1. Introduction and Scope
1.1 Overview: Welcome to Synapser (Pty) Ltd (Reg. No. 2016/102575/07) (“Synapser”, “we”, “us”, or “our”). Protecting personal information is a primary operational objective across all our websites, software development kits (SDKs), application programming interfaces (APIs), mobile applications, and cloud-hosted platforms.
1.2 Applicability: This Privacy Policy applies to:
- Visitors to Synapser websites and portals;
- Individuals who interact with any Synapser platform, including Entry, EntryIDP, EntryMFA, The Key Platform, SecureUs, Gain for Me, Project TIDE, and Utility Africa;
- Customers and developers integrating with our legacy Entry SDKs, client APIs, or hosted EntryIDP identity services; and
- End-users whose identity, document, or biometric data is processed through any Synapser product or service.
1.3 Statutory Compliance: Synapser processes personal information in strict accordance with applicable data protection laws, including the Protection of Personal Information Act 4 of 2013 (“POPIA”), the EU/UK General Data Protection Regulation (“GDPR”), and United States state biometric privacy statutes, including the Illinois Biometric Information Privacy Act (“BIPA”).
2. Definitions and Classification of Information
2.1 Personal Information: Information relating to an identifiable, living natural person (and, where applicable under POPIA, an identifiable juristic person), including full names, contact details, national identity numbers, passport scans, financial records, and employment metadata. Anonymous or de-identified data is excluded.
2.2 Biometric Data: Special category personal information resulting from specific technical processing of physical, physiological, or behavioural characteristics allowing unique identification. For Synapser products (including Entry and EntryIDP), this encompasses facial images, mathematical biometric templates, vector coordinates, and liveness telemetry.
2.3 Third-Party Submissions: Where personal information is submitted on behalf of another individual (such as a beneficiary, dependent, or employee), the submitting party warrants that lawful consent or authorization has been obtained.
2.4 Prohibition on Monetisation: Synapser does not sell, lease, trade, or commercially profit from raw biometric data, biometric vectors, or facial templates. Any release of user attributes to third parties is executed strictly upon explicit user consent.
3. Product Architecture and Processing Models
3.1 EntryIDP (Hosted OIDC Architecture)
EntryIDP functions as a hosted OpenID Connect (OIDC) identity provider utilizing facial biometrics for atomic identity verification and authentication.
- Synapser controls the hosted infrastructure and acts as the Responsible Party / Data Controller for biometric enrolment, template generation, and authentication within the hosted EntryIDP container.
- Upon successful verification, EntryIDP issues cryptographically signed JSON Web Tokens (JWTs) containing authentication assertions and authorized user claims directly to the Customer redirect URI.
- Customer applications receive claims only and are never granted access to underlying facial templates, biometric vectors, or raw enrolment artifacts.
3.2 Entry (Legacy SDK / API Architecture)
Where Customers utilize the legacy embedded Entry SDK or direct verification APIs:
- Biometric capture and transmission are governed by the Customer’s application interface;
- Synapser processes verification requests strictly in accordance with configured API parameters and applicable Data Processing Agreements; and
- Raw biometric templates remain encrypted and isolated from client application storage.
3.3 Enterprise SaaS & Digital Platforms
For SecureUs, Gain for Me, The Key Platform, Project TIDE, and Utility Africa, Synapser processes operational and identity data as required to deliver account administration, policy management, utility tracking, and platform services.
4. Collection of Personal Information
4.1 Direct Submission: Information submitted when registering an account, ordering services, requesting support, or submitting an enquiry.
4.2 Automated Metadata & State Parameters: Technical data including IP addresses, device identifiers, browser telemetry, and essential session or anti-CSRF cookies utilized during hosted redirect handoffs.
4.3 Biometric Capture Sessions: Live facial captures and identity documentation submitted directly by end-users during Entry or EntryIDP verification workflows.
5. Purpose of Processing and Lawful Bases
5.1 Lawful Bases: Processing is conducted under one or more of the following statutory bases:
- Explicit Consent (GDPR Art. 9, POPIA s 27/32, BIPA): Freely given, specific, and informed consent captured prior to biometric processing. Where an end-user declines biometric verification, non-biometric alternative flows must be provided by the initiating Customer within its own application;
- Contractual Necessity: Delivering core features across Synapser products, including authentication, policy administration, and platform access;
- Legal Obligation: Satisfying statutory identity verification, audit integrity, Know-Your-Customer (KYC), and regulatory reporting requirements; and
- Legitimate Interests: Detecting fraud, preventing account takeover, and maintaining system integrity. Where we send promotional updates or service communications, you may opt out of receiving non-transactional marketing at any time via the unsubscribe mechanism or by contacting info@synapser.com.
6. Information Sharing and Disclosure
6.1 Verification Results: Customer applications integrating with Entry or EntryIDP receive only the verification outcome and authorized identity attributes via signed assertions or secure API responses.
6.2 Infrastructure Subprocessors: Personal data is processed in secure cloud infrastructure (specifically Amazon Web Services) under rigorous Data Processing Agreements and security controls.
6.3 Financial and Regulatory Partners: Data may be shared with underwriters, financial institutions, or statutory bodies strictly where necessary to execute requested transactions (e.g., SecureUs insurance administration) or comply with legal process.
7. Biometric Data Retention and Destruction Schedule
7.1 Active Templates: Active facial biometric templates are retained solely for the duration of the active user relationship or enrolment period.
7.2 Encrypted Backups: Raw biometric artifacts captured during enrolment are archived in an encrypted state within hosted AWS infrastructure solely for disaster recovery, system restoration, and audit integrity, inaccessible via standard operational interfaces.
7.3 Deletion Thresholds: Biometric identifiers and templates across Entry and EntryIDP are permanently destroyed and deleted from Synapser’s active and backup environments upon the earliest of:
- The formal withdrawal of consent or deletion request by the data subject;
- The termination or expiration of the Customer subscription linked to the identity profile; or
- Within three (3) years of the individual’s last active interaction or authentication event with Synapser’s identity systems.
8. Data Security and International Transfers
8.1 Technical and Organisational Measures: Synapser enforces industry-standard technical safeguards, including end-to-end encryption in transit (TLS 1.2+) and at rest (AES-256), strict logical access partitioning, and continuous vulnerability monitoring.
8.2 Cross-Border Transfers: Where personal data is transferred across borders, Synapser enforces Standard Contractual Clauses (SCCs) or ensures compliance with POPIA Section 72 and GDPR Chapter V.
9. Data Subject Rights and Contact Details
9.1 Statutory Rights: Individuals possess the right to access, rectify, revoke consent for, or request the erasure of their personal information.
9.2 Contact: To exercise these rights, contact the Synapser Information Officer at info@synapser.com.