Legal
Privacy Policy
Who sees your personal information, why, where it goes, how long we keep it, and what you can do about it, under the Protection of Personal Information Act.
Effective date: 14 September 2026Version 1.0Governing law: South Africa
Plain language. This document is written to be read by the person it applies to, as section 22 of the Consumer Protection Act 68 of 2008 requires. Where a legal term is unavoidable it is explained where it first appears. It is governed by the law of the Republic of South Africa.
This policy explains what personal information we collect, why, who sees it, where it goes, how long we keep it, and what you can do about it. It is written to meet the Protection of Personal Information Act 4 of 2013 ("POPIA"). It covers this website, the product at app.synapticintelligence.ai, and our dealings with you as a prospective or current customer.
- Responsible party
- Information Officer
- When we are the responsible party and when we are an operator
- What we collect
- Why, and on what lawful basis
- Operators and third parties
- Transfers outside South Africa
- How long we keep it
- How we protect it
- Cookies and similar technologies
- Your rights
- Complaints and the Information Regulator
- Children
- Changes to this policy
1. Responsible party
The responsible party in the terms of POPIA is Synaptic Intelligence, registered in the Republic of South Africa, registration number [COMPANY REGISTRATION NUMBER].
Physical address: 81 Regent Road, Cape Town 8005, South Africa
Email: info@synapticintelligence.ai
Website: synapticintelligence.ai (this site) and app.synapticintelligence.ai (the product)
2. Information Officer
Our Information Officer, registered with the Information Regulator as section 55 of POPIA requires, is Gershon Koral. Any request, question or complaint about personal information should go to the Information Officer at info@synapticintelligence.ai, marked "Information Officer", or by post to the address above. Our PAIA manual (section 51 of the Promotion of Access to Information Act 2 of 2000) is available on request from the same address.
3. When we are the responsible party, and when we are an operator
POPIA distinguishes the responsible party, who decides why and how personal information is processed, from the operator, who processes it on the responsible party's behalf. We are both, for different information:
- We are the responsible party for the personal information of the people we deal with directly: visitors to this website, people who use the contact form, the people who sign up and administer a customer's account, and the people who sign in to use the product. Sections 4 to 14 apply in full.
- We are an operator for personal information contained in the systems and documents a customer connects: an HR directory, a payroll ledger, a CRM, a support desk, a mailbox, a shared drive. The customer is the responsible party for that information, decides what to connect and who in their company may see it, and is responsible for having a lawful basis to process it. We process it only as the product does, on the customer's instruction, under section 20 and 21 of POPIA and the Terms of Service. If you are a data subject whose information is held in a customer's systems, your request should go to that customer; we will help them answer it.
4. What we collect
| Where | Personal information | How it reaches us |
|---|---|---|
| This website | Nothing that identifies you. Our host records the IP address and requested URL in ordinary server logs. We run no analytics and set no cookies here (section 10). | Your browser |
| Contact form | Your name, email address, and optionally your company and the systems you run, together with the message you write and which of our enquiry types you chose. | You type it |
| Sign-up | Your name, work email address, company name, company website, the kind of business it is, and the tier you chose. Your card details are entered on Paddle's hosted checkout and are never sent to us; we receive a customer reference and the last state of the subscription. | You type it; Paddle confirms it |
| Signing in to the product | Your name, email address and directory identifiers from the Microsoft Entra ID token your organisation's directory issues, and the business title and access role your administrator assigns you. | Your organisation's directory; your administrator |
| Using the product | The questions you ask, the answers produced, the records each answer cited, when you asked and what it cost in credits; documents you upload or sync; the connections you configure (the credential itself is stored encrypted and is never shown again). Answers can contain personal information from your connected systems; for that information we are an operator (section 3). | Your use of the product |
| Support and billing | Emails between us, invoices, and the record of what tier your company is on and since when. | Correspondence; the payment processor |
We do not collect special personal information (section 26 of POPIA) about the people we deal with directly, and we do not ask for it in the product. A customer who connects a system that contains special personal information, such as an HR directory holding health or union data, is the responsible party for it.
5. Why, and on what lawful basis
Section 11 of POPIA allows processing only on one of a fixed list of grounds. Ours are:
| Purpose | Information | Lawful basis (POPIA s11(1)) |
|---|---|---|
| Answering an enquiry or demo request | Contact form | Your consent, given when you send it (a); and our legitimate interest in replying (f) |
| Creating and administering your company's account, taking payment, sending invoices and notices | Sign-up, billing | Necessary to conclude and perform the contract with you (b); legal obligation for tax and accounting records (c) |
| Signing you in and deciding what you may do and see | Sign-in, roles and titles | Performing the contract (b); our and the customer's legitimate interest in keeping every request scoped to the right person and company (f) |
| Producing answers, verifying their provenance, keeping them auditable | Questions, answers, cited records, documents | Performing the contract (b); as operator for the customer's information |
| Metering credits and preventing use past the allowance | Usage records | Performing the contract (b) |
| Keeping the service secure, investigating misuse, and defending claims | Server logs, usage records | Legitimate interest (f); legal obligation (c) |
| Telling you about changes to the service, prices or these policies | Administrator email addresses | Performing the contract (b) |
We do not send marketing email. If we ever do, it will be to people who opted in, with an unsubscribe in every message, as section 69 of POPIA requires. We do not sell personal information to anyone.
