1. Introduction and Acceptance
1.1 Legal Agreement: These Terms of Use (“Terms”) constitute a legally binding agreement between you (“User”, “Customer”, or “you”) and Synapser Proprietary Limited (Registration No. 2016/102575/07) (“Synapser”, “we”, “us”, or “our”).
1.2 Acceptance: By accessing, browsing, integrating with, or utilizing any Synapser platform, API, SDK, or hosted service, you agree to be bound by these Terms. If you do not agree, you must immediately discontinue use.
2. Operational Platforms and Product Suite
2.1 Covered Services: These Terms govern all Synapser platforms, applications, and services, including:
- Identity & Authentication Services: Entry (legacy SDK and API verification modules), EntryIDP (hosted OpenID Connect identity provider, accessible via entryidp.com, idp.entryidp.com, and related subdomains), EntryMFA (entrymfa.com), and The Key Platform (thekeyplatform.co);
- Financial, Insurance & Utility Platforms: SecureUs, SecureUs FS, SecureUs Insure (secureus-fs.com, secureus.co.za, secureusfs.com, secureusinsure.co.za, secureusinsure.com), Gain for Me (gain4me.com), Project TIDE (project-tide.org), and Utility Africa (utilityafrica-cp.com); and
- Corporate & General Websites: synapser.com and all associated web applications, APIs, and documentation portals.
3. Key Definitions
- “Authorised Identity Attributes” means personal or identity attributes that an end-user authorizes Synapser to return to a Customer application in a signed token payload or API response.
- “Biometric Data” means personal data generated from technical processing of physical characteristics (specifically facial recognition data and mathematical vectors) used for unique identification.
- “Customer” means any business, entity, or organization that subscribes to, integrates with, or uses Synapser Services in connection with its platforms or operations.
- “Entry” means Synapser’s legacy identity verification and biometric authentication engine, supplied via embedded SDKs or direct API integrations.
- “EntryIDP” means Synapser’s upgraded, hosted OpenID Connect identity provider delivering biometric enrolment, liveness verification, and atomic authentication via browser redirects.
- “SaaS” means the Software-as-a-Service delivery model accessed remotely over secure networks without transferring software ownership.
4. Service Description and Technical Integration Standards
4.1 Delivery Model: All Synapser platforms are delivered remotely as hosted cloud services or client integration packages (SaaS) and are not supplied for on-premises deployment unless agreed under a separate writing.
4.2 Hosted EntryIDP Integration Standards:
- EntryIDP executes biometric enrolment, liveness verification, and template matching entirely within Synapser’s hosted environment. No biometric processing takes place within Customer applications.
- Customers integrating with EntryIDP must strictly adhere to modern OIDC and OAuth 2.0 specifications, including enforcing HTTPS across all registered redirect URIs and implementing Proof Key for Code Exchange (PKCE) where applicable.
- Synapser issues cryptographically signed JWT assertions containing verification statuses and authorized identity claims to the Customer’s redirect URI.
4.3 Entry SDK / API Integration Standards:
- Customers utilizing the legacy Entry SDK or verification APIs must maintain supported client library versions and enforce secure end-to-end TLS encryption for all API endpoint calls.
- Customers shall not store, cache, or attempt to extract raw biometric vector data returned or handled during SDK operations.
4.4 Security Boundary: Synapser is not liable for session vulnerabilities, cross-site scripting (XSS), token misuse, or credential compromises occurring within Customer infrastructure once verification results or token assertions are returned.
4.5 Account Security & Paid Services: You are responsible for maintaining the confidentiality of your account login credentials. Subscription fees, payment frequency, and commercial terms are set out in the applicable order form, pricing schedule, or written agreement with Synapser.
5. Service Availability and Modifications
5.1 Availability: Services are provided on an “as available” basis. Maintenance windows, security patches, and upgrades may occur periodically.
5.2 Legacy Product Lifecycle: Synapser reserves the right to deprecate, patch, or transition features within legacy platforms (such as the Entry SDK) in favour of upgraded architectures (such as EntryIDP). Customers will receive reasonable notice of sunset schedules.
