Synapser (Pty) Ltd Privacy Policy

Effective Date: 18 August 2026

1. Introduction and Scope

1.1 Overview: Welcome to Synapser (Pty) Ltd (Reg. No. 2016/102575/07) (“Synapser”, “we”, “us”, or “our”). Protecting personal information is a primary operational objective across all our websites, software development kits (SDKs), application programming interfaces (APIs), mobile applications, and cloud-hosted platforms.

1.2 Applicability: This Privacy Policy applies to:

1.3 Statutory Compliance: Synapser processes personal information in strict accordance with applicable data protection laws, including the Protection of Personal Information Act 4 of 2013 (“POPIA”), the EU/UK General Data Protection Regulation (“GDPR”), and United States state biometric privacy statutes, including the Illinois Biometric Information Privacy Act (“BIPA”).

2. Definitions and Classification of Information

2.1 Personal Information: Information relating to an identifiable, living natural person (and, where applicable under POPIA, an identifiable juristic person), including full names, contact details, national identity numbers, passport scans, financial records, and employment metadata. Anonymous or de-identified data is excluded.

2.2 Biometric Data: Special category personal information resulting from specific technical processing of physical, physiological, or behavioural characteristics allowing unique identification. For Synapser products (including Entry and EntryIDP), this encompasses facial images, mathematical biometric templates, vector coordinates, and liveness telemetry.

2.3 Third-Party Submissions: Where personal information is submitted on behalf of another individual (such as a beneficiary, dependent, or employee), the submitting party warrants that lawful consent or authorization has been obtained.

2.4 Prohibition on Monetisation: Synapser does not sell, lease, trade, or commercially profit from raw biometric data, biometric vectors, or facial templates. Any release of user attributes to third parties is executed strictly upon explicit user consent.

3. Product Architecture and Processing Models

3.1 EntryIDP (Hosted OIDC Architecture)

EntryIDP functions as a hosted OpenID Connect (OIDC) identity provider utilizing facial biometrics for atomic identity verification and authentication.

3.2 Entry (Legacy SDK / API Architecture)

Where Customers utilize the legacy embedded Entry SDK or direct verification APIs:

3.3 Enterprise SaaS & Digital Platforms

For SecureUs, Gain for Me, The Key Platform, Project TIDE, and Utility Africa, Synapser processes operational and identity data as required to deliver account administration, policy management, utility tracking, and platform services.

4. Collection of Personal Information

4.1 Direct Submission: Information submitted when registering an account, ordering services, requesting support, or submitting an enquiry.

4.2 Automated Metadata & State Parameters: Technical data including IP addresses, device identifiers, browser telemetry, and essential session or anti-CSRF cookies utilized during hosted redirect handoffs.

4.3 Biometric Capture Sessions: Live facial captures and identity documentation submitted directly by end-users during Entry or EntryIDP verification workflows.

5. Purpose of Processing and Lawful Bases

5.1 Lawful Bases: Processing is conducted under one or more of the following statutory bases:

6. Information Sharing and Disclosure

6.1 Verification Results: Customer applications integrating with Entry or EntryIDP receive only the verification outcome and authorized identity attributes via signed assertions or secure API responses.

6.2 Infrastructure Subprocessors: Personal data is processed in secure cloud infrastructure (specifically Amazon Web Services) under rigorous Data Processing Agreements and security controls.

6.3 Financial and Regulatory Partners: Data may be shared with underwriters, financial institutions, or statutory bodies strictly where necessary to execute requested transactions (e.g., SecureUs insurance administration) or comply with legal process.

7. Biometric Data Retention and Destruction Schedule

7.1 Active Templates: Active facial biometric templates are retained solely for the duration of the active user relationship or enrolment period.

7.2 Encrypted Backups: Raw biometric artifacts captured during enrolment are archived in an encrypted state within hosted AWS infrastructure solely for disaster recovery, system restoration, and audit integrity, inaccessible via standard operational interfaces.

7.3 Deletion Thresholds: Biometric identifiers and templates across Entry and EntryIDP are permanently destroyed and deleted from Synapser’s active and backup environments upon the earliest of:

8. Data Security and International Transfers

8.1 Technical and Organisational Measures: Synapser enforces industry-standard technical safeguards, including end-to-end encryption in transit (TLS 1.2+) and at rest (AES-256), strict logical access partitioning, and continuous vulnerability monitoring.

8.2 Cross-Border Transfers: Where personal data is transferred across borders, Synapser enforces Standard Contractual Clauses (SCCs) or ensures compliance with POPIA Section 72 and GDPR Chapter V.

9. Data Subject Rights and Contact Details

9.1 Statutory Rights: Individuals possess the right to access, rectify, revoke consent for, or request the erasure of their personal information.

9.2 Contact: To exercise these rights, contact the Synapser Information Officer at info@synapser.com.