean it does not exist, and Cactus may provide it to institutional customers on request. We did not test the product or review any contract. This page is not legal advice and is not a verdict on whether any organisation's use of Paperpal complies with the GDPR. If you work at Cactus Communications or spot an error, please contact us and we will correct it.
Frequently asked questions
Does Paperpal train on my data?
Paperpal says no. Its data security page states that documents, uploads and personal information are never used for model training, on every plan including Free (checked 7 October 2026).
Where does Paperpal store data?
The Cactus privacy policy that Paperpal links to says personal information is transferred to a third-party cloud provider in Singapore, India, the USA or Japan for hosting and back-up, encrypted at rest and in transit. We did not find an EU hosting option in public documentation (checked 7 October 2026).
Does Paperpal sign a DPA?
The Cactus privacy policy says that when Cactus acts as a processor it follows a controller/processor agreement with the controller. We did not find a published Paperpal data processing agreement or template, so a university should request one as part of an institutional licence.
Who owns text edited with Paperpal?
Paperpal says you own copyright over content you produce or enhance with it, and the Cactus terms of use say you keep ownership of AI output, subject to compliance with the terms.
Can students use Paperpal under GDPR?
Students can choose to use a personal account under Cactus's privacy policy and terms, which are governed by Singapore law. If a university licenses Paperpal or requires it, the university becomes the controller for that use and should have a processing agreement, a transfer assessment and, for broad use, a DPIA.