6. Data Protection Roles and Responsibilities
6.1 Synapser as Controller / Responsible Party: Synapser acts as the independent Controller / Responsible Party for biometric processing, template storage, and atomic authentication within the Entry and EntryIDP systems. Synapser presents statutory privacy notices and obtains explicit consent.
6.2 Customer Responsibilities: The Customer acts as an independent Controller for its own platform and warrants that:
- It maintains a lawful basis for initiating verification requests;
- Information submitted to Synapser is accurate and lawful;
- It provides a non-biometric alternative within its own applications if a user declines biometric processing; and
- Downstream storage, handling, and lifecycle management of returned JWT tokens, claims, and policy data comply with applicable data protection laws.
7. User Eligibility and Representations
7.1 Capacity: Users warrant that they are 18 years of age or older (or possess authorized competent person consent where a Service lawfully permits minor use) and that information provided is truthful.
7.2 Third-Party Authority: Anyone submitting data on behalf of a third party warrants that they hold lawful authorization to do so.
8. Biometric Processing and Isolation
8.1 Direct Consent Capture: Synapser captures explicit consent directly on the hosted interface or SDK capture container prior to biometric processing.
8.2 Refusal: Users refusing consent may be unable to complete verification via Entry or EntryIDP and must utilize alternative mechanisms provided by the Customer application.
8.3 Customer Isolation: Customers receive only verification outcomes and authorized claims; Customers are never granted access to raw biometric templates or vector data.
9. Acceptable Use and Prohibited Conduct
9.1 System Integrity: Users and Customers shall not reverse-engineer, decompile, crawl, or inject malicious code into Synapser infrastructure, SDKs, or APIs.
9.2 Lawful Use: Platforms shall not be utilized for unauthorized surveillance, fraud, or violations of privacy laws. Synapser may suspend access immediately upon detecting security threats or violations.
10. Intellectual Property
10.1 Ownership: All intellectual property rights in the software, algorithms, documentation, SDKs, APIs, interfaces, and trademarks across all Synapser products belong exclusively to Synapser (Pty) Ltd or its licensors. No title or ownership transfers under these Terms.
10.2 Limited Content Licence & Linking: Subject to these Terms, you may view, download, and share publicly available website content for lawful, non-commercial informational purposes only, provided all copyright notices are retained. You may link to our homepage, but framing or linking to internal deep links without written consent is prohibited. Synapser is not responsible for external websites linked from our platforms.
11. Liability, Disclaimers, and Allocation of Risk
11.1 No General Warranty: Platforms and Services are provided “as available” without implied warranties of fitness for a specific purpose.
11.2 Technological Limitations: Biometric recognition and liveness detection are probabilistic technologies. Synapser does not warrant that every authentication attempt will be successful or error-free.
11.3 Consequential Damages Exclusion: To the fullest extent permitted by law, Synapser will not be liable under these Terms for any indirect, incidental, special, punitive, or consequential loss, including loss of profits, revenue, data, goodwill, or anticipated savings.
11.4 Limitation of Direct Liability:
- Subject to clauses 11.3, 11.4.2, and 11.4.3, Synapser’s total aggregate direct liability arising under these Terms shall be strictly limited to: (a) for paying Customers, the total amounts actually paid by the Customer for the specific Service giving rise to the claim during the three (3) months immediately preceding the event giving rise to liability; or (b) for non-paying users, evaluation access, or free trial accounts, a maximum aggregate amount of R1,000.00 (or USD equivalent).
- Nothing in these Terms excludes or limits liability for gross negligence, wilful misconduct, death, personal injury, or any other liability that cannot lawfully be excluded or limited under applicable law.
- Where a Customer has entered into a separate Master Services Agreement, Enterprise Licence, or Data Processing Agreement with Synapser, the liability ceilings and risk terms of that agreement expressly supersede this clause 11.4.
12. General Provisions
12.1 Governing Law: These Terms are governed exclusively by the laws of the Republic of South Africa.
12.2 Severability: If any provision is deemed unenforceable, the remaining provisions remain in full force.
12.3 Amendments: Synapser may update these Terms periodically by publishing the revised version with an updated effective date.