Legal

Privacy Policy

Who sees your personal information, why, where it goes, how long we keep it, and what you can do about it, under the Protection of Personal Information Act.

Effective date: 14 September 2026Version 1.0Governing law: South Africa

Plain language. This document is written to be read by the person it applies to, as section 22 of the Consumer Protection Act 68 of 2008 requires. Where a legal term is unavoidable it is explained where it first appears. It is governed by the law of the Republic of South Africa.

This policy explains what personal information we collect, why, who sees it, where it goes, how long we keep it, and what you can do about it. It is written to meet the Protection of Personal Information Act 4 of 2013 ("POPIA"). It covers this website, the product at app.synapticintelligence.ai, and our dealings with you as a prospective or current customer.

  1. Responsible party
  2. Information Officer
  3. When we are the responsible party and when we are an operator
  4. What we collect
  5. Why, and on what lawful basis
  6. Operators and third parties
  7. Transfers outside South Africa
  8. How long we keep it
  9. How we protect it
  10. Cookies and similar technologies
  11. Your rights
  12. Complaints and the Information Regulator
  13. Children
  14. Changes to this policy

1. Responsible party

The responsible party in the terms of POPIA is Synaptic Intelligence, registered in the Republic of South Africa, registration number [COMPANY REGISTRATION NUMBER].

Physical address: 81 Regent Road, Cape Town 8005, South Africa
Email: info@synapticintelligence.ai
Website: synapticintelligence.ai (this site) and app.synapticintelligence.ai (the product)

2. Information Officer

Our Information Officer, registered with the Information Regulator as section 55 of POPIA requires, is Gershon Koral. Any request, question or complaint about personal information should go to the Information Officer at info@synapticintelligence.ai, marked "Information Officer", or by post to the address above. Our PAIA manual (section 51 of the Promotion of Access to Information Act 2 of 2000) is available on request from the same address.

3. When we are the responsible party, and when we are an operator

POPIA distinguishes the responsible party, who decides why and how personal information is processed, from the operator, who processes it on the responsible party's behalf. We are both, for different information:

  • We are the responsible party for the personal information of the people we deal with directly: visitors to this website, people who use the contact form, the people who sign up and administer a customer's account, and the people who sign in to use the product. Sections 4 to 14 apply in full.
  • We are an operator for personal information contained in the systems and documents a customer connects: an HR directory, a payroll ledger, a CRM, a support desk, a mailbox, a shared drive. The customer is the responsible party for that information, decides what to connect and who in their company may see it, and is responsible for having a lawful basis to process it. We process it only as the product does, on the customer's instruction, under section 20 and 21 of POPIA and the Terms of Service. If you are a data subject whose information is held in a customer's systems, your request should go to that customer; we will help them answer it.

4. What we collect

WherePersonal informationHow it reaches us
This websiteNothing that identifies you. Our host records the IP address and requested URL in ordinary server logs. We run no analytics and set no cookies here (section 10).Your browser
Contact formYour name, email address, and optionally your company and the systems you run, together with the message you write and which of our enquiry types you chose.You type it
Sign-upYour name, work email address, company name, company website, the kind of business it is, and the tier you chose. Your card details are entered on Paddle's hosted checkout and are never sent to us; we receive a customer reference and the last state of the subscription.You type it; Paddle confirms it
Signing in to the productYour name, email address and directory identifiers from the Microsoft Entra ID token your organisation's directory issues, and the business title and access role your administrator assigns you.Your organisation's directory; your administrator
Using the productThe questions you ask, the answers produced, the records each answer cited, when you asked and what it cost in credits; documents you upload or sync; the connections you configure (the credential itself is stored encrypted and is never shown again). Answers can contain personal information from your connected systems; for that information we are an operator (section 3).Your use of the product
Support and billingEmails between us, invoices, and the record of what tier your company is on and since when.Correspondence; the payment processor

We do not collect special personal information (section 26 of POPIA) about the people we deal with directly, and we do not ask for it in the product. A customer who connects a system that contains special personal information, such as an HR directory holding health or union data, is the responsible party for it.

5. Why, and on what lawful basis

Section 11 of POPIA allows processing only on one of a fixed list of grounds. Ours are:

PurposeInformationLawful basis (POPIA s11(1))
Answering an enquiry or demo requestContact formYour consent, given when you send it (a); and our legitimate interest in replying (f)
Creating and administering your company's account, taking payment, sending invoices and noticesSign-up, billingNecessary to conclude and perform the contract with you (b); legal obligation for tax and accounting records (c)
Signing you in and deciding what you may do and seeSign-in, roles and titlesPerforming the contract (b); our and the customer's legitimate interest in keeping every request scoped to the right person and company (f)
Producing answers, verifying their provenance, keeping them auditableQuestions, answers, cited records, documentsPerforming the contract (b); as operator for the customer's information
Metering credits and preventing use past the allowanceUsage recordsPerforming the contract (b)
Keeping the service secure, investigating misuse, and defending claimsServer logs, usage recordsLegitimate interest (f); legal obligation (c)
Telling you about changes to the service, prices or these policiesAdministrator email addressesPerforming the contract (b)

We do not send marketing email. If we ever do, it will be to people who opted in, with an unsubscribe in every message, as section 69 of POPIA requires. We do not sell personal information to anyone.