No automated decisions about you. The product makes no decision with legal or similarly significant consequences for a person by automated means (section 71). It answers questions; people decide what to do with the answers.
6. Operators and third parties
The following companies process personal information on our behalf. Each receives only what its column says, under a written agreement that binds it to confidentiality and to section 21 of POPIA or an equivalent standard. Our security page describes the two that read your data to produce answers; this is the full list, including hosting and payments.
| Operator | What it does | What it receives | Where |
|---|---|---|---|
| Anthropic, PBC | Provides the language models that route each question, read the records it reaches and compose the answer | Your questions; the records and document passages a question reaches; the company profile and brief; prior turns of the conversation. Not used to train models under our agreement. | United States |
| Voyage AI | Produces the embeddings that let uploaded and synced documents be searched by meaning, when a deployment has it configured | The text of documents you upload or sync, in passages, and the search phrase a specialist uses. It does not receive connector data, ledger rows, HR records, questions or answers. | United States |
| Microsoft Corporation (Azure) | Hosts the product, its database and document storage; provides Entra ID sign-in; sends the contact form's email through Azure Communication Services | Everything the product stores, encrypted at rest; the sign-in token; the contact form's contents | South Africa (Microsoft's South African Azure region) |
| Paddle.com Market Ltd (UK) / Paddle.com Inc. (US) | Takes card payments as merchant of record and runs the monthly subscription: it sells you the subscription on our behalf, calculates and remits VAT or sales tax, and issues your receipt and invoice. For the card transaction Paddle is a responsible party in its own right, under its own privacy policy, as well as our operator | Your name, email address, company reference and billing country and address; your card details, entered on Paddle's hosted checkout and never seen by us | United Kingdom and United States |
| Google LLC (Fonts) | Serves the typefaces this website uses | Your IP address and browser details, in the request for the font files. No cookie is set. | Global |
Systems you connect. When you connect a vendor's system, we read from that vendor using the credential you granted; the vendor sees the requests we make in your name. The vendor is not our operator: it is a system you already use, under your own agreement with it.
Disclosures we may be required to make. We will disclose personal information where a law, a court order or a regulator with authority requires it. We will tell you first unless the law forbids us to, and we will disclose no more than is required.
Change of ownership. If our business is sold or merged, personal information may transfer to the successor, who will be bound by this policy. We will tell you before that happens.
7. Transfers outside South Africa
The product is hosted in South Africa. The application, its database and every document you upload or sync are held in Microsoft's South African Azure region, and sign-in and the contact form's email run through the same Microsoft tenancy. Personal information leaves the country only for the operators below, and section 72 of POPIA allows each transfer on the ground stated:
| Recipient | What leaves | Country | POPIA s72 ground |
|---|---|---|---|
| Anthropic | Your questions and the records and passages each one reaches, for the duration of the model call | United States | s72(1)(a): bound by written terms giving substantially POPIA's protections, including no training and no onward transfer; and s72(1)(c): necessary to perform the contract, since an answer cannot be composed without the model reading the question |
| Voyage AI | Document passages and search phrases, for the duration of the embedding call, when a deployment has it configured | United States | s72(1)(a) and s72(1)(c), as above |
| Paddle | Your name, email address, company reference and billing country and address, if you pay by card | United Kingdom and United States | s72(1)(c): necessary to perform the contract you chose to pay by card, which is concluded with Paddle as merchant of record; s72(1)(a): Paddle's terms and the laws it is subject to, including UK data protection law |
| Google (Fonts) | Your IP address, in the request for this website's typefaces | Wherever Google's nearest edge server is | s72(1)(a): Google's published terms; the request carries no cookie and identifies no account |
Where none of those grounds applies to a particular transfer, we rely on your consent under s72(1)(b), which you give by signing up after reading this policy and may withdraw by cancelling. If the model and embedding calls leaving the country is a constraint for you, say so on the demo call and we will tell you plainly what can and cannot be arranged; an Enterprise contract can add a data processing agreement that records the position.
8. How long we keep it
Section 14 of POPIA says we may keep personal information no longer than the purpose requires unless a law or a contract requires longer. Our periods:
| Information | Kept for |
|---|---|
| Contact form messages | Until the enquiry is closed and for 12 months after, then deleted |
| Sign-up records that did not become an account | 90 days, then deleted |
| Account, billing and invoice records | The life of the account and five years after it closes, as tax and company law require |
| Questions, answers, provenance and usage | The audit-trail period of your tier (30, 90, 365 or 730 days, or as agreed on Enterprise), then deleted. The period is measured on read, so an upgrade lets you see what a smaller tier would have hidden |
| Uploaded and synced documents, and their passages | Until you remove them or disconnect the source, or the account closes; passages are deleted with the document they belong to |
| Connection credentials | Until you remove the connection or the account closes; deleted, not archived |
| Sign-in session | Eight hours from sign-in; the cookie expires and is not renewed silently |
| Server logs | 30 days, unless kept longer for a specific security investigation |
When an account closes, the ability to ask stops at once and the remaining information is deleted at the end of the periods above. Backups are overwritten on a rolling cycle of not more than 35 days.
9. How we protect it
Section 19 of POPIA requires appropriate, reasonable technical and organisational measures. The security page describes the architecture; the measures that matter most for personal information are:
- every request is resolved to one company and one person before anything is read, and every query is scoped by that company, so no request can reach another tenant's data;
- what a person may do and what they may see are two separate controls, set by an administrator and re-checked on every request;
- connection credentials are encrypted at rest with a key held outside the database, and are never returned once saved;
- all traffic is encrypted in transit; the session cookie is HTTP-only, secure and expires in eight hours; the sign-in token is verified against the directory's published keys, never merely read;
- every connection is read-only by construction, so a compromise of the product could not be used to alter your systems;
- operator access to a customer's tenant for support is granted in the deployment's configuration, not in the product, so no administrator inside the product can grant it to themselves;
- the product host is excluded from search engines and answers no request without a session.
If something goes wrong. If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible, as section 22 of POPIA requires, and where we are the operator we will notify the responsible party immediately so that it can do so.
10. Cookies and similar technologies
This website sets no cookies and runs no analytics or advertising scripts. The fonts are loaded from Google, which sees the request (section 6). Nothing else leaves your browser.
The product at app.synapticintelligence.ai sets exactly the following:
| Name and kind | Purpose | Lasts |
|---|---|---|
| Session cookie | Keeps you signed in after your directory has authenticated you. Strictly necessary; the product does not work without it. | 8 hours |
| Handshake cookie | Carries the one-time state that protects the sign-in and connector-consent redirects from forgery. | Minutes; deleted when the redirect completes |
| Browser session storage | Remembers, for the current tab only, which company an operator is standing in and whether a tier preview is on. | Until the tab is closed |
None of these tracks you across sites, and none is used for advertising. Because they are all strictly necessary, no consent banner is shown; blocking them in your browser will prevent sign-in.
11. Your rights
Under POPIA you may, free of charge unless the Act allows a fee, and by writing to the Information Officer (section 2):
- ask whether we hold personal information about you, and for a copy of it (section 23), together with the identity of everyone who has had access to it;
- ask us to correct or delete information that is inaccurate, out of date, incomplete, misleading, or that we are not entitled to hold (section 24);
- object to processing that rests on our legitimate interests (section 11(3)), and to any direct marketing (section 11(3)(b)), on reasonable grounds;
- withdraw consent where consent is our basis (section 11(2)); this does not affect processing done before the withdrawal, and it may mean we cannot provide the service;
- ask about automated decision-making (section 71), though we make none;
- complain to the Information Regulator (section 12).
We will confirm receipt within five business days and answer within 30 days. If we need longer, we will say so and why, within that time. If we refuse a request, we will tell you why and how to complain. Where you are asking about information held in a customer's connected systems, we will pass the request to that customer as the responsible party and help them answer it.
People in a customer's company can see the questions they asked and the answers they received in the product; an administrator can remove documents and connections; and a company's administrator can end the account, which triggers the deletion in section 8.
12. Complaints and the Information Regulator
If you think we have handled your personal information wrongly, please tell the Information Officer first: we would rather fix it than be told about it later. You also have the right to lodge a complaint with the Information Regulator (South Africa) at any time:
The Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Complaints: complaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
Website: inforegulator.org.za
13. Children
The service is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18, and a person under 18 may not sign up. If you believe a child has given us personal information, tell the Information Officer and we will delete it. A customer who connects a system containing children's information, such as a school's records, is the responsible party for it and must have the competent person's consent that section 35 of POPIA requires.
14. Changes to this policy
We will change this policy when the service, the law or our operators change. Each version carries its version number and effective date at the top. A change that adds an operator who receives your data, moves it to a new country, or uses it for a new purpose will be notified to your company's administrators by email at least 30 days before it takes effect, and you may cancel before then if you do not accept it. Other changes take effect when published here. The version in force is always the one at synapticintelligence.ai/privacy.