No automated decisions about you. The product makes no decision with legal or similarly significant consequences for a person by automated means (section 71). It answers questions; people decide what to do with the answers.

6. Operators and third parties

The following companies process personal information on our behalf. Each receives only what its column says, under a written agreement that binds it to confidentiality and to section 21 of POPIA or an equivalent standard. Our security page describes the two that read your data to produce answers; this is the full list, including hosting and payments.

OperatorWhat it doesWhat it receivesWhere
Anthropic, PBCProvides the language models that route each question, read the records it reaches and compose the answerYour questions; the records and document passages a question reaches; the company profile and brief; prior turns of the conversation. Not used to train models under our agreement.United States
Voyage AIProduces the embeddings that let uploaded and synced documents be searched by meaning, when a deployment has it configuredThe text of documents you upload or sync, in passages, and the search phrase a specialist uses. It does not receive connector data, ledger rows, HR records, questions or answers.United States
Microsoft Corporation (Azure)Hosts the product, its database and document storage; provides Entra ID sign-in; sends the contact form's email through Azure Communication ServicesEverything the product stores, encrypted at rest; the sign-in token; the contact form's contentsSouth Africa (Microsoft's South African Azure region)
Paddle.com Market Ltd (UK) / Paddle.com Inc. (US)Takes card payments as merchant of record and runs the monthly subscription: it sells you the subscription on our behalf, calculates and remits VAT or sales tax, and issues your receipt and invoice. For the card transaction Paddle is a responsible party in its own right, under its own privacy policy, as well as our operatorYour name, email address, company reference and billing country and address; your card details, entered on Paddle's hosted checkout and never seen by usUnited Kingdom and United States
Google LLC (Fonts)Serves the typefaces this website usesYour IP address and browser details, in the request for the font files. No cookie is set.Global

Systems you connect. When you connect a vendor's system, we read from that vendor using the credential you granted; the vendor sees the requests we make in your name. The vendor is not our operator: it is a system you already use, under your own agreement with it.

Disclosures we may be required to make. We will disclose personal information where a law, a court order or a regulator with authority requires it. We will tell you first unless the law forbids us to, and we will disclose no more than is required.

Change of ownership. If our business is sold or merged, personal information may transfer to the successor, who will be bound by this policy. We will tell you before that happens.

7. Transfers outside South Africa

The product is hosted in South Africa. The application, its database and every document you upload or sync are held in Microsoft's South African Azure region, and sign-in and the contact form's email run through the same Microsoft tenancy. Personal information leaves the country only for the operators below, and section 72 of POPIA allows each transfer on the ground stated:

RecipientWhat leavesCountryPOPIA s72 ground
AnthropicYour questions and the records and passages each one reaches, for the duration of the model callUnited Statess72(1)(a): bound by written terms giving substantially POPIA's protections, including no training and no onward transfer; and s72(1)(c): necessary to perform the contract, since an answer cannot be composed without the model reading the question
Voyage AIDocument passages and search phrases, for the duration of the embedding call, when a deployment has it configuredUnited Statess72(1)(a) and s72(1)(c), as above
PaddleYour name, email address, company reference and billing country and address, if you pay by cardUnited Kingdom and United Statess72(1)(c): necessary to perform the contract you chose to pay by card, which is concluded with Paddle as merchant of record; s72(1)(a): Paddle's terms and the laws it is subject to, including UK data protection law
Google (Fonts)Your IP address, in the request for this website's typefacesWherever Google's nearest edge server iss72(1)(a): Google's published terms; the request carries no cookie and identifies no account

Where none of those grounds applies to a particular transfer, we rely on your consent under s72(1)(b), which you give by signing up after reading this policy and may withdraw by cancelling. If the model and embedding calls leaving the country is a constraint for you, say so on the demo call and we will tell you plainly what can and cannot be arranged; an Enterprise contract can add a data processing agreement that records the position.

8. How long we keep it

Section 14 of POPIA says we may keep personal information no longer than the purpose requires unless a law or a contract requires longer. Our periods:

InformationKept for
Contact form messagesUntil the enquiry is closed and for 12 months after, then deleted
Sign-up records that did not become an account90 days, then deleted
Account, billing and invoice recordsThe life of the account and five years after it closes, as tax and company law require
Questions, answers, provenance and usageThe audit-trail period of your tier (30, 90, 365 or 730 days, or as agreed on Enterprise), then deleted. The period is measured on read, so an upgrade lets you see what a smaller tier would have hidden
Uploaded and synced documents, and their passagesUntil you remove them or disconnect the source, or the account closes; passages are deleted with the document they belong to
Connection credentialsUntil you remove the connection or the account closes; deleted, not archived
Sign-in sessionEight hours from sign-in; the cookie expires and is not renewed silently
Server logs30 days, unless kept longer for a specific security investigation

When an account closes, the ability to ask stops at once and the remaining information is deleted at the end of the periods above. Backups are overwritten on a rolling cycle of not more than 35 days.

9. How we protect it

Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. The security page describes the architecture; the measures that matter most for personal information are:

  • every request is resolved to one company and one person before anything is read, and every query is scoped by that company, so no request can reach another tenant's data;
  • what a person may do and what they may see are two separate controls, set by an administrator and re-checked on every request;
  • connection credentials are encrypted at rest with a key held outside the database, and are never returned once saved;
  • all traffic is encrypted in transit; the session cookie is HTTP-only, secure and expires in eight hours; the sign-in token is verified against the directory's published keys, never merely read;
  • every connection is read-only by construction, so a compromise of the product could not be used to alter your systems;
  • operator access to a customer's tenant for support is granted in the deployment's configuration, not in the product, so no administrator inside the product can grant it to themselves;
  • the product host is excluded from search engines and answers no request without a session.

If something goes wrong. If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible, as section 22 of POPIA requires, and where we are the operator we will notify the responsible party immediately so that it can do so.

10. Cookies and similar technologies

This website sets no cookies and runs no analytics or advertising scripts. The fonts are loaded from Google, which sees the request (section 6). Nothing else leaves your browser.

The product at app.synapticintelligence.ai sets exactly the following:

Name and kindPurposeLasts
Session cookieKeeps you signed in after your directory has authenticated you. Strictly necessary; the product does not work without it.8 hours
Handshake cookieCarries the one-time state that protects the sign-in and connector-consent redirects from forgery.Minutes; deleted when the redirect completes
Browser session storageRemembers, for the current tab only, which company an operator is standing in and whether a tier preview is on.Until the tab is closed

None of these tracks you across sites, and none is used for advertising. Because they are all strictly necessary, no consent banner is shown; blocking them in your browser will prevent sign-in.

11. Your rights

Under POPIA you may, free of charge unless the Act allows a fee, and by writing to the Information Officer (section 2):

  • ask whether we hold personal information about you, and for a copy of it (section 23), together with the identity of everyone who has had access to it;
  • ask us to correct or delete information that is inaccurate, out of date, incomplete, misleading, or that we are not entitled to hold (section 24);
  • object to processing that rests on our legitimate interests (section 11(3)), and to any direct marketing (section 11(3)(b)), on reasonable grounds;
  • withdraw consent where consent is our basis (section 11(2)); this does not affect processing done before the withdrawal, and it may mean we cannot provide the service;
  • ask about automated decision-making (section 71), though we make none;
  • complain to the Information Regulator (section 12).

We will confirm receipt within five business days and answer within 30 days. If we need longer, we will say so and why, within that time. If we refuse a request, we will tell you why and how to complain. Where you are asking about information held in a customer's connected systems, we will pass the request to that customer as the responsible party and help them answer it.

People in a customer's company can see the questions they asked and the answers they received in the product; an administrator can remove documents and connections; and a company's administrator can end the account, which triggers the deletion in section 8.

12. Complaints and the Information Regulator

If you think we have handled your personal information wrongly, please tell the Information Officer first: we would rather fix it than be told about it later. You also have the right to lodge a complaint with the Information Regulator (South Africa) at any time:

The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: complaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za

13. Children

The service is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18, and a person under 18 may not sign up. If you believe a child has given us personal information, tell the Information Officer and we will delete it. A customer who connects a system containing children's information, such as a school's records, is the responsible party for it and must have the competent person's consent that section 35 of POPIA requires.

14. Changes to this policy

We will change this policy when the service, the law or our operators change. Each version carries its version number and effective date at the top. A change that adds an operator who receives your data, moves it to a new country, or uses it for a new purpose will be notified to your company's administrators by email at least 30 days before it takes effect, and you may cancel before then if you do not accept it. Other changes take effect when published here. The version in force is always the one at synapticintelligence.ai/privacy.

Want the security pack?

The sub-processor list, certification status and a data processing agreement are available under NDA on the demo call.